Analysis

Category Package Started Completed Duration Options Log(s) MalScore
FILE xls 2025-12-08 13:54:56 2025-12-08 13:58:20 204 seconds Show Options Show Analysis Log 10.0
vnc_port=5902
2025-12-06 18:31:41,722 [root] INFO: Date set to: 20251208T05:51:54, timeout set to: 180
2025-12-06 18:31:41,722 [root] DEBUG: Starting analyzer from: C:\tmpw7hn3wdo
2025-12-06 18:31:41,722 [root] DEBUG: Storing results at: C:\HNxZeWN
2025-12-06 18:31:41,722 [root] DEBUG: Pipe server name: \\.\PIPE\BsJripN
2025-12-06 18:31:41,722 [root] DEBUG: Python path: C:\Python38
2025-12-06 18:31:41,722 [root] INFO: analysis running as a normal user
2025-12-06 18:31:41,722 [root] INFO: analysis package specified: "xls"
2025-12-06 18:31:41,722 [root] DEBUG: importing analysis package module: "modules.packages.xls"...
2025-12-06 18:31:41,722 [root] DEBUG: imported analysis package "xls"
2025-12-06 18:31:41,722 [root] DEBUG: initializing analysis package "xls"...
2025-12-06 18:31:41,722 [lib.common.common] INFO: wrapping
2025-12-06 18:31:41,722 [lib.core.compound] ERROR: Unable to create user-defined custom folder directory
2025-12-06 18:31:41,722 [root] DEBUG: New location of moved file: C:\Users\user\AppData\Local\Temp\file
2025-12-06 18:31:41,722 [root] INFO: Analyzer: Package modules.packages.xls does not specify a DLL option
2025-12-06 18:31:41,722 [root] INFO: Analyzer: Package modules.packages.xls does not specify a DLL_64 option
2025-12-06 18:31:41,722 [root] INFO: Analyzer: Package modules.packages.xls does not specify a loader option
2025-12-06 18:31:41,722 [root] INFO: Analyzer: Package modules.packages.xls does not specify a loader_64 option
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain"
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.during_script"
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.end_noisy_tasks"
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.evtx"
2025-12-06 18:31:41,754 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-12-06 18:31:41,769 [root] DEBUG: Imported auxiliary module "modules.auxiliary.pre_script"
2025-12-06 18:31:41,769 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-12-06 18:31:41,785 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2025-12-06 18:31:41,785 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2025-12-06 18:31:41,800 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-12-06 18:31:41,800 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon"
2025-12-06 18:31:41,800 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-12-06 18:31:41,800 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage"
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Browser"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Browser' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Curtain"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Curtain' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Curtain does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.curtain"...
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.curtain
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Disguise' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-12-06 18:31:41,800 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.disguise: [WinError 5] Access is denied
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "End_noisy_tasks"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'End_noisy_tasks' from data
2025-12-06 18:31:41,800 [root] DEBUG: module End_noisy_tasks does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.end_noisy_tasks"...
2025-12-06 18:31:41,800 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wuauclt.exe
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.end_noisy_tasks
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Evtx"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Evtx' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Evtx does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.evtx"...
2025-12-06 18:31:41,800 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security State Change" /success:enable /failure:enable
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.evtx
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Human"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Human' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Human does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Pre_script"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Pre_script' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Pre_script does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.pre_script"...
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.pre_script
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-12-06 18:31:41,800 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-12-06 18:31:41,800 [root] DEBUG: Initialized auxiliary module "Sysmon"
2025-12-06 18:31:41,800 [root] DEBUG: attempting to configure 'Sysmon' from data
2025-12-06 18:31:41,800 [root] DEBUG: module Sysmon does not support data configuration, ignoring
2025-12-06 18:31:41,800 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.sysmon"...
2025-12-06 18:31:41,879 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security System Extension" /success:enable /failure:enable
2025-12-06 18:31:41,926 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wusa.exe
2025-12-06 18:31:41,941 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.sysmon: In order to use the Sysmon functionality, it is required to have the SMaster(64|32).exe file and sysmonconfig-export.xml file in the bin path. Note that the SMaster(64|32).exe files are just the standard Sysmon binaries renamed to avoid anti-analysis detection techniques.
2025-12-06 18:31:41,941 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-12-06 18:31:41,941 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-12-06 18:31:41,941 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-12-06 18:31:41,941 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-12-06 18:31:41,941 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 668
2025-12-06 18:31:41,941 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,941 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,941 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,941 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,941 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,941 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,941 [lib.api.process] DEBUG: Failed getting exit code for <Process 668 ???>
2025-12-06 18:31:41,941 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,941 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,941 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,941 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,941 [lib.api.process] WARNING: the <Process 668 ???> is not alive, injection aborted
2025-12-06 18:31:41,941 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2025-12-06 18:31:41,941 [root] DEBUG: Initialized auxiliary module "Usage"
2025-12-06 18:31:41,941 [root] DEBUG: attempting to configure 'Usage' from data
2025-12-06 18:31:41,941 [root] DEBUG: module Usage does not support data configuration, ignoring
2025-12-06 18:31:41,941 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.usage"...
2025-12-06 18:31:41,941 [root] DEBUG: Started auxiliary module modules.auxiliary.usage
2025-12-06 18:31:41,941 [root] DEBUG: Initialized auxiliary module "During_script"
2025-12-06 18:31:41,941 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"System Integrity" /success:enable /failure:enable
2025-12-06 18:31:41,941 [root] DEBUG: attempting to configure 'During_script' from data
2025-12-06 18:31:41,941 [root] DEBUG: module During_script does not support data configuration, ignoring
2025-12-06 18:31:41,941 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.during_script"...
2025-12-06 18:31:41,941 [root] DEBUG: Started auxiliary module modules.auxiliary.during_script
2025-12-06 18:31:41,988 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Driver" /success:disable /failure:disable
2025-12-06 18:31:41,988 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM WindowsUpdate.exe
2025-12-06 18:31:42,019 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other System Events" /success:disable /failure:enable
2025-12-06 18:31:42,051 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM GoogleUpdate.exe
2025-12-06 18:31:42,066 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logon" /success:enable /failure:enable
2025-12-06 18:31:42,098 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logoff" /success:enable /failure:enable
2025-12-06 18:31:42,113 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM MicrosoftEdgeUpdate.exe
2025-12-06 18:31:42,129 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Account Lockout" /success:enable /failure:enable
2025-12-06 18:31:42,176 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Main Mode" /success:disable /failure:disable
2025-12-06 18:31:42,191 [root] INFO: Restarting WMI Service
2025-12-06 18:31:42,207 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Quick Mode" /success:disable /failure:disable
2025-12-06 18:31:42,223 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DisableWindowsUpdateAccess /t REG_DWORD /d 1 /f
2025-12-06 18:31:42,238 [root] DEBUG: package modules.packages.xls does not support configure, ignoring
2025-12-06 18:31:42,238 [root] WARNING: configuration error for package modules.packages.xls: error importing data.packages.xls: No module named 'data.packages'
2025-12-06 18:31:42,238 [lib.common.common] INFO: Submitted file is missing extension, adding .xls
2025-12-06 18:31:42,238 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:42,238 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Extended Mode" /success:disable /failure:disable
2025-12-06 18:31:42,270 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,270 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Logon/Logoff Events" /success:enable /failure:enable
2025-12-06 18:31:42,316 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v EnableICMPRedirect /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,316 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
2025-12-06 18:31:42,347 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Special Logon" /success:enable /failure:enable
2025-12-06 18:31:42,378 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File System" /success:enable /failure:enable
2025-12-06 18:31:42,410 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Registry" /success:enable /failure:enable
2025-12-06 18:31:42,441 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kernel Object" /success:enable /failure:enable
2025-12-06 18:31:42,472 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"SAM" /success:disable /failure:disable
2025-12-06 18:31:42,503 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE" with arguments ""C:\Users\user\AppData\Local\Temp\file.xls" /dde" with pid 5712
2025-12-06 18:31:42,503 [lib.api.process] INFO: Monitor config for <Process 5712 EXCEL.EXE>: C:\tmpw7hn3wdo\dll\5712.ini
2025-12-06 18:31:42,503 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpw7hn3wdo\dll\lHwYLJyL.dll, loader C:\tmpw7hn3wdo\bin\dvcRkcJ.exe
2025-12-06 18:31:42,503 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Certification Services" /success:enable /failure:enable
2025-12-06 18:31:42,503 [root] DEBUG: Loader: Injecting process 5712 (thread 5412) with C:\tmpw7hn3wdo\dll\lHwYLJyL.dll.
2025-12-06 18:31:42,503 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:31:42,503 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\lHwYLJyL.dll.
2025-12-06 18:31:42,519 [lib.api.process] INFO: Injected into 32-bit <Process 5712 EXCEL.EXE>
2025-12-06 18:31:42,535 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Handle Manipulation" /success:disable /failure:disable
2025-12-06 18:31:42,566 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable
2025-12-06 18:31:42,582 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File Share" /success:enable /failure:enable
2025-12-06 18:31:42,613 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable
2025-12-06 18:31:42,644 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable
2025-12-06 18:31:42,675 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Object Access Events" /success:disable /failure:disable
2025-12-06 18:31:42,707 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:42,738 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Non Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:42,754 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Privilege Use Events" /success:disable /failure:disable
2025-12-06 18:31:42,785 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"RPC Events" /success:enable /failure:enable
2025-12-06 18:31:42,816 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Audit Policy Change" /success:enable /failure:enable
2025-12-06 18:31:42,847 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Authentication Policy Change" /success:enable /failure:enable
2025-12-06 18:31:42,879 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"MPSSVC Rule-Level Policy Change" /success:disable /failure:disable
2025-12-06 18:31:42,910 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Policy Change" /success:disable /failure:disable
2025-12-06 18:31:42,941 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Policy Change Events" /success:disable /failure:enable
2025-12-06 18:31:42,972 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable
2025-12-06 18:31:42,988 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Computer Account Management" /success:enable /failure:enable
2025-12-06 18:31:43,019 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,051 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,082 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,113 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Management Events" /success:enable /failure:enable
2025-12-06 18:31:43,129 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
2025-12-06 18:31:43,160 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
2025-12-06 18:31:43,191 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Replication" /success:disable /failure:enable
2025-12-06 18:31:43,222 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Detailed Directory Service Replication" /success:disable /failure:disable
2025-12-06 18:31:43,254 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable
2025-12-06 18:31:43,285 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Service Ticket Operations" /success:enable /failure:enable
2025-12-06 18:31:43,301 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Logon Events" /success:enable /failure:enable
2025-12-06 18:31:43,332 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Authentication Service" /success:enable /failure:enable
2025-12-06 18:31:43,363 [modules.auxiliary.evtx] DEBUG: Wiping Application
2025-12-06 18:31:43,394 [modules.auxiliary.evtx] DEBUG: Wiping HardwareEvents
2025-12-06 18:31:43,410 [modules.auxiliary.evtx] DEBUG: Wiping Internet Explorer
2025-12-06 18:31:43,441 [modules.auxiliary.evtx] DEBUG: Wiping Key Management Service
2025-12-06 18:31:43,472 [modules.auxiliary.evtx] DEBUG: Wiping OAlerts
2025-12-06 18:31:43,504 [modules.auxiliary.evtx] DEBUG: Wiping Security
2025-12-06 18:31:43,519 [modules.auxiliary.evtx] DEBUG: Wiping Setup
2025-12-06 18:31:43,551 [modules.auxiliary.evtx] DEBUG: Wiping System
2025-12-06 18:31:43,582 [modules.auxiliary.evtx] DEBUG: Wiping Windows PowerShell
2025-12-06 18:31:43,613 [modules.auxiliary.evtx] DEBUG: Wiping Microsoft-Windows-Sysmon/Operational
2025-12-06 18:31:44,535 [lib.api.process] INFO: Successfully resumed <Process 5712 EXCEL.EXE>
2025-12-06 18:31:44,582 [root] DEBUG: 5712: Python path set to 'C:\Python38'.
2025-12-06 18:31:44,582 [root] INFO: Disabling sleep skipping.
2025-12-06 18:31:44,582 [root] DEBUG: 5712: Dropped file limit defaulting to 100.
2025-12-06 18:31:44,660 [root] DEBUG: 5712: Microsoft Office settings enabled.
2025-12-06 18:31:44,660 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:31:44,660 [root] DEBUG: 5712: Monitor initialised: 32-bit capemon loaded in process 5712 at 0x73450000, thread 5412, image base 0x310000, stack from 0x38f6000-0x3900000
2025-12-06 18:31:44,660 [root] DEBUG: 5712: Commandline: "C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE" "C:\Users\user\AppData\Local\Temp\file.xls" /dde
2025-12-06 18:31:44,660 [root] DEBUG: 5712: hook_api: Warning - CoCreateInstance export address 0x76C0569D differs from GetProcAddress -> 0x756395D0 (combase.dll::0xd95d0)
2025-12-06 18:31:44,660 [root] DEBUG: 5712: hook_api: Warning - CoCreateInstanceEx export address 0x76C056DC differs from GetProcAddress -> 0x7561C540 (combase.dll::0xbc540)
2025-12-06 18:31:44,660 [root] DEBUG: 5712: hook_api: Warning - CoGetClassObject export address 0x76C05C6C differs from GetProcAddress -> 0x756051A0 (combase.dll::0xa51a0)
2025-12-06 18:31:44,660 [root] DEBUG: 5712: hook_api: Warning - CreateRemoteThreadEx export address 0x7598866C differs from GetProcAddress -> 0x75BD7630 (KERNELBASE.dll::0x137630)
2025-12-06 18:31:44,660 [root] DEBUG: 5712: hook_api: Warning - CLSIDFromProgID export address 0x76C04ED6 differs from GetProcAddress -> 0x755D16A0 (combase.dll::0x716a0)
2025-12-06 18:31:44,660 [root] DEBUG: 5712: hook_api: Warning - CLSIDFromProgIDEx export address 0x76C04F13 differs from GetProcAddress -> 0x755D0500 (combase.dll::0x70500)
2025-12-06 18:31:44,676 [root] DEBUG: 5712: Hooked 434 out of 434 functions
2025-12-06 18:31:44,676 [root] DEBUG: 5712: Syscall hook installed, syscall logging level 1
2025-12-06 18:31:44,676 [root] DEBUG: 5712: WoW64fix: Windows version 10.0 not supported.
2025-12-06 18:31:44,676 [root] INFO: Loaded monitor into process with pid 5712
2025-12-06 18:31:45,004 [root] DEBUG: 5712: DLL loaded at 0x769F0000: C:\Windows\System32\oleaut32 (0x96000 bytes).
2025-12-06 18:31:45,051 [root] DEBUG: 5712: DLL loaded at 0x73D30000: C:\Windows\SYSTEM32\CRYPTUI (0x3f000 bytes).
2025-12-06 18:31:45,051 [root] DEBUG: 5712: DLL loaded at 0x74E90000: C:\Windows\SYSTEM32\IPHLPAPI (0x33000 bytes).
2025-12-06 18:31:45,051 [root] DEBUG: 5712: DLL loaded at 0x72700000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso20win32client (0x68a000 bytes).
2025-12-06 18:31:45,098 [root] DEBUG: 5712: DLL loaded at 0x73800000: C:\Windows\SYSTEM32\wevtapi (0x49000 bytes).
2025-12-06 18:31:45,098 [root] DEBUG: 5712: DLL loaded at 0x71C20000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso30win32client (0xadc000 bytes).
2025-12-06 18:31:45,160 [root] DEBUG: 5712: DLL loaded at 0x70D90000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.2251_none_d9513b1fe1046fc7\gdiplus (0x167000 bytes).
2025-12-06 18:31:45,160 [root] DEBUG: 5712: DLL loaded at 0x70F00000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso40uiwin32client (0xd1e000 bytes).
2025-12-06 18:31:45,176 [root] DEBUG: 5712: DLL loaded at 0x73360000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso50win32client (0xef000 bytes).
2025-12-06 18:31:45,270 [root] DEBUG: 5712: DLL loaded at 0x73D20000: C:\Windows\SYSTEM32\HTTPAPI (0xb000 bytes).
2025-12-06 18:31:45,270 [root] DEBUG: 5712: DLL loaded at 0x73730000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2025-12-06 18:31:45,270 [root] DEBUG: 5712: DLL loaded at 0x73D10000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2025-12-06 18:31:45,270 [root] DEBUG: 5712: DLL loaded at 0x6F980000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso98win32client (0x1407000 bytes).
2025-12-06 18:31:45,394 [root] DEBUG: 5712: DLL loaded at 0x082E0000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\mso (0x1cc1000 bytes).
2025-12-06 18:31:45,394 [root] DEBUG: 5712: DLL loaded at 0x74ED0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2025-12-06 18:31:45,425 [root] DEBUG: 5712: DLL loaded at 0x6DA10000: C:\Windows\SYSTEM32\msi (0x298000 bytes).
2025-12-06 18:31:45,441 [root] DEBUG: 5712: DLL loaded at 0x6D800000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984\Comctl32 (0x210000 bytes).
2025-12-06 18:31:45,457 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\{7897BE6F-C3A3-4899-81F3-ED5DF4333726} - OProcSessId.dat
2025-12-06 18:31:45,472 [root] DEBUG: 5712: DLL loaded at 0x6D2E0000: C:\Windows\SYSTEM32\d2d1 (0x515000 bytes).
2025-12-06 18:31:45,488 [root] DEBUG: 5712: DLL loaded at 0x74B00000: C:\Windows\system32\uxtheme (0x74000 bytes).
2025-12-06 18:31:45,488 [root] DEBUG: 5712: DLL loaded at 0x76C40000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2025-12-06 18:31:45,503 [root] DEBUG: 5712: DLL loaded at 0x732B0000: C:\Windows\SYSTEM32\WINSTA (0x4e000 bytes).
2025-12-06 18:31:45,503 [root] DEBUG: 5712: DLL loaded at 0x6D210000: C:\Windows\SYSTEM32\dxgi (0xc2000 bytes).
2025-12-06 18:31:45,503 [root] DEBUG: 5712: DLL loaded at 0x73D00000: C:\Windows\SYSTEM32\resourcepolicyclient (0xf000 bytes).
2025-12-06 18:31:45,519 [root] DEBUG: 5712: set_hooks_by_export_directory: Hooked 0 out of 434 functions
2025-12-06 18:31:45,519 [root] DEBUG: 5712: DLL loaded at 0x74CE0000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2025-12-06 18:31:45,519 [root] DEBUG: 5712: DLL loaded at 0x74CF0000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2025-12-06 18:31:45,535 [root] DEBUG: 5712: DLL loaded at 0x73260000: C:\Windows\SYSTEM32\POWRPROF (0x44000 bytes).
