Analysis

Category Package Started Completed Duration Options Log(s) MalScore
FILE pdf 2025-12-08 13:59:58 2025-12-08 14:03:23 205 seconds Show Options Show Analysis Log 6.5
vnc_port=5901
2025-12-06 18:31:41,785 [root] INFO: Date set to: 20251208T05:51:59, timeout set to: 180
2025-12-06 18:31:41,785 [root] DEBUG: Starting analyzer from: C:\tmpw7hn3wdo
2025-12-06 18:31:41,785 [root] DEBUG: Storing results at: C:\HNxZeWN
2025-12-06 18:31:41,785 [root] DEBUG: Pipe server name: \\.\PIPE\BsJripN
2025-12-06 18:31:41,785 [root] DEBUG: Python path: C:\Python38
2025-12-06 18:31:41,785 [root] INFO: analysis running as a normal user
2025-12-06 18:31:41,785 [root] INFO: analysis package specified: "pdf"
2025-12-06 18:31:41,785 [root] DEBUG: importing analysis package module: "modules.packages.pdf"...
2025-12-06 18:31:41,785 [root] DEBUG: imported analysis package "pdf"
2025-12-06 18:31:41,785 [root] DEBUG: initializing analysis package "pdf"...
2025-12-06 18:31:41,785 [lib.common.common] INFO: wrapping
2025-12-06 18:31:41,785 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:41,785 [root] DEBUG: New location of moved file: C:\Users\user\AppData\Local\Temp\87455c255848e08c1e95.pdf
2025-12-06 18:31:41,785 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a DLL option
2025-12-06 18:31:41,785 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a DLL_64 option
2025-12-06 18:31:41,785 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a loader option
2025-12-06 18:31:41,785 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a loader_64 option
2025-12-06 18:31:41,816 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-12-06 18:31:41,816 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain"
2025-12-06 18:31:41,816 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-12-06 18:31:41,816 [root] DEBUG: Imported auxiliary module "modules.auxiliary.during_script"
2025-12-06 18:31:41,816 [root] DEBUG: Imported auxiliary module "modules.auxiliary.end_noisy_tasks"
2025-12-06 18:31:41,832 [root] DEBUG: Imported auxiliary module "modules.auxiliary.evtx"
2025-12-06 18:31:41,832 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-12-06 18:31:41,832 [root] DEBUG: Imported auxiliary module "modules.auxiliary.pre_script"
2025-12-06 18:31:41,832 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-12-06 18:31:41,847 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2025-12-06 18:31:41,847 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2025-12-06 18:31:41,863 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-12-06 18:31:41,863 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon"
2025-12-06 18:31:41,863 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-12-06 18:31:41,863 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage"
2025-12-06 18:31:41,863 [root] DEBUG: Initialized auxiliary module "Browser"
2025-12-06 18:31:41,863 [root] DEBUG: attempting to configure 'Browser' from data
2025-12-06 18:31:41,863 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-12-06 18:31:41,863 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-12-06 18:31:41,863 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-12-06 18:31:41,863 [root] DEBUG: Initialized auxiliary module "Curtain"
2025-12-06 18:31:41,863 [root] DEBUG: attempting to configure 'Curtain' from data
2025-12-06 18:31:41,863 [root] DEBUG: module Curtain does not support data configuration, ignoring
2025-12-06 18:31:41,863 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.curtain"...
2025-12-06 18:31:41,863 [root] DEBUG: Started auxiliary module modules.auxiliary.curtain
2025-12-06 18:31:41,863 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-12-06 18:31:41,863 [root] DEBUG: attempting to configure 'Disguise' from data
2025-12-06 18:31:41,863 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-12-06 18:31:41,863 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-12-06 18:31:41,863 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.disguise: [WinError 5] Access is denied
2025-12-06 18:31:41,863 [root] DEBUG: Initialized auxiliary module "End_noisy_tasks"
2025-12-06 18:31:41,863 [root] DEBUG: attempting to configure 'End_noisy_tasks' from data
2025-12-06 18:31:41,863 [root] DEBUG: module End_noisy_tasks does not support data configuration, ignoring
2025-12-06 18:31:41,863 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.end_noisy_tasks"...
2025-12-06 18:31:41,863 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wuauclt.exe
2025-12-06 18:31:41,863 [root] DEBUG: Started auxiliary module modules.auxiliary.end_noisy_tasks
2025-12-06 18:31:41,863 [root] DEBUG: Initialized auxiliary module "Evtx"
2025-12-06 18:31:41,863 [root] DEBUG: attempting to configure 'Evtx' from data
2025-12-06 18:31:41,863 [root] DEBUG: module Evtx does not support data configuration, ignoring
2025-12-06 18:31:41,863 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.evtx"...
2025-12-06 18:31:41,863 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security State Change" /success:enable /failure:enable
2025-12-06 18:31:41,863 [root] DEBUG: Started auxiliary module modules.auxiliary.evtx
2025-12-06 18:31:41,879 [root] DEBUG: Initialized auxiliary module "Human"
2025-12-06 18:31:41,879 [root] DEBUG: attempting to configure 'Human' from data
2025-12-06 18:31:41,879 [root] DEBUG: module Human does not support data configuration, ignoring
2025-12-06 18:31:41,879 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-12-06 18:31:41,879 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-12-06 18:31:41,879 [root] DEBUG: Initialized auxiliary module "Pre_script"
2025-12-06 18:31:41,879 [root] DEBUG: attempting to configure 'Pre_script' from data
2025-12-06 18:31:41,879 [root] DEBUG: module Pre_script does not support data configuration, ignoring
2025-12-06 18:31:41,879 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.pre_script"...
2025-12-06 18:31:41,879 [root] DEBUG: Started auxiliary module modules.auxiliary.pre_script
2025-12-06 18:31:41,879 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-12-06 18:31:41,879 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-12-06 18:31:41,879 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-12-06 18:31:41,879 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-12-06 18:31:41,879 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-12-06 18:31:41,879 [root] DEBUG: Initialized auxiliary module "Sysmon"
2025-12-06 18:31:41,879 [root] DEBUG: attempting to configure 'Sysmon' from data
2025-12-06 18:31:41,879 [root] DEBUG: module Sysmon does not support data configuration, ignoring
2025-12-06 18:31:41,879 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.sysmon"...
2025-12-06 18:31:41,957 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security System Extension" /success:enable /failure:enable
2025-12-06 18:31:41,988 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wusa.exe
2025-12-06 18:31:42,004 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.sysmon: In order to use the Sysmon functionality, it is required to have the SMaster(64|32).exe file and sysmonconfig-export.xml file in the bin path. Note that the SMaster(64|32).exe files are just the standard Sysmon binaries renamed to avoid anti-analysis detection techniques.
2025-12-06 18:31:42,004 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-12-06 18:31:42,004 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-12-06 18:31:42,004 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-12-06 18:31:42,004 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-12-06 18:31:42,004 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 668
2025-12-06 18:31:42,004 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,004 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,004 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,004 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,004 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,004 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,004 [lib.api.process] DEBUG: Failed getting exit code for <Process 668 ???>
2025-12-06 18:31:42,004 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,004 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,004 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,004 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,004 [lib.api.process] WARNING: the <Process 668 ???> is not alive, injection aborted
2025-12-06 18:31:42,004 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2025-12-06 18:31:42,004 [root] DEBUG: Initialized auxiliary module "Usage"
2025-12-06 18:31:42,004 [root] DEBUG: attempting to configure 'Usage' from data
2025-12-06 18:31:42,004 [root] DEBUG: module Usage does not support data configuration, ignoring
2025-12-06 18:31:42,004 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.usage"...
2025-12-06 18:31:42,004 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"System Integrity" /success:enable /failure:enable
2025-12-06 18:31:42,004 [root] DEBUG: Started auxiliary module modules.auxiliary.usage
2025-12-06 18:31:42,004 [root] DEBUG: Initialized auxiliary module "During_script"
2025-12-06 18:31:42,004 [root] DEBUG: attempting to configure 'During_script' from data
2025-12-06 18:31:42,004 [root] DEBUG: module During_script does not support data configuration, ignoring
2025-12-06 18:31:42,004 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.during_script"...
2025-12-06 18:31:42,004 [root] DEBUG: Started auxiliary module modules.auxiliary.during_script
2025-12-06 18:31:42,051 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Driver" /success:disable /failure:disable
2025-12-06 18:31:42,051 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM WindowsUpdate.exe
2025-12-06 18:31:42,098 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other System Events" /success:disable /failure:enable
2025-12-06 18:31:42,129 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM GoogleUpdate.exe
2025-12-06 18:31:42,144 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logon" /success:enable /failure:enable
2025-12-06 18:31:42,176 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logoff" /success:enable /failure:enable
2025-12-06 18:31:42,191 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM MicrosoftEdgeUpdate.exe
2025-12-06 18:31:42,207 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Account Lockout" /success:enable /failure:enable
2025-12-06 18:31:42,238 [root] INFO: Restarting WMI Service
2025-12-06 18:31:42,253 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Main Mode" /success:disable /failure:disable
2025-12-06 18:31:42,285 [root] DEBUG: package modules.packages.pdf does not support configure, ignoring
2025-12-06 18:31:42,285 [root] WARNING: configuration error for package modules.packages.pdf: error importing data.packages.pdf: No module named 'data.packages'
2025-12-06 18:31:42,285 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Quick Mode" /success:disable /failure:disable
2025-12-06 18:31:42,316 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DisableWindowsUpdateAccess /t REG_DWORD /d 1 /f
2025-12-06 18:31:42,347 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Extended Mode" /success:disable /failure:disable
2025-12-06 18:31:42,379 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:42,410 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,410 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" with arguments ""C:\Users\user\AppData\Local\Temp\87455c255848e08c1e95.pdf"" with pid 4176
2025-12-06 18:31:42,410 [lib.api.process] INFO: Monitor config for <Process 4176 Acrobat.exe>: C:\tmpw7hn3wdo\dll\4176.ini
2025-12-06 18:31:42,410 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Logon/Logoff Events" /success:enable /failure:enable
2025-12-06 18:31:42,410 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:42,410 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:42,441 [root] DEBUG: Loader: Injecting process 4176 (thread 4188) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:42,441 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:31:42,441 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:42,441 [lib.api.process] INFO: Injected into 64-bit <Process 4176 Acrobat.exe>
2025-12-06 18:31:42,457 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
2025-12-06 18:31:42,457 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v EnableICMPRedirect /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,503 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Special Logon" /success:enable /failure:enable
2025-12-06 18:31:42,535 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File System" /success:enable /failure:enable
2025-12-06 18:31:42,582 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Registry" /success:enable /failure:enable
2025-12-06 18:31:42,613 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kernel Object" /success:enable /failure:enable
2025-12-06 18:31:42,629 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"SAM" /success:disable /failure:disable
2025-12-06 18:31:42,660 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Certification Services" /success:enable /failure:enable
2025-12-06 18:31:42,691 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Handle Manipulation" /success:disable /failure:disable
2025-12-06 18:31:42,722 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable
2025-12-06 18:31:42,754 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File Share" /success:enable /failure:enable
2025-12-06 18:31:42,785 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable
2025-12-06 18:31:42,816 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable
2025-12-06 18:31:42,847 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Object Access Events" /success:disable /failure:disable
2025-12-06 18:31:42,863 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:42,894 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Non Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:42,926 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Privilege Use Events" /success:disable /failure:disable
2025-12-06 18:31:42,957 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"RPC Events" /success:enable /failure:enable
2025-12-06 18:31:42,972 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Audit Policy Change" /success:enable /failure:enable
2025-12-06 18:31:43,004 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Authentication Policy Change" /success:enable /failure:enable
2025-12-06 18:31:43,035 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"MPSSVC Rule-Level Policy Change" /success:disable /failure:disable
2025-12-06 18:31:43,066 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Policy Change" /success:disable /failure:disable
2025-12-06 18:31:43,098 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Policy Change Events" /success:disable /failure:enable
2025-12-06 18:31:43,113 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable
2025-12-06 18:31:43,144 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Computer Account Management" /success:enable /failure:enable
2025-12-06 18:31:43,176 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,207 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,238 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,254 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Management Events" /success:enable /failure:enable
2025-12-06 18:31:43,285 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
2025-12-06 18:31:43,316 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
2025-12-06 18:31:43,348 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Replication" /success:disable /failure:enable
2025-12-06 18:31:43,379 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Detailed Directory Service Replication" /success:disable /failure:disable
2025-12-06 18:31:43,410 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable
2025-12-06 18:31:43,441 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Service Ticket Operations" /success:enable /failure:enable
2025-12-06 18:31:43,473 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Logon Events" /success:enable /failure:enable
2025-12-06 18:31:43,504 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Authentication Service" /success:enable /failure:enable
2025-12-06 18:31:43,519 [modules.auxiliary.evtx] DEBUG: Wiping Application
2025-12-06 18:31:43,551 [modules.auxiliary.evtx] DEBUG: Wiping HardwareEvents
2025-12-06 18:31:43,582 [modules.auxiliary.evtx] DEBUG: Wiping Internet Explorer
2025-12-06 18:31:43,598 [modules.auxiliary.evtx] DEBUG: Wiping Key Management Service
2025-12-06 18:31:43,629 [modules.auxiliary.evtx] DEBUG: Wiping OAlerts
2025-12-06 18:31:43,660 [modules.auxiliary.evtx] DEBUG: Wiping Security
2025-12-06 18:31:43,691 [modules.auxiliary.evtx] DEBUG: Wiping Setup
2025-12-06 18:31:43,707 [modules.auxiliary.evtx] DEBUG: Wiping System
2025-12-06 18:31:43,738 [modules.auxiliary.evtx] DEBUG: Wiping Windows PowerShell
2025-12-06 18:31:43,769 [modules.auxiliary.evtx] DEBUG: Wiping Microsoft-Windows-Sysmon/Operational
2025-12-06 18:31:44,457 [lib.api.process] INFO: Successfully resumed <Process 4176 Acrobat.exe>
2025-12-06 18:31:44,473 [root] DEBUG: 4176: Python path set to 'C:\Python38'.
2025-12-06 18:31:44,473 [root] INFO: Disabling sleep skipping.
2025-12-06 18:31:44,473 [root] DEBUG: 4176: PDF (Adobe) settings enabled.
2025-12-06 18:31:44,473 [root] DEBUG: 4176: Dropped file limit defaulting to 100.
2025-12-06 18:31:44,488 [root] DEBUG: 4176: YaraInit: Compiled 41 rule files
2025-12-06 18:31:44,488 [root] DEBUG: 4176: YaraInit: Compiled rules saved to file C:\tmpw7hn3wdo\data\yara\capemon.yac
2025-12-06 18:31:44,488 [root] DEBUG: 4176: GetAddressByYara: ModuleBase 0x00007FFAEACB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:31:44,504 [root] DEBUG: 4176: RtlInsertInvertedFunctionTable 0x00007FFAEACC090E, LdrpInvertedFunctionTableSRWLock 0x00007FFAEAE1D510
2025-12-06 18:31:44,504 [root] DEBUG: 4176: YaraScan: Scanning 0x00007FF639720000, size 0x56d710
2025-12-06 18:31:44,519 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:31:44,519 [root] DEBUG: 4176: Monitor initialised: 64-bit capemon loaded in process 4176 at 0x00007FFAC6D60000, thread 4188, image base 0x00007FF639720000, stack from 0x00000001000F5000-0x0000000100100000
2025-12-06 18:31:44,519 [root] DEBUG: 4176: Commandline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\87455c255848e08c1e95.pdf"
2025-12-06 18:31:44,519 [root] DEBUG: 4176: hook_api: LdrpCallInitRoutine export address 0x00007FFAEACC99BC obtained via GetFunctionAddress
2025-12-06 18:31:44,519 [root] DEBUG: 4176: hook_api: Warning - CoCreateInstance export address 0x00007FFAE9AE42CB differs from GetProcAddress -> 0x00007FFAE912A420 (combase.dll::0x2a420)
2025-12-06 18:31:44,519 [root] DEBUG: 4176: hook_api: Warning - CoCreateInstanceEx export address 0x00007FFAE9AE430A differs from GetProcAddress -> 0x00007FFAE91A4180 (combase.dll::0xa4180)
