Analysis

Category Package Started Completed Duration Options Log(s)
FILE exe 2025-06-14 00:44:51 2025-06-14 01:15:46 1855 seconds Show Options Show Analysis Log
procmemdump=1
import_reconstruction=1
unpacker=2
norefer=1
no-iat=1
2024-11-25 13:37:15,272 [root] INFO: Date set to: 20250613T15:51:07, timeout set to: 1800
2025-06-13 16:51:07,711 [root] DEBUG: Starting analyzer from: C:\tmp_gell1p8
2025-06-13 16:51:07,711 [root] DEBUG: Storing results at: C:\GwwbIFegx
2025-06-13 16:51:07,711 [root] DEBUG: Pipe server name: \\.\PIPE\gFcGUflta
2025-06-13 16:51:07,711 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32
2025-06-13 16:51:07,711 [root] INFO: analysis running as an admin
2025-06-13 16:51:07,711 [root] INFO: analysis package specified: "exe"
2025-06-13 16:51:07,711 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-06-13 16:51:08,195 [root] DEBUG: imported analysis package "exe"
2025-06-13 16:51:08,195 [root] DEBUG: initializing analysis package "exe"...
2025-06-13 16:51:08,211 [lib.common.common] INFO: wrapping
2025-06-13 16:51:08,211 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation
2025-06-13 16:51:08,211 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\rstrui.exe
2025-06-13 16:51:08,211 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-06-13 16:51:08,211 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-06-13 16:51:08,211 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-06-13 16:51:08,211 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-06-13 16:51:08,383 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-06-13 16:51:08,414 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2025-06-13 16:51:08,555 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-06-13 16:51:08,555 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-06-13 16:51:08,570 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-06-13 16:51:08,570 [lib.api.screenshot] ERROR: No module named 'PIL'
2025-06-13 16:51:08,570 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-06-13 16:51:08,586 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-06-13 16:51:08,586 [root] DEBUG: Initialized auxiliary module "Browser"
2025-06-13 16:51:08,586 [root] DEBUG: attempting to configure 'Browser' from data
2025-06-13 16:51:08,586 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-06-13 16:51:08,586 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-06-13 16:51:08,586 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-06-13 16:51:08,586 [root] DEBUG: Initialized auxiliary module "DigiSig"
2025-06-13 16:51:08,586 [root] DEBUG: attempting to configure 'DigiSig' from data
2025-06-13 16:51:08,586 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2025-06-13 16:51:08,586 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2025-06-13 16:51:08,586 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2025-06-13 16:51:08,773 [modules.auxiliary.digisig] DEBUG: File is not signed
2025-06-13 16:51:08,773 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2025-06-13 16:51:08,773 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2025-06-13 16:51:08,773 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-06-13 16:51:08,773 [root] DEBUG: attempting to configure 'Disguise' from data
2025-06-13 16:51:08,789 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-06-13 16:51:08,789 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-06-13 16:51:08,789 [modules.auxiliary.disguise] INFO: Disguising GUID to 83e84e0d-fc0c-4181-be4b-009264b9bbf7
2025-06-13 16:51:08,789 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-06-13 16:51:08,789 [root] DEBUG: Initialized auxiliary module "Human"
2025-06-13 16:51:08,789 [root] DEBUG: attempting to configure 'Human' from data
2025-06-13 16:51:08,789 [root] DEBUG: module Human does not support data configuration, ignoring
2025-06-13 16:51:08,789 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-06-13 16:51:08,789 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-06-13 16:51:08,789 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-06-13 16:51:08,789 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-06-13 16:51:08,789 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-06-13 16:51:08,789 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-06-13 16:51:08,805 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2025-06-13 16:51:08,805 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-06-13 16:51:08,805 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-06-13 16:51:08,805 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-06-13 16:51:08,805 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-06-13 16:51:08,805 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-06-13 16:51:08,805 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696
2025-06-13 16:51:08,820 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmp_gell1p8\dll\696.ini
2025-06-13 16:51:08,820 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2025-06-13 16:51:08,820 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2025-06-13 16:51:08,820 [lib.api.process] INFO: Option 'unpacker' with value '2' sent to monitor
2025-06-13 16:51:08,820 [lib.api.process] INFO: Option 'norefer' with value '1' sent to monitor
2025-06-13 16:51:08,820 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2025-06-13 16:51:08,820 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-06-13 16:51:08,820 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp_gell1p8\dll\vNrdqc.dll, loader C:\tmp_gell1p8\bin\KKGjHlEY.exe
2025-06-13 16:51:08,899 [root] DEBUG: Loader: IAT patching disabled.