2025-12-06 18:31:45,550 [root] DEBUG: 5712: DLL loaded at 0x73D00000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2025-12-06 18:31:45,582 [root] DEBUG: 5712: DLL loaded at 0x6D030000: C:\Windows\SYSTEM32\d3d11 (0x1e0000 bytes).
2025-12-06 18:31:45,582 [root] DEBUG: 5712: DLL loaded at 0x76940000: C:\Windows\System32\shcore (0x87000 bytes).
2025-12-06 18:31:45,597 [root] DEBUG: 5712: DLL loaded at 0x6CA60000: C:\Windows\SYSTEM32\d3d10warp (0x5c2000 bytes).
2025-12-06 18:31:45,613 [root] DEBUG: 5712: DLL loaded at 0x744A0000: C:\Windows\SYSTEM32\Wldp (0x25000 bytes).
2025-12-06 18:31:45,613 [root] DEBUG: 5712: DLL loaded at 0x744D0000: C:\Windows\SYSTEM32\windows.storage (0x60d000 bytes).
2025-12-06 18:31:45,613 [root] DEBUG: 5712: DLL loaded at 0x75420000: C:\Windows\System32\cfgmgr32 (0x3b000 bytes).
2025-12-06 18:31:45,629 [root] DEBUG: 5712: DLL loaded at 0x73CC0000: C:\Windows\SYSTEM32\dxcore (0x2c000 bytes).
2025-12-06 18:31:45,629 [root] DEBUG: 5712: DLL loaded at 0x73C80000: C:\Windows\SYSTEM32\profapi (0x18000 bytes).
2025-12-06 18:31:45,644 [root] DEBUG: 5712: DLL loaded at 0x73720000: C:\Windows\SYSTEM32\Secur32 (0xa000 bytes).
2025-12-06 18:31:45,644 [root] DEBUG: 5712: DLL loaded at 0x76640000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2025-12-06 18:31:45,660 [root] DEBUG: 5712: DLL loaded at 0x6C850000: C:\Windows\SYSTEM32\DWrite (0x20c000 bytes).
2025-12-06 18:31:45,675 [root] DEBUG: 5712: DLL loaded at 0x6C670000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2025-12-06 18:31:45,675 [root] DEBUG: 5712: DLL loaded at 0x6C750000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0xf9000 bytes).
2025-12-06 18:31:45,675 [root] DEBUG: 5712: DLL loaded at 0x6C630000: C:\Windows\System32\netprofm (0x32000 bytes).
2025-12-06 18:31:45,675 [root] DEBUG: 5712: DLL loaded at 0x6C5D0000: C:\Windows\SYSTEM32\mscoree (0x52000 bytes).
2025-12-06 18:31:45,691 [root] DEBUG: 5712: DLL loaded at 0x6C540000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x88000 bytes).
2025-12-06 18:31:45,691 [root] DEBUG: 5712: DLL loaded at 0x73350000: C:\Windows\System32\npmproxy (0xa000 bytes).
2025-12-06 18:31:45,691 [root] DEBUG: 5712: DLL loaded at 0x75D10000: C:\Windows\System32\Normaliz (0x7000 bytes).
2025-12-06 18:31:45,707 [root] DEBUG: 5712: DLL loaded at 0x6C470000: C:\Program Files (x86)\Microsoft Office\root\Office16\MsoAria (0xcd000 bytes).
2025-12-06 18:31:45,707 [root] DEBUG: 5712: DLL loaded at 0x6C3A0000: C:\Windows\SYSTEM32\WINHTTP (0xca000 bytes).
2025-12-06 18:31:45,722 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:45,722 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:45,722 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:45,722 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:45,722 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:45,722 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:45,722 [lib.api.process] DEBUG: Failed getting exit code for <Process 792 ???>
2025-12-06 18:31:45,722 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:45,722 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:45,722 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:45,722 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:45,722 [lib.api.process] WARNING: the <Process 792 ???> is not alive, injection aborted
2025-12-06 18:31:45,722 [root] DEBUG: 5712: set_hooks_by_export_directory: Hooked 0 out of 434 functions
2025-12-06 18:31:45,722 [root] DEBUG: 5712: DLL loaded at 0x6C360000: C:\Windows\SYSTEM32\sppcs (0x1c000 bytes).
2025-12-06 18:31:45,722 [root] DEBUG: 5712: DLL loaded at 0x73340000: C:\Windows\SYSTEM32\sppc (0x9000 bytes).
2025-12-06 18:31:45,722 [root] DEBUG: 5712: DLL loaded at 0x6C380000: C:\Windows\SYSTEM32\slc (0x1f000 bytes).
2025-12-06 18:31:45,722 [root] DEBUG: 5712: DLL loaded at 0x6C340000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2025-12-06 18:31:45,722 [root] DEBUG: 5712: DLL loaded at 0x74D60000: C:\Windows\system32\mswsock (0x52000 bytes).
2025-12-06 18:31:45,738 [root] DEBUG: 5712: DLL loaded at 0x76910000: C:\Windows\System32\NSI (0x7000 bytes).
2025-12-06 18:31:45,738 [root] DEBUG: 5712: DLL loaded at 0x73340000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2025-12-06 18:31:45,754 [root] DEBUG: 5712: DLL loaded at 0x6C110000: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\RICHED20 (0x283000 bytes).
2025-12-06 18:31:45,754 [root] DEBUG: 5712: DLL loaded at 0x74E70000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2025-12-06 18:31:45,754 [root] DEBUG: 5712: DLL loaded at 0x74E50000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2025-12-06 18:31:45,769 [root] DEBUG: 5712: DLL loaded at 0x6BD30000: C:\Windows\SYSTEM32\iertutil (0x22d000 bytes).
2025-12-06 18:31:45,786 [root] DEBUG: 5712: DLL loaded at 0x6BD10000: C:\Windows\SYSTEM32\srvcli (0x1d000 bytes).
2025-12-06 18:31:45,786 [root] DEBUG: 5712: DLL loaded at 0x6BD00000: C:\Windows\SYSTEM32\netutils (0xb000 bytes).
2025-12-06 18:31:45,786 [root] DEBUG: 5712: DLL loaded at 0x6BF60000: C:\Windows\SYSTEM32\urlmon (0x1a8000 bytes).
2025-12-06 18:31:45,832 [root] DEBUG: 5712: DLL loaded at 0x6B830000: C:\Windows\SYSTEM32\twinapi.appcore (0x194000 bytes).
2025-12-06 18:31:45,832 [root] DEBUG: 5712: DLL loaded at 0x6B790000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2025-12-06 18:31:45,848 [root] DEBUG: 5712: DLL loaded at 0x6BB80000: C:\Windows\System32\WindowManagementAPI (0x73000 bytes).
2025-12-06 18:31:45,848 [root] DEBUG: 5712: DLL loaded at 0x6B4E0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2025-12-06 18:31:45,848 [root] DEBUG: 5712: DLL loaded at 0x6B510000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2025-12-06 18:31:45,848 [root] DEBUG: 5712: DLL loaded at 0x6BAC0000: C:\Windows\System32\TextInputFramework (0xb9000 bytes).
2025-12-06 18:31:45,848 [root] DEBUG: 5712: DLL loaded at 0x6B9D0000: C:\Windows\System32\InputHost (0xed000 bytes).
2025-12-06 18:31:45,863 [root] DEBUG: 5712: DLL loaded at 0x6BC00000: C:\Windows\System32\Windows.UI (0xf3000 bytes).
2025-12-06 18:31:45,879 [root] DEBUG: 5712: DLL loaded at 0x6B080000: C:\Windows\SYSTEM32\WININET (0x455000 bytes).
2025-12-06 18:31:45,879 [root] DEBUG: 5712: DLL loaded at 0x6AF90000: C:\Windows\System32\Windows.UI.Immersive (0xec000 bytes).
2025-12-06 18:31:45,894 [root] DEBUG: 5712: DLL loaded at 0x6AF70000: C:\Windows\SYSTEM32\ondemandconnroutehelper (0x12000 bytes).
2025-12-06 18:31:45,894 [root] DEBUG: 5712: set_hooks_by_export_directory: Hooked 0 out of 434 functions
2025-12-06 18:31:45,894 [root] DEBUG: 5712: DLL loaded at 0x6AF40000: C:\Windows\SYSTEM32\sppcs (0x1c000 bytes).
2025-12-06 18:31:45,910 [root] DEBUG: 5712: DLL loaded at 0x6AF60000: C:\Windows\SYSTEM32\sppc (0x9000 bytes).
2025-12-06 18:31:45,910 [root] DEBUG: 5712: DLL loaded at 0x6AEC0000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2025-12-06 18:31:45,910 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Content\Anonymous\Insights.json to files\fafb3b8db54b6d2b64c782ccc5550c1df58ef9bf02d87cf9047275d32079bed4; Size is 390; Max size: 100000000
2025-12-06 18:31:45,910 [root] DEBUG: 5712: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2025-12-06 18:31:45,910 [root] DEBUG: 5712: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2025-12-06 18:31:45,926 [root] DEBUG: 5712: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2025-12-06 18:31:45,926 [root] DEBUG: 5712: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2025-12-06 18:31:45,926 [root] DEBUG: 5712: DLL loaded at 0x74DC0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2025-12-06 18:31:45,926 [root] DEBUG: 5712: DLL loaded at 0x6AE90000: C:\Windows\SYSTEM32\XmlLite (0x2b000 bytes).
2025-12-06 18:31:45,926 [root] DEBUG: 5712: DLL loaded at 0x6AE80000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2025-12-06 18:31:45,941 [root] DEBUG: 5712: DLL loaded at 0x6AE60000: C:\Windows\SYSTEM32\Cabinet (0x20000 bytes).
2025-12-06 18:31:45,941 [root] DEBUG: 5712: DLL loaded at 0x6AE20000: C:\Windows\SYSTEM32\d3d10_1core (0xc000 bytes).
2025-12-06 18:31:45,941 [root] DEBUG: 5712: DLL loaded at 0x6AE30000: C:\Windows\SYSTEM32\d3d10_1 (0x29000 bytes).
2025-12-06 18:31:45,957 [root] DEBUG: 5712: DLL loaded at 0x6AD30000: C:\Windows\SYSTEM32\webservices (0xef000 bytes).
2025-12-06 18:31:45,973 [root] DEBUG: 5712: DLL loaded at 0x6ACF0000: C:\Windows\System32\OneCoreCommonProxyStub (0x3d000 bytes).
2025-12-06 18:31:45,988 [root] DEBUG: 5712: DLL loaded at 0x6ACC0000: C:\Windows\SYSTEM32\dwmapi (0x26000 bytes).
2025-12-06 18:31:45,988 [root] DEBUG: 5712: DLL loaded at 0x6AC80000: C:\Windows\System32\vaultcli (0x37000 bytes).
2025-12-06 18:31:46,019 [root] DEBUG: 5712: DLL loaded at 0x6ABE0000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2025-12-06 18:31:46,019 [root] DEBUG: 5712: DLL loaded at 0x6ABB0000: C:\Windows\System32\aadWamExtension (0x23000 bytes).
2025-12-06 18:31:46,113 [root] DEBUG: 5712: DLL loaded at 0x69F40000: C:\Program Files (x86)\Microsoft Office\root\Office16\oart (0xc68000 bytes).
2025-12-06 18:31:46,144 [root] DEBUG: 5712: DLL loaded at 0x69EB0000: C:\Windows\system32\twinapi (0x82000 bytes).
2025-12-06 18:31:46,191 [root] DEBUG: 5712: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2025-12-06 18:31:46,191 [root] DEBUG: 5712: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2025-12-06 18:31:46,207 [root] DEBUG: 5712: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2025-12-06 18:31:46,207 [root] DEBUG: 5712: DLL loaded at 0x74D40000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2025-12-06 18:31:46,222 [root] DEBUG: 5712: DLL loaded at 0x74D10000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2025-12-06 18:31:46,332 [root] DEBUG: 5712: DLL loaded at 0x69D90000: C:\Windows\System32\msvcp110_win (0x65000 bytes).
2025-12-06 18:31:46,332 [root] DEBUG: 5712: DLL loaded at 0x69E00000: C:\Windows\System32\policymanager (0x85000 bytes).
2025-12-06 18:31:46,332 [root] DEBUG: 5712: DLL loaded at 0x69E90000: C:\Windows\System32\HvsiManagementApi (0x1a000 bytes).
2025-12-06 18:31:46,347 [root] DEBUG: 5712: DLL loaded at 0x69CF0000: C:\Windows\System32\Windows.Web (0x92000 bytes).
2025-12-06 18:31:46,363 [root] DEBUG: 5712: DLL loaded at 0x69CE0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2025-12-06 18:31:46,363 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres
2025-12-06 18:31:46,379 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\5475cb191e478c39370a215b2da98a37e9dc813d.tbres'
2025-12-06 18:31:46,379 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\5475cb191e478c39370a215b2da98a37e9dc813d.tbres'
2025-12-06 18:31:46,379 [root] DEBUG: 5712: api-rate-cap: NtEnumerateValueKey hook disabled due to rate
2025-12-06 18:31:46,379 [root] DEBUG: 5712: DLL loaded at 0x69C40000: C:\Windows\System32\Windows.StateRepositoryPS (0x93000 bytes).
2025-12-06 18:31:46,394 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres'
2025-12-06 18:31:46,394 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres'
2025-12-06 18:31:46,394 [root] DEBUG: 5712: DLL loaded at 0x69C20000: C:\Windows\SYSTEM32\MPR (0x19000 bytes).
2025-12-06 18:31:46,410 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e0495fde257df2ef62ee7e3fdb1ebb9d7ff72300.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\e0495fde257df2ef62ee7e3fdb1ebb9d7ff72300.tbres'
2025-12-06 18:31:46,410 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e0495fde257df2ef62ee7e3fdb1ebb9d7ff72300.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\e0495fde257df2ef62ee7e3fdb1ebb9d7ff72300.tbres'
2025-12-06 18:31:46,410 [root] DEBUG: 5712: DLL loaded at 0x69C00000: C:\Windows\SYSTEM32\FLTLIB (0x8000 bytes).
2025-12-06 18:31:46,410 [root] DEBUG: 5712: DLL loaded at 0x69C10000: C:\Windows\SYSTEM32\virtdisk (0xf000 bytes).
2025-12-06 18:31:46,425 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres'
2025-12-06 18:31:46,425 [root] INFO: Error dumping file from path "C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres": [Errno 13] Permission denied: 'C:\\Users\\user\\AppData\\Local\\Microsoft\\TokenBroker\\Cache\\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres'
2025-12-06 18:31:46,425 [root] DEBUG: 5712: DLL loaded at 0x76E20000: C:\Windows\System32\coml2 (0x5e000 bytes).
2025-12-06 18:31:46,425 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\~$file.xls
2025-12-06 18:31:46,441 [root] DEBUG: 5712: DLL loaded at 0x69BC0000: C:\Windows\system32\mlang (0x34000 bytes).
2025-12-06 18:31:46,472 [root] DEBUG: 5712: DLL loaded at 0x69B30000: C:\Windows\system32\directmanipulation (0x86000 bytes).
2025-12-06 18:31:46,488 [root] DEBUG: 5712: DLL loaded at 0x699B0000: C:\Windows\SYSTEM32\WindowsCodecs (0x171000 bytes).
2025-12-06 18:31:46,504 [root] DEBUG: 5712: api-rate-cap: NtOpenKey hook disabled due to rate
2025-12-06 18:31:46,504 [root] DEBUG: 5712: api-rate-cap: NtQueryKey hook disabled due to rate
2025-12-06 18:31:46,519 [root] DEBUG: 5712: DLL loaded at 0x699A0000: C:\Windows\SYSTEM32\MSIMG32 (0x6000 bytes).
2025-12-06 18:31:46,535 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
2025-12-06 18:31:46,535 [root] DEBUG: 5712: DLL loaded at 0x69830000: C:\Windows\SYSTEM32\dcomp (0x164000 bytes).
2025-12-06 18:31:46,566 [root] DEBUG: 5712: hook_api: Warning - ScriptIsComplex export address 0x69811714 differs from GetProcAddress -> 0x765F0FB0 (gdi32full.dll::0xa0fb0)
2025-12-06 18:31:46,566 [root] DEBUG: 5712: DLL loaded at 0x69810000: C:\Windows\SYSTEM32\usp10 (0x17000 bytes).
2025-12-06 18:31:46,582 [root] DEBUG: 5712: DLL loaded at 0x69670000: C:\Windows\System32\Bcp47Langs (0x48000 bytes).
2025-12-06 18:31:46,597 [root] DEBUG: 5712: DLL loaded at 0x69640000: C:\Windows\System32\bcp47mrm (0x22000 bytes).
2025-12-06 18:31:46,597 [root] DEBUG: 5712: DLL loaded at 0x696C0000: C:\Windows\System32\Windows.Globalization (0x145000 bytes).
2025-12-06 18:31:46,613 [root] DEBUG: 5712: DLL loaded at 0x695D0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x61000 bytes).
2025-12-06 18:31:46,613 [root] DEBUG: 5712: DLL loaded at 0x695B0000: C:\Windows\SYSTEM32\globinputhost (0x1c000 bytes).
2025-12-06 18:31:46,632 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
2025-12-06 18:31:46,663 [root] DEBUG: 5712: hook_api: NetUserGetInfo export address 0x6959E1DE obtained via GetFunctionAddress
2025-12-06 18:31:46,671 [root] DEBUG: 5712: hook_api: NetGetJoinInformation export address 0x6959D233 obtained via GetFunctionAddress
2025-12-06 18:31:46,671 [root] DEBUG: 5712: hook_api: NetUserGetLocalGroups export address 0x6959E20A obtained via GetFunctionAddress
2025-12-06 18:31:46,671 [root] DEBUG: 5712: hook_api: DsEnumerateDomainTrustsW export address 0x6959BC9F obtained via GetFunctionAddress
2025-12-06 18:31:46,671 [root] DEBUG: 5712: DLL loaded at 0x69590000: C:\Windows\SYSTEM32\netapi32 (0x14000 bytes).
2025-12-06 18:31:46,686 [root] DEBUG: 5712: DLL loaded at 0x69480000: C:\Windows\SYSTEM32\DSREG (0x110000 bytes).
2025-12-06 18:31:47,662 [root] DEBUG: 5712: DLL loaded at 0x694E0000: C:\Windows\System32\Windows.Networking.Connectivity (0x8f000 bytes).
2025-12-06 18:31:47,687 [root] DEBUG: 5712: DLL loaded at 0x69410000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xc1000 bytes).
2025-12-06 18:31:47,707 [root] DEBUG: 5712: DLL loaded at 0x69050000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x3b9000 bytes).
2025-12-06 18:31:47,737 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:47,737 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:47,737 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:47,737 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:47,737 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:47,737 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:47,737 [lib.api.process] DEBUG: Failed getting exit code for <Process 2664 ???>
2025-12-06 18:31:47,737 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:47,737 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:47,737 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:47,737 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:47,737 [lib.api.process] WARNING: the <Process 2664 ???> is not alive, injection aborted
2025-12-06 18:31:49,747 [root] DEBUG: 5712: DLL loaded at 0x68FD0000: C:\Windows\SYSTEM32\wbemcomn (0x70000 bytes).
2025-12-06 18:31:49,747 [root] DEBUG: 5712: DLL loaded at 0x69040000: C:\Windows\system32\wbem\wbemprox (0xd000 bytes).
2025-12-06 18:31:49,763 [root] DEBUG: 5712: DLL loaded at 0x68FC0000: C:\Windows\system32\wbem\wbemsvc (0x10000 bytes).
2025-12-06 18:31:49,763 [root] DEBUG: 5712: DLL loaded at 0x68EF0000: C:\Windows\system32\wbem\fastprox (0xc9000 bytes).
2025-12-06 18:31:49,778 [root] DEBUG: 5712: DLL loaded at 0x68ED0000: C:\Windows\SYSTEM32\amsi (0x18000 bytes).
2025-12-06 18:31:49,778 [root] DEBUG: 5712: DLL loaded at 0x68E90000: C:\Program Files (x86)\Windows Defender\MpOav (0x38000 bytes).
2025-12-06 18:31:51,122 [modules.auxiliary.human] INFO: Found button "yes", clicking it
2025-12-06 18:31:52,169 [root] DEBUG: 5712: DLL loaded at 0x68CB0000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2025-12-06 18:31:52,185 [root] DEBUG: 5712: DLL loaded at 0x68C70000: C:\Windows\system32\dataexchange (0x31000 bytes).
2025-12-06 18:31:52,216 [root] DEBUG: 5712: DLL loaded at 0x68790000: C:\Program Files (x86)\Microsoft Office\root\Office16\gfx (0x4d4000 bytes).
2025-12-06 18:31:52,232 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\FontCache\4\CatalogCacheMetaData2.xml
2025-12-06 18:31:52,310 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\ASkwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDBfTnVsbAA.S
2025-12-06 18:31:52,310 [root] DEBUG: 5712: api-rate-cap: NtQueryValueKey hook disabled due to rate
2025-12-06 18:31:52,325 [root] DEBUG: 5712: api-rate-cap: RtlSetCurrentTransaction hook disabled due to rate
2025-12-06 18:31:52,388 [root] DEBUG: 5712: DLL loaded at 0x686F0000: C:\Program Files (x86)\Microsoft Office\root\Office16\osfshared (0xa0000 bytes).
2025-12-06 18:32:03,138 [root] DEBUG: 5712: DLL loaded at 0x68650000: C:\Windows\System32\SLC (0x1f000 bytes).
2025-12-06 18:32:03,154 [root] DEBUG: 5712: DLL loaded at 0x68670000: C:\Windows\System32\appresolver (0x71000 bytes).
2025-12-06 18:32:03,154 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MI2HV2EPK8J0SC9WPPHS.temp
2025-12-06 18:32:03,154 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4596
2025-12-06 18:32:03,154 [lib.api.process] INFO: Monitor config for <Process 4596 explorer.exe>: C:\tmpw7hn3wdo\dll\4596.ini
2025-12-06 18:32:03,154 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:32:03,169 [root] DEBUG: Loader: Injecting process 4596 with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:32:03,185 [root] DEBUG: 4596: Python path set to 'C:\Python38'.
2025-12-06 18:32:03,185 [root] INFO: Disabling sleep skipping.
2025-12-06 18:32:03,185 [root] DEBUG: 4596: Dropped file limit defaulting to 100.
2025-12-06 18:32:03,185 [root] DEBUG: 4596: YaraInit: Compiled 41 rule files
2025-12-06 18:32:03,185 [root] DEBUG: 4596: YaraInit: Compiled rules saved to file C:\tmpw7hn3wdo\data\yara\capemon.yac
2025-12-06 18:32:03,185 [root] DEBUG: 4596: GetAddressByYara: ModuleBase 0x00007FFAEACB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:32:03,201 [root] DEBUG: 4596: RtlInsertInvertedFunctionTable 0x00007FFAEACC090E, LdrpInvertedFunctionTableSRWLock 0x00007FFAEAE1D510
2025-12-06 18:32:03,201 [root] DEBUG: 4596: YaraScan: Scanning 0x00007FF71EBE0000, size 0x50b15a
2025-12-06 18:32:03,216 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:32:03,216 [root] DEBUG: 4596: Monitor initialised: 64-bit capemon loaded in process 4596 at 0x00007FFAC61C0000, thread 7164, image base 0x00007FF71EBE0000, stack from 0x0000000008D32000-0x0000000008D40000
2025-12-06 18:32:03,216 [root] DEBUG: 4596: Commandline: C:\Windows\Explorer.EXE
2025-12-06 18:32:03,232 [root] DEBUG: 4596: hook_api: LdrpCallInitRoutine export address 0x00007FFAEACC99BC obtained via GetFunctionAddress
2025-12-06 18:32:03,232 [root] DEBUG: 4596: hook_api: Warning - CoCreateInstance export address 0x00007FFAE9AE42CB differs from GetProcAddress -> 0x00007FFAE912A420 (combase.dll::0x2a420)
2025-12-06 18:32:03,232 [root] DEBUG: 4596: hook_api: Warning - CoCreateInstanceEx export address 0x00007FFAE9AE430A differs from GetProcAddress -> 0x00007FFAE91A4180 (combase.dll::0xa4180)
2025-12-06 18:32:03,232 [root] DEBUG: 4596: hook_api: Warning - CoGetClassObject export address 0x00007FFAE9AE489A differs from GetProcAddress -> 0x00007FFAE912EB00 (combase.dll::0x2eb00)
2025-12-06 18:32:03,232 [root] DEBUG: 4596: hook_api: Warning - CLSIDFromProgID export address 0x00007FFAE9AE3B16 differs from GetProcAddress -> 0x00007FFAE91A8570 (combase.dll::0xa8570)
2025-12-06 18:32:03,232 [root] DEBUG: 4596: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FFAE9AE3B53 differs from GetProcAddress -> 0x00007FFAE91A8A40 (combase.dll::0xa8a40)
2025-12-06 18:32:03,232 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:32:03,248 [root] DEBUG: 4596: set_hooks: Unable to hook LockResource
2025-12-06 18:32:03,248 [root] DEBUG: 4596: hook_api: Warning - NetUserGetInfo export address 0x00007FFADE681F5E differs from GetProcAddress -> 0x00007FFADE692C40 (samcli.dll::0x2c40)
2025-12-06 18:32:03,248 [root] DEBUG: 4596: hook_api: Warning - NetGetJoinInformation export address 0x00007FFADE680FB3 differs from GetProcAddress -> 0x00007FFAE75516F0 (wkscli.dll::0x16f0)
2025-12-06 18:32:03,248 [root] DEBUG: 4596: hook_api: Warning - NetUserGetLocalGroups export address 0x00007FFADE681F8A differs from GetProcAddress -> 0x00007FFADE691C60 (samcli.dll::0x1c60)