2025-12-06 18:31:44,519 [root] DEBUG: 4176: hook_api: Warning - CoGetClassObject export address 0x00007FFAE9AE489A differs from GetProcAddress -> 0x00007FFAE912EB00 (combase.dll::0x2eb00)
2025-12-06 18:31:44,535 [root] DEBUG: 4176: hook_api: Warning - CLSIDFromProgID export address 0x00007FFAE9AE3B16 differs from GetProcAddress -> 0x00007FFAE91A8570 (combase.dll::0xa8570)
2025-12-06 18:31:44,535 [root] DEBUG: 4176: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FFAE9AE3B53 differs from GetProcAddress -> 0x00007FFAE91A8A40 (combase.dll::0xa8a40)
2025-12-06 18:31:44,535 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:31:44,535 [root] DEBUG: 4176: set_hooks: Unable to hook LockResource
2025-12-06 18:31:44,535 [root] DEBUG: 4176: Hooked 605 out of 606 functions
2025-12-06 18:31:44,535 [root] DEBUG: 4176: Syscall hook installed, syscall logging level 1
2025-12-06 18:31:44,535 [root] INFO: Loaded monitor into process with pid 4176
2025-12-06 18:31:44,535 [root] DEBUG: 4176: YaraScan: Scanning 0x00007FF639720000, size 0x56d710
2025-12-06 18:31:44,582 [root] DEBUG: 4176: caller_dispatch: Added region at 0x00007FF639720000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00007FF639A35111, thread 4188).
2025-12-06 18:31:44,582 [root] DEBUG: 4176: YaraScan: Scanning 0x00007FF639720000, size 0x56d710
2025-12-06 18:31:44,598 [root] DEBUG: 4176: ProcessImageBase: Main module image at 0x00007FF639720000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:31:44,598 [root] DEBUG: 4176: DLL loaded at 0x00007FFADAC70000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\Comctl32 (0x29a000 bytes).
2025-12-06 18:31:44,598 [root] DEBUG: 4176: DLL loaded at 0x00007FFAEA620000: C:\Windows\System32\shcore (0xad000 bytes).
2025-12-06 18:31:44,613 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7510000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2025-12-06 18:31:44,613 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD3520000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3E50000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1b000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE5990000: C:\Windows\SYSTEM32\VCRUNTIME140_1 (0xc000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD9580000: C:\Windows\SYSTEM32\MSVCP140 (0x8e000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE83C0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAEA800000: C:\Windows\System32\SETUPAPI (0x468000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC5E60000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AGM (0x703000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3E00000: C:\Program Files\Adobe\Acrobat DC\Acrobat\BIB (0x24000 bytes).
2025-12-06 18:31:44,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE9E00000: C:\Windows\System32\SHELL32 (0x744000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC6930000: C:\Program Files\Adobe\Acrobat DC\Acrobat\CoolType (0x42a000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD5D90000: C:\Windows\SYSTEM32\dbghelp (0x1e4000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE5F70000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00007FFADF420000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC6800000: C:\Program Files\Adobe\Acrobat DC\Acrobat\ACE (0x12e000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3DF0000: C:\Windows\SYSTEM32\SensApi (0xa000 bytes).
2025-12-06 18:31:44,926 [root] DEBUG: 4176: DLL loaded at 0x00000000559D0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat (0x3c27000 bytes).
2025-12-06 18:31:44,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAEA620000: C:\Windows\System32\shcore (0xad000 bytes).
2025-12-06 18:31:44,941 [root] DEBUG: 4176: set_hooks_by_export_directory: Hooked 0 out of 606 functions
2025-12-06 18:31:44,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE6260000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2025-12-06 18:31:44,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE8900000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2025-12-06 18:31:44,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE5D70000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2025-12-06 18:31:44,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE9D30000: C:\Windows\System32\OLEAUT32 (0xcd000 bytes).
2025-12-06 18:31:44,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE9B30000: C:\Windows\System32\MSCTF (0x114000 bytes).
2025-12-06 18:31:44,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7D70000: C:\Windows\SYSTEM32\Wldp (0x2e000 bytes).
2025-12-06 18:31:44,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE6460000: C:\Windows\SYSTEM32\windows.storage (0x793000 bytes).
2025-12-06 18:31:44,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE82D0000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2025-12-06 18:31:44,988 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:44,988 [root] DEBUG: 4176: hook_api: NetUserGetInfo export address 0x00007FFADE681F5E obtained via GetFunctionAddress
2025-12-06 18:31:44,988 [root] DEBUG: 4176: hook_api: Warning - NetGetJoinInformation export address 0x00007FFADE680FB3 differs from GetProcAddress -> 0x00007FFAE75516F0 (WKSCLI.DLL::0x16f0)
2025-12-06 18:31:44,988 [root] DEBUG: 4176: hook_api: NetUserGetLocalGroups export address 0x00007FFADE681F8A obtained via GetFunctionAddress
2025-12-06 18:31:44,988 [root] DEBUG: 4176: hook_api: DsEnumerateDomainTrustsW export address 0x00007FFADE67FA1F obtained via GetFunctionAddress
2025-12-06 18:31:44,988 [root] DEBUG: 4176: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:31:45,003 [root] DEBUG: 4176: DLL loaded at 0x00007FFADFE80000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2025-12-06 18:31:45,003 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE8250000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2025-12-06 18:31:45,003 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:31:45,003 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:31:45,003 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:31:45,035 [root] DEBUG: 4176: DLL loaded at 0x00007FFAEA570000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2025-12-06 18:31:45,035 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3EC0000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2025-12-06 18:31:45,066 [root] DEBUG: 4176: api-rate-cap: RegEnumValueA hook disabled due to rate
2025-12-06 18:31:45,066 [root] DEBUG: 4176: api-rate-cap: RegQueryValueExW hook disabled due to rate
2025-12-06 18:31:45,082 [root] DEBUG: 4176: api-rate-cap: RegEnumValueA hook disabled due to rate
2025-12-06 18:31:45,082 [root] DEBUG: 4176: api-rate-cap: RegQueryValueExW hook disabled due to rate
2025-12-06 18:31:45,082 [root] DEBUG: 4176: api-rate-cap: NtEnumerateValueKey hook disabled due to rate
2025-12-06 18:31:45,097 [root] DEBUG: 4176: api-rate-cap: NtQueryValueKey hook disabled due to rate
2025-12-06 18:31:45,113 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE8250000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2025-12-06 18:31:45,113 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE2E20000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2025-12-06 18:31:45,113 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE2E40000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2025-12-06 18:31:45,144 [root] DEBUG: 4176: api-rate-cap: GetKeyboardLayout hook disabled due to rate
2025-12-06 18:31:45,160 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD8CD0000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2025-12-06 18:31:45,191 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE6C40000: C:\Windows\system32\dxgi (0xf3000 bytes).
2025-12-06 18:31:45,191 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE44C0000: C:\Windows\system32\d3d11 (0x263000 bytes).
2025-12-06 18:31:45,191 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE4E70000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2025-12-06 18:31:45,191 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD1B90000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2025-12-06 18:31:45,207 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3080000: C:\Windows\system32\twinapi.appcore (0x207000 bytes).
2025-12-06 18:31:45,253 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD1EC0000: C:\Windows\System32\oleacc (0x66000 bytes).
2025-12-06 18:31:45,269 [root] DEBUG: 4176: DLL loaded at 0x00007FFACCAC0000: C:\Windows\SYSTEM32\Msftedit (0x348000 bytes).
2025-12-06 18:31:45,285 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE5890000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2025-12-06 18:31:45,285 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3F00000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2025-12-06 18:31:45,285 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE51B0000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes).
2025-12-06 18:31:45,285 [root] DEBUG: 4176: DLL loaded at 0x00007FFADCD00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2025-12-06 18:31:45,316 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD1880000: C:\Windows\system32\explorerframe (0x220000 bytes).
2025-12-06 18:31:45,316 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE4730000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2025-12-06 18:31:45,332 [root] DEBUG: 4176: DLL loaded at 0x00000000559A0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AXE8SharedExpat (0x2b000 bytes).
2025-12-06 18:31:45,332 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7AD0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2025-12-06 18:31:45,363 [root] DEBUG: 4176: DLL loaded at 0x00007FFADD8A0000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2025-12-06 18:31:45,363 [root] DEBUG: 4176: DLL loaded at 0x00007FFADD830000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2025-12-06 18:31:45,363 [root] DEBUG: 4176: DLL loaded at 0x00007FFADA610000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2025-12-06 18:31:45,363 [root] DEBUG: 4176: DLL loaded at 0x00007FFADD780000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2025-12-06 18:31:45,378 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
2025-12-06 18:31:45,410 [root] DEBUG: 4176: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2025-12-06 18:31:45,503 [root] DEBUG: 4176: DLL loaded at 0x0000000055940000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\weblink.api (0x5f000 bytes).
2025-12-06 18:31:45,519 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE9730000: C:\Windows\System32\PSAPI (0x8000 bytes).
2025-12-06 18:31:45,519 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD1E40000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2025-12-06 18:31:45,519 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC5A80000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\EScript.api (0x3e0000 bytes).
2025-12-06 18:31:45,550 [root] DEBUG: 4176: api-rate-cap: memcpy hook disabled due to rate
2025-12-06 18:31:45,613 [root] DEBUG: 4176: api-rate-cap: NtQueryKey hook disabled due to rate
2025-12-06 18:31:46,394 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:46,394 [root] DEBUG: 4176: OpenProcessHandler: Injection info created for process 4596, handle 0x5c4: Error obtaining target process name
2025-12-06 18:31:47,863 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3DC0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\BIBUtils (0x2b000 bytes).
2025-12-06 18:31:48,800 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD8930000: C:\Program Files\Adobe\Acrobat DC\Acrobat\sqlite (0xa9000 bytes).
2025-12-06 18:31:48,816 [root] DEBUG: 4176: CreateProcessHandler: Injection info set for new process 944: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe, ImageBase: 0x00007FF716B40000
2025-12-06 18:31:48,816 [root] INFO: Announced 64-bit process name: AcroCEF.exe pid: 944
2025-12-06 18:31:48,816 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
2025-12-06 18:31:48,816 [lib.api.process] INFO: Monitor config for <Process 944 AcroCEF.exe>: C:\tmpw7hn3wdo\dll\944.ini
2025-12-06 18:31:48,816 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:48,816 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:48,816 [root] DEBUG: Loader: Injecting process 944 (thread 5292) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:48,816 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:31:48,816 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:48,816 [lib.api.process] INFO: Injected into 64-bit <Process 944 AcroCEF.exe>
2025-12-06 18:31:48,832 [root] INFO: Announced 64-bit process name: AcroCEF.exe pid: 944
2025-12-06 18:31:48,832 [lib.api.process] INFO: Monitor config for <Process 944 AcroCEF.exe>: C:\tmpw7hn3wdo\dll\944.ini
2025-12-06 18:31:48,832 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:48,832 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:48,832 [root] DEBUG: Loader: Injecting process 944 (thread 5292) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:48,832 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-06 18:31:48,832 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:48,832 [lib.api.process] INFO: Injected into 64-bit <Process 944 AcroCEF.exe>
2025-12-06 18:31:48,847 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7CC0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2025-12-06 18:31:48,847 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE73F0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2025-12-06 18:31:48,847 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE8120000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2025-12-06 18:31:48,863 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store
2025-12-06 18:31:48,863 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei
2025-12-06 18:31:48,910 [root] DEBUG: 4176: DLL loaded at 0x00007FFADB390000: C:\Windows\SYSTEM32\msi (0x336000 bytes).
2025-12-06 18:31:48,910 [root] DEBUG: 4176: DLL loaded at 0x0000000055900000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Updater.api (0x31000 bytes).
2025-12-06 18:31:48,925 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
2025-12-06 18:31:48,972 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
2025-12-06 18:31:49,019 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\acroNGLLog.txt
2025-12-06 18:31:49,019 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4596
2025-12-06 18:31:49,019 [lib.api.process] INFO: Monitor config for <Process 4596 explorer.exe>: C:\tmpw7hn3wdo\dll\4596.ini
2025-12-06 18:31:49,019 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:49,019 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:49,035 [root] DEBUG: Loader: Injecting process 4596 with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:49,035 [root] DEBUG: 4596: Python path set to 'C:\Python38'.
2025-12-06 18:31:49,035 [root] DEBUG: 4596: Dropped file limit defaulting to 100.
2025-12-06 18:31:49,035 [root] INFO: Disabling sleep skipping.
2025-12-06 18:31:49,035 [root] DEBUG: 4596: YaraInit: Compiled rules loaded from existing file C:\tmpw7hn3wdo\data\yara\capemon.yac
2025-12-06 18:31:49,035 [root] DEBUG: 4596: GetAddressByYara: ModuleBase 0x00007FFAEACB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:31:49,050 [root] DEBUG: 4596: RtlInsertInvertedFunctionTable 0x00007FFAEACC090E, LdrpInvertedFunctionTableSRWLock 0x00007FFAEAE1D510
2025-12-06 18:31:49,050 [root] DEBUG: 4596: YaraScan: Scanning 0x00007FF71EBE0000, size 0x50b15a
2025-12-06 18:31:49,082 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:31:49,082 [root] DEBUG: 4596: Monitor initialised: 64-bit capemon loaded in process 4596 at 0x00007FFAC6D60000, thread 2124, image base 0x00007FF71EBE0000, stack from 0x0000000008FE2000-0x0000000008FF0000
2025-12-06 18:31:49,082 [root] DEBUG: 4596: Commandline: C:\Windows\Explorer.EXE
2025-12-06 18:31:49,082 [root] DEBUG: 4596: hook_api: LdrpCallInitRoutine export address 0x00007FFAEACC99BC obtained via GetFunctionAddress
2025-12-06 18:31:49,082 [root] DEBUG: 4596: hook_api: Warning - CoCreateInstance export address 0x00007FFAE9AE42CB differs from GetProcAddress -> 0x00007FFAE912A420 (combase.dll::0x2a420)
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - CoCreateInstanceEx export address 0x00007FFAE9AE430A differs from GetProcAddress -> 0x00007FFAE91A4180 (combase.dll::0xa4180)
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - CoGetClassObject export address 0x00007FFAE9AE489A differs from GetProcAddress -> 0x00007FFAE912EB00 (combase.dll::0x2eb00)
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - CLSIDFromProgID export address 0x00007FFAE9AE3B16 differs from GetProcAddress -> 0x00007FFAE91A8570 (combase.dll::0xa8570)
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FFAE9AE3B53 differs from GetProcAddress -> 0x00007FFAE91A8A40 (combase.dll::0xa8a40)
2025-12-06 18:31:49,097 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:31:49,097 [root] DEBUG: 4596: set_hooks: Unable to hook LockResource
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - NetUserGetInfo export address 0x00007FFADE681F5E differs from GetProcAddress -> 0x00007FFADE692C40 (samcli.dll::0x2c40)
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - NetGetJoinInformation export address 0x00007FFADE680FB3 differs from GetProcAddress -> 0x00007FFAE75516F0 (wkscli.dll::0x16f0)
2025-12-06 18:31:49,097 [root] DEBUG: 4596: hook_api: Warning - NetUserGetLocalGroups export address 0x00007FFADE681F8A differs from GetProcAddress -> 0x00007FFADE691C60 (samcli.dll::0x1c60)
2025-12-06 18:31:49,113 [root] DEBUG: 4596: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x00007FFADE67FA1F differs from GetProcAddress -> 0x00007FFAE78F8780 (LOGONCLI.DLL::0x18780)
2025-12-06 18:31:49,113 [root] DEBUG: 4596: Hooked 605 out of 606 functions
2025-12-06 18:31:49,113 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 4176, handle 0x1268: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
2025-12-06 18:31:49,113 [root] DEBUG: 4596: Syscall hook installed, syscall logging level 1
2025-12-06 18:31:49,113 [root] INFO: Loaded monitor into process with pid 4596
2025-12-06 18:31:49,129 [root] DEBUG: 4596: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2025-12-06 18:31:49,129 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-06 18:31:49,129 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:49,129 [lib.api.process] INFO: Injected into 64-bit <Process 4596 explorer.exe>
2025-12-06 18:31:49,129 [root] DEBUG: 4176: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2025-12-06 18:31:49,129 [root] DEBUG: 4176: DLL loaded at 0x00007FFADFE80000: C:\Windows\system32\version (0xa000 bytes).
2025-12-06 18:31:49,144 [root] DEBUG: 4176: DLL loaded at 0x00007FFADFE80000: C:\Windows\system32\version (0xa000 bytes).