2025-06-13 16:51:08,899 [root] DEBUG: Loader: Injecting process 696 with C:\tmp_gell1p8\dll\vNrdqc.dll.
2025-06-13 16:51:08,914 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'.
2025-06-13 16:51:08,914 [root] INFO: Disabling sleep skipping.
2025-06-13 16:51:08,914 [root] DEBUG: 696: Full process memory dumps enabled.
2025-06-13 16:51:08,914 [root] DEBUG: 696: Import reconstruction of process dumps enabled.
2025-06-13 16:51:08,914 [root] DEBUG: 696: Active unpacking of payloads enabled
2025-06-13 16:51:08,914 [root] DEBUG: 696: CAPE debug - unrecognised key norefer.
2025-06-13 16:51:08,914 [root] DEBUG: 696: TLS secret dump mode enabled.
2025-06-13 16:51:08,930 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542
2025-06-13 16:51:08,945 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable
2025-06-13 16:51:08,945 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0
2025-06-13 16:51:08,945 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF8234D0000, thread 3088, image base 0x00007FF60D500000, stack from 0x0000008EFACF4000-0x0000008EFAD00000
2025-06-13 16:51:08,945 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe
2025-06-13 16:51:08,961 [root] DEBUG: 696: Hooked 5 out of 5 functions
2025-06-13 16:51:08,961 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-06-13 16:51:08,961 [root] DEBUG: Successfully injected DLL C:\tmp_gell1p8\dll\vNrdqc.dll.
2025-06-13 16:51:08,961 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe>
2025-06-13 16:51:08,961 [root] DE <truncated>

    

    

    

Machine

Name Label Manager Started On Shutdown On Route
win10-2 win10-2 KVM 2025-06-14 00:44:51 2025-06-14 01:15:25 none

File Details

File Name
rstrui.exe
File Type PE32+ executable (GUI) x86-64, for MS Windows
File Size 269312 bytes
MD5 3aa4970b3d30f9ad1ec6ed10034ea21e
SHA1 57810b063ebe4918e6404d775065de34cd3096c8
SHA256 28bb332d73ddd4147c6009cb10ac073b6072be2114554f85c5c37f557af0fc8b [VT] [MWDB] [Bazaar]
SHA3-384 58cdbc905b816dac0d6b4531f1de1210d78aa41ee6a291b3850622798622ed5c164e79c0e719d2e2efb491f15bf97015
CRC32 3F0AF377
TLSH T11044AE003224C3FAD53AD174CA87A93BEAB63040277242DF569895BE6F17FF1B936215
Ssdeep 6144:p5SUgd8I9kjkKyi0twIOeS0GStDangQ2+UvQ/KpmOq:p5SUDlyftwI9z9tDK2vQ/Kp
File BinGraph Vba2Graph VirusTotal

SxFillRectClr
_createVolumeMap
pA^_^[]
@.data
SelectObject
##((++
hA_A^A]A\_^[]
REH9)
GetStartupInfoW
k__\\RRPMM
l$<D9q
Msftedit.dll
CSharedWizData::CleanupSharedData
IsSREnabled
_SetSRRestoreBOOLs
CBlockingTaskExec::SetCurrentProgress
u*9Q<|%
InvalidVolumeName
LaunchWizardElevate
L$xE3
;/o7l/
p@'&$)
SpawnCOMRegisterThread
EndDialog
]%~!$2
)099(,5=<FJIKXPP1DD222DD
<autoElevate xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</autoElevate>
!]0!]@!]HH!]