2025-12-06 18:32:03,248 [root] DEBUG: 4596: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x00007FFADE67FA1F differs from GetProcAddress -> 0x00007FFAE78F8780 (LOGONCLI.DLL::0x18780)
2025-12-06 18:32:03,248 [root] DEBUG: 4596: Hooked 605 out of 606 functions
2025-12-06 18:32:03,248 [root] DEBUG: 4596: Syscall hook installed, syscall logging level 1
2025-12-06 18:32:03,248 [root] INFO: Loaded monitor into process with pid 4596
2025-12-06 18:32:03,248 [root] DEBUG: 4596: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2025-12-06 18:32:03,263 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-06 18:32:03,263 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:32:03,263 [lib.api.process] INFO: Injected into 64-bit <Process 4596 explorer.exe>
2025-12-06 18:32:03,388 [root] DEBUG: 4596: caller_dispatch: Added region at 0x00007FF71EBE0000 to tracked regions list (user32::MsgWaitForMultipleObjectsEx returns to 0x00007FF71EC5C0F9, thread 4776).
2025-12-06 18:32:03,388 [root] DEBUG: 4596: YaraScan: Scanning 0x00007FF71EBE0000, size 0x50b15a
2025-12-06 18:32:03,404 [root] DEBUG: 4596: ProcessImageBase: Main module image at 0x00007FF71EBE0000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:32:24,716 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5712, handle 0x1f24: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
2025-12-06 18:32:25,497 [root] DEBUG: 5712: DLL loaded at 0x685F0000: C:\Windows\System32\oleacc (0x53000 bytes).
2025-12-06 18:32:29,747 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:32:29,747 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5976, handle 0x1e20: Error obtaining target process name
2025-12-06 18:32:29,747 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:32:29,747 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6696, handle 0x520: Error obtaining target process name
2025-12-06 18:32:29,747 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:32:29,747 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5192, handle 0x1eb8: Error obtaining target process name
2025-12-06 18:32:29,747 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:32:29,747 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5636, handle 0x1f0c: Error obtaining target process name
2025-12-06 18:32:29,747 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:32:29,747 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6704, handle 0x1f08: Error obtaining target process name
2025-12-06 18:32:42,232 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
2025-12-06 18:32:42,247 [root] DEBUG: 5712: DLL loaded at 0x68560000: C:\Windows\SYSTEM32\sxs (0x87000 bytes).
2025-12-06 18:32:42,247 [root] DEBUG: 4596: DLL loaded at 0x00007FFADA610000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2025-12-06 18:32:42,263 [root] DEBUG: 4596: DLL loaded at 0x00007FFACA650000: C:\Windows\System32\icu (0x22e000 bytes).
2025-12-06 18:32:42,263 [root] DEBUG: 4596: api-rate-cap: memcpy hook disabled due to rate
2025-12-06 18:32:49,278 [root] DEBUG: 4596: OpenProcessHandler: Image base for process 5712 (handle 0x1ef0): 0x0000000000310000.
2025-12-06 18:32:52,575 [root] DEBUG: 5712: DLL loaded at 0x684E0000: C:\Windows\SYSTEM32\WINSPOOL.DRV (0x76000 bytes).
2025-12-06 18:32:52,591 [root] DEBUG: 5712: CreateProcessHandler: Injection info set for new process 4680: C:\Windows\splwow64.exe, ImageBase: 0x00000000
2025-12-06 18:32:52,591 [root] INFO: Announced 64-bit process name: splwow64.exe pid: 4680
2025-12-06 18:32:52,591 [lib.api.process] INFO: Monitor config for <Process 4680 splwow64.exe>: C:\tmpw7hn3wdo\dll\4680.ini
2025-12-06 18:32:52,591 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:32:52,607 [root] DEBUG: Loader: Injecting process 4680 (thread 4900) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:32:52,607 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:32:52,607 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:32:52,607 [lib.api.process] INFO: Injected into 64-bit <Process 4680 splwow64.exe>
2025-12-06 18:32:52,622 [root] DEBUG: 4680: Python path set to 'C:\Python38'.
2025-12-06 18:32:52,622 [root] DEBUG: 4680: Dropped file limit defaulting to 100.
2025-12-06 18:32:52,622 [root] INFO: Disabling sleep skipping.
2025-12-06 18:32:52,622 [root] DEBUG: 4680: YaraInit: Compiled rules loaded from existing file C:\tmpw7hn3wdo\data\yara\capemon.yac
2025-12-06 18:32:52,622 [root] DEBUG: 4680: GetAddressByYara: ModuleBase 0x00007FFAEACB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:32:52,638 [root] DEBUG: 4680: RtlInsertInvertedFunctionTable 0x00007FFAEACC090E, LdrpInvertedFunctionTableSRWLock 0x00007FFAEAE1D510
2025-12-06 18:32:52,638 [root] DEBUG: 4680: YaraScan: Scanning 0x00007FF638C20000, size 0x2c346
2025-12-06 18:32:52,638 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:32:52,638 [root] DEBUG: 4680: Monitor initialised: 64-bit capemon loaded in process 4680 at 0x00007FFAC61C0000, thread 4900, image base 0x00007FF638C20000, stack from 0x0000000000A75000-0x0000000000A80000
2025-12-06 18:32:52,638 [root] DEBUG: 4680: Commandline: C:\Windows\splwow64.exe 8192
2025-12-06 18:32:52,638 [root] DEBUG: 4680: hook_api: LdrpCallInitRoutine export address 0x00007FFAEACC99BC obtained via GetFunctionAddress
2025-12-06 18:32:52,638 [root] DEBUG: 4680: hook_api: Warning - CoCreateInstance export address 0x00007FFAE9AE42CB differs from GetProcAddress -> 0x00007FFAE912A420 (combase.dll::0x2a420)
2025-12-06 18:32:52,638 [root] DEBUG: 4680: hook_api: Warning - CoCreateInstanceEx export address 0x00007FFAE9AE430A differs from GetProcAddress -> 0x00007FFAE91A4180 (combase.dll::0xa4180)
2025-12-06 18:32:52,638 [root] DEBUG: 4680: hook_api: Warning - CoGetClassObject export address 0x00007FFAE9AE489A differs from GetProcAddress -> 0x00007FFAE912EB00 (combase.dll::0x2eb00)
2025-12-06 18:32:52,653 [root] DEBUG: 4680: hook_api: Warning - CLSIDFromProgID export address 0x00007FFAE9AE3B16 differs from GetProcAddress -> 0x00007FFAE91A8570 (combase.dll::0xa8570)
2025-12-06 18:32:52,653 [root] DEBUG: 4680: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FFAE9AE3B53 differs from GetProcAddress -> 0x00007FFAE91A8A40 (combase.dll::0xa8a40)
2025-12-06 18:32:52,653 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:32:52,653 [root] DEBUG: 4680: set_hooks: Unable to hook LockResource
2025-12-06 18:32:52,653 [root] DEBUG: 4680: Hooked 605 out of 606 functions
2025-12-06 18:32:52,653 [root] DEBUG: 4680: Syscall hook installed, syscall logging level 1
2025-12-06 18:32:52,653 [root] INFO: Loaded monitor into process with pid 4680
2025-12-06 18:32:52,653 [root] DEBUG: 4680: caller_dispatch: Added region at 0x00007FF638C20000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF638C328F1, thread 4900).
2025-12-06 18:32:52,653 [root] DEBUG: 4680: YaraScan: Scanning 0x00007FF638C20000, size 0x2c346
2025-12-06 18:32:52,653 [root] DEBUG: 4680: ProcessImageBase: Main module image at 0x00007FF638C20000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:32:52,669 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD4F40000: C:\Windows\SYSTEM32\SPOOLSS (0x1f000 bytes).
2025-12-06 18:32:52,669 [root] DEBUG: 4680: set_hooks_by_export_directory: Hooked 0 out of 606 functions
2025-12-06 18:32:52,669 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD4DF0000: C:\Windows\SYSTEM32\PrintIsolationProxy (0x1d000 bytes).
2025-12-06 18:32:52,669 [root] DEBUG: 4680: set_hooks_by_export_directory: Hooked 0 out of 606 functions
2025-12-06 18:32:52,669 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE6260000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2025-12-06 18:32:52,669 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE8900000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2025-12-06 18:32:52,669 [root] DEBUG: 4680: DLL loaded at 0x00007FFAEA570000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2025-12-06 18:32:52,778 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:32:52,778 [root] DEBUG: 4680: OpenProcessHandler: Injection info created for process 5712, handle 0x2d0: Error obtaining target process name
2025-12-06 18:32:52,794 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE9D30000: C:\Windows\System32\OLEAUT32 (0xcd000 bytes).
2025-12-06 18:32:52,794 [root] DEBUG: 4680: DLL loaded at 0x00007FFADFE80000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2025-12-06 18:32:52,794 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3D30000: C:\Windows\SYSTEM32\prntvpt (0x32000 bytes).
2025-12-06 18:32:52,794 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE8250000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2025-12-06 18:32:52,794 [root] DEBUG: 4680: DLL loaded at 0x00007FFAC5E00000: C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_cce2ae2d764e8510\Amd64\PrintConfig (0x3b4000 bytes).
2025-12-06 18:32:52,810 [root] DEBUG: 4680: api-rate-cap: memcpy hook disabled due to rate
2025-12-06 18:32:52,825 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD65B0000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2025-12-06 18:32:52,841 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE0D80000: C:\Windows\System32\iertutil (0x2b1000 bytes).
2025-12-06 18:32:52,841 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE0D30000: C:\Windows\System32\srvcli (0x28000 bytes).
2025-12-06 18:32:52,841 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE78D0000: C:\Windows\System32\netutils (0xc000 bytes).
2025-12-06 18:32:52,841 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE10F0000: C:\Windows\SYSTEM32\urlmon (0x1ec000 bytes).
2025-12-06 18:32:52,841 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE5D70000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2025-12-06 18:32:52,857 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3D90000: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\VCRUNTIME140 (0x1b000 bytes).
2025-12-06 18:32:52,857 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3DC0000: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\VCRUNTIME140_1 (0xc000 bytes).
2025-12-06 18:32:52,857 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3DD0000: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF (0x13000 bytes).
2025-12-06 18:32:52,888 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE83C0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2025-12-06 18:32:52,888 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD95A0000: C:\Windows\SYSTEM32\Print.PrintSupport.Source (0x61000 bytes).
2025-12-06 18:32:52,935 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD8960000: C:\Windows\System32\jscript (0xd6000 bytes).
2025-12-06 18:32:52,935 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:32:52,935 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE82D0000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2025-12-06 18:32:52,935 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB7B0000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2025-12-06 18:32:52,966 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE8130000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2025-12-06 18:32:52,997 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:32:53,013 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:32:53,060 [root] DEBUG: 4680: DLL loaded at 0x00007FFADA7C0000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2025-12-06 18:32:53,060 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3EC0000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2025-12-06 18:32:53,060 [root] DEBUG: 4680: DLL loaded at 0x00007FFACF6E0000: C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_8c12706b076a4ca4\Amd64\mxdwdrv (0xd1000 bytes).
2025-12-06 18:32:53,107 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE2390000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7cd000 bytes).
2025-12-06 18:32:53,122 [root] DEBUG: 4680: DLL loaded at 0x00007FFAC6960000: C:\Windows\SYSTEM32\opcservices (0x21d000 bytes).
2025-12-06 18:32:53,138 [root] DEBUG: 4680: DLL loaded at 0x00007FFAC5B40000: C:\Windows\SYSTEM32\xpsservices (0x2bc000 bytes).
2025-12-06 18:32:53,138 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD8900000: C:\Windows\SYSTEM32\XpsPushLayer (0x60000 bytes).
2025-12-06 18:32:53,169 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE2DF0000: C:\Windows\system32\FontSub (0x23000 bytes).
2025-12-06 18:32:53,200 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:32:53,247 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3D20000: C:\Windows\SYSTEM32\MSIMG32 (0x7000 bytes).
2025-12-06 18:32:53,247 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE9E00000: C:\Windows\System32\SHELL32 (0x744000 bytes).
2025-12-06 18:32:53,247 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD88D0000: C:\Windows\system32\compstui (0x23000 bytes).
2025-12-06 18:32:53,247 [root] DEBUG: 4680: DLL loaded at 0x00007FFADAC70000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes).
2025-12-06 18:32:53,263 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE7D70000: C:\Windows\SYSTEM32\Wldp (0x2e000 bytes).
2025-12-06 18:32:53,263 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE6460000: C:\Windows\SYSTEM32\windows.storage (0x793000 bytes).
2025-12-06 18:32:53,263 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:32:53,294 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:32:53,325 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE3D20000: C:\Windows\SYSTEM32\MSIMG32 (0x7000 bytes).
2025-12-06 18:32:53,325 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE9E00000: C:\Windows\System32\SHELL32 (0x744000 bytes).
2025-12-06 18:32:53,325 [root] DEBUG: 4680: DLL loaded at 0x00007FFAD88D0000: C:\Windows\system32\compstui (0x23000 bytes).
2025-12-06 18:32:53,325 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE7D70000: C:\Windows\SYSTEM32\Wldp (0x2e000 bytes).
2025-12-06 18:32:53,325 [root] DEBUG: 4680: DLL loaded at 0x00007FFAE6460000: C:\Windows\SYSTEM32\windows.storage (0x793000 bytes).
2025-12-06 18:32:53,341 [root] DEBUG: 4680: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:33:40,294 [root] INFO: Process with pid 4596 appears to have terminated
2025-12-06 18:34:23,403 [root] DEBUG: 5712: DLL loaded at 0x67E80000: C:\Windows\System32\NETAPI32 (0x14000 bytes).
2025-12-06 18:34:23,419 [root] DEBUG: 5712: DLL loaded at 0x67E60000: C:\Windows\System32\WKSCLI (0x11000 bytes).
2025-12-06 18:34:23,419 [root] DEBUG: 5712: DLL loaded at 0x67EA0000: C:\Windows\System32\ieframe (0x63d000 bytes).
2025-12-06 18:34:23,435 [root] DEBUG: 5712: DLL loaded at 0x67E10000: C:\Windows\SYSTEM32\msIso (0x46000 bytes).
2025-12-06 18:34:23,513 [root] DEBUG: 5712: DLL loaded at 0x66BB0000: C:\Windows\SYSTEM32\MSHTML (0x1253000 bytes).
2025-12-06 18:34:45,294 [root] INFO: Analysis timeout hit, terminating analysis
2025-12-06 18:34:45,294 [lib.api.process] INFO: Terminate event set for <Process 5712 EXCEL.EXE>
2025-12-06 18:34:45,294 [root] DEBUG: 5712: Terminate Event: Attempting to dump process 5712
2025-12-06 18:34:45,325 [root] DEBUG: 5712: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:34:45,325 [root] DEBUG: 5712: Terminate Event: Current region empty
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\1380790193167760279.C4
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-shm
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-wal
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\file.xls
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302413377100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log
2025-12-06 18:34:45,325 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302412540100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log
2025-12-06 18:34:45,325 [lib.api.process] INFO: Termination confirmed for <Process 5712 EXCEL.EXE>
2025-12-06 18:34:45,325 [root] DEBUG: 5712: Terminate Event: CAPE shutdown complete for process 5712
2025-12-06 18:34:45,325 [root] INFO: Terminate event set for process 5712
2025-12-06 18:34:45,325 [lib.api.process] INFO: Terminate event set for <Process 4680 splwow64.exe>
2025-12-06 18:34:45,341 [root] DEBUG: 4680: Terminate Event: Attempting to dump process 4680
2025-12-06 18:34:45,341 [root] DEBUG: 4680: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:34:45,341 [root] DEBUG: 4680: Terminate Event: Current region empty
2025-12-06 18:34:45,341 [lib.api.process] INFO: Termination confirmed for <Process 4680 splwow64.exe>
2025-12-06 18:34:45,341 [root] DEBUG: 4680: Terminate Event: CAPE shutdown complete for process 4680
2025-12-06 18:34:45,341 [root] INFO: Terminate event set for process 4680
2025-12-06 18:34:45,341 [root] INFO: Created shutdown mutex
2025-12-06 18:34:46,357 [root] INFO: Shutting down package
2025-12-06 18:34:46,357 [root] INFO: Stopping auxiliary modules
2025-12-06 18:34:46,357 [root] INFO: Stopping auxiliary module: Browser
2025-12-06 18:34:46,357 [root] INFO: Stopping auxiliary module: Curtain
2025-12-06 18:34:46,357 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [Errno 13] Permission denied: 'C:\\curtain.log'
2025-12-06 18:34:46,357 [modules.auxiliary.curtain] ERROR: Curtain log file not found!
2025-12-06 18:34:46,357 [root] INFO: Stopping auxiliary module: End_noisy_tasks
2025-12-06 18:34:46,357 [root] INFO: Stopping auxiliary module: Evtx
2025-12-06 18:34:46,357 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Application.evtx to zip dump
2025-12-06 18:34:46,357 [root] WARNING: Cannot terminate auxiliary module Evtx: [Errno 13] Permission denied: 'C:/windows/Sysnative/winevt/Logs\\Application.evtx'
2025-12-06 18:34:46,357 [root] INFO: Stopping auxiliary module: Human
2025-12-06 18:34:56,357 [root] WARNING: Failed to join {aux} thread.
2025-12-06 18:34:56,357 [root] INFO: Stopping auxiliary module: Pre_script
2025-12-06 18:34:56,357 [root] INFO: Stopping auxiliary module: Screenshots
2025-12-06 18:34:58,451 [root] INFO: Stopping auxiliary module: Usage
2025-12-06 18:34:59,482 [root] INFO: Stopping auxiliary module: During_script
2025-12-06 18:34:59,482 [root] INFO: Finishing auxiliary modules
2025-12-06 18:34:59,482 [root] INFO: Shutting down pipe server and dumping dropped files
2025-12-06 18:34:59,482 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres to files\3bf364d8a5fa3aaf48da4e4754bf7e5e9acc88db5e1229c5d4817afc1706b711; Size is 4542; Max size: 100000000
2025-12-06 18:34:59,482 [root] INFO: Error dumping file from path "c:\users\user\appdata\local\temp\~$file.xls": [Errno 13] Permission denied: 'c:\\users\\user\\appdata\\local\\temp\\~$file.xls'
2025-12-06 18:34:59,482 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres to files\77a05af76960632703062392cc933d470edc116e4cf28859fc965b2e94eae2aa; Size is 2278; Max size: 100000000
2025-12-06 18:34:59,482 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres to files\ac4863b7b7788eca2d46f74ea8517242beebd5270fbe64dd0921c7b476bfcacc; Size is 2684; Max size: 100000000
2025-12-06 18:34:59,482 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\FontCache\4\CatalogCacheMetaData2.xml to files\68d6c684e5d5a8bb917d811f0ab7c5299d9b2f327ebd3f758be8fcd380941a5c; Size is 1929; Max size: 100000000
2025-12-06 18:34:59,497 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\ASkwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDBfTnVsbAA.S to files\7a59f8d1d4d082b69b6652eb2ed6d67e44c7db8541074d1b61063ce69659d9b3; Size is 87; Max size: 100000000
2025-12-06 18:34:59,497 [lib.common.results] INFO: Uploading file c:\users\user\appdata\roaming\microsoft\windows\recent\customdestinations\b8ab77100df80ab2.customdestinations-ms to files\90bf6baa6f968a285f88620fbf91e1f5aa3e66e2bad50fd16f37913280ad8228; Size is 24; Max size: 100000000
2025-12-06 18:34:59,513 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat to files\7ab4047101e2ba8d04f95bdc33242687832ad63d7c2fcc899bd36065e6e48d9c; Size is 996; Max size: 100000000
2025-12-06 18:34:59,513 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\1380790193167760279.C4 to files\c35020473aed1b4642cd726cad727b63fff2824ad68cedd7ffb73c7cbd890479; Size is 32768; Max size: 100000000
2025-12-06 18:34:59,513 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-shm to files\15e1afb286b24dadcec06bc7d2e3647cf3a053580b86cf6b222561414874334b; Size is 32768; Max size: 100000000
2025-12-06 18:34:59,513 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-wal to files\1be72704f6439a4c5cbb3e32437066e6519880735cd5e678cefa9dc70c2a2ad9; Size is 4152; Max size: 100000000
2025-12-06 18:34:59,513 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db to files\a8f257b04613cd3d2aadbf2fa760f19b79721663778fb44491195cd3c9d67a5f; Size is 36864; Max size: 100000000
2025-12-06 18:34:59,529 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\file.xls to files\d1af4d77f5ebde1b70dc7a9c5cc71757d9e457afb713b1b5c84968af69a06658; Size is 8825; Max size: 100000000
2025-12-06 18:34:59,575 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302413377100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log to files\cd52d81e25f372e6fa4db2c0dfceb59862c1969cab17096da352b34950c973cc; Size is 20971520; Max size: 100000000
2025-12-06 18:34:59,700 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302412540100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log to files\d4c0c6e58c5a30aaaf5b5b7ad11cdbd21bf893594480f5d092c15cadc46df10b; Size is 20971520; Max size: 100000000
2025-12-06 18:34:59,780 [root] WARNING: Folder at path "C:\HNxZeWN\debugger" does not exist, skipping
2025-12-06 18:34:59,780 [root] WARNING: Folder at path "C:\HNxZeWN\tlsdump" does not exist, skipping
2025-12-06 18:34:59,780 [root] INFO: Analysis completed