2025-12-06 18:31:49,144 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:49,144 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:49,144 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:49,144 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:49,144 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:49,144 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:49,144 [lib.api.process] DEBUG: Failed getting exit code for <Process 792 ???>
2025-12-06 18:31:49,144 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:49,144 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:49,144 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:49,144 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:49,144 [lib.api.process] WARNING: the <Process 792 ???> is not alive, injection aborted
2025-12-06 18:31:49,160 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
2025-12-06 18:31:49,160 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal to files\713f1644132e8e011f786f37efe68a5eef87a3d1f7e4d4fa52a1265234e9e99f; Size is 8720; Max size: 100000000
2025-12-06 18:31:49,176 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
2025-12-06 18:31:49,191 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal to files\1d403b2225a58d3aaa9b93bb14d9e9f60db5ee5d17eca1f8e85709a86294076c; Size is 8720; Max size: 100000000
2025-12-06 18:31:49,207 [root] DEBUG: 4176: DLL loaded at 0x00007FFADE550000: C:\Windows\SYSTEM32\wbemcomn (0x90000 bytes).
2025-12-06 18:31:49,207 [root] DEBUG: 4176: DLL loaded at 0x00007FFADEBB0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2025-12-06 18:31:49,207 [root] DEBUG: 4176: DLL loaded at 0x00007FFADD760000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2025-12-06 18:31:49,223 [root] DEBUG: 4176: DLL loaded at 0x00007FFADD900000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2025-12-06 18:31:49,238 [root] DEBUG: 4176: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:31:49,238 [root] DEBUG: 4176: DLL loaded at 0x00007FFADB7B0000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2025-12-06 18:31:49,238 [root] DEBUG: 4176: DLL loaded at 0x00007FFADFE80000: C:\Windows\system32\version (0xa000 bytes).
2025-12-06 18:31:49,332 [root] DEBUG: 4596: caller_dispatch: Added region at 0x00007FF71EBE0000 to tracked regions list (msvcrt::memcpy returns to 0x00007FF71EC3492D, thread 4776).
2025-12-06 18:31:49,332 [root] DEBUG: 4596: YaraScan: Scanning 0x00007FF71EBE0000, size 0x50b15a
2025-12-06 18:31:49,363 [root] DEBUG: 4596: ProcessImageBase: Main module image at 0x00007FF71EBE0000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:31:49,426 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE8560000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2025-12-06 18:31:49,426 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7F00000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2025-12-06 18:31:49,441 [root] DEBUG: 4176: DLL loaded at 0x00007FFAEA550000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2025-12-06 18:31:49,488 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE6C10000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2025-12-06 18:31:49,504 [root] DEBUG: 4176: api-rate-cap: RegQueryInfoKeyW hook disabled due to rate
2025-12-06 18:31:49,941 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC7780000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.2251_none_91a40448cc8846c1\gdiplus (0x1a5000 bytes).
2025-12-06 18:31:49,941 [root] DEBUG: 4176: DLL loaded at 0x0000000054E90000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Annots.api (0xa67000 bytes).
2025-12-06 18:31:49,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:49,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:31:49,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:31:49,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:31:49,972 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:31:50,003 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:50,019 [root] DEBUG: 4176: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:31:50,035 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:31:50,035 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:31:50,035 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:31:50,050 [root] DEBUG: 4176: DLL loaded at 0x0000000054E40000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\IA32.api (0x44000 bytes).
2025-12-06 18:31:50,066 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD8F00000: C:\Windows\SYSTEM32\WININET (0x4d6000 bytes).
2025-12-06 18:31:50,066 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:50,097 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD7DD0000: C:\Windows\SYSTEM32\ondemandconnroutehelper (0x17000 bytes).
2025-12-06 18:31:50,097 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE77C0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3c000 bytes).
2025-12-06 18:31:50,097 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE9B20000: C:\Windows\System32\NSI (0x8000 bytes).
2025-12-06 18:31:50,113 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE2CB0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2025-12-06 18:31:50,113 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE0D10000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2025-12-06 18:31:50,113 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE1640000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2025-12-06 18:31:50,915 [root] DEBUG: 4176: Dropped file limit reached.
2025-12-06 18:31:51,163 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:51,163 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:51,163 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:51,163 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:51,163 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:51,163 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:51,163 [lib.api.process] DEBUG: Failed getting exit code for <Process 2664 ???>
2025-12-06 18:31:51,163 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:51,163 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:51,163 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:51,163 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:51,163 [lib.api.process] WARNING: the <Process 2664 ???> is not alive, injection aborted
2025-12-06 18:31:51,186 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC4D00000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeXMP (0x135000 bytes).
2025-12-06 18:31:56,847 [root] DEBUG: 4596: api-cap: GetSystemMetrics hook disabled due to count: 5000
2025-12-06 18:31:58,362 [root] DEBUG: 4596: OpenProcessHandler: Image base for process 4176 (handle 0x1ea4): 0x00007FF639720000.
2025-12-06 18:31:58,362 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
2025-12-06 18:31:58,378 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,378 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5976, handle 0x1268: Error obtaining target process name
2025-12-06 18:31:58,378 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,378 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6696, handle 0x1f44: Error obtaining target process name
2025-12-06 18:31:58,378 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,378 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5192, handle 0x1ef0: Error obtaining target process name
2025-12-06 18:31:58,378 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,378 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5636, handle 0x1f50: Error obtaining target process name
2025-12-06 18:31:58,378 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,378 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6704, handle 0x1f58: Error obtaining target process name
2025-12-06 18:31:58,472 [root] DEBUG: 4176: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2025-12-06 18:31:58,487 [root] DEBUG: 4176: api-rate-cap: NtClose hook disabled due to rate
2025-12-06 18:31:58,487 [root] DEBUG: 4176: api-rate-cap: FindFirstFileExW hook disabled due to rate
2025-12-06 18:31:58,885 [root] DEBUG: 4596: api-cap: memcpy hook disabled due to count: 5000
2025-12-06 18:32:00,663 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 1632, handle 0x1f48: C:\Windows\System32\conhost.exe
2025-12-06 18:32:00,678 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:00,678 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:01,709 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 808, handle 0x1eec: C:\Windows\System32\conhost.exe
2025-12-06 18:32:01,709 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:01,709 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:02,762 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5412, handle 0x1ea4: C:\Windows\System32\conhost.exe
2025-12-06 18:32:02,762 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:02,762 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:03,793 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5792, handle 0x1f48: C:\Windows\System32\conhost.exe
2025-12-06 18:32:03,809 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:03,809 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:04,825 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 2472, handle 0xf94: C:\Windows\System32\conhost.exe
2025-12-06 18:32:04,825 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:04,825 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:05,841 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7800000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2025-12-06 18:32:05,841 [root] DEBUG: 4176: DLL loaded at 0x00007FFADB2D0000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2025-12-06 18:32:06,122 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 3788, handle 0xc28: C:\Windows\System32\conhost.exe
2025-12-06 18:32:06,122 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:06,122 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:06,871 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3380000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2025-12-06 18:32:06,871 [root] DEBUG: 4176: DLL loaded at 0x00007FFADCBA0000: C:\Windows\System32\InputHost (0x152000 bytes).
2025-12-06 18:32:06,887 [root] DEBUG: 4176: DLL loaded at 0x00007FFADCE00000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2025-12-06 18:32:07,168 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 3860, handle 0x1f58: C:\Windows\System32\conhost.exe
2025-12-06 18:32:07,184 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:07,184 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:07,465 [root] DEBUG: 4176: DLL loaded at 0x0000013438C60000: C:\Program Files\Adobe\Acrobat DC\Acrobat\icudt69 (0x1b87000 bytes).
2025-12-06 18:32:07,465 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC4A80000: C:\Program Files\Adobe\Acrobat DC\Acrobat\icuuc69 (0x27d000 bytes).
2025-12-06 18:32:07,465 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD2010000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeLinguistic (0x8a000 bytes).
2025-12-06 18:32:07,465 [root] DEBUG: 4176: DLL loaded at 0x0000000054DD0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Spelling.api (0x64000 bytes).
2025-12-06 18:32:07,543 [root] DEBUG: 4176: DLL loaded at 0x0000000053B90000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AXSLE (0xa7000 bytes).
2025-12-06 18:32:07,559 [root] DEBUG: 4176: DLL loaded at 0x0000000053C40000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\AcroForm.api (0x118e000 bytes).
2025-12-06 18:32:07,559 [root] DEBUG: 4176: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:32:07,559 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:32:07,559 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:32:07,559 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:32:07,575 [root] DEBUG: 4176: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:32:07,575 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:32:07,575 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:32:07,575 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:32:07,590 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC48E0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\DigSig.api (0x191000 bytes).
2025-12-06 18:32:07,637 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3DB0000: C:\Windows\SYSTEM32\WSOCK32 (0x9000 bytes).
2025-12-06 18:32:07,637 [root] DEBUG: 4176: DLL loaded at 0x0000000053130000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\PPKLite.api (0xa5d000 bytes).
2025-12-06 18:32:07,699 [root] DEBUG: 4176: DLL loaded at 0x00007FFAC3710000: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\AdobeHunspellPlugin (0x7e7000 bytes).
2025-12-06 18:34:00,545 [root] DEBUG: 4596: OpenProcessHandler: Image base for process 6704 (handle 0x122c): 0x00007FF735750000.
2025-12-06 18:34:00,576 [root] DEBUG: 4596: DLL loaded at 0x00007FFACEC80000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2025-12-06 18:34:00,607 [root] DEBUG: 4176: DLL loaded at 0x00007FFAE3570000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2025-12-06 18:34:00,623 [root] DEBUG: 4596: DLL loaded at 0x00007FFAE3D30000: C:\Windows\System32\NPSMDesktopProvider (0x38000 bytes).
2025-12-06 18:34:00,623 [root] DEBUG: 4176: DLL loaded at 0x00007FFAD17E0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2025-12-06 18:34:00,654 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2025-12-06 18:34:00,654 [root] DEBUG: 4596: DLL loaded at 0x00007FFAD8A00000: C:\Windows\System32\CapabilityAccessManagerClient (0x3f000 bytes).
2025-12-06 18:34:00,654 [root] DEBUG: 4596: OpenProcessHandler: Image base for process 6696 (handle 0x1368): 0x00007FF6A14B0000.
2025-12-06 18:34:00,670 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db
2025-12-06 18:34:00,717 [root] DEBUG: 4596: DLL loaded at 0x00007FFAE3DA0000: C:\Windows\System32\WppRecorderUM (0x7000 bytes).
2025-12-06 18:34:00,717 [root] DEBUG: 4596: DLL loaded at 0x00007FFAD88C0000: C:\Windows\System32\BthAvctpSvc (0x64000 bytes).
2025-12-06 18:34:45,138 [root] INFO: Analysis timeout hit, terminating analysis
2025-12-06 18:34:45,138 [lib.api.process] INFO: Terminate event set for <Process 4176 Acrobat.exe>
2025-12-06 18:34:45,138 [root] DEBUG: 4176: Terminate Event: Attempting to dump process 4176
2025-12-06 18:34:45,138 [root] DEBUG: 4176: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:34:45,138 [root] DEBUG: 4176: Terminate Event: Current region empty
2025-12-06 18:34:45,138 [lib.api.process] INFO: Termination confirmed for <Process 4176 Acrobat.exe>
2025-12-06 18:34:45,138 [root] INFO: Terminate event set for process 4176
2025-12-06 18:34:45,138 [root] DEBUG: 4176: Terminate Event: CAPE shutdown complete for process 4176
2025-12-06 18:34:45,138 [lib.api.process] INFO: Terminate event set for <Process 4596 explorer.exe>
2025-12-06 18:34:45,138 [root] DEBUG: 4596: Terminate Event: Attempting to dump process 4596
2025-12-06 18:34:45,138 [root] DEBUG: 4596: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:34:45,154 [root] DEBUG: 4596: Terminate Event: Current region empty
2025-12-06 18:34:45,154 [lib.api.process] INFO: Termination confirmed for <Process 4596 explorer.exe>
2025-12-06 18:34:45,154 [root] DEBUG: 4596: Terminate Event: CAPE shutdown complete for process 4596
2025-12-06 18:34:45,154 [root] INFO: Terminate event set for process 4596
2025-12-06 18:34:45,154 [root] INFO: Created shutdown mutex
2025-12-06 18:34:46,170 [root] INFO: Shutting down package
2025-12-06 18:34:46,170 [root] INFO: Stopping auxiliary modules
2025-12-06 18:34:46,170 [root] INFO: Stopping auxiliary module: Browser
2025-12-06 18:34:46,170 [root] INFO: Stopping auxiliary module: Curtain
2025-12-06 18:34:46,170 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [Errno 13] Permission denied: 'C:\\curtain.log'
2025-12-06 18:34:46,170 [modules.auxiliary.curtain] ERROR: Curtain log file not found!
2025-12-06 18:34:46,170 [root] INFO: Stopping auxiliary module: End_noisy_tasks
2025-12-06 18:34:46,170 [root] INFO: Stopping auxiliary module: Evtx
2025-12-06 18:34:46,170 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Application.evtx to zip dump
2025-12-06 18:34:46,170 [root] WARNING: Cannot terminate auxiliary module Evtx: [Errno 13] Permission denied: 'C:/windows/Sysnative/winevt/Logs\\Application.evtx'
2025-12-06 18:34:46,170 [root] INFO: Stopping auxiliary module: Human
2025-12-06 18:34:56,170 [root] WARNING: Failed to join {aux} thread.
2025-12-06 18:34:56,170 [root] INFO: Stopping auxiliary module: Pre_script
2025-12-06 18:34:56,170 [root] INFO: Stopping auxiliary module: Screenshots
2025-12-06 18:34:58,748 [root] INFO: Stopping auxiliary module: Usage
2025-12-06 18:34:59,529 [root] INFO: Stopping auxiliary module: During_script
2025-12-06 18:34:59,529 [root] INFO: Finishing auxiliary modules
2025-12-06 18:34:59,529 [root] INFO: Shutting down pipe server and dumping dropped files
2025-12-06 18:34:59,529 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json to files\70546c738a9c57ff4e3b735af4ff0778069ef98e2b313b6053918a1d5bea4376; Size is 138; Max size: 100000000
2025-12-06 18:34:59,529 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages to files\83be4623d80ffb402fbdec4125671df532845a3828a1b378d99bd243a4fd8ff2; Size is 57344; Max size: 100000000
2025-12-06 18:34:59,545 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store to files\5a70a9d1b526743c71c5c2540249f45afbd9bfdced207d483bb917aa37e6636c; Size is 10240; Max size: 100000000
2025-12-06 18:34:59,560 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei to files\f0ea757bad7a1d57600522d4b43b0f6e5a469e73afb08db21dad71b396540888; Size is 24152; Max size: 100000000
2025-12-06 18:34:59,576 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING to files\81ff65efc4487853bdb4625559e69ab44f19e0f5efbd6d5b2af5e3ab267c8e06; Size is 4; Max size: 100000000
2025-12-06 18:34:59,576 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents to files\d17c7e07a81b0bf82fb47c5b5a3d7f19b55726f6785175034d47808e96a55013; Size is 12288; Max size: 100000000
2025-12-06 18:34:59,591 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\acroNGLLog.txt to files\d8273c1dab2952eebc17ebc63fdde19f36c5a8cbc10f7846d7ed3f4e23a83522; Size is 5876; Max size: 100000000
2025-12-06 18:34:59,591 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat to files\7ab4047101e2ba8d04f95bdc33242687832ad63d7c2fcc899bd36065e6e48d9c; Size is 996; Max size: 100000000
2025-12-06 18:34:59,591 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db to files\d97ec017e99ed9ce08101b2a6cfbc5d86bd8d3291a85fba1ba7cd57fb385079b; Size is 14688; Max size: 100000000
2025-12-06 18:34:59,607 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db to files\1ec69c5de90d598e705eae66838f799a21df5b59f56a632bcadbfee88196ce4c; Size is 1048576; Max size: 100000000
2025-12-06 18:34:59,623 [root] WARNING: Folder at path "C:\HNxZeWN\debugger" does not exist, skipping
2025-12-06 18:34:59,623 [root] WARNING: Folder at path "C:\HNxZeWN\tlsdump" does not exist, skipping
2025-12-06 18:34:59,623 [root] WARNING: Monitor injection attempted but failed for process 944
2025-12-06 18:34:59,623 [root] INFO: Analysis completed