6658D
zDZp|
</security>
CLSIDFromString
blbres.dll
HxVUW
SetEntriesInAclW
VWAVH
!|$XI
_TweakBiDiDateFlags
SxGet0XLogFileCount
Microsoft Corporation
+"=<FIGHH*n
v=TwwE
LoadLibraryExW
::StringCchCopy( pwszVolumeName, cchVolumeName, pwszShortest )
memcmp
:9:99:
%P1u]
type="win32"
wpww}||qlo
0ThPT
_XcptFilter
V8WSK
_lock
Log_SR_ERROR_SYSTEMRESTORE_UNSPECIFIED
K%ds9
USVWATAUAVAWH
A8H;E
_CheckNoOtherInstances
D9l$8v:H
AE0,14u
nxuuusi`
%s %s
_SetupFinalPageMessage
-,()(((11100"0///
_initterm
NLLLP
.idata$5
]Z)6lX
_FormatRestorePointFriendlyName
_SetWizStateError
h UAVAWH
%)))(((
Windows System Restore
SxStartTracing
tFDDDFLL
CBlockingTaskExec::OnTaskDlgCreate
.pdata
wcschr
_UpdateRestorePointVolumes
!t$hM
ubVyx
Microsoft
_acmdln
shVolume != INVALID_HANDLE_VALUE
e%s %s %s
NN>;9347""1P
"a`ABOTT
D$XfD
_IsRPBootVolume
CloseServiceHandle
@SUVWATAUAVH
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
_WasVolumeProtected
fD94Bu
&( 110"//""//+2,'-
SetEvent
CSharedWizData::_BuildFont
_exit
D$$D9
KKKXZZB
0A^_^
8\u*f
DPN{NNPN
MoveFileExW
_MsgSortRestorePointPicker
``YV~zzz
wp}}}}{{l
D$LA;
T*ajj
0A_A^A\_^
@8o8t
(((1+&
_MsgFinishPageConfirm
SxShowDirtyVolumeDialog
SxIsVolumeInteresting
F H9xPtc@8
p WAVAWH
_FindSppExternalGroup
VWWGWWW
_DetailsInsertListView
WinSqmAddToStreamEx
G8H;FHu
CoCreateInstance
GetCommandLineW
DestroyPropertySheetPage
%)((11000///7774446658
'7777
SrGuiStopTracing
SxCheckWBDiagSession
_MsgIntroErrorPageSetActive
_RealSystemRestoreOfflineThreadFunc
GetFileAttributesW
_RebootSystem
%systemroot%\system32\systempropertiesprotection.exe
CSxVolumeLocator::FindVolumeById
.CRT$XIA
RtlNtStatusToDosError
SrFreeRestoreStatus
CBlockingTaskExec::OnCancelNotification
_RealSystemRestoreThreadFunc
<=qqq
_ToggleVolumeState
S$<HmZv
CreateColorBitmap
SxPaintTopWhitePart
|$(E3
DispatchMessageW
ir=>K
0CZ+"
::DeleteFile( strTracingDirectory )
1[6oa
x UAVAWH
TeVCrL
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
U*"=<FJIGHLD
FileDescription
DvPPN{A
GetLocaleInfoEx
CSxApp::Init
[9:(6=<FIGHHW
#((1100///7774446558
GeDlD
UWATAVAWH
d6}{LC
BeginPaint
_LookForPriorInstallPointOrNothing
EHXL9JXL
ntdll.dll
Button
zzz:~
10.0.17763.1
DeviceIoControl
InitializeCriticalSection
8% kCL\
"$Zczj
SetWindowLongPtrW
fTKe0q
B8H+A8H
SetWindowLongW
AdjustTokenPrivileges
l$0E3
tlLFDD
lx6_`
version="6.0.0.0"
D$(E3
SxFindExistingWindow
SetSecurityDescriptorGroup
w%{A~
I+G@H
$iM[i+
IDATC
|annnrvv
L$(E3
UVWAVAWH
CBlockingTaskExec::OnCancelClicked
GetSysColor
tuxtheme.dll
owwWH.
InflateRect
A_A^A\_]
InitiateShutdownW
O:BAG:BAD:P(A;OICI;GA;;;BA)(A;OICI;GA;;;SY)
FrA2d
@*'*((11000///77
TerminateProcess
IsWinPE
A;E0r
fg=k{d
U/000/,6=?<FJKOXXXXXXXPXYi
V;Y^\
D$lD9}
##(++
%=R%:'
/////-,5=?<FINWWWWWWXXVYi
SxGetVolumeSize
GetDiffAreaInfo
HcF H
wDDDDD
CloseThemeData
.text$x
T$ E3
L!u8H
A^_^
GetModuleHandleW
MoveFile
GetTimeFormatW
L$ E3
SOFTWARE\Microsoft\RecoveryEnvironment
+66558v
_MsgFinishPageInitDlg
.giats
uLD9k(uFH
rstrui.exe
0A_A^_
nv}m|{ql]
OriginalFilename
GdiFlush
FileTimeToSystemTime
000///73-
uKD9k(uEH
AssertPrivilege
,['!<Z&
fD94Au
CheckGroupPolicy
RestoreUI
\$8E3
f9}gt
ImageList_Add
wwwwp
EnableWindow
X\\D.