    

    

    

    

Machine

Name Label Manager Started On Shutdown On
win10-64bit-tiny-3 win10-64bit-tiny-3 KVM 2025-12-08 13:54:56 2025-12-08 13:58:20

File Details

File Name
file
File Type Microsoft Excel 2007+
File Size 8825 bytes
MD5 908c30167b8fd8419f1014c127b8506d
SHA1 79a83a99d7ae31db88cb367fac01b7616608be8f
SHA256 d1af4d77f5ebde1b70dc7a9c5cc71757d9e457afb713b1b5c84968af69a06658 [VT] [MWDB] [Bazaar]
SHA3-384 aae6135e927179e87b340f207858611d93a46783d5018f5e03111d5c936fdd1ba0086b7f51ddb135772d43bb9a77efbb
CRC32 32C8B93B
TLSH T16C026BAEE5319D2EC776803CA05C55FAE86C35C1A245A94F6C5CB04BAA412C343AF3DE
Ssdeep 192:wc8mVa2BIIb3UrbOdVvlfm7T4edPS9TLwKFaoaaFM:wc3clI3wbele7ZIn1aoaaFM
File BinGraph Vba2Graph

BKwAH
xl/styles.xmlPK
Bn/1L]K
docProps/core.xmlPK
E[]mN
P!XS)bR
_rels/.relsPK
_rels/.rels
r:"y_dl
GJy(v
xl/worksheets/sheet1.xml
HM-qI,I
DO97*
EKDG$g-
xl/worksheets/sheet1.xmlPK
dJhyB
)Uzf6
[Content_Types].xmlPK
iZiEo
z4|[4
xl/_rels/workbook.xml.rels
0ADI?
docProps/core.xml
IL"L-
xl/workbook.xml
xl/_rels/workbook.xml.relsPK
C{MUit
docProps/app.xml
[Content_Types].xml
xl/workbook.xmlPK
d5mGb
0^FjbJj
dt3_,
xl/styles.xml
xl/theme/theme1.xml
USh9i
ji){^
xl/sharedStrings.xmlPK
,(cgj
@{wN%
sy?tG{
xl/sharedStrings.xml4
xl/theme/theme1.xmlPK
docProps/app.xmlPK
U2TR(.H
S{dKrc
0u2js
=#S%;
5]4Ot

SummaryInformation Metadata

created 2024-04-09T01:06:37Z
creator keevan.kwok.yh
lastModifiedBy KEEVAN KWOK YUANHENG
modified 2024-04-09T01:08:29Z

DocumentSummaryInformation Metadata

AppVersion 16.0300
Application Microsoft Excel
DocSecurity 0
HyperlinksChanged false
LinksUpToDate false
ScaleCrop false
SharedDoc false


XLM Macro

            
        

Reports: JSON HTML Lite

Defense Evasion Discovery Command and Control Privilege Escalation
  • T1564 - Hide Artifacts
    • stealth_file
  • T1055 - Process Injection
    • resumethread_remote_process
  • T1070 - Indicator Removal
    • deletes_files
  • T1070.004 - File Deletion
    • deletes_files
  • T1221 - Template Injection
    • network_document_http
  • T1564.001 - Hidden Files and Directories
    • stealth_file
  • T1082 - System Information Discovery
    • antivm_checks_available_memory
  • T1057 - Process Discovery
    • createtoolhelp32snapshot_module_enumeration
  • T1071 - Application Layer Protocol
    • network_document_http
    • http_request
    • multiple_useragents
  • T1055 - Process Injection
    • resumethread_remote_process

Usage


Processing ( 5.28 seconds )

  • 4.517 CAPE
  • 0.756 BehaviorAnalysis
  • 0.007 Heatmap
  • 0.003 AnalysisInfo
  • 0.001 Debug

Signatures ( 0.17 seconds )

  • 0.047 antiav_detectreg
  • 0.02 territorial_disputes_sigs
  • 0.018 infostealer_ftp
  • 0.01 antianalysis_detectreg
  • 0.01 infostealer_im
  • 0.005 antivm_vbox_keys
  • 0.004 antivm_vmware_keys
  • 0.004 ransomware_files
  • 0.003 antianalysis_detectfile
  • 0.003 antiav_detectfile
  • 0.003 ketrican_regkeys
  • 0.003 masquerade_process_name
  • 0.002 antivm_generic_diskreg
  • 0.002 antivm_parallels_keys
  • 0.002 antivm_vpc_keys
  • 0.002 antivm_xen_keys
  • 0.002 geodo_banking_trojan
  • 0.002 darkcomet_regkeys
  • 0.002 infostealer_bitcoin
  • 0.002 ransomware_extensions
  • 0.002 recon_fingerprint
  • 0.002 remcos_regkeys
  • 0.001 accesses_netlogon_regkey
  • 0.001 antidebug_devices
  • 0.001 antivm_bochs_keys
  • 0.001 antivm_hyperv_keys
  • 0.001 antivm_vbox_files
  • 0.001 browser_security
  • 0.001 bypass_firewall
  • 0.001 registry_credential_store_access
  • 0.001 poullight_files
  • 0.001 office_martian_children
  • 0.001 packer_armadillo_regkey
  • 0.001 medusalocker_regkeys
  • 0.001 revil_mutexes
  • 0.001 limerat_regkeys
  • 0.001 modirat_behavior
  • 0.001 warzonerat_regkeys
  • 0.001 ursnif_behavior

Reporting ( 2.91 seconds )

  • 2.783 MITRE_TTPS
  • 0.046 ReportHTML
  • 0.042 LiteReport
  • 0.042 JsonDump

Signatures

Checks available memory
Queries the keyboard layout
SetUnhandledExceptionFilter detected (possible anti-debug)
Uses Windows APIs to generate a cryptographic key
Office loads COM DLLs, indicative of Office Macros spawning CMD process for execution
Deletes files from disk
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Content\Anonymous\Insights.json
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Schemas\MS Excel_restart.xml
Performs HTTP requests potentially not found in PCAP.
url: support.office.com:443//client/results?HelpID=126385&lcid=1033&syslcid=1033&uilcid=1033&ShowNav=true&VERSION=16&NS=EXCEL
Resumed a thread in another process
thread_resumed: Process excel.exe with process ID 5712 resumed a thread in another process with the process ID 5712
thread_resumed: Process explorer.exe with process ID 4596 resumed a thread in another process with the process ID 4596
Enumerates the modules from a process (may be used to locate base addresses in process injection)
module: pid 5712 module ntdll.dll
module: pid 5712 module KERNEL32.DLL
module: pid 5712 module KERNELBASE.dll
module: pid 5712 module apphelp.dll
module: pid 5712 module CRYPT32.dll
module: pid 5712 module ucrtbase.dll
module: pid 5712 module WS2_32.dll
module: pid 5712 module RPCRT4.dll
module: pid 5712 module USER32.dll
module: pid 5712 module win32u.dll
module: pid 5712 module GDI32.dll
module: pid 5712 module gdi32full.dll
module: pid 5712 module msvcp_win.dll
module: pid 5712 module ADVAPI32.dll
module: pid 5712 module msvcrt.dll
module: pid 5712 module sechost.dll
module: pid 5712 module ole32.dll
module: pid 5712 module combase.dll
module: pid 5712 module SHLWAPI.dll
module: pid 5712 module bcrypt.dll
module: pid 5712 module VCRUNTIME140.dll
module: pid 5712 module MSVCP140.dll
module: pid 5712 module AppVIsvSubsystems32.dll
module: pid 5712 module SHELL32.dll
module: pid 5712 module USERENV.dll
module: pid 5712 module c2r32.dll
module: pid 5712 module IMM32.DLL
module: pid 5712 module CRYPTBASE.DLL
module: pid 5712 module SspiCli.dll
module: pid 5712 module oleaut32.dll
module: pid 5712 module mso20win32client.dll
module: pid 5712 module CRYPTUI.dll
module: pid 5712 module IPHLPAPI.DLL
module: pid 5712 module mso30win32client.dll
module: pid 5712 module wevtapi.dll
module: pid 5712 module mso40uiwin32client.dll
module: pid 5712 module gdiplus.dll
module: pid 5712 module mso50win32client.dll
module: pid 5712 module mso98win32client.dll
module: pid 5712 module HTTPAPI.dll
module: pid 5712 module PROPSYS.dll
module: pid 5712 module WTSAPI32.dll
module: pid 5712 module mso.dll
module: pid 5712 module bcryptPrimitives.dll
module: pid 5712 module msi.dll
module: pid 5712 module Comctl32.dll
module: pid 5712 module d2d1.dll
module: pid 5712 module uxtheme.dll
module: pid 5712 module MSCTF.dll
module: pid 5712 module WINSTA.dll
module: pid 5712 module dxgi.dll
module: pid 5712 module kernel.appcore.dll
module: pid 5712 module VERSION.dll
module: pid 5712 module POWRPROF.dll
module: pid 5712 module UMPDC.dll
module: pid 5712 module d3d11.dll
module: pid 5712 module shcore.dll
module: pid 5712 module d3d10warp.dll
module: pid 5712 module windows.storage.dll
module: pid 5712 module Wldp.dll
module: pid 5712 module dxcore.dll
module: pid 5712 module cfgmgr32.dll
module: pid 5712 module profapi.dll
module: pid 5712 module Secur32.dll
module: pid 5712 module clbcatq.dll
module: pid 5712 module DWrite.dll
module: pid 5712 module Windows.Security.Authentication.Web.Core.dll
module: pid 5712 module wintypes.dll
module: pid 5712 module netprofm.dll
module: pid 5712 module mscoree.dll
module: pid 5712 module mscoreei.dll
module: pid 5712 module npmproxy.dll
module: pid 5712 module Normaliz.dll
module: pid 5712 module MsoAria.dll
module: pid 5712 module WINHTTP.dll
module: pid 5712 module mswsock.dll
module: pid 5712 module WINNSI.DLL
module: pid 5712 module NSI.dll
module: pid 5712 module RICHED20.DLL
module: pid 5712 module dhcpcsvc6.DLL
module: pid 5712 module dhcpcsvc.DLL
module: pid 5712 module urlmon.dll
module: pid 5712 module iertutil.dll
module: pid 5712 module srvcli.dll
module: pid 5712 module netutils.dll
module: pid 5712 module Windows.UI.dll
module: pid 5712 module WindowManagementAPI.dll
module: pid 5712 module TextInputFramework.dll
module: pid 5712 module InputHost.dll
module: pid 5712 module twinapi.appcore.dll
module: pid 5712 module CoreMessaging.dll
module: pid 5712 module CoreUIComponents.dll
module: pid 5712 module ntmarta.dll
module: pid 5712 module WININET.dll
module: pid 5712 module Windows.UI.Immersive.dll
module: pid 5712 module ondemandconnroutehelper.dll
module: pid 5712 module sppc.dll
module: pid 5712 module sppcs.dll
module: pid 5712 module webio.dll
module: pid 5712 module DNSAPI.dll
module: pid 5712 module XmlLite.dll
module: pid 5712 module rasadhlp.dll
module: pid 5712 module Cabinet.dll
module: pid 5712 module d3d10_1.dll
module: pid 5712 module d3d10_1core.dll
module: pid 5712 module webservices.dll
module: pid 5712 module OneCoreCommonProxyStub.dll
module: pid 5712 module dwmapi.dll
module: pid 5712 module vaultcli.dll
module: pid 5712 module TextShaping.dll
module: pid 5712 module aadWamExtension.dll
module: pid 5712 module oart.dll
module: pid 5712 module twinapi.dll
module: pid 5712 module CRYPTSP.dll
module: pid 5712 module rsaenh.dll
module: pid 5712 module HvsiManagementApi.dll
module: pid 5712 module policymanager.dll
module: pid 5712 module msvcp110_win.dll
Checks for presence of debugger via IsDebuggerPresent
Office loads MSHTML DLL, indicative of ActiveX execution
Network activity contains more than one unique useragent.
process: EXCEL.EXE
user-agent:
process: EXCEL.EXE
user-agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
A document file initiated network communications indicative of a potential exploit or payload download
http_request_path: excel.exe_HttpOpenRequestW_/client/results?HelpID=126385&lcid=1033&syslcid=1033&uilcid=1033&ShowNav=true&VERSION=16&NS=EXCEL
Creates a hidden or system file
file: C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
file: C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
A document or script file initiated network communications indicative of a potential exploit or payload download

Screenshots

No playback available.

Hosts

No hosts contacted.

DNS

No domains contacted.