    

    

    

    

Machine

Name Label Manager Started On Shutdown On
win10-64bit-tiny-3 win10-64bit-tiny-3 KVM 2025-12-08 13:59:58 2025-12-08 14:03:23

File Details

File Name
87455c255848e08c1e95.pdf
File Type PDF document, version 1.4, 1 page(s)
File Size 184824 bytes
MD5 e51789e6769e567dfe2ed2cc98b9f4d7
SHA1 d021b46c74e131124a7b4c3b6b004ff8e38d5395
SHA256 87455c255848e08c1e95370d6744c196a9d6ba793353312d929e43a4e2c006ea [VT] [MWDB] [Bazaar]
SHA3-384 f5eebab39b5cbb511b10cf7a57d0a1db8c2d1451604997c056fd8077f8086b1c9fcd828ba2f7e84ec4926332167b139e
CRC32 03DB18B1
TLSH T164041279E87FE48AD8464C7BDD6A359F4B29B10283FA19B2B0754F5A9004E71F272370
Ssdeep 3072:7vRtf4KV41iOBoekcHFXJnHbtuzj7yNp40UFI/z/92+xNhNr5+m8hH4:7vAhk6gKnHbQzj7Umxczg+Jp5+mWH4
  • multiple_versions - Written very generically and doesn't hold any weight - just something that might be useful to know about to help show incremental updates to the file being analyzed - Author: Glenn Edwards (@hiddenillusion)
File BinGraph Vba2Graph

whxTnAQCcS
'`;cs
/Length 4498>> stream
xb:SI
Wg'#}
skx S_
|\+#'
&F3N
#?EJfTf,G
o6751
/Type /Action
sBXEC
WDY"|"
%4e~d`{BR9|
HSY%O
hxdT6
AQa2Kt
0000179236 00000 n
3QM#S
$+#=11!
cnnanaik
HJM+)+ojn
/K [24 0 R 25 0 R 27 0 R <</Type /MCR
0000000015 00000 n
p}ME|t
l+/-JN
"(wqn^659
9gqj.
:m:-n
6a6#*
^x~E/
4F8jN
/Creator (Mozilla/5.0 \(Windows NT 10.0; Win64; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/114.0.0.0 Safari/537.36)
|A 2Q
]xrw?
`^uW0
iFb5$
|C6sC
<</Type /Pages
0000174431 00000 n
zcscueib|
XYYYa
95-pg
4R:fy
([J$+
QNt^)
/ToUnicode 37 0 R>>
~6k}h
EFgde
~WE(fN
:;;Z[
Sv'2o
K'eGz
_PXV^QU
66&FF
!n\GF
0000169688 00000 n
2>5-dC
/Length 158780>> stream
m,*&.;7
?19I[.
;P$Z'
ctj?/
Ik1YO<
K9J&
/K [28 0 R <</Type /OBJR
0000174188 00000 n
H{;PV
aw+6N;'O~\
[23 0 R 24 0 R 26 0 R 28 0 R]
voooO
)FXD;
$,Fm2
/C1 [.71 .71 .71]
WQYY^V"X
Iz2%I
&bp5
;m5-M
m`RH
2#*=G
0000164445 00000 n
/IDTree 32 0 R>>
0Fs}W
7,bqPB
MdoY(
o ugb=
G&%''
(%sG3
<<2:==
zX.j|
37 0 obj
VPY|c
'?5eO
"~4&sc
/ColorSpace /DeviceGray
13 0 obj
U[o~n
/CapHeight 705
WNt y
0000184122 00000 n
e@iEEe=m
Z[#"740x
AcCg$6Z
t-B+3Ku.
2<6&699%===5%9&
OYVu1
-O=iO^
*Yj~|%eI
=?Y/8
S+WfK
gGD9T
/Length 3524>> stream
/Rect [228.09583 225.91119 366.90414 265.67786]
UyUJ/e
JWO'{
%Nugn
d/;9W
kfU(C
hkianx
PVYpg
WXDdzfveM]Wo
&&'gde
<</Filter /FlateDecode
og.&Ua
21 0 obj
pptll
)j|zjna
Hgy:&
gYjVU#Z
~n8yn
^R#0a
626&e
~h`4o
MJgf|
20 0 obj
=5UeI
iAkM~NfXH
i_)/}5
k{OJc
s1R1U
cX<28
APBtx
/Flags 4
EtjNVk
/Resources <</ProcSet [/PDF /Text /ImageB /ImageC /ImageI]
n(^:g
wOT1(
26 0 obj
'F}qz
xow{A6
/TilingType 1
'/\:9<~
x`4#<
UN'ES
pGbjA
ptksmuir|X
M;w2@:
JC76U
N8k,O
{q'{y
<</Type /Pattern
}/I70
/ExtGState <</G3 3 0 R>>
0i.T=
kk}vf
<</Type /Annot
}}CC#
t%0BUcD
WWoz:h
?cS?7
u!l#g
FA~^zZjbbBbbRFf&
0000183139 00000 n
0000173578 00000 n
<</Type /Catalog
O^po&
IUfxR
ZX#L&
3 0 obj
Qe.0HdlqYU
pKW:#
F\amc
/FontFile2 34 0 R>>
/SMask 16 0 R
/Ordering (Identity)
7 0 obj
OHMMMNN
oN"jvk
}6mxcK
/ID (node00000001)>>
lCdh2f
4)wxc>
9xH!=
/Size 38
X8Yw5
1cG{eEy
,18y[y5
|)o5#
VD)`1*
_joi9?
/StructTreeRoot 22 0 R>>
xJzM*
_1FNi
<</Type /Page
0000178786 00000 n
c<s>i
aH2xsOr
fDtq-v
/Prev 183283
PCmUZr
nDJ,<H
0~[O/E
<</Type /StructElem
/P 25 0 R
/Length 4044>> stream
/MediaBox [0 0 594.95996 841.91998]
/CIDSystemInfo <</Registry (Adobe)
XY[gK9
:\II/t cMq
S7+aT0\|
a8mj;
e4TZ#L
zYegt$
\42C3
_677Q
NeXAr&NW
2222^
J2^'OZ
qt#Cc#
y_v5Vch
& OsP[j(
0000173757 00000 n
W_}a .
!Qc-L}
%kCaR
Iea00
!Gip
9U\"8
7oril
/Matrix [.025081571 0 0 -.025081571 232.55019 502.77753]
5479jQ
EGzyx
=B~A&
35?###
3nd,Q
27 0 obj
j%i5L
-XO,
19 0 obj
/Length 2104>> stream
/XObject <</X4 4 0 R>>
jWM$T
8!mUeF
/StructParent 100000
@cNlweyad
y{8WS
/ID (node00000007)>>
^ggD<
d|2h/
yQKsZOD
B&" D>
q"$cvF
I3;:c#
*{B|P!
`_pk,
%+jJu
qXlmKS
,m3zL,
/Domain [0 1]
3Nlr<
0000179386 00000 n
ZPf:O
=;-Hu
:EE^U
!r{Wpy
uUWQC
<</Type /ParentTree
:+{JM
Ve.QP
!Q_!E
yT8Z"
vJWm++
/DescendantFonts [36 0 R]
)c-;B
c61V\
/+;';;+991"L
trailer
&+g[
/Pattern <</P10 10 0 R
[`I0C
q77w__
;1LS!5
j<)]s
y~~|t
)1M46
/***(0
pwvvvs
&rJ&-
<</Root 33 0 R
"Dr4&
TR;<!W
=H1yu
p_oOGG{KKsCC]yyinvVbB|xxXppPP
=;-BUN
<.P{A
4?U_1CT
z{4wZs
(4M>p
/StructParents 0
ynEi-
0000000262 00000 n
0000179959 00000 n
<</ca .102
32 0 obj
Qnf")
=y<X[=
-tEBv^
/Info 1 0 R>>
/ShadingType 2
]n8 bR[
DIzXF3&
<</ca .05
23 0 obj
booowwwggg{{
3Bf/f
`{j]_
/DW 0>>
Ij6TgS
2'|\3C
e ^G>?
c$l$
#nv\[94
JcFJCS
C`Iz7
oN v*{Z
FdoY(
tub$VnYa
An%=>
^>,,q
0000178905 00000 n
#@;=W
b3|CrQ
wOt>Z
+?VFcc
/URI (https://firstviewautoservice.com//men/Prefer Quotation.zip)
4qpDv
/XObject <</X13 13 0 R
,|Z0G
_D{h6
/XStep 301
4@lnf
/BM /Normal>>
innoA
rN:l!
{Aa}Ea-
29 0 obj
/Marked true>>
R@blbjcg
yW`OGg
`nqAL!
ON=}R
E~vww
KGY tv
gg{sscmmuuuemmmcssgg
ANt|L
^P\v3
t^"U^
L.Lfa3
=e[eI
ZIcCEY
'''U?3{fddd,W
]]]<E
74457wtv
/Yla?>
f`XUT
/Names [(node00000001) 23 0 R (node00000006) 24 0 R (node00000007) 25 0 R (node00000008) 26 0 R (node00000009) 27 0 R (node00000010) 28 0 R]>>
eqiieyI:
m d^`
Lm;wJ
/P12 12 0 R
/MarkInfo <</Type /MarkInfo
0*3ph
ab(8P[TL\~qIkG
He`j%8
;pa@J
7#nF?v
/Length 80>> stream
7348
Od]!1
183283
25 0 obj
lnnr{mm
VD]Wx`
G>[9p&4
gOg[~v
/Pg 2 0 R
hwk0R
/Length 155>> stream
e"9]'
:T\D%
/K [26 0 R]
/Lang (en)
H%[j{6
3A.Sj
8k@H)
sA"!8716
tpD$&h
qHJI+.-
sF^ 5@B
<</Kids [31 0 R]>>
/CreationDate (D:20230701093147+00'00')
f.CgE&
Fxf5r
$z%eUj
v'>nC
FhfNAkg
oGianDh
T#13Id
7-\K)@
]+l&f
I)dH>
12 0 obj
I<P'!Q9
@X^3/
#HLagG%U
vckx@
V2222
/Rect [228.0958 225.9112 366.9041 265.6779]
iGWo9
U'gW_
/BaseFont /AAAAAA+Poppins-Bold
:::Caz
_-b+7Q
nom*+)
_ iiE
22222
%%EOF
0000165107 00000 n
<Q"4%}
/ModDate (D:20230701093147+00'00')>>
/Border [0 0 0]
KKKr?
24 0 obj
QxsfL}
z]ZZNMyQ
rMX6v
q'::9
giimgO
1sxJ\#
Xfp2D
/Matrix [1.00000012 0 0 -.99999982 147 503]
/ID (node00000009)>>
o``lltxh
VfslJm#
/Shading <</Function <</C0 [.937 .937 .937]
:Q"bn
ah6Zs
0000182149 00000 n
}fVNye
h0`;sD
im>$-T
DW{KANFH
GnUgt
b_';WZi
-0GVc
G'3VN!
/PatternType 1
[\^as
0000000000 65535 f
bF#Ky
\8M*S
D/ Bb
aQaAA^JrBP
Hih)
<</Type /StructTreeRoot
?uX90
PlvGx
e:7N|E
s2a4V:;
Y8%V'Cb:
Ss<$I
/ItalicAngle 0
S{yjG
5,J$)%
BzaEab
(9-?nVg
lZF5v
ZXdiaAS
7:8<R
7B6NNN
]&j_U
TWWWUUU2T
^,-FJ
I9~ejk
&1\P_
Q+o<);
/P 22 0 R
/FontBBox [-562 -606 2477 1108]
/Nums [0 29 0 R 100000 27 0 R]>>
/Subtype /Link
zymdF7Ig
A{/-.H
(irjjq
qx^QIc3
{fddd
=Lb>`
9XR@%h;
tgkmuyN6;99>2"
Hwd7c
/W [0 [500 0 0 212 392] 36 [737 0 0 727 541 547 0 0 295 0 0 477 0 0 0 624 0 652 615 0 0 730 1052 0 671] 68 69 679 70 [605 679 616] 76 79 295 82 [637 0 0 428 558 406 674 0 0 0 632 0 0 291]]
8 0 obj
NGCm"<
swgkN:
I3222^
BmO-I
_d7p[b
;b\,E9:\
30 0 obj
4n|r"
/Encoding /Identity-H
B<H07[
2{fddd,{T
5 0 obj
)?Og5
>T&Rt)
>qngq
twnv{
hK2Z@
0000165461 00000 n
0000173382 00000 n
f| qno
/,)kjnioo
0000178276 00000 n
Uq)wBP
&J#"]#@5Q
;G%Og
kc.ObI
-.Gw]
OAnzzZF
ppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppp
CAz{{
0W{1X
/YStep 151.000031
-3Xzo
&26m+
DWG+r
ar.*5
=Y=s0
h`jhnjn
I\[[[
8MN%#
}}}]]]Z
d`dllV&
0000174228 00000 n
z.Dn8)
/ParentTree 30 0 R
>PhWFC$'Nr
dcR)EN
!0+vn
UiTTC/`k
On!M(
-K6}}6
8,<95
/BitsPerComponent 8
/X8 8 0 R>>>>
|xUvy
bqxddBRrN^~EuuSsKgWW_
y9x$]
35 0 obj
gPLH[{AhY;w
!6=#]]
o:<t{
yw--8
,zv9a
0000164681 00000 n
sIQ7{V(
pgV;q
b`pjFv
OW<<9.
aal3\ye
.vYl7.
_/[k+a
`28;LV>av|\H
D5]S7
.}WhWBd
-a[mL^
%PDF-1.4
=3222
@\8Se
K ,(&
s3eRCD=
ST Xr
/Filter /FlateDecode
Z/qb2
gahd#
|\0}h
8xGG[5
YPgmuefzjX
NH@>d
/Length 321>> stream
RjfCS
kH]7$W
];GblR
33 0 obj
-##cy
QGd#?
|:]ei~d
0000178611 00000 n
%looK
[*=%#c
$A)||s
w]m%&
b"2)`=
BR<nx
w$:G>M
6Le$9
<=<Q#
u+g\]
e22^wL
;B%h7
/G11 11 0 R
(Arnq
] ~7
JN3#j
/Subtype /Type0
"0Zq~b,
N=E^A!
,;JTRO
#lHYv
Noo/7
6`4mc{fU
!,=-|o
D-nr@o
+c3Kj?
r2UHfIoM0
36noo
TaoAK
WS,eb
/Annots [19 0 R]
1 0 obj
/ColorSpace /DeviceRGB>>>>
H<P^{/{V
/FontName /AAAAAA+Poppins-Bold
ne}9K
U&qq_
/BBox [0 0 301 151.000031]
/Obj 19 0 R
)x_>QHk
0000179432 00000 n
;#L4`#
jgsy.
m]2@<|
jh)zqqQZw
e1gP
/0X=W
fEw1V
H|V.@
2m%cg
dD|*,
uPEOc
k-aAZg
;zUH=
/Subtype /CIDFontType2
nxtlVJV
\nFFFF
JNb8]
'a=s-,
o`p||t
@{[Kuueaaann^^^>~).
-MZ3j
6~gneO}
~v jD
IhB94
(&0"1
XyCbn
/Font <</F5 5 0 R>>>>
]UUp{
/P 27 0 R
0000182348 00000 n
9n-1
ViF\hOU
kNSai
'2*&-=#;+3)!.
%Ma,+
<</Creator (Mozilla/5.0 \(Windows NT 10.0; Win64; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/114.0.0.0 Safari/537.36)
^FFFFFFFFFF
H#::*"""<<<
0?)!N
16 0 obj
9fmmmfffjjnec
UW{:f8L
UW[FF
Xax"!W
;sKcs
/Producer (Skia/PDF m114)
uE <!
/P 23 0 R
F3.o3
P_WYYQ^VVYY
w7VH/
^'9M
jk$sKZN
pffF*
ni<#re
SCRwcu
NSO7c
H*<.S(9
j\MC,EWM
df!Z{
)E_|\P
u/Ka">
=f2ofdddd
m&~j~
BiCSgNdM
<</Type /XObject
/URI (https://bafkreihkpq6ipoor44lurk55pcdqgzv43upgiyfwotxm7dgvpulqcjo6py.ipfs.dweb.link)>>
/Height 800
/ExtGState <</G3 3 0 R
HffZjj|\,>
ach.m
0X,,E
qDTtBb
J7O;k+p
RO*|fK
&i,nywm
an)3VT
ja428
/XObject <</X6 6 0 R
fLk,$
/Subtype /Image
D41}H
Lff^Q
F<,$j
;Pz`1
/S /H1
XwWGC}mYiI!PTXZ^^[_
{uu{yy{ye{eug}]
/Width 618
3}NSS
Meu=L&
'1)D4&h^
O/J$6M
/Length 17>> stream
/P17 17 0 R>>
36 0 obj
id^]^]
/'Vb[
8X:ahq
n9H&k
y\8"y
[jV4]]
)%U|=)
/Length 71>> stream
184664
_462x
`_m%'&_
YZVZZR
&{R1My}
W|6%,
/Supplement 0>>
RPv[kX[WO
n&Q-G
/Root 33 0 R
xOBGb{
oXDdZFVeM-
tuuuww
U@cn?
/A <</S /URI
|KD&)
J+UOq
z|A\*1ZD
A^4T'L /
endstream
vVTFQ
0000159584 00000 n
k7GM=L
E9w4F
/A <</Type /Action
!=(a#?:
bZF75
he06wD?v
xo0It
/S /Document
w'hsM
/Ascent 1050
?/}f,oTtO
UQgy0`
HxOf.
8DT)T
T]UY\T
f9dE.
xzzJu
1'SYZ$
669)c
Fnymc
whGW|
,V{Xl
~9:>:999=;
:'oiB
yj-Yl
17 0 obj
[@f- z
ookknnnm
%$feg
RV?3^
W'C=]
YeuW/
i_DhG?xZ
LwBax
9 0 obj
QhnbjA#2
NHOE1
wrrrZAp
[,-$oYj
0000179702 00000 n
t~tqqE
)*5{1
~"KJ?
=CF7nL
HMHC`
0000000299 00000 n
H5aNc!*
X3lf.
/Height 151
0000159249 00000 n
_^Qt3
/ID (node00000010)>>
j7<;u
<</Type /FontDescriptor
4 0 obj
I!K1}
{C?gi
teSU|Ha
F(5<P
18 0 obj
@c}MzJ
&CLlr
B+|p&
4|QLp$
104495
0000178991 00000 n
F]]n_
<GJrg
oinq~f
HjLFs=
/Parent 21 0 R>>
/FontDescriptor 35 0 R
a1ef!
MH366N
JsLZs
~\hx)F
gnoll
/MCID 3>>]
^2<:&
/Contents 20 0 R
yhgGKj--,
mI9f<
DA/[Z
,7';>.6(
4.###=-5:2
0<EZ~
a,xIIJ
$g 8@
/X15 15 0 R>>>>
lvbb|xxxhhpxddbrR*
0000164251 00000 n
8_vvLw!
;>HxR_Yfc
|}U:3
Fu/k&q
@KL7k
<YvXK7
C"?,x
/K 23 0 R
JIIN`
. >"9V
0000184377 00000 n
uB**EE
N!("b
#~H5"
CpvG=
jUfj/
teAd@
/Pg 2 0 R>>]
+++SS
8Qh0Z
m|(|A
abF#,
0000178667 00000 n
endobj
r<###
Q"iDO
lCi}\H
+..48
6 0 obj
ReOWZ
B%=,f.
mmm-XW
/StemV 172
/ID (node00000006)>>
K-nVK
xwfm'
=Akd(\\m1
<</Length1 3396
/SMask 14 0 R
/ParentTreeNextKey 1
/CIDToGIDMap /Identity
T85Ls
)RB>
^;\__
k=q_!
jli4"z
e =2^S
V:]lsm
/Length 13>> stream
/N 1>>
@~MvA
Kj#sF<
@]1*g
Fd#qR
h)Fi1T
8;3=*<
D0hZEX
uOXXH
15 0 obj
-+n`v9
+,,)-
7IP5eiI
N_e8EX;'-G
g`jhnjn
mvne5b
e@BM:
0000182747 00000 n
_]9lH
'__OO
?8815
8ZxI4
[7nl^
R,Wbg
!tDS:
.VR[
=<mzVN]}cGGGsSCA^Vhp
i>5h2
ec#C]
ngoeea
6E*ig
!'CA*
Nc== y
\_-z]
~Wm''
0000179737 00000 n
<</Size 38
<</F 4
2f(?^
.WIXh
0)P3sh
Okg'~A
/0$#;
7GG'4
Gr&n^
u3h@9
Hmy0?
/Coords [1296.82996 1783.25 3848.49 6046.2402]
7'(wa
_6gXGG!
M--Mu
.1o]apL
m8BWP
m1P@3%
startxref
260T0
`H9b^Q
64JZZZ
"Zc?{
,MZ3w.
GL~3Hx
<</Limits [(node00000001) (node00000010)]
uwjMV
B]p>Q
<R<Uf
t>P5?
/Width 301
]#r,*
q`\c.
#YyTE=
1ujzY
/S /URI
22 0 obj
0000165148 00000 n
O///T
h6Ai,
0000179501 00000 n
gd,}t
'Ovuu
J5]d2w
.}{;/U!|YQ
EA.+(
,lesN6AY#
x$qBQ
]e2^A
\5lVq
_g=.g
/Descent 350
.S."x
}Cm=o
`Ow7ak
X<"qx
sq$?Z
e?+()+
07O!c
yJ+45
/Length 81>> stream
^MS/f=
X/5[l
~/LTy
Wa(8r
fD9D(
/K%rjI
J;;TF*
0T[vfZX(
lnqqaf
=#ylB
(Nf u,w
o3 M
@K[f{n)
.JwP,n[i}
-ET"`
\]]]\]=<E~
/SMask 9 0 R
SS9;w
3Oz#<v
/S /Link
fx\(=
f$Lr2.?
11 0 obj
tqr051z
s^\+W
U pS:W
y>:::<<<`
yl b@
o~2&+
YJWsA
WFf1Ol
hpxx{ {
>N_Kw
4 oL=
-?Sere
rQ]7KWZi
P-UO=
g4JWP
T{*WnP
/Type /Annot
Bm69&
oM#Hbs%
uO@xN
/ColorSpace /DeviceRGB
14 0 obj
oC;M!$
0000179110 00000 n
4f.Xo&
LsH6d.?
a6tt"T
V6/(6:
t!4kS
Gl=P#6ukX
@Hqf\L]a
/PatternType 2
gha+'ia.
/Kids [2 0 R]>>
/ID (node00000008)>>
tvfdx
C#K+k
G&D>N
|lB195?
/Height 1
W>ehuya
:tvZ+U
<</ModDate (D:20230917220725+01'00')
`qI\K
34 0 obj
a<02j?
!P48T
FSZZ91
kVMWm
q6U=#
4/7'-
/MCID 1>>]
Mgz>,H
pf2{f,STtO
sjcXe
-&&k%
1`"0o)mf
dYBe:
"22**2
e&@2^GT
v~73.
!JbN^A]
rRMW0}
i#aA*gn
*q*=*Rji70
\m}2h
L$uV8
8bL"~
/G18 18 0 R>>
E)HwT
J-E?J
&AJ ;x
/K [<</Type /MCR
_V.8t
-F_`$
ln~a^6:
rz3'^sJ%GGk
j8+|iM
19==?/
|VvNQQ
LIX<D
3DX?':
"lX_[
NrH<h
;7#E(p/
2 0 obj
:{Mhn
10 0 obj
Jj5##c
X@V]2E
HasBb5
/Count 1
X?8@`
V4cGk
t)2p;
l)V5wR
y}Qo~:
1b r8
AngxOa
&J@X)
j^[y{
/S /NonStruct
28 0 obj
/Pages 21 0 R
1%Guc
/PaintType 1
1i-:C
/K = \
GEr"Z
u~;N r;
:_NuI
<</Type /Font
/Length 3773>> stream
3{fddd
F{+thig{kYi1
aM+/O
/MCID 2>>]
f<aJ#
I&o/M(lD
.nA!a
1M,S1.
rrrB'
+]CNf
/MCID 0>>]
4dH8c
XZQM2
31 0 obj
ug{s^6
x#`J7M
Pw-Q/B
/StructParent 100000>>
yG+~^
/Info 1 0 R
vun.;
Bzk-!
nhd47
EH^[Sg4
,Fsk,
LK/,*ilj
/FunctionType 2
R 5Fz
]9IB#
%tvMWC\
apxtaiy
aidi6c
G}q:;
N![H'
/SMask 7 0 R
0000179844 00000 n
[gn=LJ
JlZ&s
l~nmm}gw
}xg^;66E;
<</ca 1
89{zz
/k6Z&9
|v:US;]0Q13
*Ke"P
]+{{;
bpnD'
/Extend [true true]
q#v4{
\W*hX
K~>ey
D0`GD~
N]yFg