mnpvzusif_
PropertySheetW
UVWATAUAVAWH
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
CreatePropertySheetPageW
D?PN{
DisableConfig
CloseHandle
_IsSystemVolumeRestorable
739;<<=
@.reloc
?{>MS
_IsBackupOnTarget
P)TJE
SxGetUserAccessLevelForHandle
"",5)
GetSystemTimeAsFileTime
SeShutdownPrivilege
ControlTraceW
H!|$
_MsgRestorePointItemChanged
EPNAydxVUUXWWXx
_SetRPListDefaultState
2K25777785X
|$HE3
[Uln^
y^mvvv
RegisterWindowMessageW
L9s(tLH
SetUnhandledExceptionFilter
ss4FF
D9.v*L
wcscmp
_MsgDetailsDlgInit
avyv`rxuyvvyq
wwxxx
NN{{{
D$ E3
.text
[6?>JI744`
SSS887
_GetGuidVolumeName
P((CM
SRCORE.dll
.rdata$brc
_MsgVolumePickerPageNext
SetWindowPos
Z7WVV
G0H;F@u
_DoRunOnceSpawn
_PopulateVolumePickerList
ControlService
xxxxxx
SetClassLongPtrW
L$`E3
.-,+0 )(
_RealMain
kJ(H!
<=c#.
T|7an
LocalAlloc
_GetSelectedRestorePoint
##$(+*
.idata$4
RegisterCOMObjectsInGIT
GetTokenInformation
xddHHVVU
__dllonexit
xl/wn
VUMcc
?dbbUUVV
SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations
DrawThemeBackgroundEx
InitializeSecurityDescriptor
I:]8G
D$4E3
COMCTL32.dll
((11000///774446656vPC
qksnc
_AddInterestingVolumes
SafeGetClassName
7[ }>
__C_specific_handler
RtlEnumerateGenericTableAvl
TraceMessage
D$4D9l$htwH
@fE98u
_PrepareForRestore
GetSystemId
GetSysColorBrush
_MsgRestorePointPageNext
%s.%d.%s
[C%n*
WinSqmAddToStream
S~[5O
[\vvvt&;)pxpS{{||G
RJ?=::
6Ifup<
CreateEventW
E9M0v+H
\\?\Volume{
DeleteObject
.text$mn$00
t$ WH
</windowsSettings>
_SetupDetailsLvColumns
SetLastError
_DoRestore
.rsrc$01
D$DE3
Xd-Y[n
n'.Et
A_A^A]A\_^[]
(is|
OMOcfz
OffsetRect
_SRConfirm
T$`9w
fE9<Pu
CoTaskMemRealloc
p.-98/0001*1**+*0++0p
_FindNewestAndSuggestedRestorePoints
GetWindowRect
GetTraceEnableLevel
111*3383
_ComputeAggregateState
SxIsElevatedWindow
EndPaint
IsWindow
E$PHX`0
t`D8t$ t
wp}}|zupqm
LeaveCriticalSection
FindFirstVolumeW
'D9.u%
pA^A]_^]
ILLL$&
Software\Microsoft\Windows NT\CurrentVersion\SystemRestore
"22/3355.
GetTraceLoggerHandle
D9l$8v
Microsoft Corporation. All rights reserved.