Summary

C:\Windows\Globalization\Sorting\sortdefault.nls
C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker
\Device\CNG
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\msowercrash.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\Cultures\OFFICE.ODF
C:\Users\user\AppData\Local\Temp\{7897BE6F-C3A3-4899-81F3-ED5DF4333726} - OProcSessId.dat
C:\Program Files (x86)\Microsoft Office\root\Office16\WINSTA.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\winsta.dll
C:\Windows\SysWOW64\winsta.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\resourcepolicyclient.dll
C:\Windows\SysWOW64\resourcepolicyclient.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\kernel.appcore.dll
C:\Windows\SysWOW64\kernel.appcore.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\d3d10warp.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\d3d10warp.dll
C:\Windows\SysWOW64\d3d10warp.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSO40UIRES.DLL
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSO99LRES.DLL
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSORES.DLL
C:\Windows\system32
C:
C:\Program Files (x86)\Microsoft Office\root\Office16\1033\XLINTL32.DLL
C:\Program Files (x86)\Microsoft Office\root\Office16\XLINTL32.COMMON.DLL
C:\Program Files (x86)\Microsoft Office\root\SystemResources\XLINTL32.COMMON.DLL.mun
C:\Program Files (x86)\Microsoft Office\root\Office16\SystemResources\XLINTL32.DLL.mun
C:\Windows\SystemResources\USER32.dll.mun
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\SystemResources\USER32.dll.mun
C:\Program Files (x86)\Microsoft Office\root\Office16\isolatedwindowsenvironmentutils.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\isolatedwindowsenvironmentutils.dll
C:\Windows\SysWOW64\isolatedwindowsenvironmentutils.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\windows.storage.dll
C:\Windows\SysWOW64\windows.storage.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\Wldp.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\wldp.dll
C:\Windows\SysWOW64\wldp.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\DXCore.dll
C:\Windows\SysWOW64\DXCore.dll
\Device\DeviceApi\CMApi
C:\Users\user\AppData\Roaming\Microsoft\Excel\
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\1033\msointl30.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\1033\MSOINTL.DLL
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\mscoree.dll.local
C:\Windows\SysWOW64\mscoree.dll.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE.config
C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\*.log
C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302412540100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log
C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\
C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302413377100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log
C:\Program Files (x86)\Microsoft Office\root\Office16\MSOARIA.DLL
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\RICHED20.DLL
C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\OFFICE\Licenses\5\Perpetual
C:\ProgramData\Microsoft\OFFICE\Licenses\5\Perpetual
C:\Users\user\AppData\Local\Microsoft\Office\Licenses\5\Grace\1
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\SystemResources\RICHED20.DLL.mun
C:\Program Files (x86)\Common Files\Microsoft Shared\SystemResources\RICHED20.DLL.mun
C:\Users\user\AppData\Local\Microsoft\FontCache\4\Purge\*
C:\Users
C:\Users\user
C:\Users\user\AppData
C:\Users\user\AppData\Local
C:\Users\user\AppData\Local\Microsoft
C:\Users\user\AppData\Local\Microsoft\Office
C:\Users\user\AppData\Local\Microsoft\Office\16.0
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate
C:\Users\user\AppData\Local\Temp\{00142791-63ED-4D74-BA21-06FE97D3B01C}\
C:\Windows
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\wininet.dll
C:\Windows\SysWOW64\wininet.dll
C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules.xml
C:\Users\user\AppData\Local\Microsoft\FontCache\4\Catalog\ListAll.Json
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Governance\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Content\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Content\Anonymous\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Content\Anonymous\Insights.json
C:\Windows\sysnative\en-US\d2d1.dll.mui
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\**
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Aptos\*
C:\Program Files (x86)\Microsoft Office\root\Office16\XmlLite.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\xmllite.dll
C:\Windows\SysWOW64\xmllite.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\SystemResources\MSOINTL.DLL.mun
C:\Program Files (x86)\Common Files\Microsoft Shared\Office16\SystemResources\MSOINTL.DLL.mun
C:\Windows\SysWOW64\cabinet.dll
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7FC4597D-A890-4397-8628-0A7DFCBFBA28
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\uxtheme.dll.Config
C:\Windows\SysWOW64\uxtheme.dll.Config
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\uxtheme.dll
C:\Windows\SysWOW64\uxtheme.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE.Local\
C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache
C:\Users\user\AppData\Local\Microsoft\Windows
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.IE5
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE
C:\Users\user\AppData\Local\Microsoft\Windows\INetCookies
C:\Users\user\AppData\Local\Microsoft\Windows\INetCookies\ESE\
\Device\RasAcd
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\en-US\Windows.Security.Authentication.Web.Core.dll.mui
C:\Windows\SysWOW64\en-US\Windows.Security.Authentication.Web.Core.dll.mui
C:\Program Files (x86)\Microsoft Office\root\vfs\System\en-US\Windows.Security.Authentication.Web.Core.dll.mui
C:\Windows\sysnative\en-US\Windows.Security.Authentication.Web.Core.dll.mui
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Temp
C:\Windows\Temp
C:\Program Files (x86)\Microsoft Office\root\Office16\TextShaping.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\TextShaping.dll
C:\Windows\SysWOW64\TextShaping.dll
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres
C:\Program Files (x86)\Microsoft Office\root\vfs\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Program Files (x86)\Microsoft Office\root\SystemResources\EXCEL.EXE.mun
C:\Program Files (x86)\Microsoft Office\root\Office16\OART.DLL
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984
C:\Program Files (x86)\Microsoft Office\root\Office16\oartgrfserver.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\oartgrfserver.dll
C:\Windows\SysWOW64\oartgrfserver.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\CRYPTSP.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\cryptsp.dll
C:\Windows\SysWOW64\cryptsp.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\Fonts\
C:\Windows\Fonts\EUDC.TTE
C:\Program Files (x86)\Microsoft Office\root\Office16
C:\Users\user\AppData\Roaming\Microsoft\AddIns\
C:\Program
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft
C:\Program Files (x86)\Microsoft
C:\Users\user\AppData\Local\Temp
C:\Users\user\Documents\
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\*.*
C:\Program Files (x86)\Microsoft Office\root\Office16\XLSTART\*.*
C:\Users\user\AppData\Local\Temp\file.xls
\??\MountPointManager
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\en-US\Windows.Web.dll.mui
C:\Windows\SysWOW64\en-US\Windows.Web.dll.mui
C:\Program Files (x86)\Microsoft Office\root\vfs\System\en-US\Windows.Web.dll.mui
C:\Windows\sysnative\en-US\Windows.Web.dll.mui
C:\
C:\Program Files (x86)\Microsoft Office\root\Office16\DPAPI.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\dpapi.dll
C:\Windows\SysWOW64\dpapi.dll
C:\Users\user\AppData\Local\Microsoft\Windows\Caches
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000016.db
C:\Users\desktop.ini
C:\Users\user\Desktop
C:\Users\user\Desktop\desktop.ini
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\propsys.dll
C:\Windows\SysWOW64\propsys.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\System\propsys.dll
C:\Windows\sysnative\propsys.dll
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e0495fde257df2ef62ee7e3fdb1ebb9d7ff72300.tbres
C:\Users\user\AppData\Local\
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbreq
C:\Users\user\AppData\Local\Temp\~$file.xls
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
C:\Users\user\AppData\Roaming\Microsoft\Templates\
C:\Users\user\AppData\Roaming\Microsoft
C:\Users\user\AppData\Roaming\Microsoft\Templates
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\SystemResources\MSORES.DLL.mun
C:\Program Files (x86)\Common Files\Microsoft Shared\SystemResources\MSORES.DLL.mun
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\dcomp.dll
C:\Windows\SysWOW64\dcomp.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\OFFSYM.TTF
C:\Program Files (x86)\Microsoft Office\root\Office16\OFFSYMB.TTF
C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\root\Office16\OFFSYMB.TTF
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\*.tbres
C:\Program Files (x86)\Microsoft Office\root\vfs\Fonts\staticcache.dat
C:\Windows\Fonts\staticcache.dat
C:\Windows\SysWOW64\globinputhost.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\OFFSYMXB.TTF
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\SystemResources\mso.dll.mun
C:\Program Files (x86)\Common Files\Microsoft Shared\SystemResources\mso.dll.mun
C:\Program Files (x86)\Microsoft Office\root\Office16\imageres.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\imageres.dll
C:\Windows\SysWOW64\imageres.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\SystemResources\imageres.dll.mun
C:\Windows\SystemResources\imageres.dll.mun
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Users\user\AppData\Local\Microsoft\Office\OTele
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-journal
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-wal
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-shm
C:\Users\user\AppData\Local\Temp\
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Windows Defender\MpOAV.dll
C:\Program Files (x86)\Windows Defender\MpOAV.dll
C:\Program Files (x86)\Microsoft Office\root\Office16\GFX.DLL
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Aptos Narrow\31558910439.ttf
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CatalogCacheMetaData2.xml
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Aptos Narrow\24153076628.ttf
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Aptos Display\23001069669.ttf
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Aptos Narrow\37262344671.ttf
C:\Users\user\AppData\Roaming\Microsoft\Office\
C:\Users\user\AppData\Roaming\Microsoft\Office\review.rcd
C:\Users\user\AppData\Roaming\Microsoft\Office\adhoc.rcd
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\ink\InkObj.dll
C:\Program Files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll
C:\Users\user\AppData\Local\Temp\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\1380790193167760279.C4
C:\Users\user\Pictures\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\*
C:\Users\user\Videos\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\ASkwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDBfTnVsbAA.S
C:\Users\user\Downloads\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Excel\Purge\*
C:\Users\user\AppData\Local\Microsoft\Excel\Metadata
C:\Users\user\AppData\Local\Microsoft\Office\
C:\Users\user\Searches\desktop.ini
C:\Users\user\Contacts\desktop.ini
C:\Users\user\Favorites\desktop.ini
C:\Users\user\Links\desktop.ini
C:\Users\user\Saved Games\desktop.ini
C:\ProgramData
C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\OFFICE\Heartbeat
C:\Program Files (x86)\Microsoft Office\root\Office16\osfshared.dll
C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\OFFICE\Heartbeat\HeartbeatCache.xml
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Wef
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Wef\prewarm.dat
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Wef\prewarmtoken.dat
C:\Program Files (x86)\Microsoft Office\root\Office16\Microsoft.Office.PolicyTips.dll
C:\Users\user\AppData\Local\Microsoft\Schemas\MS Excel_restart.xml
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b8ab77100df80ab2.customDestinations-ms
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MI2HV2EPK8J0SC9WPPHS.temp
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\SystemResources\MSO99LRES.DLL.mun
C:\Program Files (x86)\Common Files\Microsoft Shared\SystemResources\MSO99LRES.DLL.mun
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\sxs.dll
C:\Windows\SysWOW64\sxs.dll
C:\Users\user\AppData\Local\Microsoft\Office\Excel.officeUI
C:\Windows\splwow64.exe
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\splwow64.exe
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\splwow64.exe 8192
C:\Windows\splwow64.exe 8192
C:\Program Files (x86)\Microsoft Office\root\vfs\Windows
C:\Users\user\AppData\Local\Microsoft\Office\16.0\aggmru
C:\Users\user\AppData\Local\Microsoft\Office\16.0\aggmru\mru-cr.json
C:\Program Files (x86)\Microsoft Office\root\vfs\Fonts\segoeuil.ttf
C:\Windows\Fonts\segoeuil.ttf
C:\Program Files (x86)\Microsoft Office\root\vfs\Fonts\seguisb.ttf
C:\Windows\Fonts\seguisb.ttf
C:\Program Files (x86)\Microsoft Office\root\vfs\Fonts\SEGOEUISL.TTF
C:\Windows\Fonts\SEGOEUISL.TTF
C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\root\Office16\OFFSYM.TTF
C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\SystemResources\MSO40UIRES.DLL.mun
C:\Program Files (x86)\Common Files\Microsoft Shared\SystemResources\MSO40UIRES.DLL.mun
C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\en-US\ieframe.dll.mui
C:\Windows\SysWOW64\en-US\ieframe.dll.mui
C:\Program Files (x86)\Microsoft Office\root\vfs\System\en-US\ieframe.dll.mui
C:\Windows\sysnative\en-US\ieframe.dll.mui
C:\Users\user\AppData\Local\Microsoft\PenWorkspace
C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
\Device\Bam
C:\Windows\System32\icu.dll
C:\Windows\globalization\ICU\zoneinfo64.res
C:\Windows\Globalization\Time Zone\timezones.xml
C:\Windows\globalization\ICU\windowsZones.res
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\b8ab77100df80ab2.automaticDestinations-ms
C:\Windows\bcastdvr\KnownGameList.bin
C:\Windows\bcastdvr
C:\Windows\System32\kernel.appcore.dll
C:\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_b1142994fb10cf54\MPDW-manifest.ini
C:\Windows\System32\spool\V4Dirs\FC63BAE9-521C-4DB0-9535-DF1D94494B7C\69b8a4a.BUD
C:\Windows\System32\spool\V4Dirs\FC63BAE9-521C-4DB0-9535-DF1D94494B7C\69b8a4a.gpd
C:\Windows\System32\urlmon.dll
C:\Windows\System32\iertutil.dll
C:\Windows\System32\srvcli.dll
C:\Windows\System32\netutils.dll
C:\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_b1142994fb10cf54\MPDW_devmode_map.xml
C:\Windows\System32\en-US\combase.dll.mui
C:\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_b1142994fb10cf54\MPDW-constraints.js
C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_cce2ae2d764e8510\Amd64\PrintConfig.dll
C:\Windows\System32\sxs.dll
C:\Windows\System32\stdole2.tlb
C:\Windows\System32\msxml6.dll\1
C:\Windows\System32\msxml6.dll
C:\Windows\System32\spool\V4Dirs\FC63BAE9-521C-4DB0-9535-DF1D94494B7C\pdc.xml
C:\Windows\System32\en-US\localspl.dll.mui
C:\Windows\System32\en-US\prntvpt.dll.mui
C:\Users\user\AppData\Local\Temp\{7897BE6F-C3A3-4899-81F3-ED5DF4333726} - OProcSessId.dat
C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302412540100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log
C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1765096302413377100_7897BE6F-C3A3-4899-81F3-ED5DF4333726.log
\Device\RasAcd
C:\Users\user\AppData\Local\Temp\~$file.xls
C:\Users\user\AppData\Local\Temp\file.xls
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-wal
C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db-shm
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CatalogCacheMetaData2.xml
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\1380790193167760279.C4
C:\Users\user\AppData\Local\Microsoft\Office\16.0\UsageMetricsStore\FileActivityStore\Excel\ASkwMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDBfTnVsbAA.S
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MI2HV2EPK8J0SC9WPPHS.temp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b8ab77100df80ab2.customDestinations-ms
C:\Users\user\AppData\Local\Microsoft\Office\16.0\aggmru\mru-cr.json
C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Personalization\Content\Anonymous\Insights.json
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e0495fde257df2ef62ee7e3fdb1ebb9d7ff72300.tbres
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres
C:\Users\user\AppData\Local\Microsoft\Schemas\MS Excel_restart.xml
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MI2HV2EPK8J0SC9WPPHS.temp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids
HKEY_LOCAL_MACHINE\Software\Microsoft\ClickToRun\OverRide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\MID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\SusClientId
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\PackageLockerPath
HKEY_LOCAL_MACHINE\Software\Microsoft\SoftGrid\4.5\Client\AppFS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppVISV
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppVISV\c:\program files (x86)\microsoft office
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppV\Subsystem\Disabled
HKEY_LOCAL_MACHINE\
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\AppV\Subsystem\VirtualRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\AppV\Subsystem\VirtualRegistry\PassThroughPaths
HKEY_LOCAL_MACHINE\SYSTEM\SELECT
HKEY_LOCAL_MACHINE\SYSTEM\Select\Current
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppV\Subsystem\ComExclusions
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppVISV\Virtualized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Excel\Options
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel\Options
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel\Options\DllPrevention
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\AvoidLargeAddresses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\STE
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office Test\Special\Perf
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\common\filespaths
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\common\filespaths\mso.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\common\filespaths\mso.dll
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AppRecoveryPingInterval
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\ShownFileFmtPrompt
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Control Panel\International\Geo
HKEY_CURRENT_USER\Control Panel\International\Geo\Nation
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software\Policies\Microsoft\Cloud
HKEY_CURRENT_USER\Software\Microsoft\Office
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office
HKEY_LOCAL_MACHINE\Software\Microsoft\Office
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office
HKEY_CURRENT_USER\Software\Policies\Microsoft\Cloud\Office
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\cloud\Office
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\ClientTelemetry\Sampling
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\CountryCode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\SDXInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\SDXInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\SDXInfo\SDXIdAndVersion
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Experiment\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel\Language
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\DevInstall
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common
HKEY_CURRENT_USER\Software\Microsoft\Office\Common
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\LabMachine
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\UpdateSupport\ExpiredBuild
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\AudienceId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\ActiveConfiguration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\8D3810A9-D4E0-49C6-A71B-357728C38039\culture\x-none.16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\8D3810A9-D4E0-49C6-A71B-357728C38039\culture\x-none.16\StreamPackageUrl
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\AllowConsecutiveSlashesInUrlPathComponent
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\ExperimentDogfood
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\Experiment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\Overrides
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\excel\Overrides
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\all\Overrides
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\ExternalFeatureOverrides\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\Expires
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\ApplicationUpgradeCandidate\excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\ApplicationUpgradeCandidate\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\ApplicationUpgradeCandidate\excel\BuildVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSessionUpgradeCandidate\excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSessionUpgradeCandidate\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSessionUpgradeCandidate\excel\BuildVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSession\excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSession\excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSession\excel\Expires
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData\VersionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData\ChunkCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigIds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ETag
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\common
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\MsoWerCrashDllPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\common\MsoWerCrashDllPath
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\CrashPersistence\EXCEL
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\CrashPersistence\EXCEL\5712
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\CrashPersistence\EXCEL\5712
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\CrashPersistence\EXCEL\5712\0
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\Common\GOM
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\Common\GOM\ComplexRanges
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Debug
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Debug
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\CVH\VirtualProductInfo
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\CVH\VirtualProductInfo\PackageGUID
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-932793227-1321892499-785312009-1001\Components\0BC77486A266BF84FAE259379C82967F
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0BC77486A266BF84FAE259379C82967F
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\ProductCodeListForC2RGimme
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\ProductCodeListForC2RGimme\{90160000-000F-0000-0000-0000000FF1CE}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Registration\{90160000-000F-0000-0000-0000000FF1CE}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Registration\{90160000-000F-0000-0000-0000000FF1CE}\ClickToRun
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme\ProductFiles
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-932793227-1321892499-785312009-1001\Installer\Products\00006109F00000000000000000F01FEC
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001\Software\Microsoft\Installer\Products\00006109F00000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00006109F00000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A725889A5DF965C4E84A0253A39A5952
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A725889A5DF965C4E84A0253A39A5952\00006109F00000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\SKULanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages\en-US
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\LanguageResources
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreviousPreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackSource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\InstalledUICultures
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\InstalledUICultures\en-us
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UISnapshotLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackLanguages
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-932793227-1321892499-785312009-1001\Installer\Components\1A705E72D3831594090DD020E37EFC1A
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001\Software\Microsoft\Installer\Components\1A705E72D3831594090DD020E37EFC1A
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Components\1A705E72D3831594090DD020E37EFC1A
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreferredUILanguageTagPendingInstall
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\FollowSystemUILanguage
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\UILanguageInstallerFallbackOrder
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpFallbackLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageExplicit
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LanguagePackTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UILanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\ExeMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\LanguageResources\EnabledLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LangTuneUp
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\AuthoringLanguageCloud
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\LanguageResources\LocalCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LocalCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LocalCache\RegionalAndLanguageSettingsAccount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\InstallFonts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Graphics\EnableWinCompBackEnd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Graphics
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Graphics
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_CURRENT_USER\Software\Microsoft\Direct3D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Direct3D
HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Direct3D\Drivers
HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\Drivers
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\Drivers\Size
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\Drivers\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList
HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\DX6TextureEnumInclusionList
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Size
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Name
HKEY_LOCAL_MACHINE\Software\Microsoft\SecurityManager\TransientObjects\%5C%5C.%5CRpc%5CAllowLpacAppExperience%5CInterface
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\SecurityManager\TransientObjects\%5C%5C.%5CRpc%5CAllowLpacAppExperience%5CInterface\SecurityDescriptor
HKEY_CURRENT_USER\Software\Microsoft\DirectX\UserGpuPreferences
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1EDD7E79811EB814A93FCB6559FABECE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1EDD7E79811EB814A93FCB6559FABECE\00006109F00000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A09ECE35544363439463E4AB55A621E
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A09ECE35544363439463E4AB55A621E\00006109F00000000000000000F01FEC
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Resiliency
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Resiliency
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Resiliency
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Resiliency\AddInList
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\ebt
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UID
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration\ProductReleaseIds
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration\ProPlusRetail.TenantId
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D3588D4312FC664C94D84B670142C50
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D3588D4312FC664C94D84B670142C50\00006109F00000000000000000F01FEC
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Resiliency\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\Security
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Security\EnableProcessAslrPolicy
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\GridLineScaleByDpi
HKEY_CURRENT_USER\Software\Policies\Policies\Microsoft\Office\16.0\Excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\RenderForMonitorDpi
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MachineId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_LOCAL_MACHINE\Hardware\Description\System\BIOS
HKEY_LOCAL_MACHINE\Hardware\Description\System\BIOS\SystemFamily
HKEY_LOCAL_MACHINE\Hardware\Description\System\BIOS\SystemSKU
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\MotherboardUUID
HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-932793227-1321892499-785312009-1001\Components\820E548C190EE2442820125F695C950A
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\820E548C190EE2442820125F695C950A
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme\EXCELFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ImmersiveWorkbookDirtySentinel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelWorkbookAutoRecoverDirty
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelWorkbookOpenedCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoRecoverTime
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelPreviousSessionVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelPreviousSessionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UseSystemSeparators
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ThousandsSeparator
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DecimalSeparator
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Toolbars\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ShowLensTooltip
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableTouchUIA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AirDrop
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\AccessDE_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Access_Core
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Access_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Excel_Intl
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Excel_Intl\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Graph_Core
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Graph_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\LYNC_HKCU
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\LYNC_HKCU\Order
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en-US
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Misc_SpsOutlookAddin
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Misc_SpsOutlookAddin\Order
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_CoreReg
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Intl
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Intl\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToPPTAddin
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToPPTAddin\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToWordAddin
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToWordAddin\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\outexum
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Core
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Intl
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Intl\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Core
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\MicrosoftDataStreamerforExcel
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\MicrosoftDataStreamerforExcel\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPivotExcelAddin
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPivotExcelAddin\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPivotExcelAddin
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPivotExcelAddin\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerViewExcelAddin
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerViewExcelAddin
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerViewExcelAddin\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Excel_Core
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Excel_Core
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Excel_Intl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_CoreReg\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_CoreReg
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_CoreReg\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_Intl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToIEAddin
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToIEAddin\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\OneNoteToIEAddin
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\OneNoteToIEAddin\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Outlook_Intl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Outlook_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_SocialConnector
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_SocialConnector\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Access_Core\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Access_Core
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Access_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPoint_Core
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPoint_Core\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPoint_Core
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPoint_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPoint_Intl
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPoint_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPoint_Intl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPoint_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Ace_OdbcCurrentUser
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Ace_OdbcCurrentUser\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Ace_OdbcCurrentUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Ace_OdbcCurrentUser\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Core\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Word_Core
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Word_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Intl
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Word_Intl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Word_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\XDocs_XMLEditVerbHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\XDocs_XMLEditVerbHandler\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\XDocs_XMLEditVerbHandler
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\XDocs_XMLEditVerbHandler\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Migration
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Migration\InstallationPath
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Migration\Office
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Migration\Office
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Migration\Office\OfficeInstallationPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Maximized
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\MonitorTopologyFingerprint
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Pos
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AlertForLargeOperations
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\LargeOperationCellCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options3
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options5
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options6
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options95
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\OptionFormat
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\BinaryOptions
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Options\BinaryOptions
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DDECleaned
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DDEAllowed
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\General
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\PasteOptions
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefSheets
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoChartFontScaling
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SortCaseSensitive
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\MoveEnterDir
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ExtendList
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoRecoverPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\PivotTableNetworkResiliency
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoHyperlink
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoExpandListRange
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoCreateCalcCol
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Error Checking
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Error Checking
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableAutoRepublish
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableAutoRepublishWarning
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Xl9_Hijri
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\QFE_Jasper
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\WarnFuncConflict
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\LivePreview
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SuppressDisplayAlerts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableParenFlash
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableBestFitMT
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EmbedUpdateRemoteReferences
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableMTP
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\IME
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\IME
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP
HKEY_CURRENT_USER\Software\Policies\Microsoft\CTF
HKEY_CURRENT_USER\Software\Microsoft\CTF
HKEY_CURRENT_USER\Software\Microsoft\CTF\Disable Thread Input Manager
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{03b5835f-f03c-411b-9ce2-aa23e1171e36}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{03b5835f-f03c-411b-9ce2-aa23e1171e36}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{531fdebf-9b4c-4a43-a2aa-960e8fcdc732}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{531fdebf-9b4c-4a43-a2aa-960e8fcdc732}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\LanguageProfile\0x00000804
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\LanguageProfile\0x00000804\{82590C13-F4DD-44f4-BA1D-8667246FDF8E}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\LanguageProfile\0x00000804\{82590C13-F4DD-44f4-BA1D-8667246FDF8E}\Enable
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{7C472071-36A7-4709-88CC-859513E583A9}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{7C472071-36A7-4709-88CC-859513E583A9}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\LanguageProfile\0x00000804
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\LanguageProfile\0x00000804\{FA550B04-5AD7-411f-A5AC-CA038EC515D7}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\LanguageProfile\0x00000804\{FA550B04-5AD7-411f-A5AC-CA038EC515D7}\Enable
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{81EA0A17-AA39-455B-BA20-EA79A8F98966}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{81EA0A17-AA39-455B-BA20-EA79A8F98966}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\LanguageProfile\0x0000ffff
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\LanguageProfile\0x0000ffff\{B37D4237-8D1A-412E-9026-538FE16DF216}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\LanguageProfile\0x0000ffff\{B37D4237-8D1A-412E-9026-538FE16DF216}\Enable
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{a028ae76-01b1-46c2-99c4-acd9858ae02f}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{a028ae76-01b1-46c2-99c4-acd9858ae02f}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{a1e2b86b-924a-4d43-80f6-8a820df7190f}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{a1e2b86b-924a-4d43-80f6-8a820df7190f}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{B115690A-EA02-48D5-A231-E3578D2FDF80}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{B115690A-EA02-48D5-A231-E3578D2FDF80}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{C2CB2CF0-AF47-413E-9780-8BC3A3C16068}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{C2CB2CF0-AF47-413E-9780-8BC3A3C16068}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404\{037B2C25-480C-4D7F-B027-D6CA6B69788A}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404\{037B2C25-480C-4D7F-B027-D6CA6B69788A}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404\{D38EFF65-AA46-4FD5-91A7-67845FB02F5B}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404\{D38EFF65-AA46-4FD5-91A7-67845FB02F5B}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000473
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000473\{3CAB88B7-CC3E-46A6-9765-B772AD7761FF}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000473\{3CAB88B7-CC3E-46A6-9765-B772AD7761FF}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000478
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000478\{409C8376-007B-4357-AE8E-26316EE3FB0D}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000478\{409C8376-007B-4357-AE8E-26316EE3FB0D}\Enable
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\LanguageProfile\0x0000FFFF
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\LanguageProfile\0x0000FFFF\{F2510000-2FC8-4EB3-A41A-CCE5F08541E6}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\LanguageProfile\0x0000FFFF\{F2510000-2FC8-4EB3-A41A-CCE5F08541E6}\Enable
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\LanguageProfile
HKEY_CURRENT_USER\Software\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\0x0000FFFF
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\0x0000FFFF\{38445657-9381-11D6-B41A-00065B83EE53}
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\0x0000FFFF\{38445657-9381-11D6-B41A-00065B83EE53}\Enable
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\UseOfficeUIFont
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel\Options\AirspaceDisable
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\FontInfoCache
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\DisableTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteTelemetryEventsToNexus
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Identity
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableOneAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableExchangeOnPremModernAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableAuthentication
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableADAL
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ServiceAuthInfoCache\LiveIdServerToServiceParams
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ServiceAuthInfoCache\SpoServerToServiceParams
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ServiceAuthInfoCache\ADALServerToServiceParams
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ServiceAuthInfoCache\AadServerToServiceParams
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\ONetConfig
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ONetConfig
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ONetConfig
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ServiceAuthInfoCache\AuthContextToServiceParams
HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityCRL
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\ServiceEnvironment
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ScriptRun\IdentityRun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Canary
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Version
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3\Com+Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\NoDomainUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\FederationSignInName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\FederationProvider
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\FederationConfigError
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Identities
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ServiceAuthInfoCache\CredStoreKeyToAuthScheme
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\GELPrefs
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\GELPrefs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session Manager
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\ResourcePolicies
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\TreatAs
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\TreatAs
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\DllPath
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\TrustLevel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\CustomAttributes
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\AppUserIdleResetInterval
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\ActivateOnHostFlags
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001_Classes
HKEY_CURRENT_USER\Software\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters\ClientCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableAADWAM
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Profiles
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Internet
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\msoridShouldUseReauthRequestProxy