Yara Details

Strings
  • %PDF
  • trailer
  • %%EOF
String Name: Address
  • magic: 0
  • s0: 184732
  • s1: 184817

PDF Information

Total Entropy 7.986129
Entropy In Streams 7.994827
Entropy Out of Streams 0.000000
Count of "%% EOF" 2
PDF Header %PDF-1.4
Data After EOF 0 bytes
File Size 184824 bytes
Number of Pages 1

PDF Date(s)

Name Value
/CreationDate 2023/07/01 09:31:47 GMT+00
/ModDate 2023/07/01 09:31:47 GMT+00
/CreationDate 2023/07/01 09:31:47 GMT+00
/ModDate 2023/09/17 22:07:25 GMT+01

Keyword Counts

Keyword Count
obj 39
endobj 39
stream 14
endstream 14
xref 2
trailer 2
startxref 2
/Page 1
/Encrypt 0
/ObjStm 0
/JS 0
/JavaScript 0
/AA 0
/OpenAction 0
/AcroForm 0
/JBIG2Decode 0
/RichMedia 0
/Launch 0
/EmbeddedFile 0
/XFA 0
/Colors > 2^24 0


Reports: JSON HTML Lite

Credential Access Discovery Command and Control Defense Evasion Privilege Escalation Execution
  • T1003 - OS Credential Dumping
    • registry_credential_store_access
  • T1082 - System Information Discovery
    • antivm_checks_available_memory
  • T1071 - Application Layer Protocol
    • binary_yara
  • T1055 - Process Injection
    • resumethread_remote_process
  • T1070 - Indicator Removal
    • deletes_files
  • T1070.004 - File Deletion
    • deletes_files
  • T1055 - Process Injection
    • resumethread_remote_process
  • T1203 - Exploitation for Client Execution
    • exploit_heapspray

Usage


Processing ( 3.58 seconds )

  • 2.94 CAPE
  • 0.624 BehaviorAnalysis
  • 0.007 Heatmap
  • 0.003 AnalysisInfo
  • 0.001 Debug

Signatures ( 0.09 seconds )

  • 0.021 antiav_detectreg
  • 0.009 territorial_disputes_sigs
  • 0.008 infostealer_ftp
  • 0.005 antianalysis_detectreg
  • 0.004 antiav_detectfile
  • 0.004 infostealer_im
  • 0.004 masquerade_process_name
  • 0.004 ransomware_files
  • 0.003 antianalysis_detectfile
  • 0.003 infostealer_mail
  • 0.003 ransomware_extensions
  • 0.002 antidebug_devices
  • 0.002 antivm_vbox_files
  • 0.002 antivm_vbox_keys
  • 0.002 antivm_vmware_keys
  • 0.002 infostealer_bitcoin
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_parallels_keys
  • 0.001 antivm_vpc_keys
  • 0.001 antivm_xen_keys
  • 0.001 ketrican_regkeys
  • 0.001 geodo_banking_trojan
  • 0.001 darkcomet_regkeys
  • 0.001 poullight_files
  • 0.001 revil_mutexes
  • 0.001 limerat_regkeys
  • 0.001 recon_fingerprint
  • 0.001 remcos_regkeys
  • 0.001 ursnif_behavior

Reporting ( 2.79 seconds )

  • 2.671 MITRE_TTPS
  • 0.044 ReportHTML
  • 0.039 LiteReport
  • 0.036 JsonDump

Signatures

Checks available memory
A possible heap spray exploit has been detected
Queries the keyboard layout
SetUnhandledExceptionFilter detected (possible anti-debug)
Accessed credential storage registry keys
regkey: HKEY_LOCAL_MACHINE\System
Deletes files from disk
DeletedFile: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
DeletedFile: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
DeletedFile: C:\Users\user\AppData\Local\Temp\A91qd0lqx_dbfhu8_380.tmp
DeletedFile: C:\Users\user\AppData\Local\Temp\A9oh4lqr_dbfhu9_380.tmp
Resumed a thread in another process
thread_resumed: Process acrobat.exe with process ID 4176 resumed a thread in another process with the process ID 4176
thread_resumed: Process explorer.exe with process ID 4596 resumed a thread in another process with the process ID 4596
Checks for presence of debugger via IsDebuggerPresent
Binary file triggered YARA rule
Binary triggered YARA rule: multiple_versions

Screenshots

No playback available.

Hosts

No hosts contacted.

DNS

No domains contacted.