%SystemDrive%\
SxRegReadString
GetDateFormatW
.text$yd
;bOHS
l?9eU
@..820001(
GetWindowLongPtrW
CreateDirectoryW
nyvvxr`v|||b~~c
LcA<E3
SxGetVolumeIdentifier
@USVWAUAVAWH
D9gDtSI
L9egt
#$(+T
@.rsrc
blblog
_MsgVolumePickerKeyDown
?\UNC\
)jnooqql
`A_A^A]A\_^]
l$ E3
fD9$qu
LegalCopyright
CallWindowProcW
SendMessageTimeoutW
_MsgSuccessDialogInit
&)))(((111
version="1.0.0.0"
<dependentAssembly>
tFas+
eT9lD
xr.!<
;L$8r
T*amm
48:>>>pN
t:K[;
KY8g3(
.rdata$zzzdbg
IsSystemVolumeInClient
_GetDisplayNameOfVolume
LoadStringW
RtlInsertElementGenericTableAvl
WAVAWH
1)/('%%8@@@AAA>:
GetDriveTypeW
.rdata
|$XE3
#((&Bhsi]
hmr0|
CleanupParameters
RegisterEventSourceW
_AddSqmDatapointsAtWizardCompletion
OpenSCManagerW
wwwp}wrq|q]
%)((11000///774446655-
A;v r
::GetVolumeNameForVolumeMountPoint( wszVolume, pwszUnique, cchUnique )
wcsstr
_FindSrVolumeInBackup
D$$I;
h_^[]
<assemblyIdentity
ImageList_Create
SetLayout
WaitForSingleObject
netmsg.dll
QG8~<s
_AppendStatus
[Ufe-
OpenProcessToken
97vwH
;`aC0
Nuz{{
::StringCchCopy( STRING_CCH_PARAM( wszVolume ), pwszVolume )
SystemParametersInfoW
StartTraceW
MessageBoxW
g2jwz
hFHnbb"
Clll`eE$
memcpy
SetForegroundWindow
.idata$3
_GetPresentableVolumeName
8Pq\w:
SxShellExecuteWithElevate
5RRRRTTTUUTY
SetErrorMode
D$DD9w
SxGetWindowsDirectory
n++>I]
vsstrace.dll
SxRotateLogs
E\Q:CB
ExpandEnvironmentStringsW
DeleteFile
]Ubyi
__setusermatherr
D;uPs
UATAUAVAWH
UWATAUAVH
~"|]o
GetTickCount
u\L;@
txqNC%
]X/9q
SxShowIcon
_MsgRestorePointPageInitDlg
.CRT$XIY
s?6==}h
GetVolumeInformationW
PostMessageW
_InitWbengine
#$(+4
&GBs=;
/>
_FindBackup
pL=wH
mmmmAX
"2I't
zsWWW[
f&:=A
UWAVH
z\cg84
A_A^A\
Dv?PNN{A
-X `V
iswspace
UWAUAVAWH
>6^6Q
SetFileShortName
UnregisterTraceGuids
Pgdeefe
%s.0.%s
WaitForCOMRegisterThread
9LKMOId
SHELL32.dll
@#'-..'()((1000//777444666559=?
:\ubf
jhse|
|$hE3
)30^wtsi]
_MsgIntroErrorPageInitDlg
_ismbblead
_HighlightSelectedRestorePoint
Hc@ D
p;gI'
%465;>>?
//39:.:;:
g|DFL
'Z]&7n$I
9E@u0H
CreateProcessW
y!dHxU
dl&fu
WATAUAVAWH
##$(%V
DisableSR
RFHJQ@
qsuU,ba[x
NN{NNN{AA
D$4D9g
hnl`l|
A_A^A]A\_
|$ E3
.CRT$XCAA
\$@E3
_BackupRestorePointPageNext
L!t$ H
\$ UH
ADVAPI32.dll
#$$+%Q
CreateThread
SetBkMode
.00cfg
_wcsicmp
SPP.dll
DialogBoxParamW
FreeLibrary
@SUVWH
UAVAWI
_FillDetailsPage
GetWindowTextW
_MsgIntroPageInitDlg
T$0E3
DuplicateToken
V2%3,
K(D9y
UVWATAVH
ydHVUU
GetKeyState
CompanyName
N3c'H
cI $F
GetCurrentThreadId
{=:8377" 111*1(p
7773:<<
__getmainargs
dkgJV
u3c[6
DnG`L
fSxGetTimeZoneString
u HcA<H
_MsgRestorePointPageSetActive
SetThreadPreferredUILanguages
OpenThemeData
_MsgVolumePickerClickItem
Sleep
ydHxVU
dl0Dh4
q=ft}
1L G!)
v7%oL9
GlobalFree
t$ UWATAVAWH
RtlInitializeGenericTableAvl
ShellExecuteExW
+7774446665.