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\SpoAuthenticatorHeaderEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\IsOnRequestCompletedActivityEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableMSAWAM
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ScriptRun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ScriptRun\OLicenseCleanup
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ConnectedAccountWamAad
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ConnectedAccountCID
HKEY_CURRENT_USER\Software\Policies\Microsoft\Security
HKEY_CURRENT_USER\Software\Microsoft\Security
HKEY_CLASSES_ROOT\CLSID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{dcb00c01-570f-4a9b-8d69-199fdba5723b}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{dcb00c01-570f-4a9b-8d69-199fdba5723b}\InsecureQI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\System\Setup
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\System\Setup\SystemSetupInProgress
HKEY_CURRENT_USER\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\AppID
HKEY_CURRENT_USER\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\LocalService
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ServiceParameters
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\RunAs
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ActivateAtStorage
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ROTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\AppIDFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\MGOTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\AuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\RemoteServerName
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\SRPTrustLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\PreferredServerBitness
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ProtectionLevel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\LocalServer
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Upgrades
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\Policy\Upgrades
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\ErrorDialog
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\Fod
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\FodConservativeMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Security\AutomationSecurity
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Research\Translation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\CurrentProvider
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\MaxWords
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\MaxWordsJapan
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\UseOnline
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\PreferOffline
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\UseMT
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\UseOnlineContent
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Logging
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Logging
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\EnablePhoneOnlyAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ConfigEnvironment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\EndDate
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\StartDate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\FilePath
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\TelemetryClientId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\QMEnable
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\ClientTelemetry\ViewerSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\ViewerSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SessionId
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesXmlDir
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified\excel.exe_queried
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified\excel.exe_expiration
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ClientTelemetry\Debug
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\Debug
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToAsimov
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToFile
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\excel.exe
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\excel.exe
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\ULSQueueAbortThreshold
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\DeferredConfigs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\TrustCenter\Experimentation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation\DisableFeatureRollout
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel\BuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling\ClientSamplingOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableTelemetryGrf
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DisableServerReachability
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Roaming
HKEY_CURRENT_USER\Software\Policies\Policies\Microsoft\Office\16.0\Common\Roaming
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Roaming
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\SchemaVersion
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\LicensingNext
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\LicensingNext
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\Common\Licensing
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Licensing
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\Identities
HKEY_CURRENT_USER\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\Elevation
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\ServicePlanFeatures
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\ServicePlanFeatures
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\LastUILang
HKEY_CURRENT_USER\Software\Policies\Microsoft\Shared
HKEY_CURRENT_USER\Software\Microsoft\Shared
HKEY_CURRENT_USER\Software\Microsoft\Shared\OfficeUILanguage
HKEY_CURRENT_USER\Software\Policies\Microsoft\Cloud\Office\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\SendTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SendTelemetryTime
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Privacy
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\FRESettingsMigrated
HKEY_CURRENT_USER\Software\Policies\Microsoft\Cloud\Office\16.0\Common\Privacy
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\ControllerConnectedServicesEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\ControllerConnectedServicesStateTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\DeviceAccess
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\DisconnectedState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\DisconnectedState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\UserContentDisabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\DownloadContentDisabled
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Cloud\Office\16.0\common\officesvcmanager
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\RequiredDiagnosticDataNoticeVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\OptionalDiagnosticDataConsentVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\ConnectedExperiencesNoticeVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\OptionalConnectedExperiencesNoticeVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\RoamingNotificationState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ServerReachabilityTimeout
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\UseDeviceLevelConnectivity
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Excel\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WinHttpSecureProtocols
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ForceDefaultAutoLogonLevelLow
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\UseAlternateOutlookAppUserModelId
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Fonts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts\CloudFontsVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\GracefulExit\EXCEL
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\GracefulExit\EXCEL\2840
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\GracefulExit\EXCEL\2840\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\GracefulExit\EXCEL\2840
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\FileFormatBallotBoxTelemetrySent
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbControl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbOn
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbSysIcon
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbTips
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbST
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\NetworkStatusCache\officeclient.microsoft.com
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\LCCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Deprecated
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\NextUpdate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03090430
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457444
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033917
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033919
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033921
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457464
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033925
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457475
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM10001114
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033927
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457485
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457491
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457496
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM10001115
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457503
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457510
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033929
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033937
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457515
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03090434
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\NextUpdate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328884
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328893
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328905
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328908
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328916
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328919
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328925
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328932
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328935
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328940
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328998
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328972
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328951
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328975
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328983
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328986
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328990
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\NotificationsNeverShowAgainLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableBackgrounds
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\OSM
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\OSM
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\OSM
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Met
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Met
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\UI Theme
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\Common
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Default UI Theme
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Default UI Theme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\NetworkStatusCache\www.microsoft.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\ZoneMap\Ranges
HKEY_LOCAL_MACHINE\ZoneMap\Ranges
HKEY_CURRENT_USER\ZoneMap\Ranges
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\(Default)
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\EXCEL.EXE
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\EXCEL.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
HKEY_USERS\.DEFAULT
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSAPIforCrack
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\EXCEL.EXE
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\EXCEL.EXE
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableZlibDeflate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FromCacheTimeout
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableKeepAlive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IdnEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreConnectLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreResolveLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CacheMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableNegotiate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBasicOverClearChannel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutoProxyResultCache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisplayScriptDownloadFailureUI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSServername
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UTF8ServerNameRes
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableReadRange
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketSendBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketReceiveBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\KeepAliveTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxHttpRedirects
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ServerInfoTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableNTLMPreAuth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertCacheNoValidate
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HttpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FtpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\LeashLegacyCookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendExtraCRLF
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MimeExclusionListForCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Containers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Containers
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Containers\SecureAutoProxy
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\FeatureEnableTokenBindingOverride
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_TOKEN_BINDING
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEntries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnAlwaysOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnZoneCrossing
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnBadCertRecving
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AlwaysDrainOnRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\TcpAutotuning
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\TcpAutotuning
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableHttp2ConnectionSharing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableHttp2ConnectionSharing
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\XAML
HKEY_LOCAL_MACHINE\Software\Microsoft\XAML
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\XAML\OneCoreTransformsEnabledByDefault
HKEY_CURRENT_USER\Control Panel\Colors
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent
HKEY_CURRENT_USER\Software\Classes\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\InprocHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UseFirstAvailable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CombineFalseStartData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableFalseStartBlocklist
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp2Upgrade
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DuoProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableSpdyDebugAsserts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableTcpFastOpen
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\PolicyExtensions
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\PolicyExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Accent
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Personalization
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\MigrateProxy
HKEY_CLASSES_ROOT\CLSID\{fdb00e52-a214-4aa1-8fba-4357bb0072ec}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\ValidationSinkHandlerName
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Security\DLP
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Security\DLP
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\OPerfMon
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\0
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\1
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\2
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\2
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\3
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\3
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\4
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Classes\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\NetworkStatusCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\BootTimeSkuOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\BootTimeSkuOverride\{C845E028-E091-442E-8202-21F596C559A0}
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\BootTimeSkuOverride
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel\SubscriptionCustomerLicenseInfo
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Personalization\Insights
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Personalization\Insights
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\PerpetualLicenseInfo
HKEY_CLASSES_ROOT\Outlook.Application
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableRobustifiedUNC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Defender\Features
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Defender\Features\SenseDlpEnabled
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\FixedFormat
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\FixedFormat
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Security\Labels
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Security\Labels
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Font
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UndoHistory
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DontSupportUndoForLargePivotTables
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\CLSID\{0000034B-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{0000034B-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0000034B-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\CLSID\{0000034B-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\PackagedCom
HKEY_LOCAL_MACHINE\Software\Classes\PackagedCom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Wow6432Node\Microsoft\LanguageOverlay\OverlayPackages\en-US
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\en-US
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FormulaBarExpandedLines
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FormulaBarExpanded
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\UseHVSocket
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\SignedOutMSAUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableUnsecureNtlmRetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\Url
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\Properties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\Compatibility\EXCEL.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\EXCEL.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\System\CurrentControlSet\Control\Compression
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Compression
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\System\CurrentControlSet\Control\GraphicsDrivers
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\GraphicsDrivers
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\NameBoxWidth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\LicenseCategoryInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\LicenseSKUInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\ProviderId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\NetworkStatusCache\ecs.office.com
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\FileIO
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\FileIO
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\TrustedSiteUrlForUserAgentVersionInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\TokenBroker\ActivatableClasses
HKEY_CURRENT_USER\Software\Classes\Interface\{07650A66-66EA-489D-AA90-0DABC75F3567}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{07650A66-66EA-489D-AA90-0DABC75F3567}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{07650A66-66EA-489D-AA90-0DABC75F3567}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10
HKEY_CURRENT_USER\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies
HKEY_CURRENT_USER\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\ClickToRun\Inventory\Office\16.0
HKEY_CURRENT_USER\Software\Classes\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\3dDialogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ADALEnvironment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\MsoTbCust
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\CmdBarData
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Toolbars
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\BtnSize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Tooltips
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\EnablePaneManagement
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Settings\Microsoft Excel AWDropdownHidden
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\StatusBar
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\StatusBar
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableAccChecker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Policies\Microsoft\AuthN
HKEY_CURRENT_USER\Software\Microsoft\AuthN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\DisableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.Aad.AadWamExtension
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.Aad.AadWamExtension
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ProviderIds
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ExtensionCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ProviderIds
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ExtensionType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ExtensionCapabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TokenBroker\TestHooks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Avalon.Graphics
HKEY_LOCAL_MACHINE\Software\Microsoft\Avalon.Graphics
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InProcHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SplashScreenLicense
HKEY_CURRENT_USER\Control Panel\International\Calendars\TwoDigitYearMax
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Sort
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\TrustCenter
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\EnableLogging
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Security\Trusted Documents
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SmartList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Gfx
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Gfx
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\FontSmoothingThreshold
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Word\Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Wow6432Node\Microsoft\Windows\Tablet PC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Tablet PC
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\Tablet PC\IsTabletPC
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Office Graphics
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Office Graphics
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
HKEY_CURRENT_USER\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{529a9e6b-6587-4f23-ab9e-9c7d683e3c50}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529a9e6b-6587-4f23-ab9e-9c7d683e3c50}\InsecureQI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\OOBE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\OOBE\LaunchUserOOBE
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Security\NoOleLoadFromStreamChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\CTF\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MOTIF\FlexUIAutomation
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\DiagnosticMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\TeachingCallouts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TeachingCallouts
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\PowerUI\Stats\Microsoft.Excel.Workbook
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\PowerUI\Stats\Microsoft.Excel.Workbook
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableComingSoon
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\OverridePointerMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\ResetTabletModeOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\PointerModeInitVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TurnOffPhotograph
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DeveloperTools
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Signals\Stats\Anonymous\Microsoft.Excel.Workbook
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Signals\Stats\Anonymous\Microsoft.Excel.Workbook
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Signals\Stats\Anonymous\Microsoft.Excel.Workbook\ClicksData
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Feedback
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\UseMockCollabCoordinator
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\HideBuiltInTableStyles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\HideBuiltInStyles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingLastSyncTimeExcel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingConfigurableSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\ar-SA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\ar-SA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\he-IL
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\he-IL
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\ur-PK
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\ur-PK
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\fa-IR
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\fa-IR
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\sd-Deva-IN
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\sd-Deva-IN
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts\EnableApplicationFonts
HKEY_CURRENT_USER\EUDC\1252
HKEY_CURRENT_USER\EUDC
HKEY_CURRENT_USER\Software\Microsoft\Avalon.Graphics
HKEY_CURRENT_USER\Software\Microsoft\Avalon.Graphics\DISPLAY1
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\NOFPU
HKEY_LOCAL_MACHINE\Hardware\Description\System\FloatingPointProcessor
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Randomize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\WK? Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Line Print
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Line Print
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Delete Commands
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Init Menus
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Init Commands
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ScriptAnchorVis
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AddIns
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\LoadBehavior
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\FriendlyName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\RequireShutdownNotification
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\Manifest
HKEY_CURRENT_USER\Software\Classes\ExcelPlugInShell.PowerMapConnect\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\ExcelPlugInShell.PowerMapConnect\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\ExcelPlugInShell.PowerMapConnect\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\ExcelPlugInShell.PowerMapConnect\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\ExcelPlugInShell.PowerMapConnect\Clsid\(Default)
HKEY_CLASSES_ROOT\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\OverrideDefaultDisable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\LoadBehavior
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\FriendlyName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\RequireShutdownNotification
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\Manifest
HKEY_CURRENT_USER\Software\Classes\NativeShim.InquireConnector.1\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\NativeShim.InquireConnector.1\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\NativeShim.InquireConnector.1\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\NativeShim.InquireConnector.1\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\NativeShim.InquireConnector.1\Clsid\(Default)
HKEY_CLASSES_ROOT\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\OverrideDefaultDisable
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\LoadBehavior
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\FriendlyName
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\RequireShutdownNotification
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Manifest
HKEY_CURRENT_USER\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Clsid\(Default)
HKEY_CLASSES_ROOT\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Description
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\OverrideDefaultDisable
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\LoadBehavior
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\FriendlyName
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\RequireShutdownNotification
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\Manifest
HKEY_CURRENT_USER\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\Clsid\(Default)
HKEY_CLASSES_ROOT\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\Description
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\OverrideDefaultDisable
HKEY_CLASSES_ROOT\Excel.Chart.8\protocol\StdFileEditing\server
HKEY_CLASSES_ROOT\CLSID\{00024500-0000-0000-C000-000000000046}\LocalServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00024500-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00024500-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\OPEN
HKEY_CURRENT_USER\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020830-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020832-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Policies\0ff1ce15-a989-479d-af46-f275c6370663
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Policies\0ff1ce15-a989-479d-af46-f275c6370663\Value
HKEY_CURRENT_USER\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00020833-0000-0000-C000-000000000046}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InProcHandler32\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{0000034b-0000-0000-c000-000000000046}
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultPath
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\OpenDir
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableAnimations
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\Xlstart
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AltStartup
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\CoauthDebugMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\UserInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UserInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UserInfo\UserName
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UserInfo\UserInitials
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\QFE_17407
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FirstRun
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\WEF\TrustedCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\AllowUserDefinedFileShareCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\DisableAllCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\DisableOMEXCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\RequireServerVerification
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Excel_RequireForceRefreshAtBoot
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\WEF
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Excel_RibbonCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\ExcelOMEXRefreshPending
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Excel_AggregatedCache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\PowerPivot\Settings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPivot\Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office Test\Special
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\DeferredCheckDisabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableCoauthLegacyVersionMitigation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\XLDesktopCoauthActive
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UseClusterConnector
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ClusterConnector
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DoNotCheckIfOfficeIsHTMLEditor
HKEY_LOCAL_MACHINE\Software\Microsoft\Shared\HTML
HKEY_LOCAL_MACHINE\Software\Microsoft\Shared\MHTML
HKEY_CLASSES_ROOT\.htm
HKEY_LOCAL_MACHINE\Software\Classes\.htm\(Default)
HKEY_CLASSES_ROOT\htmlfile\shell
HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\edit\command
HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\print\command
HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\edit\command\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\print\command\(Default)
HKEY_CLASSES_ROOT\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\16
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\16\(Default)
HKEY_CLASSES_ROOT\.mht
HKEY_LOCAL_MACHINE\Software\Classes\.mht\(Default)
HKEY_CLASSES_ROOT\mhtmlfile\shell
HKEY_LOCAL_MACHINE\Software\Classes\mhtmlfile\shell\edit\command
HKEY_LOCAL_MACHINE\Software\Classes\mhtmlfile\shell\print\command
HKEY_LOCAL_MACHINE\Software\Classes\mhtmlfile\shell\edit\command\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\mhtmlfile\shell\print\command\(Default)
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office Test\Idle Task Manager
HKEY_CURRENT_USER\Software\Microsoft\Office Test\Idle Task Manager
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\OnlinePollTimeMs
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\DRM
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\DRM
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\OEM
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Office Application Guard PreWarm
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\ClickToRun\Configuration
HKEY_LOCAL_MACHINE\Software\Microsoft\MRUS\Profiles
HKEY_LOCAL_MACHINE\Software\Microsoft\MRUS\Office365
HKEY_LOCAL_MACHINE\Software\FSLogix\Profiles
HKEY_LOCAL_MACHINE\Software\Policies\FSLogix\ODFC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateOnHostFlags
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Policies\0ff1ce15-a989-479d-af46-f275c6370663\de52bd50-9564-4adc-8fcb-a345c17f84f9
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Policies\0ff1ce15-a989-479d-af46-f275c6370663\de52bd50-9564-4adc-8fcb-a345c17f84f9\Value
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\LicenseAggregateSubscription
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\CurrentSkuIdAggregationForApp
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\CurrentSkuIdAggregationForApp\Excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\CurrentSkuIdAggregationForApp
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\Resiliency
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\Resiliency\TimeOfFailure
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\Resiliency
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Registration\DESKTOP-SUAFK0F
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Registration\DESKTOP-SUAFK0F
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Registration\DESKTOP-SUAFK0F\ProPlusRetail.AttemptGetKey
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\NextUserLicensingLicensedUserIds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\RemoveOOBE
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\TestFeatureMapping
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\EligibleForExtendedGrace
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\FirstCleanValidation
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\CachedLicenseData
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\CachedLicenseData
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\CachedLicenseData\excel.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\PolicyType
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\MergeAlgorithm
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicyname
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicypath
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicyismultisz
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\ADMXMetadataUser
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\7DValue
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\Value
HKEY_LOCAL_MACHINE\software\policies\Microsoft\AppHVSI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\PolicyManager\current\Device\AppHVSI
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\AppHVSI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\ClickToRunLicensing
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ClickToRunLicensing
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\Common\General
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Viewer
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UseSentinelFile
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DisabledItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\EXCEL.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\EXCEL.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\EXCEL.EXE\RequiredFile
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\EXCEL.EXE\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\Namespace\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\Namespace\ValidateRegItems
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\Namespace\MonitorRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivationType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\TrustLevel
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\RemoteServer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\Generation
HKEY_CURRENT_USER\Software\Classes\Drive\shellex\FolderExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions
HKEY_LOCAL_MACHINE\Software\Classes\Drive\shellex\FolderExtensions
HKEY_CURRENT_USER\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-100000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\LocalServer
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowStatusBar
HKEY_CURRENT_USER\Software\Classes\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Directory
HKEY_LOCAL_MACHINE\Software\Classes\Directory
HKEY_CURRENT_USER\Software\Classes\Directory\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Directory\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\Software\Classes\Directory\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Classes\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Folder
HKEY_LOCAL_MACHINE\Software\Classes\Folder
HKEY_CURRENT_USER\Software\Classes\Folder\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Folder\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\Software\Classes\Folder\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Classes\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AllFilesystemObjects
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects
HKEY_CURRENT_USER\Software\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\Software\Classes\Directory\DocObject
HKEY_CURRENT_USER\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\Folder\DocObject
HKEY_CURRENT_USER\Software\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\DocObject
HKEY_CURRENT_USER\Software\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\Directory\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\Software\Classes\Folder\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\Directory\Clsid
HKEY_CURRENT_USER\Software\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\Folder\Clsid
HKEY_CURRENT_USER\Software\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\Software\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\Software\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\Software\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\NeverShowExt
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\DrawAlerts\FTP Sites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Open Find
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HubMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-932793227-1321892499-785312009-1001
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-932793227-1321892499-785312009-1001
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-932793227-1321892499-785312009-1001\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\DefaultUserEnviroment
HKEY_LOCAL_MACHINE\SOFTWARE\DefaultUserEnviroment
HKEY_CURRENT_USER\Environment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\VolumePref
HKEY_CURRENT_USER\Volatile Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Category
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\CustomAttributes
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\CustomAttributes
HKEY_CURRENT_USER\Volatile Environment\1
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\ExePath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\CommandLine
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\ActivatableClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\ServerType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\AppId
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\Identity
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{8645456F-D9A2-4B82-AFEC-58F0E8DF0ACF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{8645456F-D9A2-4B82-AFEC-58F0E8DF0ACF}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\Interface\{89BC3F49-F8D9-5103-BA13-DE497E609167}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{89BC3F49-F8D9-5103-BA13-DE497E609167}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{89BC3F49-F8D9-5103-BA13-DE497E609167}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\SystemPropertyHandlers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\PropertySystem\SystemPropertyHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.xls
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{97E467B4-98C6-4F19-9588-161B7773D6F6}\OverrideFileSystemProperties
HKEY_CURRENT_USER\Software\Classes\CLSID\{97E467B4-98C6-4F19-9588-161B7773D6F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{97E467B4-98C6-4F19-9588-161B7773D6F6}
HKEY_CURRENT_USER\Software\Classes\ExplorerCLSIDFlags\{97E467B4-98C6-4F19-9588-161B7773D6F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\ExplorerCLSIDFlags\{97E467B4-98C6-4F19-9588-161B7773D6F6}
HKEY_LOCAL_MACHINE\Software\Classes\ExplorerCLSIDFlags\{97E467B4-98C6-4F19-9588-161B7773D6F6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\LocalServer
HKEY_CURRENT_USER\Software\Classes\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager
HKEY_CURRENT_USER\Software\Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcHandler32
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\DisableROForSharedDocs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SupportUNCMappedDriveSaveAs
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Offline\Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Security\FileBlock
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\FileBlock
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Security\FileValidation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ActiveX Cache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Security\ProtectedView\Locations
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Security\ProtectedView\Locations
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\162F61E\162F61E
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\Offline\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Offline\Options\CheckoutToDraftsEnabled
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Excel\Text Converters\OOXML Converters\Import
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Excel\Text Converters\OOXML Converters\Export
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\Common\Security
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\LocalServer
HKEY_CURRENT_USER\Software\Classes\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InProcHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{275c23e2-3747-11d0-9fea-00aa003f8646}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275c23e2-3747-11d0-9fea-00aa003f8646}\InsecureQI
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\Common\OpenXMLFormat\BlockedRelationshipTypes
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableLogUnsupportedFeaturesToAppStorage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\RevisionTrimSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultSheetR2L
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\A4Letter
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\CursorVisual
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ControlCharacters
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultFormat
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\VbaOff
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\VbaOff
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme\VBAFiles