Summary

C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.3.Manifest
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
C:\Program Files\Adobe
C:\Program Files\Adobe\Acrobat DC\Acrobat
C:\Windows\System32\ntmarta.dll
C:\Windows\System32\KBDUS.DLL
C:\Windows\System32\kernel.appcore.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\user\AppData\Local\Temp\agm.ini
C:\agm.ini
C:\Users\user\AppData\Local\Adobe\Acrobat\DC
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin
C:\Windows\system32
C:\Windows
C:\Program Files\Adobe\Acrobat DC\Acrobat\XmlLite.dll
C:\Windows\System32\xmllite.dll
C:\Windows\System32\shell32.dll
C:\Windows\System32\spool\drivers\color\D65.camp
C:\Windows\System32\spool\drivers\color\Photo.gmmp
C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
C:\Windows\Fonts\staticcache.dat
C:\Program Files\Adobe\Acrobat DC\Acrobat\TextShaping.dll
C:\Windows\System32\TextShaping.dll
C:\Windows\System32\twinapi.appcore.dll
C:\Program Files\Adobe\Acrobat DC\Acrobat\
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\SendMail.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Spelling.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\MakeAccessible.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\SaveAsRTF.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Search.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\AcroForm.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\PDDom.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\DigSig.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\PPKLite.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Accessibility.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\EScript.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\weblink.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Annots.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Multimedia.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\reflow.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\DVA.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\IA32.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Checkers.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Updater.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\ReadOutLoud.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\MSRMS.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\DropboxStorage.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\eBook.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\StorageConnectors.api
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\*.*
C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\*.api
C:\Users\user\AppData\Local\Temp\87455c255848e08c1e95.pdf
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat
C:\Windows\System32
C:\Users\user\AppData\Local\Temp
C:\program files\Adobe\acrobat dc\SystemResources\acrobatres.dll.mun
C:\Windows\System32\textinputframework.dll
C:\Windows\System32\CoreUIComponents.dll
C:\Windows\System32\CoreMessaging.dll
C:\Windows\System32\WinTypes.dll
C:\Program Files\Adobe\Acrobat DC\Acrobat\PROPSYS.dll
C:\Windows\System32\propsys.dll
C:\Windows\SysWOW64\propsys.dll
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Viewer.aapp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\Privileged\DC\JavaScripts
C:\Program Files\Adobe\Acrobat DC\Acrobat\JavaScripts
C:\Program Files\Adobe\Acrobat DC\Acrobat\JavaScripts\*
C:\Windows\System32\globinputhost.dll
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
C:\Users\user\AppData\Local\Temp\A92ueklm_dbfhu2_380.tmp
C:\
C:\Users\user\AppData\Roaming\Adobe\CoreSync\plugins\livetype\r\
C:\Program Files\Common Files
C:\Program Files
C:\Users\user\AppData\Local\Microsoft\Windows\Caches
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000016.db
C:\Program Files\desktop.ini
C:\Program Files\Common Files\Adobe
C:\Users
C:\Users\desktop.ini
C:\Users\user
C:\Users\user\AppData
C:\Users\user\AppData\Local
C:\Users\user\Desktop\desktop.ini
C:\Users\user\Documents\desktop.ini
C:\Users\user\Music\desktop.ini
C:\Users\user\Pictures\desktop.ini
C:\Users\user\Videos\desktop.ini
C:\Users\user\Downloads\desktop.ini
C:\Users\user\AppData\Local\Adobe
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeComFnt23.lst
C:\Program Files\Common Files\Adobe\Fonts\Reqrd\CMaps\*.*
C:\Program Files\Common Files\Adobe\Fonts\*.*
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Reqrd\CMaps\*.*
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\*.*
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H
C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-V
C:\Users\user\AppData\Roaming\Adobe\PseudoFontsCache\AdobeFnt_PseudoFonts.lst
C:\Users\user\AppData\Roaming\Adobe\CoreSync\plugins\livetype\w\Reqrd\CMaps\*.*
C:\Users\user\AppData\Roaming\Adobe\CoreSync\plugins\livetype\w\*.*
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AcroFnt23.lst
C:\Program Files\Adobe\Acrobat DC\Resource\CIDFont\*.*
C:\Program Files\Adobe\Acrobat DC\Resource\Font\*.*
C:\Program Files\Adobe\Acrobat DC\Resource\Font\AdobePIStd.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-Bold.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-BoldOblique.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-Oblique.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-Bold.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-BoldIt.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-It.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-Regular.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-Bold.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-BoldIt.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-It.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-Regular.otf
C:\Program Files\Adobe\Acrobat DC\Resource\Font\SY______.PFB
C:\Program Files\Adobe\Acrobat DC\Resource\Font\SY______.pfm
C:\Program Files\Adobe\Acrobat DC\Resource\Font\Pfm\SY______.PFM
C:\Program Files\Common Files\Adobe\TypeSupport
C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZX______.PFB
C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZX______.mmm
C:\Program Files\Adobe\Acrobat DC\Resource\Font\mmm\ZX______.mmm
C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZY______.PFB
C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZY______.mmm
C:\Program Files\Adobe\Acrobat DC\Resource\Font\mmm\ZY______.mmm
C:\Program Files\Adobe\Acrobat DC\Resource\Font\Pfm\*.*
C:\Program Files\Adobe\Acrobat DC\Resource\Font\Pfm\zx______.pfm
C:\Program Files\Adobe\Acrobat DC\Resource\Font\Pfm\zy______.pfm
C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1
C:\Users\user\AppData\Local\Temp\acrocef_low
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-wal
C:\Program Files\Adobe\Acrobat DC\Resource\CIDFont
C:\Users\user\AppData\Roaming\Adobe\CoreSync\plugins\livetype\w\
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storek
C:\Program Files\Adobe\Acrobat DC\Acrobat\DPAPI.dll
C:\Windows\System32\dpapi.dll
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\EPDF_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\version.js
C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\variant.js
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-wal
C:\Users\user\AppData\Local\Temp\acroNGLLog.txt
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\libcef.dll
C:\Users\user\AppData\Local\Temp\A9129ncec_dbfhu3_380.tmp
C:\Users\user\AppData\Local\Temp\NGL\NGLClientDefault.trace
C:\Users\user\AppData\Local\Temp\NGL\NGLClientDefault.debug
C:\Users\user\AppData\Local\Temp\NGL\asu.trace
C:\Users\user\AppData\Local\Temp\NGL\asu.debug
C:\Users\user\AppData\Local\Temp\NGL\
C:\ProgramData\Adobe\OperatingConfigs\QWNyb2JhdFJlYWRlcjF7fTIwMTgwNzIwMDQ-*.operatingconfig
C:\ProgramData\Adobe\OperatingConfigs\QWNyb2JhdFJlYWRlcjF7*.operatingconfig
C:\ProgramData\Adobe\OperatingConfigs\QWNyb2JhdFJlYWRlcjE.bc
C:\Users\user\AppData\Local\Temp\NGL\NGLClient_Ingest.nglconfig
C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow
C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe
C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe
C:\Users\user\AppData\Local\Adobe\OOBE\temp_lbs_wid
C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources
C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources\ui\index.html
C:\ProgramData\Adobe\OperatingConfigs\EnableIEBrowserWF.CONFIG
C:\ProgramData\Adobe\OperatingConfigs\EnableUrlLogging.CONFIG
C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources\cef_strings.json
C:\Users\user\AppData\Local\Temp\NGL\NGLClient_AcrobatReader1.ngllogcontrolconfig
C:\Users\user\AppData\Local\Adobe\licflags
\??\PhysicalDrive0
C:\Windows\Temp
C:\Program Files\Windows Defender\MpOAV.dll
C:\Windows\System32\ci.dll
C:\Windows\System32\dnsapi.dll
C:\Windows\System32\fveui.dll
C:\Windows\System32\wuaueng.dll
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
C:\Windows\System32\NgcRecovery.dll
C:\Windows\System32\en-US\CRYPT32.dll.mui
C:\Windows\System32\gpapi.dll
C:\Users\user\AppData\Local\Temp\A913n6tsq_dbfhu4_380.tmp
C:\Users\user\AppData\Local\Temp\A9hayf8w_dbfhu5_380.tmp
C:\Program Files\Adobe\Acrobat DC\Acrobat\iertutil.dll
C:\Windows\System32\iertutil.dll
C:\Program Files\Adobe\Acrobat DC\Acrobat\IPHLPAPI.DLL
C:\Windows\System32\IPHLPAPI.DLL
C:\Windows\System32\winnsi.dll
\??\Nsi
\??\pipe\com.adobe.acrobat.rna.user.DC.0
C:\Users\user\AppData\Local\Temp\A9kx7wv3_dbfhu6_380.tmp
C:\Users\user\AppData\Local\Temp\A914b6hzu_dbfhu7_380.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences
C:\Users\user\AppData\Local\Temp\NGL\NGLClient_AcrobatReader123.6.20320.6 *
C:\Users\user\AppData\Local\Temp\NGLClient_AcrobatReader123.6.20320.6 *
C:\Users\user\Downloads\Acrobat_Set-Up.exe
C:\Users\user\Downloads\Acrobat_DC_Set-Up.exe
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\UICustomization
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\*
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\ConvertPDF_Full.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\AppCenter_R.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Home.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Certificates_R.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\CollectSignatures.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\InAppSign.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Comments.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\FillSign.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Measure.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Stamp.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\UnifiedShare.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\CPDF_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\ConvertPDF_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\CPDF_Full.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Combine_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Developer_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Pages_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\EPDF_Full.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\TrackedSend.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Edit_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Edit_R_Full.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Edit_R_Menu.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\MoreTools.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Index_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\RichMedia_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\CCX_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Redact_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Protect_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\OptimizePDF_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\OptimizePDF_R_CTX.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Review_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Scan_R_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Edit_R_Exp_RHP.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Edit_DelayedPaywall.aapp
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\
C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\
C:\Users\user\AppData\Local\Temp\
C:\Users\user\AppData\Local\Temp\A91qd0lqx_dbfhu8_380.tmp
\Device\RasAcd
C:\Users\user\AppData\Local\Temp\A9oh4lqr_dbfhu9_380.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Forms\
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Forms\AdhocWorkflow
C:\Program Files\Common Files\Adobe\Acrobat\DC\
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2
C:\Users\user\AppData\Local\Temp\lilo.4176
C:\Program Files\Common Files\Adobe\Linguistics\10.0\LanguageNames2
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\
C:\Providers\Plugins2\
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\plugin.X.manifest
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Info.plist
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\all
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Adobe\Products.txt
\??\mailslot\Lilo1
\??\mailslot\Lilo10
\??\mailslot\Lilo11
\??\mailslot\Lilo12
\??\mailslot\Lilo13
\??\mailslot\Lilo14
\??\mailslot\Lilo15
\??\mailslot\Lilo16
\??\mailslot\Lilo17
\??\mailslot\Lilo18
\??\mailslot\Lilo19
\??\mailslot\Lilo2
\??\mailslot\Lilo20
\??\mailslot\Lilo21
\??\mailslot\Lilo22
\??\mailslot\Lilo23
\??\mailslot\Lilo24
\??\mailslot\Lilo25
\??\mailslot\Lilo26
\??\mailslot\Lilo27
\??\mailslot\Lilo28
\??\mailslot\Lilo29
\??\mailslot\Lilo3
\??\mailslot\Lilo30
\??\mailslot\Lilo31
\??\mailslot\Lilo32
\??\mailslot\Lilo33
\??\mailslot\Lilo34
\??\mailslot\Lilo35
\??\mailslot\Lilo36
\??\mailslot\Lilo37
\??\mailslot\Lilo38
\??\mailslot\Lilo39
\??\mailslot\Lilo4
\??\mailslot\Lilo40
\??\mailslot\Lilo41
\??\mailslot\Lilo42
\??\mailslot\Lilo43
\??\mailslot\Lilo44
\??\mailslot\Lilo45
\??\mailslot\Lilo46
\??\mailslot\Lilo47
\??\mailslot\Lilo48
\??\mailslot\Lilo49
\??\mailslot\Lilo5
\??\mailslot\Lilo50
\??\mailslot\Lilo51
\??\mailslot\Lilo52
\??\mailslot\Lilo53
\??\mailslot\Lilo54
\??\mailslot\Lilo55
\??\mailslot\Lilo56
\??\mailslot\Lilo57
\??\mailslot\Lilo58
\??\mailslot\Lilo59
\??\mailslot\Lilo6
\??\mailslot\Lilo60
\??\mailslot\Lilo61
\??\mailslot\Lilo62
\??\mailslot\Lilo63
\??\mailslot\Lilo64
\??\mailslot\Lilo65
\??\mailslot\Lilo66
\??\mailslot\Lilo67
\??\mailslot\Lilo68
\??\mailslot\Lilo69
\??\mailslot\Lilo7
\??\mailslot\Lilo70
\??\mailslot\Lilo71
\??\mailslot\Lilo72
\??\mailslot\Lilo73
\??\mailslot\Lilo74
\??\mailslot\Lilo75
\??\mailslot\Lilo76
\??\mailslot\Lilo77
\??\mailslot\Lilo78
\??\mailslot\Lilo79
\??\mailslot\Lilo8
\??\mailslot\Lilo80
\??\mailslot\Lilo81
\??\mailslot\Lilo82
\??\mailslot\Lilo83
\??\mailslot\Lilo84
\??\mailslot\Lilo85
\??\mailslot\Lilo86
\??\mailslot\Lilo87
\??\mailslot\Lilo88
\??\mailslot\Lilo89
\??\mailslot\Lilo9
\??\mailslot\Lilo90
\??\mailslot\Lilo91
\??\mailslot\Lilo92
\??\mailslot\Lilo93
\??\mailslot\Lilo94
\??\mailslot\Lilo95
\??\mailslot\Lilo96
\??\mailslot\Lilo97
\??\mailslot\Lilo98
\??\mailslot\Lilo99
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\ar_AE
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\bg_BG
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\ca_ES
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\cs_CZ
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\da_DK
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\de_CH
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\de_DE
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\el_GR
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\es_ES
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\et_EE
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\fr_FR
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\fr_CA
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\he_IL
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\hr_HR
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\hu_HU
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\it_IT
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\lt_LT
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\lv_LV
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\nb_NO
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\nl_NL
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\nn_NO
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\pl_PL
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\pt_BR
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\pt_PT
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\ro_RO
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\ru_RU
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\sk_SK
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\sl_SI
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\sv_SE
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\tr_TR
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\uk_UA
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\Dictionaries\th_TH
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\bn_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\gu_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\hi_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\kn_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ml_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\mr_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\or_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\pa_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\ta_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\te_IN
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\de_CH
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\de_DE
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\en_CA
C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\LanguageNames2\DisplayLanguageNames.en_US.txt
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\en_GB
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\en_US
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\nl_NL
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\pt_BR
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\id_ID
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\km_KH
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\lo_LA
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\my_MM
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\UserDictionaries\Adobe Custom Dictionary\si_LK
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\
C:\Windows\System32\edputil.dll
C:\Windows\bcastdvr\KnownGameList.bin
C:\Windows\bcastdvr
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles\CachedImage_1024_768_POS4.jpg
C:\Users\user\AppData\Local\Microsoft\PenWorkspace
C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
\Device\Bam
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f065ac336abcaa3e.automaticDestinations-ms
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\CachedFiles
C:\Windows\System32\ApplicationFrameHost.exe
C:\Windows\System32\capauthz.dll
C:\Windows\ImmersiveControlPanel\resources.pri
C:\Windows\ImmersiveControlPanel\pris\resources*.pri
C:\Windows\rescache\_merged\987641329\29879607.pri
C:\Windows\ImmersiveControlPanel\pris\resources.en-US.pri
C:\Windows\System32\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
C:\Windows\ImmersiveControlPanel\desktop.ini
C:\Windows\ImmersiveControlPanel
C:\Windows\ImmersiveControlPanel\images
C:\Windows\ImmersiveControlPanel\images\desktop.ini
C:\Windows\ImmersiveControlPanel\images\logo.scale-100_altform-unplated.png
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
C:\Users\user\AppData\Local\Temp\acroNGLLog.txt
C:\Users\user\AppData\Local\Temp\NGL\
\??\pipe\com.adobe.acrobat.rna.user.DC.0
C:\Users\user\AppData\Local\Temp\A91qd0lqx_dbfhu8_380.tmp
\Device\RasAcd
C:\Users\user\AppData\Local\Temp\A9oh4lqr_dbfhu9_380.tmp
\??\mailslot\Lilo1
\??\mailslot\Lilo10
\??\mailslot\Lilo11
\??\mailslot\Lilo12
\??\mailslot\Lilo13
\??\mailslot\Lilo14
\??\mailslot\Lilo15
\??\mailslot\Lilo16
\??\mailslot\Lilo17
\??\mailslot\Lilo18
\??\mailslot\Lilo19
\??\mailslot\Lilo2
\??\mailslot\Lilo20
\??\mailslot\Lilo21
\??\mailslot\Lilo22
\??\mailslot\Lilo23
\??\mailslot\Lilo24
\??\mailslot\Lilo25
\??\mailslot\Lilo26
\??\mailslot\Lilo27
\??\mailslot\Lilo28
\??\mailslot\Lilo29
\??\mailslot\Lilo3
\??\mailslot\Lilo30
\??\mailslot\Lilo31
\??\mailslot\Lilo32
\??\mailslot\Lilo33
\??\mailslot\Lilo34
\??\mailslot\Lilo35
\??\mailslot\Lilo36
\??\mailslot\Lilo37
\??\mailslot\Lilo38
\??\mailslot\Lilo39
\??\mailslot\Lilo4
\??\mailslot\Lilo40
\??\mailslot\Lilo41
\??\mailslot\Lilo42
\??\mailslot\Lilo43
\??\mailslot\Lilo44
\??\mailslot\Lilo45
\??\mailslot\Lilo46
\??\mailslot\Lilo47
\??\mailslot\Lilo48
\??\mailslot\Lilo49
\??\mailslot\Lilo5
\??\mailslot\Lilo50
\??\mailslot\Lilo51
\??\mailslot\Lilo52
\??\mailslot\Lilo53
\??\mailslot\Lilo54
\??\mailslot\Lilo55
\??\mailslot\Lilo56
\??\mailslot\Lilo57
\??\mailslot\Lilo58
\??\mailslot\Lilo59
\??\mailslot\Lilo6
\??\mailslot\Lilo60
\??\mailslot\Lilo61
\??\mailslot\Lilo62
\??\mailslot\Lilo63
\??\mailslot\Lilo64
\??\mailslot\Lilo65
\??\mailslot\Lilo66
\??\mailslot\Lilo67
\??\mailslot\Lilo68
\??\mailslot\Lilo69
\??\mailslot\Lilo7
\??\mailslot\Lilo70
\??\mailslot\Lilo71
\??\mailslot\Lilo72
\??\mailslot\Lilo73
\??\mailslot\Lilo74
\??\mailslot\Lilo75
\??\mailslot\Lilo76
\??\mailslot\Lilo77
\??\mailslot\Lilo78
\??\mailslot\Lilo79
\??\mailslot\Lilo8
\??\mailslot\Lilo80
\??\mailslot\Lilo81
\??\mailslot\Lilo82
\??\mailslot\Lilo83
\??\mailslot\Lilo84
\??\mailslot\Lilo85
\??\mailslot\Lilo86
\??\mailslot\Lilo87
\??\mailslot\Lilo88
\??\mailslot\Lilo89
\??\mailslot\Lilo9
\??\mailslot\Lilo90
\??\mailslot\Lilo91
\??\mailslot\Lilo92
\??\mailslot\Lilo93
\??\mailslot\Lilo94
\??\mailslot\Lilo95
\??\mailslot\Lilo96
\??\mailslot\Lilo97
\??\mailslot\Lilo98
\??\mailslot\Lilo99
C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
C:\Users\user\AppData\Local\Temp\A91qd0lqx_dbfhu8_380.tmp
C:\Users\user\AppData\Local\Temp\A9oh4lqr_dbfhu9_380.tmp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\UBR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockdown
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\FeatureState
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\FeatureState
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\bIsSingleClientApp
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\bIsSCAcroAppInstalled
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\SCAPackageLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\IsAcrInstalledInRdrMode
HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Privileged
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged\bProtectedMode
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Keyboard Layout\Preload
HKEY_CURRENT_USER\Keyboard Layout\Preload\1
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000409
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layouts\00000409\Layout File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layouts\00000409\Attributes
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Security
bEnforceReadRestrictions
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged\bEnforceReadRestrictions
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged\bEnableEventViewerLogging
HKEY_CLASSES_ROOT\Software\Adobe\Acrobat\Exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\Adobe\Acrobat\Exe\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\SoftGrid
HKEY_CURRENT_USER\SOFTWARE\Adobe\AcroPerf
HKEY_CLASSES_ROOT\Software\Adobe\Acrobat\MURD
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVGeneral
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\bEnableThemedScrollBar
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en
HKEY_LOCAL_MACHINE\System
HKEY_LOCAL_MACHINE\Software\Adobe
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Installer\Migrated
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Language\path
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Language\path
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Language\select
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Language\UseMUI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Language\UseMUI\bUseMUI
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Language\next
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Language\next\(Default)
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Language\current
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Language\current\(Default)
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AdobeViewer
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\MaxDoc
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\MaxApp
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\PrintToFile
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DontMarkPostScriptJob
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\bDocumentsInTaskbar
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\SDI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SDI\bNullDocMaximized
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Originals
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Originals\bDisplayedSplash
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Adobe\Adobe Acrobat\DC\FeatureState
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\23.0\AVPrivate
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\6.0\Installer
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\sMRUList
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cDockables
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cEditMenuRationalizeExperiment
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\aFS
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\tDIText
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\tFileName
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sFileAncestors
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sDI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sDate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sAssetId
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentToolsList
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRHPAlignmentExperiment
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cTaskPanes
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cTaskPanes\cBasicCommentPane
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars\cAdvCommenting
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars\cBasicCommenting
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars\cCommenting
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cToolbars\cCommenting\cStamp
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cUUIDs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cUUIDs\suser
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVGeneral
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\TestChecks
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\TestChecks
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVPrivate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\iLogLevel
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Private
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Private
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVDisplay
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVDisplay
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\ProductInfoCache
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AdobeViewer
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\ProductInfoCache
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ExitSection
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection\bLastExitNormal
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConversionToPDF\cSettings
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVConversionToPDF
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConversionFromPDF\cSettings
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVConversionFromPDF
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\EnableProcAnalyticsLogging
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\EnableProcAnalyticsLogging
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\FeatureLockdown
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\UsageMeasurement
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\UsageMeasurement
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC\Acrobat.com\
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Synchronizer\DC\Acrobat.com\bThirdPartyLogSession
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bDumpStartupZStrings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\iuiStringFilter
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\SendForSignature
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\SendForSignature
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\RIF
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\RIF
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Selection
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Selection\aDefaultSelect
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Selection
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Touch
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Touch
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Intl
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Intl
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Security
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c290FA7E61053E8763C6055E6333A99EFB83ECACB
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c290FA7E61053E8763C6055E6333A99EFB83ECACB\cAdobe_OCSPRevChecker
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c290FA7E61053E8763C6055E6333A99EFB83ECACB\cAdobe_OCSPRevChecker\cAuthorizedResponder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c290FA7E61053E8763C6055E6333A99EFB83ECACB\cAdobe_OCSPRevChecker\cAuthorizedResponder\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s9
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cAuthorizedResponder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cAuthorizedResponder\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSendNonce
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSendNonce\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSignCertOID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSignCertOID\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSignCertOID\c0\sValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSignRequest
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSignRequest\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cURLToConsult
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cURLToConsult\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s9
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cAuthorizedResponder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cAuthorizedResponder\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSendNonce
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSendNonce\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSignCertOID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSignCertOID\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSignCertOID\c0\sValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSignRequest
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSignRequest\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cURLToConsult
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cURLToConsult\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_ChainBuilder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_ChainBuilder\cAllowCAToIssueAC
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_ChainBuilder\cAllowCAToIssueAC\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_ChainBuilder\cCheckCABasicConstraints
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_ChainBuilder\cCheckCABasicConstraints\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_CRLRevChecker
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_CRLRevChecker\cRequireAKI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_CRLRevChecker\cRequireAKI\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_OCSPRevChecker
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_OCSPRevChecker\cAllowOCSPNoCheck
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_OCSPRevChecker\cAllowOCSPNoCheck\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_OCSPRevChecker\cRequireOCSPCertHash
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_OCSPRevChecker\cRequireOCSPCertHash\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_Validation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_Validation\cValidityModel
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E332E33362E382E312E310000\cAdobe_Validation\cValidityModel\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cDigSig
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cDigSig\cCustomDownload
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cPPKHandler
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\FlashDebug
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\FlashDebug
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVAlert
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVAlert
HKEY_CLASSES_ROOT\.pdf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdf\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice
HKEY_CLASSES_ROOT\CLSID\{591209C7-767B-42B2-9FBA-44EE4615F2C7}\Instance
HKEY_CLASSES_ROOT\.pdf\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithProgids
HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Extensions\windows.fileTypeAssociation\.pdf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList\MRUList
HKEY_CLASSES_ROOT\Acrobat.Document.DC
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Acrobat.Document.DC\AllowSilentDefaultTakeOver
HKEY_CURRENT_USER\Software\Classes\Acrobat.Document.DC\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Acrobat.Document.DC\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Acrobat.Document.DC\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Acrobat.Document.DC\Progid
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\IMS
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\IMS
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ShareIdentity
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ShareIdentity
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC\Acrobat.com
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Synchronizer\DC\Acrobat.com\tActiveSettings
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC\Acrobat.com.v2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Synchronizer\DC\Acrobat.com.v2\tActiveSettings
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AcroApp
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\sLocale
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a9
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFeatured
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c35
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c35\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c36
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c37
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c38
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c39
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c40
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c41
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c42
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c43
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c9
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AcroApp
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-1033-FF00-7760-BC15014EA700}
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Workflows
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Workflows\cServices
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Workflows\cServices\cAccessLevelsConfiguration
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Workflows\cServices\cScanAppKillSwitch
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Workflows
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\IPM
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\IPM
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\sDailyAnalyticsLastSyncDate
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVPrivate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bLoadAllPluginsAtStartup
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\VirgoLeftRail
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\VirgoLeftRail
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ArmUpsell
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ArmUpsell
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ARMReqManager
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ARMReqManager
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\SCA
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\SCA
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\FillSign
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\FillSign
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\InstallPath
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\InstallPath
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AcroLogging
HKEY_LOCAL_MACHINE\Software\Adobe\Licensing\FeatureRestrictedLicensing
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\MicrosoftAIP
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\MicrosoftAIP
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Originals\sProofingSpace
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Originals
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClusSvc
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\ProfileAssociations\Display
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96e-e325-11ce-bfc1-08002be10318}\0002
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\ProfileAssociations\Display\{4d36e96e-e325-11ce-bfc1-08002be10318}\0002
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\TrustManager
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\TrustManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_CURRENT_USER\Software\Classes\AppID\Acrobat.exe
HKEY_CURRENT_USER\Software\Classes\AppID\{DE43C480-3D61-480E-8DB9-CC22422A878D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_CURRENT_USER\Software\Classes\Interface\{00000160-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\Extensions
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\WebResource
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bEnableFlickerFreeDrawing
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\SessionManagement
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsPrev
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsPrev\cWin0
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\SessionManagement
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\SDI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bShowAds
HKEY_CURRENT_USER\Software\Classes\.pdf
HKEY_CURRENT_USER\Software\Classes\Acrobat.Document.DC
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\FTEDialog
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\FTEDialog
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\VirgoHome
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\VirgoHome
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AutoSaveDocs
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AutoSaveDocs
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVEntitlement
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sAppEntitlementStatus
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sDeviceID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductVersion
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sUserEmail
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sUserGUID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductName
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductGUID
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVEntitlement
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\TMS
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\TMS
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\WebResource
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Collab
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cDocumentCenter
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cDocumentCenter\cSettings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cEmailDistribution
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cEmailDistribution\cSettings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cInitiationWizardFirstLaunch
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cInternalServer
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cInternalServer\cSettings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Collab\cServerSettings
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Collab
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cTrustedFolders\cTrustedForPV
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\TrustManager\cTrustedFolders\cTrustedForPV
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cTrustedSites\cTrustedForPV
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\TrustManager\cTrustedSites\cTrustedForPV
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cTrustedSitesPrivate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\TrustManager
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\23.1536\AVPrivate
HKEY_CURRENT_USER\Control Panel\Cursors
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ADM
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ADM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\Acrobat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\IPMExperiments
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\IPMExperiments
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ConvertPDFExperiment
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ConvertPDFExperiment
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AdvancedSignTools
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AdvancedSignTools
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ToolCenterApps
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ToolCenterApps
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\HomeWelcome
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\HomeWelcome
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\UnifiedShare
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\UnifiedShare
HKEY_CLASSES_ROOT\CLSID\{56AD4C5D-B908-4F85-8FF1-7940C29B3BCF}\Instance
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ToolsSearch
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ToolsSearch
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CURRENT_USER\Control Panel\Desktop\CaretWidth
HKEY_CURRENT_USER\Control Panel\Desktop\CursorBlinkRate
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\Diagnosis
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ExportPDFExperiment
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ExportPDFExperiment
HKEY_CURRENT_USER\Software\Adobe\AcroPerf
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AdobeSignExperiments
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AdobeSignExperiments
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Preview
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Preview
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bEnableIdleDrawing
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Access
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Access
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\LayoutAndZoom
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\LayoutAndZoom
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC\ACPMigrationAcrobat
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Workflow
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Workflow
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Citrix
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Citrix\ProductVersion
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Annots
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cAnnot
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cFreeText_003aFreeTextCallout
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cFreeText_003aFreeTextCallout\cstrokeColor
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cHighlight_003aHighlightNote
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cHighlight_003aHighlightNote\cstrokeColor
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cLine_003aLineArrow
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Annots\cAnnots\cLine_003aLineArrow\cstrokeColor
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Annots
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bExternalIcons
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\TaskButtons
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\TaskButtons
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\NoTimeOut
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\NoTimeOut
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bPluginNotice
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\RememberedViews
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\RememberedViews
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\MeasuringGeo
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\MeasuringGeo
HKEY_CURRENT_USER\Software\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}
HKEY_CURRENT_USER\Software\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}
HKEY_CURRENT_USER\Software\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85DE1C45-2C66-101B-B02E-04021C009402}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}
HKEY_CURRENT_USER\Software\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72498821-3203-101B-B02E-04021C009402}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}
HKEY_CURRENT_USER\Software\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF76CB60-2E68-101B-B02E-04021C009402}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EAF0840-690A-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C400-4E34-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{335E7240-6B49-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C401-4E34-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D12C402-4E34-101B-9CA8-9240CE2738AE}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3F0-4981-101B-9CA8-9240CE2738AE}
HKEY_LOCAL_MACHINE\Software\Classes\PackagedCom
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3E8-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3E7-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3F1-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3ED-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3E6-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3EC-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{9B4CD3EE-4981-101B-9CA8-9240CE2738AE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{FD888B93-6CBF-4A6E-ADCB-652F5E04D0D7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-100000000000}\
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_CURRENT_USER\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CLASSES_ROOT\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Classes\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_CURRENT_USER\Software\Classes\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_CURRENT_USER\Software\Classes\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-932793227-1321892499-785312009-1001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\IdListAliasTranslations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\IdListAliasTranslations
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Type 1 Installer\Type 1 Fonts
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\CCX
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\CCX
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\NewUserForModernizationFlushed2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-932793227-1321892499-785312009-1001\Installer\UpgradeCodes\66EDAE6A0000000084E4E7A854000000
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001\Software\Microsoft\Installer\UpgradeCodes\66EDAE6A0000000084E4E7A854000000
HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\66EDAE6A0000000084E4E7A854000000
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\HomeViewFirstMileSophiaContent
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\HomeViewFirstMileSophiaContent
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\CoolOffProcSchedulerSection
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\CoolOffProcSchedulerSection
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\CEF
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\CEF
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\BlueHeron
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\BlueHeron
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVGeneral\CrashDataAtLaunch
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\CrashDataAtLaunch\iCrashCountAtLaunch
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\bNGLWinHttpAsyncAvailable
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\bSynchronizeOPL
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Activation
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\NGL\SyncAuth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\Acrobat.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Acrobat.exe
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DLLInjection
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DLLInjection\bBlockDLLInjection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\caccounts
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\caccounts\cdef
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\cconnectors
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\cconnectors\cen0us
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\ssection_key
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c0\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c1\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c2\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c3\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c4\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c5\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c1\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c2\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c3\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c4\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c5\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c0\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c1\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c2\sname
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c3\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c4\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c5\sname
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVConnector
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Identity\UserSpecificIdentity
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\AMSI\Providers
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\Software\Microsoft\AMSI
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Elevation
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\EULAAcceptedForBrowser
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllPutSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetCaps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.10.3.37!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.10.3.37!7
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\38\52C64B7E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.10.3.42!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.10.3.42!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.76.6.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.76.6.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.92.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.92.1.1!7
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Cryptography\ECCParameters
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllVerifyIndirectData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CI\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CI\Config\Default
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\CA\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Root\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Root\CRLs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\31F9FC8BA3805986B721EA7295C65B3A44534274
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\trust\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\bNormalExit
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent\cWin0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent\cWin0\iTabCount
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent\iWinCount
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bCollab_OfflineDocs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bCollab_Workflows
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\AVTracker
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\AVTracker
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag
HKEY_USERS\.DEFAULT
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Containers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\dnscache
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\PolicyExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\PolicyExtensions\TenantRestrictionsPlugin.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\QuicTestHost
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Privileged\Attachments
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\Attachments
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC\WebServers
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\DC\WebSocketNotifInfra
HKEY_CURRENT_USER\Software\Classes\.pdf\OpenWithProgids
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-932793227-1321892499-785312009-1001\Installer\UpgradeCodes\68AB67CA000000007706E7A854000000
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001\Software\Microsoft\Installer\UpgradeCodes\68AB67CA000000007706E7A854000000
HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\68AB67CA000000007706E7A854000000
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-932793227-1321892499-785312009-1001\Installer\Products\68AB67CA330100FF7706CB5110E47A00
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001\Software\Microsoft\Installer\Products\68AB67CA330100FF7706CB5110E47A00
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\68AB67CA330100FF7706CB5110E47A00
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA330100FF7706CB5110E47A00\InstallProperties
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\PopupLimits
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\PopupLimits
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\ConnectorIconCache
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\ConnectorIconCache
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj
HKEY_CLASSES_ROOT\Acrobat.Document.DC\shell\Open\command
HKEY_CURRENT_USER\Software\Classes\Acrobat.Document.DC\shell\Open\command
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\CrossSurfaceDiscovery
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\CrossSurfaceDiscovery
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\AppCompatClassName
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\Input
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\Clients\{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\Clients\{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}\pv
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\OEM
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttpLowerCaseHost
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.Core.CoreWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.Core.CoreWindow\CustomAttributes
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\PICommonPrefs
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\PICommonPrefs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bForms_AdhocWorkflow
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bForms_AdhocWorkflowBackup
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\FormsPrefs
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\FormsPrefs
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\HomeWelcomeFirstMile
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\HomeWelcomeFirstMile\sLastTimeShown
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\HomeWelcomeFirstMile
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\OnBoardingSection
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\sappVersion
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\slocale
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sBannerContent
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sBannerTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sCardContent
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sCardTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sCardType
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sOffset
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\OnBoardingSection
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\HomeWelcomeFirstMileReader
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\HomeWelcomeFirstMileReader
HKEY_CURRENT_USER\Software\Classes\Interface\{0000010E-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000010e-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{0000010e-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\UpsellExperiments
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\DC\UpsellExperiments
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Acrobat.exe\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Acrobat.exe\NoStartPage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Acrobat.exe\IsHostApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates\2BD63D28D7BCD0E251195AEB519243C13142EBC3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates\2BD63D28D7BCD0E251195AEB519243C13142EBC3
HKEY_CURRENT_USER\Control Panel\Desktop\PaintDesktopVersion
HKEY_CLASSES_ROOT\Applications\Acrobat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\Instance
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_CLASSES_ROOT\.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_CLASSES_ROOT\exefile
HKEY_CURRENT_USER\Software\Classes\exefile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo\112DF3B9-46FD-489C-9225-38E8C540F72A
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Nqbor\Npebong QP\Npebong\Npebong.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\SearchboxTaskbarMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\TraySearchBoxVisible
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\TraySearchBoxVisibleOnAnyMonitor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Feeds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\IsFeedsAvailable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudExperienceHost\Fullscreen
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\SystemUsesLightTheme
HKEY_CLASSES_ROOT\Applications\ApplicationFrameHost.exe
HKEY_CURRENT_USER\Software\Classes\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}
HKEY_CURRENT_USER\Software\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\windows.immersivecontrolpanel_cw5n1h2txyewy\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\windows.immersivecontrolpanel_cw5n1h2txyewy\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy\Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SuppressedSplashScreenTimeout
HKEY_CURRENT_USER\Software\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\ActivateOnHostFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\WRT:windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel+1+00000000000201EA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\WRT:windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel+1+00000000000201EA\ShowInSwitchers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\WRT:windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel+1+00000000000201EA\VirtualDesktop
HKEY_CURRENT_USER\Software\Classes\Interface\{F7A88EC3-6F33-46BF-83B8-78AAF94AC396}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{f7a88ec3-6f33-46bf-83b8-78aaf94ac396}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}
HKEY_CURRENT_USER\Software\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Interface\{F3E74273-0BE4-580A-A90B-D7880A95B914}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{f3e74273-0be4-580a-a90b-d7880a95b914}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{f3e74273-0be4-580a-a90b-d7880a95b914}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Metadata
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\User\Index\UserSid\S-1-5-21-932793227-1321892499-785312009-1001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageExternalLocation\Index\UserAndPackage\3^10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageExternalLocation\Index\UserAndPackage\0^10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\InstalledLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\MutableLink
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\AppModel\StateChange\PackageList\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\PackageOrigin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\Flags
HKEY_LOCAL_MACHINE\Software\Microsoft\SecurityManager\CapAuthz
HKEY_LOCAL_MACHINE\Software\Microsoft\SecurityManager\CapAuthz\HasRepaired
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Mrt\_Merged
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapAuthz
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy\CapSids
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy\ApplicationFlags
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows.immersivecontrolpanel_cw5n1h2txyewy\ResourcesConfig
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\SecurityManager\AdminCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\packageQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateOnHostFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\ColorPrevalence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\EnableTransparency
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ImmersiveShell\PersistedApplicationData\Volatile\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\NowPlayingSessionManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NowPlayingSessionManager\LocalProvider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry
HKEY_CURRENT_USER\Software\Classes\Interface\{D0D73345-806E-4526-8AD6-3B3BB2EC2895}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ThumbnailCache
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D0D73345-806E-4526-8AD6-3B3BB2EC2895}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\backgroundMediaPlayback
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\windows.immersivecontrolpanel_cw5n1h2txyewy\ApplicationFrame
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\windows.immersivecontrolpanel_cw5n1h2txyewy\ApplicationFrame\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Scaling
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\accessoryManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\accessoryManager\Edition
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\DeviceAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\ActivePolicyCode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\accessoryManager\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\accessoryManager\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\activity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\activity\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\ActivePolicyCode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\activity\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\activity\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appDiagnostics
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appDiagnostics\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appDiagnostics\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appDiagnostics\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointments\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointments\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointments\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointmentsSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointmentsSystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointmentsSystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointmentsSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\backgroundSpatialPerception
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\backgroundSpatialPerception\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\backgroundSpatialPerception\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\backgroundSpatialPerception\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.genericAttributeProfile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.genericAttributeProfile\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.genericAttributeProfile\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.genericAttributeProfile\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.rfcomm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.rfcomm\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.rfcomm\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.rfcomm\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothAdapter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothAdapter\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothAdapter\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothAdapter\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothSync
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothSync\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothSync\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothSync\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\broadFilesystemAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\broadFilesystemAccess\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\broadFilesystemAccess\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\broadFilesystemAccess\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularData\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularData\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularData\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularDeviceControl\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularDeviceControl\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chat\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chat\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chat\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chatSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chatSystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chatSystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chatSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\comPort