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\16.0\Common\OfficeUpdate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutomaticPictureCompressionDefault
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DiscardImageEdits
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultImageDPI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole\MaximumAllowedAllocationSize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\QFE_Saskatchewan
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\ExtensionHardening
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\UserTemplates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\Templates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\SharedTemplates
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-932793227-1321892499-785312009-1001\Installer\Components\8F622368F04F7B849A7B2021EE668F21
HKEY_USERS\S-1-5-21-932793227-1321892499-785312009-1001\Software\Microsoft\Installer\Components\8F622368F04F7B849A7B2021EE668F21
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Components\8F622368F04F7B849A7B2021EE668F21
HKEY_CURRENT_USER\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\(Default)
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\DirectManipulation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\DirectManipulation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\WindowsRuntime\WellKnownContracts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\WellKnownContracts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\WellKnownContracts\Windows.Foundation.UniversalApiContract
HKEY_CURRENT_USER\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}\CLSID
HKEY_CURRENT_USER\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Author
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FriendlyName
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Version
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SpecVersion
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Vendor
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ContainerFormat
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceManufacturer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceModels
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ColorManagementVersion
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\MimeTypes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FileExtensions
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportAnimation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportChromakey
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportLossless
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportMultiframe
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ArbitrationPriority
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Formats
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Formats
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Formats
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Pattern
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Mask
HKEY_CURRENT_USER\Software\Classes\CLSID\{A26CEC36-234C-4950-AE16-E34AACE71D0D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{A26CEC36-234C-4950-AE16-E34AACE71D0D}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A26CEC36-234C-4950-AE16-E34AACE71D0D}
HKEY_CURRENT_USER\Software\Classes\CLSID\{E9A4A80A-44FE-4DE4-8971-7150B10A5199}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{E9A4A80A-44FE-4DE4-8971-7150B10A5199}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E9A4A80A-44FE-4DE4-8971-7150B10A5199}
HKEY_CURRENT_USER\Software\Classes\CLSID\{7693E886-51C9-4070-8419-9F70738EC8FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{7693E886-51C9-4070-8419-9F70738EC8FA}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7693E886-51C9-4070-8419-9F70738EC8FA}
HKEY_CURRENT_USER\Software\Classes\CLSID\{AC4CE3CB-E1C1-44CD-8215-5A1665509EC2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{AC4CE3CB-E1C1-44CD-8215-5A1665509EC2}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{AC4CE3CB-E1C1-44CD-8215-5A1665509EC2}
HKEY_CURRENT_USER\Software\Classes\CLSID\{0DBECEC1-9EB3-4860-9C6F-DDBE86634575}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{0DBECEC1-9EB3-4860-9C6F-DDBE86634575}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0DBECEC1-9EB3-4860-9C6F-DDBE86634575}
HKEY_CURRENT_USER\Software\Classes\CLSID\{72B624DF-AE11-4948-A65C-351EB0829419}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{72B624DF-AE11-4948-A65C-351EB0829419}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{72B624DF-AE11-4948-A65C-351EB0829419}
HKEY_CURRENT_USER\Software\Classes\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}
HKEY_CURRENT_USER\Software\Classes\CLSID\{E7E79A30-4F2C-4FAB-8D00-394F2D6BBEBE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{E7E79A30-4F2C-4FAB-8D00-394F2D6BBEBE}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E7E79A30-4F2C-4FAB-8D00-394F2D6BBEBE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{7F12E753-FC71-43D7-A51D-92F35977ABB5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{7F12E753-FC71-43D7-A51D-92F35977ABB5}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7F12E753-FC71-43D7-A51D-92F35977ABB5}
HKEY_CURRENT_USER\Software\Classes\CLSID\{AA94DCC2-B8B0-4898-B835-000AABD74393}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Registry\Machine\Software\Classes\Wow6432Node\CLSID\{AA94DCC2-B8B0-4898-B835-000AABD74393}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{1B0D3570-0877-5EC2-8A2C-3B9539506ACA}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{FE2F3D47-5D47-5499-8374-430C7CDA0204}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{5DB5FA32-707C-5849-A06B-91C8EB9D10E8}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{09335560-6C6B-5A26-9348-97B781132B20}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateOnHostFlags
HKEY_USERS\.default\Software\Microsoft\IdentityCRL\AppData\00000000480728C5\FirstParty
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66B59040-7C93-5F96-B52F-2C098D1557D0}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{E0798D3D-2B4A-589A-AB12-02DCCC158AFC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{199E065C-8195-55DA-9C10-8AEAF9AC1062}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\GipActivityBypass
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{00000035-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32\DiagMatchAnyMask
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ADUserName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\SignedOutADUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\Identities\Anonymous\Settings\1186\{00000000-0000-0000-0000-000000000000}
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingLastWriteTimeExcel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\Software\Policies\Policies\Microsoft\Office\16.0\Common
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\Audience
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Audience
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents\TrustRecords
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents\LastPurgeTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{2ABC0864-9677-42E5-882A-D415C556C284}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{22D2E146-1A68-40B8-949C-8FD848B415E6}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\ClientTelemetry\Volatile
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Volatile
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}\ApplicationFlags
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}\DeviceId
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{05F9F2EC-5950-56F8-B7F8-22E20B984679}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityCRL\ClockData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\ClockData
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}\DeviceTicket
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\GlobalDeviceUpdateTime
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\ClockSkew
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Property\0018000D024F8B00
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{4590f811-1d3a-11d0-891f-00aa004b2e24}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590f811-1d3a-11d0-891f-00aa004b2e24}\InsecureQI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\MGOTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ProtectionLevel
HKEY_CURRENT_USER\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InProcHandler
HKEY_CURRENT_USER\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\DllSurrogate
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcHandler
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\AMSI\FeatureBits
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\IsVailContainer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Input\ResyncResetTime
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Input\MaxResyncAttempts
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Excel\Security\FileBlock\Override
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\FileBlock\OoxmlConverters
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\162F61E
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\FileBlock\FileTypeBlockList
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InProcHandler
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{88d96a0c-f192-11d4-a65f-0040963251e5}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88d96a0c-f192-11d4-a65f-0040963251e5}\InsecureQI
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\Extensions\DragDropExtension
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcHandler
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\NoTrack
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ReviewCycle
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle\ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DrawInkTab
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Draw
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Draw
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Draw\CanvasInkOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AnimationDiagnostic
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\Smart Tag
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\DisableDocumentAssemblies
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FullCalcOnLoadOldFile
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\BlockOleAutoActivate
HKEY_CURRENT_USER\SOFTWARE\SyncEngines\Providers\OneDrive
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\PolicyType
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\MergeAlgorithm
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicyname
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicypath
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicyismultisz
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\ADMXMetadataUser
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\7DValue
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\Value
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\Workflow\Cache
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Workflow\Cache
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Workflow\WorkgroupCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\CreateVbeProjOnLoad
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\ReentryToken
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\infoCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\=:x
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\1630D21
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\1630D21\1630D21
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Icon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A0C69A99-21C8-4671-8703-7934162FCF1D}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{0DDD015D-B06C-45D5-8C4C-F59713854639}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\FolderValueFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\StorageDelegateSuppressionPolicy
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\StorageDelegate
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\Attributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\DescriptionID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\HelpTopic
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\AllowChildAliasRegistration
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\RecursiveSearch
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\TargetKnownFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts\CloudFontsURL
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\LocalizedName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\CustomUIRoaming
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\DefinitionFlags
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\AccChecker
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\AccChecker
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\ShownFirstRunOptin
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Registration
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Registration
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Registration\AcceptAllEulas
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Registration
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Registration\AcceptAllEulas
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\EulasSetAccepted
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\UserCCSDisabled
HKEY_CURRENT_USER\Software\Classes\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{88d96a05-f192-11d4-a65f-0040963251e5}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88d96a05-f192-11d4-a65f-0040963251e5}\InsecureQI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\Automation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\Automation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\EmulateOLS
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\LastKnownC2RProductReleaseId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\LastKnownC2RProductReleaseId\Excel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Licensing\LastKnownC2RProductReleaseId
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\WEF\Signal\PreWarm
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Signal\PreWarm
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Signal\PreWarm\ExcelLastUseTimestamp
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\FOLDERID_Desktop
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\FOLDERID_Documents
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU\FOLDERID_Desktop
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU\FOLDERID_Documents
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Recent Files
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\Recent Files
HKEY_CURRENT_USER\Software\Policies\Policies\Microsoft\Office\16.0\Word\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\DefaultFormat
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\FileFormatBallotBoxTelemetryEventSent
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\TargetedMessagingService
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TargetedMessagingService
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\DLP
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\DLP
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\UpsellState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\Resiliency\ResiliencySimulator
HKEY_CLASSES_ROOT\TypeLib\{9B92EB61-CBC1-11D3-8C2D-00A0CC37B591}\1.2\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{9B92EB61-CBC1-11D3-8C2D-00A0CC37B591}\1.2\0\win32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\FriendlyName
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\LabelText
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\Save
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\ShowButtons
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\ShowIndicators
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoLabelOption
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoSaveOption
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoButtonOption
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoIndicatorOption
HKEY_CURRENT_USER\Software\Classes\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{00000344-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00000344-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{77f10cf0-3db5-4966-b520-b7c54fd35ed6}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77f10cf0-3db5-4966-b520-b7c54fd35ed6}\InsecureQI
HKEY_CURRENT_USER\Software\Classes\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{3237555C-C043-4836-AFDE-570D63E9EDAB}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3237555C-C043-4836-AFDE-570D63E9EDAB}
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\ScreenTipScheme
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Animation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\ShowKbdShortcuts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\FontView
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\DontShowWhatsNew
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\WhatsNew
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\WhatsNew
HKEY_CURRENT_USER\Software\Classes\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InsecureQI
HKEY_CURRENT_USER\Software\Classes\CLSID\{000CDB0D-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{000CDB0D-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\InProcServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\Sound
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\IsCustomAddinTabDefaultBackstagePlace
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\HomePageUserSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\nvz
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\StartupDialog
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableHyperlinksToWebTemplates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableOfficeTemplates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\OfficeStart
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\OfficeStart
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ServicesManagerCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\Lcid
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\SysLcid
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\UiLcid
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Thumbnails
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Thumbnails
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\Quick Access Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\Max Quick Access Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Thumbnails
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DisableOnPremAutoDiscover
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU\Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED\Metadata
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Cloud Storage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\Identities
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\SkipOpenAndSaveAsPlace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows365
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\MID
HKEY_CURRENT_USER\Software\Classes\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\AppID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{8856f961-340a-11d0-a96b-00c04fd705a2}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856f961-340a-11d0-a96b-00c04fd705a2}\InsecureQI
HKEY_CURRENT_USER\Software\Classes\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\InProcHandler32
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\InProcHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\AppID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.RKPRY.RKR.15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000020292
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Classes\Microsoft.Office.EXCEL.EXE.15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\FirstEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\LastEntry
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo\112DF3B9-46FD-489C-9225-38E8C540F72A
HKEY_CLASSES_ROOT\CLSID\{56AD4C5D-B908-4F85-8FF1-7940C29B3BCF}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\Instance
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_CLASSES_ROOT\.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_CLASSES_ROOT\exefile
HKEY_CURRENT_USER\Software\Classes\exefile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\SplWOW64TimeOutSeconds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\SplWOW64TimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_CURRENT_USER\Software\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}
HKEY_CURRENT_USER\Software\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseActivationAuthenticationLevel
HKEY_CURRENT_USER\Software\Classes\AppID\splwow64.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\splwow64.exe\AppID
HKEY_CURRENT_USER\Software\Classes\AppID\{CB363445-F453-4C1E-8EE4-BD123C5E394F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CB363445-F453-4C1E-8EE4-BD123C5E394F}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CB363445-F453-4C1E-8EE4-BD123C5E394F}\AccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\10
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\SynchronousPrintHandleAccessMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\PrinterDriverUnloadTimeOutMinutes
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URI_DISABLECACHE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\file\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FILEPROTOCOL_NOFINDFIRST_KB947853
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FILEPROTOCOL_NOFINDFIRST_KB947853
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml\CLSID
HKEY_CURRENT_USER\Software\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}
HKEY_CURRENT_USER\Software\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\Elevation
HKEY_CURRENT_USER\Software\Classes\Interface\{79EAC9E4-BAF9-11CE-8C82-00AA004BA90B}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\\xed\xa0\xbc\xed\xbc\x8e\xed\xa0\xbc\xed\xbc\x8f\xed\xa0\xbc\xed\xbc\x8d
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\EnableJavaScriptDebugging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\COM+Enabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\splwow64.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\splwow64.exe\JScriptSetScriptStateStarted
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64
HKEY_CURRENT_USER\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\Diagnosis
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ExePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\CommandLine
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\IdentityType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ActivatableClasses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ServerType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\Identity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ServiceName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ExplicitPsmActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\CustomAttributes
HKEY_CURRENT_USER\Software\Classes\Interface\{9DEBA2EE-C7E4-47AE-85D5-56C59D090DA5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DEBA2EE-C7E4-47AE-85D5-56C59D090DA5}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DEBA2EE-C7E4-47AE-85D5-56C59D090DA5}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}
HKEY_CURRENT_USER\Software\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_CURRENT_USER\Software\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF86E2E0-B12D-4c6a-9C5A-D7AA65101E90}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF86E2E0-B12D-4c6a-9C5A-D7AA65101E90}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{801156FD-7E96-4274-821E-96D94E0C2B1F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{801156FD-7E96-4274-821E-96D94E0C2B1F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{801156FD-7E96-4274-821E-96D94E0C2B1F}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{3CE4B87D-0ABF-4E76-A557-A2082325270A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CE4B87D-0ABF-4E76-A557-A2082325270A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CE4B87D-0ABF-4E76-A557-A2082325270A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\DontUseArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\MDDWDriver\DebugFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\MID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\SusClientId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\PackageLockerPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppVISV\c:\program files (x86)\microsoft office
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\AppV\Subsystem\VirtualRegistry\PassThroughPaths
HKEY_LOCAL_MACHINE\SYSTEM\Select\Current
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel\Options\DllPrevention
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\AvoidLargeAddresses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\STE
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\common\filespaths\mso.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\common\filespaths\mso.dll
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AppRecoveryPingInterval
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\ShownFileFmtPrompt
HKEY_CURRENT_USER\Control Panel\International\Geo\Nation
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling\1
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\CountryCode
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\SDXInfo\SDXIdAndVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel\Language
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\DevInstall
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\LabMachine
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\AudienceId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\ActiveConfiguration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\8D3810A9-D4E0-49C6-A71B-357728C38039\culture\x-none.16\StreamPackageUrl
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\AllowConsecutiveSlashesInUrlPathComponent
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\Expires
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\ApplicationUpgradeCandidate\excel\BuildVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSessionUpgradeCandidate\excel\BuildVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\FirstSession\excel\Expires
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData\VersionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData\ChunkCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigContextData\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ConfigIds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\ETag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\MsoWerCrashDllPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\common\MsoWerCrashDllPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\CVH\VirtualProductInfo\PackageGUID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\ProductCodeListForC2RGimme\{90160000-000F-0000-0000-0000000FF1CE}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Registration\{90160000-000F-0000-0000-0000000FF1CE}\ClickToRun
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme\ProductFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A725889A5DF965C4E84A0253A39A5952\00006109F00000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\SKULanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages\en-US
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreviousPreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackSource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\InstalledUICultures\en-us
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UISnapshotLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreferredUILanguageTagPendingInstall
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\FollowSystemUILanguage
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\LanguageResources\UILanguageInstallerFallbackOrder
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpFallbackLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageExplicit
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LanguagePackTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UILanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\ExeMode
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LangTuneUp
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\AuthoringLanguageCloud
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LocalCache\RegionalAndLanguageSettingsAccount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\InstallFonts
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\Drivers\Size
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\Drivers\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Size
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\SecurityManager\TransientObjects\%5C%5C.%5CRpc%5CAllowLpacAppExperience%5CInterface\SecurityDescriptor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1EDD7E79811EB814A93FCB6559FABECE\00006109F00000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A09ECE35544363439463E4AB55A621E\00006109F00000000000000000F01FEC
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\ebt
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UID
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration\ProductReleaseIds
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration\ProPlusRetail.TenantId
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D3588D4312FC664C94D84B670142C50\00006109F00000000000000000F01FEC
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Security\EnableProcessAslrPolicy
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\GridLineScaleByDpi
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\RenderForMonitorDpi
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MachineId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_LOCAL_MACHINE\Hardware\Description\System\BIOS\SystemFamily
HKEY_LOCAL_MACHINE\Hardware\Description\System\BIOS\SystemSKU
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\MotherboardUUID
HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme\EXCELFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ImmersiveWorkbookDirtySentinel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelWorkbookAutoRecoverDirty
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelWorkbookOpenedCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoRecoverTime
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelPreviousSessionVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelPreviousSessionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UseSystemSeparators
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ThousandsSeparator
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DecimalSeparator
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ShowLensTooltip
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableTouchUIA
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\AccessDE_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Access_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Excel_Intl\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Graph_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\LYNC_HKCU\Order
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en-US
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Misc_SpsOutlookAddin\Order
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Intl\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToPPTAddin\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToWordAddin\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Intl\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Core\Order
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\MicrosoftDataStreamerforExcel\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPivotExcelAddin\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPivotExcelAddin\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerViewExcelAddin\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_CoreReg\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_CoreReg\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Mso_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Mso_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\OneNoteToIEAddin\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\OneNoteToIEAddin\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Outlook_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Outlook_SocialConnector\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Access_Core\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Access_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPoint_Core\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPoint_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\PowerPoint_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\PowerPoint_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Ace_OdbcCurrentUser\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Ace_OdbcCurrentUser\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Core\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Word_Core\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\Word_Intl\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\Word_Intl\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\User Settings\XDocs_XMLEditVerbHandler\Count
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\User Settings\XDocs_XMLEditVerbHandler\Count
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Migration\InstallationPath
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Migration\Office\OfficeInstallationPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Maximized
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\MonitorTopologyFingerprint
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Pos
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AlertForLargeOperations
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\LargeOperationCellCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options3
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options5
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options6
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Options95
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\OptionFormat
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DDECleaned
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DDEAllowed
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\PasteOptions
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefSheets
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoChartFontScaling
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SortCaseSensitive
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\MoveEnterDir
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ExtendList
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoRecoverPath
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\PivotTableNetworkResiliency
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoHyperlink
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoExpandListRange
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutoCreateCalcCol
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableAutoRepublish
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableAutoRepublishWarning
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Xl9_Hijri
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\QFE_Jasper
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\WarnFuncConflict
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\LivePreview
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SuppressDisplayAlerts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableParenFlash
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableBestFitMT
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EmbedUpdateRemoteReferences
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableMTP
HKEY_CURRENT_USER\Software\Microsoft\CTF\Disable Thread Input Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{6a498709-e00b-4c45-a018-8f9e4081ae40}\LanguageProfile\0x00000804\{82590C13-F4DD-44f4-BA1D-8667246FDF8E}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{81d4e9c9-1d3b-41bc-9e6c-4b40bf79e35e}\LanguageProfile\0x00000804\{FA550B04-5AD7-411f-A5AC-CA038EC515D7}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\LanguageProfile\0x0000ffff\{B37D4237-8D1A-412E-9026-538FE16DF216}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404\{037B2C25-480C-4D7F-B027-D6CA6B69788A}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000404\{D38EFF65-AA46-4FD5-91A7-67845FB02F5B}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000473\{3CAB88B7-CC3E-46A6-9765-B772AD7761FF}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\LanguageProfile\0x00000478\{409C8376-007B-4357-AE8E-26316EE3FB0D}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\LanguageProfile\0x0000FFFF\{F2510000-2FC8-4EB3-A41A-CCE5F08541E6}\Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\0x0000FFFF\{38445657-9381-11D6-B41A-00065B83EE53}\Enable
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\UseOfficeUIFont
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Excel\Options\AirspaceDisable
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\FontInfoCache
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\DisableTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteTelemetryEventsToNexus
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableOneAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableExchangeOnPremModernAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableAuthentication
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableADAL
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\ServiceEnvironment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ScriptRun\IdentityRun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Canary
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Version
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3\Com+Enabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\NoDomainUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\FederationSignInName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\FederationProvider
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\FederationConfigError
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\ResourcePolicies
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\AppID
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\TrustLevel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\AppUserIdleResetInterval
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters\ClientCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableAADWAM
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\msoridShouldUseReauthRequestProxy
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\SpoAuthenticatorHeaderEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\IsOnRequestCompletedActivityEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableMSAWAM
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ConnectedAccountWamAad
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ConnectedAccountCID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{dcb00c01-570f-4a9b-8d69-199fdba5723b}\InsecureQI
HKEY_LOCAL_MACHINE\System\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A47979D2-C419-11D9-A5B4-001185AD2B89}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\LocalService
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ServiceParameters
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\RunAs
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ActivateAtStorage
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ROTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\AppIDFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\MGOTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\AuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\RemoteServerName
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\SRPTrustLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\PreferredServerBitness
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{C96887DA-A652-4426-905E-4A37546F847C}\ProtectionLevel
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\ErrorDialog
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\Fod
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\.NETFramework\FodConservativeMode
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Security\AutomationSecurity
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\CurrentProvider
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\MaxWords
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\MaxWordsJapan
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\UseOnline
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\PreferOffline
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Research\Translation\UseMT
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\UseOnlineContent
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\EnablePhoneOnlyAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ConfigEnvironment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\EndDate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\StartDate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\FilePath
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\TelemetryClientId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\QMEnable
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SessionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesXmlDir
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified\excel.exe_queried
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified\excel.exe_expiration
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToAsimov
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToFile
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\ULSQueueAbortThreshold
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\excel\DeferredConfigs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation\DisableFeatureRollout
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel\BuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling\ClientSamplingOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableTelemetryGrf
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DisableServerReachability
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\SchemaVersion
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.RetailInfo\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\LastUILang
HKEY_CURRENT_USER\Software\Microsoft\Shared\OfficeUILanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\SendTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SendTelemetryTime
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\FRESettingsMigrated
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\ControllerConnectedServicesEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\ControllerConnectedServicesStateTime
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\DisconnectedState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\DisconnectedState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\UserContentDisabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\DownloadContentDisabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\RequiredDiagnosticDataNoticeVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\OptionalDiagnosticDataConsentVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\ConnectedExperiencesNoticeVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\OptionalConnectedExperiencesNoticeVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous\RoamingNotificationState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ServerReachabilityTimeout
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\UseDeviceLevelConnectivity
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00000327-0000-0000-C000-000000000046}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{00024512-0000-0000-C000-000000000046}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD0-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD1-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD2-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD3-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD4-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD5-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD8-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WinHttpSecureProtocols
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BD9-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ForceDefaultAutoLogonLevelLow
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDA-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{06290BDB-48AA-11D2-8432-006008C3FBFC}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336920-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{25336921-03F9-11CF-8FD0-00AA00686F13}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360200-FFF5-11d1-8d03-00a0c959bc0a}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F4D8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F5C8-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{3050F67D-98B5-11CF-BB82-00AA00BDCE0B}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{528D46B3-3A4B-4B13-BF74-D9CBD7306E07}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{8856F961-340A-11D0-A96B-00C04FD705A2}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{CE39D6F3-DAB7-41B3-9F7D-BD1CC4E92399}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFC7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABAFD0-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C5-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{ECABB0C7-7F19-11D2-978E-0000F8757E2A}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\ActivationFilterOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\AlternateCLSID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\ScopedActivationOLEActiveXOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\COM Compatibility\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\ScopedActivationOLEJSOverride
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\UseAlternateOutlookAppUserModelId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts\CloudFontsVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\GracefulExit\EXCEL\2840\0
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\CrashPersistence\EXCEL\5712\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\FileFormatBallotBoxTelemetrySent
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbControl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbOn
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbSysIcon
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbTips
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AcbST
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Deprecated
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\NextUpdate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03090430
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457444
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033917
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033919
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033921
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457464
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033925
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457475
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM10001114
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033927
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457485
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457491
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457496
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM10001115
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457503
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457510
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033929
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM04033937
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03457515
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\Themes\1033\TM03090434
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\NextUpdate
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328884
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328893
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328905
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328908
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328916
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328919
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328925
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328932
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328935
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328940
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328998
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328972
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328951
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328975
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328983
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328986
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\SmartArt\1033\TM03328990
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\NotificationsNeverShowAgainLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableBackgrounds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\UI Theme
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\Default UI Theme
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Default UI Theme
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UISettings\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\EXCEL.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\EXCEL.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InitFolderHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSAPIforCrack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\EXCEL.EXE
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\EXCEL.EXE
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableZlibDeflate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FromCacheTimeout
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\LegacyTLSAppcompat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableKeepAlive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IdnEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreConnectLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreResolveLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CacheMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableNegotiate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBasicOverClearChannel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutoProxyResultCache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisplayScriptDownloadFailureUI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSServername
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UTF8ServerNameRes
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableReadRange
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketSendBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketReceiveBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\KeepAliveTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxHttpRedirects
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ServerInfoTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableNTLMPreAuth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertCacheNoValidate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HttpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FtpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\LeashLegacyCookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendExtraCRLF
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MimeExclusionListForCache
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Containers\SecureAutoProxy
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\FeatureEnableTokenBindingOverride
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEntries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnAlwaysOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnZoneCrossing
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnBadCertRecving
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AlwaysDrainOnRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\TcpAutotuning
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\TcpAutotuning
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableHttp2ConnectionSharing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableHttp2ConnectionSharing
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnableInsecureTlsFallback
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\XAML\OneCoreTransformsEnabledByDefault
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{2DBDBA9D-20DA-519D-9078-09F835BC5BC7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{144C71F2-7F10-4AB2-BB07-C38F5B9AE05E}\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UseFirstAvailable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CombineFalseStartData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableFalseStartBlocklist
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp2Upgrade
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DuoProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableSpdyDebugAsserts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableTcpFastOpen
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\MigrateProxy
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\ValidationSinkHandlerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{733B7764-5C0C-4AD6-BB4B-D0585E993E0E}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\BootTimeSkuOverride\{C845E028-E091-442E-8202-21F596C559A0}
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\excel\SubscriptionCustomerLicenseInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\PerpetualLicenseInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableRobustifiedUNC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Defender\Features\SenseDlpEnabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Font
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UndoHistory
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DontSupportUndoForLargePivotTables
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.EnterpriseData.ProtectionPolicyManager\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FormulaBarExpandedLines
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FormulaBarExpanded
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\UseHVSocket
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\SignedOutMSAUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableUnsecureNtlmRetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\Url
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16924&crev=3\0\Properties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\NameBoxWidth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\LicenseCategoryInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\LicenseSKUInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\ProviderId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\TrustedSiteUrlForUserAgentVersionInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.TokenBrokerInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\TokenBroker\ActivatableClasses
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\AppID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{57D369EE-7364-4AB0-A307-BDD25BCE408C}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{B5A6F1BC-1641-5F4C-B946-79084E41EE35}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{9E8E4BD8-BFC5-4785-94C2-B210DB698776}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\3dDialogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ADALEnvironment
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Web.WamProviderRegistration\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{E60E20A2-87A0-4B34-8502-EE3B8FB4EC16}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{63A0A1E5-F8FE-4BA6-8508-CAEF1277DD35}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountProviderInternal\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\MsoTbCust
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\CmdBarData
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\BtnSize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Tooltips
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\EnablePaneManagement
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Settings\Microsoft Excel AWDropdownHidden
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableAccChecker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequest\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\DisableExtensions
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ProviderIds
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ExtensionCapabilities
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ProviderIds
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ExtensionType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\TokenBroker\Extensions\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ExtensionCapabilities
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.Aad.AadWamExtension\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.ValueSet\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataWriter\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.Streams.DataReader\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F1C46D71-B791-4110-8D5C-7108F22C1010}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{878F3F2A-34DB-42CE-A02B-D637B10A89FF}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SplashScreenLicense
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Sort
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\EnableLogging
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SmartList
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\FontSmoothingThreshold
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\Tablet PC\IsTabletPC
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{529a9e6b-6587-4f23-ab9e-9c7d683e3c50}\InsecureQI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\OOBE\LaunchUserOOBE
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Security\NoOleLoadFromStreamChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\CTF\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\DiagnosticMode
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableComingSoon
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\OverridePointerMode
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.UIViewSettings\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\ResetTabletModeOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\PointerModeInitVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TurnOffPhotograph
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DeveloperTools
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Signals\Stats\Anonymous\Microsoft.Excel.Workbook\ClicksData
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\UseMockCollabCoordinator
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\HideBuiltInTableStyles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\HideBuiltInStyles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingLastSyncTimeExcel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingConfigurableSettings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\ar-SA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\ar-SA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\he-IL
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\he-IL
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\ur-PK
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\ur-PK
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\fa-IR
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\fa-IR
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\sd-Deva-IN
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\sd-Deva-IN
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts\EnableApplicationFonts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\NOFPU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\Randomize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ScriptAnchorVis
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\AddIns
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\LoadBehavior
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\FriendlyName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\RequireShutdownNotification
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\Manifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\ExcelPlugInShell.PowerMapConnect\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\ExcelPlugInShell.PowerMapConnect\Clsid\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{F39D01F3-69C1-45E1-93B2-7BF0BC6EB63E}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\ExcelPlugInShell.PowerMapConnect\OverrideDefaultDisable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\LoadBehavior
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\FriendlyName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\RequireShutdownNotification
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\Manifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\NativeShim.InquireConnector.1\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\NativeShim.InquireConnector.1\Clsid\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{237428F1-F2C7-4F86-B7ED-ADE148ACF95F}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Excel\Addins\NativeShim.InquireConnector.1\OverrideDefaultDisable
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\LoadBehavior
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\FriendlyName
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\RequireShutdownNotification
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Manifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Clsid\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{509E7382-B849-49A4-8A3F-BEAB7E7D904C}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\Description
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\AdHocReportingExcelClientLib.AdHocReportingExcelClientAddIn.1\OverrideDefaultDisable
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\LoadBehavior
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\FriendlyName
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\RequireShutdownNotification
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\Manifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\PowerPivotExcelClientAddIn.NativeEntry.1\Clsid\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A2DBA3BE-42CC-4D0E-95FD-BCAA051BA798}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\Description
HKEY_CURRENT_USER\Software\Microsoft\Office\Excel\Addins\PowerPivotExcelClientAddIn.NativeEntry.1\OverrideDefaultDisable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00024500-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\OPEN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020820-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020821-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020830-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020832-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Policies\0ff1ce15-a989-479d-af46-f275c6370663\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{00020833-0000-0000-C000-000000000046}\InProcHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InprocHandler32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{EABCECDB-CC1C-4A6F-B4E3-7F888A5ADFC8}\InProcHandler32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultPath
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\OpenDir
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableAnimations
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\Xlstart
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AltStartup
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\CoauthDebugMode
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UserInfo\UserName
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UserInfo\UserInitials
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\QFE_17407
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FirstRun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\AllowUserDefinedFileShareCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\DisableAllCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\DisableOMEXCatalogs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\TrustedCatalogs\RequireServerVerification
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Excel_RequireForceRefreshAtBoot
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Excel_RibbonCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\ExcelOMEXRefreshPending
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Excel_AggregatedCache
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\DeferredCheckDisabled
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DisableCoauthLegacyVersionMitigation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\XLDesktopCoauthActive
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UseClusterConnector
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ClusterConnector
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DoNotCheckIfOfficeIsHTMLEditor
HKEY_LOCAL_MACHINE\Software\Classes\.htm\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\edit\command\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\print\command\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{42042206-2D85-11D3-8CFF-005004838597}\Version\16\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\.mht\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\mhtmlfile\shell\edit\command\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\mhtmlfile\shell\print\command\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\OnlinePollTimeMs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Office Application Guard PreWarm
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Isolation.IsolatedWindowsEnvironmentHost\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenRequestResult\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateOnHostFlags
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Policies\0ff1ce15-a989-479d-af46-f275c6370663\de52bd50-9564-4adc-8fcb-a345c17f84f9\Value
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\LicenseAggregateSubscription
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\CurrentSkuIdAggregationForApp\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\Resiliency\TimeOfFailure
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Registration\DESKTOP-SUAFK0F\ProPlusRetail.AttemptGetKey
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\NextUserLicensingLicensedUserIds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\RemoveOOBE
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\TestFeatureMapping
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\EligibleForExtendedGrace
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\FirstCleanValidation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\CachedLicenseData\excel.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\PolicyType
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\MergeAlgorithm
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicyname
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicypath
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicyismultisz
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\ADMXMetadataUser
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\7DValue
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\AppHVSI\AllowAppHVSI\Value
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Viewer
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\UseSentinelFile
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\EXCEL.EXE\RequiredFile
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\EXCEL.EXE\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\Namespace\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\Namespace\ValidateRegItems
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\Namespace\MonitorRegistry
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivationType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\TrustLevel
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\RemoteServer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{c0a8b6a3-0000-0000-0000-300300000000}\Generation
HKEY_LOCAL_MACHINE\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\AppID
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\TrustLevel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowStatusBar
HKEY_LOCAL_MACHINE\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\Software\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\Software\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\Software\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\Software\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\Software\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HubMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-932793227-1321892499-785312009-1001\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\VolumePref
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\Name
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.StateRepository.FileTypeAssociation\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\ExePath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\CommandLine
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\ActivatableClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\ServerType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\AppId
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\Server\StateRepository\Identity
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{8645456F-D9A2-4B82-AFEC-58F0E8DF0ACF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C53E07EC-25F3-4093-AA39-FC67EA22E99D}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{76765B11-3F95-4AF2-AC9D-EA55D8994F1A}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9AC9FBE1-E0A2-4AD6-B4EE-E212013EA917}\InProcServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\DisableROForSharedDocs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\SupportUNCMappedDriveSaveAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Offline\Options\CheckoutToDraftsEnabled
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{275c23e2-3747-11d0-9fea-00aa003f8646}\InsecureQI
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\EnableLogUnsupportedFeaturesToAppStorage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\RevisionTrimSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultSheetR2L
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\A4Letter
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\CursorVisual
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\ControlCharacters
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultFormat
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Common\VbaOff
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\VbaOff
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\FeatureListForC2RGimme\VBAFiles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AutomaticPictureCompressionDefault
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DiscardImageEdits
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DefaultImageDPI
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole\MaximumAllowedAllocationSize
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\QFE_Saskatchewan
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\ExtensionHardening
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\UserTemplates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\Templates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\SharedTemplates
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\WellKnownContracts\Windows.Foundation.UniversalApiContract
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Author
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FriendlyName
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Version
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SpecVersion
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Vendor
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ContainerFormat
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceManufacturer
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceModels
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ColorManagementVersion
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\MimeTypes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FileExtensions
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportAnimation
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportChromakey
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportLossless
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportMultiframe
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ArbitrationPriority
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Pattern
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Position
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\EndOfStream
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Mask
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{1B0D3570-0877-5EC2-8A2C-3B9539506ACA}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{11659A23-5884-4D1B-9CF6-67D6F4F90B36}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{FE2F3D47-5D47-5499-8374-430C7CDA0204}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{5DB5FA32-707C-5849-A06B-91C8EB9D10E8}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{09335560-6C6B-5A26-9348-97B781132B20}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41FD88F7-F295-4D39-91AC-A85F3149A05B}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Credentials.WebAccountInternal\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Language\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtension\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.Authentication.OnlineId.MicrosoftAccountWAMExtensionForUser\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebTokenResponse\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.Web.Core.WebProviderError\ActivateOnHostFlags
HKEY_USERS\.default\Software\Microsoft\IdentityCRL\AppData\00000000480728C5\FirstParty
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66B59040-7C93-5F96-B52F-2C098D1557D0}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{E0798D3D-2B4A-589A-AB12-02DCCC158AFC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{199E065C-8195-55DA-9C10-8AEAF9AC1062}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\GipActivityBypass
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{00000035-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32\DiagMatchAnyMask
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\ADUserName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\SignedOutADUser
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingLastWriteTimeExcel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{2ABC0864-9677-42E5-882A-D415C556C284}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1299CF18-C4F5-4B6A-BB0F-2299F0398E27}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{22D2E146-1A68-40B8-949C-8FD848B415E6}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.SystemAuthenticatorInternal\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivationType
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Server
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\DllPath
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Threading
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\TrustLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\RemoteServer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateAsUser
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Permissions
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateOnHostFlags
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}\ApplicationFlags
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}\DeviceId
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{05F9F2EC-5950-56F8-B7F8-22E20B984679}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Wow6432Node\Microsoft\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}\DeviceTicket
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\GlobalDeviceUpdateTime
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\IdentityCRL\ClockSkew
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Immersive\production\Property\0018000D024F8B00
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4590f811-1d3a-11d0-891f-00aa004b2e24}\InsecureQI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\MGOTFlags
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ProtectionLevel
HKEY_LOCAL_MACHINE\Software\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\DllSurrogate
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\AMSI\FeatureBits
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\IsVailContainer
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Input\ResyncResetTime
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Input\MaxResyncAttempts
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88d96a0c-f192-11d4-a65f-0040963251e5}\InsecureQI
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{00000160-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\Extensions\DragDropExtension
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}\InProcServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\NoTrack
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\DrawInkTab
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Draw\CanvasInkOverride
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\AnimationDiagnostic
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\DisableDocumentAssemblies
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\FullCalcOnLoadOldFile
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\BlockOleAutoActivate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackDocs
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\PolicyType
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\MergeAlgorithm
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicyname
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicypath
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicyismultisz
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\ADMXMetadataUser
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\7DValue
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Start\HideRecentJumplists\Value
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\CreateVbeProjOnLoad
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\ReentryToken
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\infoCache
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F42EE2D3-909F-4907-8871-4C22FC0BF756}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A0C69A99-21C8-4671-8703-7934162FCF1D}\Icon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A0C69A99-21C8-4671-8703-7934162FCF1D}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0DDD015D-B06C-45D5-8C4C-F59713854639}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{0DDD015D-B06C-45D5-8C4C-F59713854639}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\FolderValueFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\StorageDelegateSuppressionPolicy
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\StorageDelegate
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\CLSID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\Attributes
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\DescriptionID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\HelpTopic
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\AllowChildAliasRegistration
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\RecursiveSearch
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\Instance\InitPropertyBag\TargetKnownFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{4DF0C730-DF9D-4AE3-9153-AA6B82E9795A}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Fonts\CloudFontsURL
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\LocalizedName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\CustomUIRoaming
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Icon
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\DefinitionFlags
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\Attributes
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\FolderTypeID
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1}\InitFolderHandler
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Category
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Name
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParentFolder
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Description
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\RelativePath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParsingName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InfoTip
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalizedName
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Security
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResource
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResourceType
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Roamable
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PreCreate
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Stream
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PublishExpandedPath
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\DefinitionFlags
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\ShownFirstRunOptin
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Registration\AcceptAllEulas
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\16.0\Registration\AcceptAllEulas
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\EulasSetAccepted
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Privacy\UserCCSDisabled
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{88d96a05-f192-11d4-a65f-0040963251e5}\InsecureQI
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\EmulateOLS
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\LastKnownC2RProductReleaseId\Excel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\WEF\Signal\PreWarm\ExcelLastUseTimestamp
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\FOLDERID_Desktop
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\FOLDERID_Documents
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU\FOLDERID_Desktop
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU\FOLDERID_Documents
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\DefaultFormat
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\FileFormatBallotBoxTelemetryEventSent
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\UpsellState
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing\Resiliency\ResiliencySimulator
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{9B92EB61-CBC1-11D3-8C2D-00A0CC37B591}\1.2\0\win32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\FriendlyName
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\LabelText
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\Save
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\ShowButtons
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\ShowIndicators
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoLabelOption
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoSaveOption
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoButtonOption
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN\NoIndicatorOption
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{77f10cf0-3db5-4966-b520-b7c54fd35ed6}\InsecureQI
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{660B90C8-73A9-4B58-8CAE-355B7F55341B}\AppID
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\ScreenTipScheme
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\Animation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\ShowKbdShortcuts
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Toolbars\FontView
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\DontShowWhatsNew
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InsecureQI
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{000CDB0D-0000-0000-C000-000000000046}\AppID
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\Sound
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\IsCustomAddinTabDefaultBackstagePlace
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\HomePageUserSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\nvz
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options\StartupDialog
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableHyperlinksToWebTemplates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\DisableOfficeTemplates
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\Lcid
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\SysLcid
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ServicesManagerCache\UiLcid
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\Quick Access Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\File MRU\Max Quick Access Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DisableOnPremAutoDiscover
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Place MRU\Max Display
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\General\SkipOpenAndSaveAsPlace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Office\Common\MID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\AppID
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{8856f961-340a-11d0-a96b-00c04fd705a2}\InsecureQI
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{C2EA74E0-0ED2-11CF-A9BB-00AA004AE837}\AppID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.RKPRY.RKR.15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\FirstEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\LastEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\SplWOW64TimeOutSeconds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\SplWOW64TimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7B3C0E0-FB47-49F6-A66B-8A7C2E4E7B9C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseActivationAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\splwow64.exe\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CB363445-F453-4C1E-8EE4-BD123C5E394F}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CB363445-F453-4C1E-8EE4-BD123C5E394F}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\SynchronousPrintHandleAccessMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\PrinterDriverUnloadTimeOutMinutes
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{807583E5-5146-11D5-A672-00B0D022E945}\AppID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\EnableJavaScriptDebugging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\COM+Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\splwow64.exe\JScriptSetScriptStateStarted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Internal.Printing.Workflow.WorkflowSessionManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ExePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\CommandLine
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\IdentityType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ActivatableClasses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ServerType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\Identity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ServiceName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\Server\PrintWorkflowUserSvc\ExplicitPsmActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DEBA2EE-C7E4-47AE-85D5-56C59D090DA5}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF86E2E0-B12D-4c6a-9C5A-D7AA65101E90}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{801156FD-7E96-4274-821E-96D94E0C2B1F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CE4B87D-0ABF-4E76-A557-A2082325270A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\DontUseArchive
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling\1
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\CrashPersistence\EXCEL\5712
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\CrashPersistence\EXCEL\5712\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages\en-US
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UISnapshotLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\ebt
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ImmersiveWorkbookDirtySentinel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelPreviousSessionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SessionId
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingConfigurableSettings
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\162F61E\162F61E
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\ExcelWorkbookOpenedCount
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingLastSyncTimeExcel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Roaming\RoamingLastWriteTimeExcel
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Documents\LastPurgeTime
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\FileBlock
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\FileBlock\FileTypeBlockList
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ReviewCycle\ReviewToken
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\1630D21
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\DocumentRecovery\1630D21\1630D21
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\nvz
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.RKPRY.RKR.15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo\112DF3B9-46FD-489C-9225-38E8C540F72A
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\splwow64.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\splwow64.exe\JScriptSetScriptStateStarted
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\GracefulExit\EXCEL\2840\0
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\ebt
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Resiliency\StartupItems\=:x
C:\Windows\splwow64.exe 8192
Global\ClickToRunPackageLocker
Local\SM0:5712:168:WilStaging_02
Office.16.916BB0BF-2D21-4499-83C7-555DB4C3F8E8
Local\10MU_ACBPIDS_S-1-5-5-0-203751
Local\10MU_ACB10_S-1-5-5-0-203751
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
Local\SessionImmersiveColorMutex
_ClassificationAuditCacheMutex_
{540C3015-CFCF-4C7C-85E7-E18AD81E4A31}16ContentAnonymousInsights.json
Local\SM0:5712:64:WilError_03
Local\MSCTF.Asm.MutexDefault1
CicLoadWinStaWinSta0
Local\MSCTF.CtfMonitorInstMutexDefault1
Local\F99C425F-9135-43ed-BD7D-396DE488DC53_Office16
Global\552FFA80-3393-423d-8671-7BA046BB5906
743DD871-568C-4AB6-8834-ABCE03440726-VER16
Global\MTX_MSO_Formal1_S-1-5-21-932793227-1321892499-785312009-1001
Global\MTX_MSO_AdHoc1_S-1-5-21-932793227-1321892499-785312009-1001
Local\Microsoft_Office_UsageMetricsStoreFileStore_16
Local\UsageMetrics_NLMicrosoft_Office_16_3319437661
Local\StorageWin32Mutex_Microsoft_Office_16_NamespaceLifecycle_3192105584
Local\Disco_Microsoft_Office_16_Catalog
Local\Disco_Microsoft_Office_16_MappingLock
Local\Disco_Shm_Microsoft_Office_16_MA_244114e7
Local\Storage_Microsoft_Office_16_NM_Seq_4e537u69913576p
Local\Disco_Shm_Microsoft_Office_16_MA_90a23ea2
Local\WinSpl64To32Mutex_31d3e_0_2000
5CAC3FAB-87F0-4750-984D-D50144543427Office-VER16
mru-cr
Local\!BrowserEmulation!SharedMemory!Mutex
Local\SM0:4680:304:WilStaging_02
No results
Sorry! No behavior.
Sorry! No tracee.
Sorry! No strace.
Sorry! No tracee.

No hosts contacted.

No TCP connections recorded.

No UDP connections recorded.

No domains contacted.

HTTP Requests

No HTTP(s) requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No Suricata Extracted files.
Sorry! No dropped files.
Sorry! No process dumps.