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\comPort\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\comPort\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\comPort\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contacts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contacts\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contacts\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contacts\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contactsSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contactsSystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contactsSystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contactsSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\documentsLibrary
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\documentsLibrary\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\documentsLibrary\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\documentsLibrary\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\email
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\email\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\email\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\email\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\emailSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\emailSystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\emailSystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\emailSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\gazeInput
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\gazeInput\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\gazeInput\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\gazeInput\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\graphicsCaptureWithoutBorder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\graphicsCaptureWithoutBorder\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\graphicsCaptureWithoutBorder\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\graphicsCaptureWithoutBorder\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\humanInterfaceDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\humanInterfaceDevice\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\humanInterfaceDevice\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\humanInterfaceDevice\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClient
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClient\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClient\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClient\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClientServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClientServer\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClientServer\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClientServer\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectAudio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectAudio\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectAudio\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectAudio\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectVision
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectVision\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectVision\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectVision\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\location
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\location\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\location\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\location\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\locationHistory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\locationHistory\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\locationHistory\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\locationHistory\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\lowLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\lowLevel\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\lowLevel\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\lowLevel\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\microphone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\microphone\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\microphone\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\microphone\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\optical
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\optical\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\optical\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\optical\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageManagement
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageManagement\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageManagement\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageManagement\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageQuery\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageQuery\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageQuery\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCall\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCall\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCall\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistory\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistory\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistory\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistoryPublic
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistoryPublic\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistoryPublic\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistoryPublic\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistorySystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistorySystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistorySystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistorySystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallSystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallSystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\picturesLibrary
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\picturesLibrary\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\picturesLibrary\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\picturesLibrary\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\pointOfService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\pointOfService\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\pointOfService\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\pointOfService\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\preemptiveCamera
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\preemptiveCamera\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\preemptiveCamera\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\preemptiveCamera\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\privateNetworkClientServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\privateNetworkClientServer\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\privateNetworkClientServer\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\privateNetworkClientServer\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\proximity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\proximity\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\proximity\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\proximity\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\radios
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\radios\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\radios\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\radios\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sensors.custom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sensors.custom\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sensors.custom\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sensors.custom\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\serialCommunication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\serialCommunication\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\serialCommunication\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\serialCommunication\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sms
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sms\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sms\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sms\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\smsSend
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\smsSend\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\smsSend\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\smsSend\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\usb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\usb\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\usb\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\usb\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation\Apps\Windows.ImmersiveControlPanel_cw5n1h2txyewy\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasks\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasks\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasks\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasksSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasksSystem\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasksSystem\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasksSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userNotificationListener
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userNotificationListener\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userNotificationListener\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userNotificationListener\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\videosLibrary
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\videosLibrary\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\videosLibrary\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\videosLibrary\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\webcam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\webcam\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\webcam\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\webcam\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiControl\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiControl\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiControl\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wifiData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wifiData\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wifiData\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wifiData\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiDirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiDirect\Edition
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiDirect\Apps\windows.immersivecontrolpanel_cw5n1h2txyewy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiDirect\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\cellularData
HKEY_CURRENT_USER\Software\Classes\Interface\{0F4521BE-A0B8-4116-B3B1-BFECEBAEEBE6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0F4521BE-A0B8-4116-B3B1-BFECEBAEEBE6}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0F4521BE-A0B8-4116-B3B1-BFECEBAEEBE6}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{EAD1A538-3BB4-45D9-B6C9-DC167E21D959}
HKEY_CURRENT_USER\Software\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\wifiData
HKEY_CURRENT_USER\Software\Classes\Interface\{D22F448D-39DC-415F-8325-91EDDF0D5264}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D22F448D-39DC-415F-8325-91EDDF0D5264}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D22F448D-39DC-415F-8325-91EDDF0D5264}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\Elevation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\jvaqbjf.vzzrefvirpbagebycnary_pj5a1u2gklrjl!zvpebfbsg.jvaqbjf.vzzrefvirpbagebycnary
HKEY_CURRENT_USER\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}
HKEY_CURRENT_USER\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\UBR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\bIsSingleClientApp
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\bIsSCAcroAppInstalled
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\SCAPackageLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\Installer\IsAcrInstalledInRdrMode
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged\bProtectedMode
HKEY_CURRENT_USER\Keyboard Layout\Preload\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layouts\00000409\Layout File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layouts\00000409\Attributes
bEnforceReadRestrictions
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged\bEnforceReadRestrictions
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Privileged\bEnableEventViewerLogging
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\Adobe\Acrobat\Exe\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\bEnableThemedScrollBar
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Language\UseMUI\bUseMUI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Language\next\(Default)
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Language\current\(Default)
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\MaxDoc
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\MaxApp
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogX5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogY5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogW5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DialogH5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\PrintToFile
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\DontMarkPostScriptJob
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\bDocumentsInTaskbar
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SDI\bNullDocMaximized
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Originals\bDisplayedSplash
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\sMRUList
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\aFS
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\tDIText
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\tFileName
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sFileAncestors
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sDI
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sDate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1\sAssetId
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cUUIDs\suser
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\iLogLevel
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\ProductInfoCache
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\ProductInfoCache
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection\bLastExitNormal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Synchronizer\DC\Acrobat.com\bThirdPartyLogSession
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bDumpStartupZStrings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\iuiStringFilter
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Selection\aDefaultSelect
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s9
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E310000\cAdobe_OCSPRevChecker\cSignCertOID\c0\sValue
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c0\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s9
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_ChainBuilder\cAcceptablePolicyOIDs\c1\cValue\s11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Security\cASPKI\cASPKI\cCustomCertPrefs\c312E322E3834302E3131343032312E312E312E310000\cAdobe_OCSPRevChecker\cSignCertOID\c0\sValue
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdf\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithList\MRUList
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Acrobat.Document.DC\AllowSilentDefaultTakeOver
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Synchronizer\DC\Acrobat.com\tActiveSettings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Synchronizer\DC\Acrobat.com.v2\tActiveSettings
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\sLocale
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a1
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a3
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a4
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a5
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a6
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a7
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a8
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a9
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a10
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cFavorites\a11
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c0\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c1\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c10\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c11\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c12\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c13\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c14\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c15\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c16\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c17\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c18\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c19\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c2\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c20\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c21\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c22\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c23\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c24\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c25\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c26\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c27\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c28\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c29\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c3\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c30\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c31\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c32\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c33\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\aID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tLocation
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tPath
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tav2Description
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\tav2Title
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c34\trichTooltip
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AcroApp\cRegistered\c35\tDescription
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\sDailyAnalyticsLastSyncDate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bLoadAllPluginsAtStartup
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\Originals\sProofingSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bEnableFlickerFreeDrawing
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bShowAds
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sAppEntitlementStatus
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sDeviceID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductVersion
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sUserEmail
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sUserGUID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductName
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductGUID
HKEY_CURRENT_USER\Control Panel\Desktop\CaretWidth
HKEY_CURRENT_USER\Control Panel\Desktop\CursorBlinkRate
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bEnableIdleDrawing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Citrix\ProductVersion
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bExternalIcons
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\bPluginNotice
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVPrivate\NewUserForModernizationFlushed2
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\ssection_key
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c0\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c1\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c2\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c3\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c4\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_add\c0\csection_order\c5\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c1\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c2\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c3\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c4\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_file_sel_dlg\c5\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c0\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c1\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c2\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c3\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c4\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVConnector\cv1\corder\cen0us\corder_for_left_rail\c5\sname
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bCollab_OfflineDocs
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bCollab_Workflows
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\QuicTestHost
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\Clients\{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}\pv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttpLowerCaseHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\AutodialDLL
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bForms_AdhocWorkflow
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bForms_AdhocWorkflowBackup
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\HomeWelcomeFirstMile\sLastTimeShown
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\sappVersion
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\slocale
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sBannerContent
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sBannerTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sCardContent
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sCardTitle
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sCardType
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\OnBoardingSection\chomeView\sOffset
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Acrobat.exe\NoStartPage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Acrobat.exe\IsHostApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DisplayVersion
HKEY_CURRENT_USER\Control Panel\Desktop\PaintDesktopVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Nqbor\Npebong QP\Npebong\Npebong.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\SearchboxTaskbarMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\IsFeedsAvailable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\SystemUsesLightTheme
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c53e07ec-25f3-4093-aa39-fc67ea22e99d}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\windows.immersivecontrolpanel_cw5n1h2txyewy\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy\Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SuppressedSplashScreenTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.PackagePolicy\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{f7a88ec3-6f33-46bf-83b8-78aaf94ac396}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Tiles.TileQueryFilter\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37987DB6-9D85-4381-8D7D-3189661223D1}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{f3e74273-0be4-580a-a90b-d7880a95b914}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\InstalledLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\MutableLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\PackageOrigin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\10\Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy\CapSids
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapAuthz\ApplicationsEx\windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy\ApplicationFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\WindowsUdk.ApplicationModel.AppExtensions.AppExtensionCatalog\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\packageQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.AppExtension\ActivateOnHostFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\ColorPrevalence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\EnableTransparency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NowPlayingSessionManager\LocalProvider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D0D73345-806E-4526-8AD6-3B3BB2EC2895}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\backgroundMediaPlayback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\ActivePolicyCode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\accessoryManager\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\ActivePolicyCode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\activity\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appDiagnostics\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointments\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\appointmentsSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\backgroundSpatialPerception\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.genericAttributeProfile\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetooth.rfcomm\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothAdapter\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\bluetoothSync\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\broadFilesystemAccess\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularData\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\cellularDeviceControl\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chat\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\chatSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\comPort\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contacts\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\contactsSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\documentsLibrary\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\email\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\emailSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\gazeInput\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\graphicsCaptureWithoutBorder\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\humanInterfaceDevice\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClient\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\internetClientServer\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectAudio\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\kinectVision\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\location\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\locationHistory\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\lowLevel\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\microphone\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\optical\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageManagement\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\packageQuery\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCall\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistory\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistoryPublic\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallHistorySystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\phoneCallSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\picturesLibrary\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\pointOfService\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\preemptiveCamera\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\privateNetworkClientServer\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\proximity\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\radios\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sensors.custom\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\serialCommunication\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\sms\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\smsSend\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\usb\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation\Apps\Windows.ImmersiveControlPanel_cw5n1h2txyewy\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userAccountInformation\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasks\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userDataTasksSystem\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\userNotificationListener\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\videosLibrary\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\webcam\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiControl\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wifiData\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\Capabilities\wiFiDirect\AppLaunchAccessCheckRequired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\cellularData
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0F4521BE-A0B8-4116-B3B1-BFECEBAEEBE6}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ead1a538-3bb4-45d9-b6c9-dc167e21d959}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\AdminCapabilities\wifiData
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D22F448D-39DC-415F-8325-91EDDF0D5264}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\AppID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\jvaqbjf.vzzrefvirpbagebycnary_pj5a1u2gklrjl!zvpebfbsg.jvaqbjf.vzzrefvirpbagebycnary
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection\bLastExitNormal
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\CrashDataAtLaunch\iCrashCountAtLaunch
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\bNGLWinHttpAsyncAvailable
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\bSynchronizeOPL
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DLLInjection\bBlockDLLInjection
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement\sProductGUID
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\EULAAcceptedForBrowser
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\bNormalExit
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent\cWin0
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent\cWin0\iTabCount
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\SessionManagement\cWindowsCurrent\iWinCount
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\DiskCabs\bForms_AdhocWorkflowBackup
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo\112DF3B9-46FD-489C-9225-38E8C540F72A
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Nqbor\Npebong QP\Npebong\Npebong.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\TraySearchBoxVisible
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\TraySearchBoxVisibleOnAnyMonitor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\WRT:windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel+1+00000000000201EA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\WRT:windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel+1+00000000000201EA\ShowInSwitchers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\WRT:windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel+1+00000000000201EA\VirtualDesktop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ImmersiveShell\PersistedApplicationData\Volatile\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\jvaqbjf.vzzrefvirpbagebycnary_pj5a1u2gklrjl!zvpebfbsg.jvaqbjf.vzzrefvirpbagebycnary
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AdobeViewer\ProductInfoCache
Global\ARM Update Mutex
Global\Acro Update Mutex
Local\Acrobat Instance Mutex
Local\SM0:4176:304:WilStaging_02
Local\SM0:4176:120:WilError_03
Local\MSCTF.Asm.MutexDefault1
CicLoadWinStaWinSta0
Local\MSCTF.CtfMonitorInstMutexDefault1
com.adobe.acrobat.rna.AcroCefBrowserLock.DC
Local\SM0:4596:120:WilError_03
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_48.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_768.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1280.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1920.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_2560.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_wide.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_exif.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_wide_alternate.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_custom_stream.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!018
WinHttpAutoProxySvc
No results
Sorry! No behavior.
Sorry! No tracee.
Sorry! No strace.
Sorry! No tracee.

No hosts contacted.

No TCP connections recorded.

No UDP connections recorded.

No domains contacted.

HTTP Requests

No HTTP(s) requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No Suricata Extracted files.
Sorry! No dropped files.
Sorry! No process dumps.