GetVolumePathNamesForVolumeNameW
RegOpenKeyExW
~gtX;
SetBkColor
CopyRect
_wcsnicmp
FindFirstFileW
_ShowNoOSSelectedMessage
CSxVolumeLocator::FinalConstruct
@8~pt~
|zpAo
SetSecurityDescriptorDacl
(1Xn'
SxInitializeUiLib
`A_A^A\_^[]
"1|5=
L9E8v
SxGetInterestingVolumes
p@2!H
SetSecurityDescriptorOwner
'*)(((111
n/RUNONCELAUNCH
SxSetupWinREUILang
r$+LHy
A`#60
_RegisterCOMInterfaceInGIT
I@2 p
UnregisterCOMObjectsInGIT
CheckTokenMembership
_ValidateVolumeStates
ShH92t
n/~A+
vvv?PNN{{A
~?FX{
!\$XI
!!$I7J
UILanguage
##$(%N
T$hE3
S@f!C8H
ImageList_AddMasked
memmove
SHGetStockIconInfo
uiAccess="false"
#sGqp
strchr
@8y(t
_callnewh
OpenProcess
i*PYJ
InitRPFromSnapshot
__set_app_type
\ynqq
R.B_w
CSxVolumeLocator::_AddVolumes
LoadIconW
D$LE3
C0C0k!
GetVolumeNameForVolumeMountPointW
IDATx
GetUserDefaultLCID
SrGuiStartTracing
XP9'*
_MsgSuggestPageSetActive
040904B0
@.',%#)))##
W))*hVVW
M8D8ITt
023'898
@USVWAVH
a1`/(&&#,,,68ABBBBBKIL
F|t{m
-\NY;>
ReleaseDC
HcA<H
#yUDm
A_A^A]A\_^]
,&.-((11100///77744466658v
SxIsDirtyVolume
c6 -p
PeekMessageW
A_A^]
rstrui.pdb
fE9,Xu
SxWaitForSingleObjectWithMsgLoop
f\j\[e
'Zpop
_FilterRestorePointsBySystemId
ryjnn
fuxrjkfjjjjmrl
D$4D9mh
9%=?FJIGHK`]spmsuxv||bh~~oe]
GetClientRect
%s (0x%x)
txD8e@t
SxStopTracing
_MsgFinishPageSetActive
c267y<CE
sDa${+
F>>>t~~~
fyyttutm{|b~~h~o
SxCheckDiskViaShell
RegQueryValueExW
lOHH%
_MsgRestorePointCheckboxClicked
t$(E3
NgOh6
VarFileInfo
LLNNNNPPPOS
_fmode
{VxVUT
ImageList_Destroy
::GetVolumePathName( strPath, STRING_CCH_PARAM( wszRootPath ) )
C$&((11100///7774446655.
>{nx7
5EjAa
,,,0}
SxEnableTraceDefault
qLOO#
SxLocalSystemTimeToString
v?PN{A
s(D9n
DoCrashCleanup
_vsnwprintf
?`0=3===
CreateDIBSection
Software\Policies\Microsoft\Windows NT\SystemRestore
CreateFileW
>RhIuJ
000+8-9-:-
!N=;:9
<&'+x
CSxApp::GetResourceString
/OFFLINE:
FormatMessageW
GetTimeZoneInformation
processorArchitecture="amd64"
_IsTargetPresent
'_pSN
InitializeCriticalSectionAndSpinCount
`.&######,,655@BCCCCCCKCc
<security>
IcGPH
GetInterfaceFromGIT
CoUninitialize
<!-- Copyright (c) Microsoft Corporation -->
<requestedExecutionLevel
fA94@A
A_A^A]A\_
10.0.17763.1 (WinBuild.160101.0800)
SxIsBootVolume
DeleteCriticalSection
%s%s(0x%08X)
GetWindowLongW
$V77>y
C.,&+1
FillRectClr
t$HL9m
RtlCaptureContext
3232337-
_DoRestoreWizard
d$8E3
x ATAVAWH
Pu8D9
l$ VWAWH
9kXvLH
u5D9g
_MsgVolumePickerPageSetActive
%s (%s)
~eEz!
GetDeviceCaps
GetWindowThreadProcessId
A9GTu
` UAVAWH
CVUHHd
EnumWindows
/+U^[
publicKeyToken="6595b64144ccf1df"
WinSqmIncrementDWORD
\$XE3
A_A^_
BVc2c
SxGetUniqueVolumeForPath
SxShowLuaMessage
_PopulateRestorePointList
l@b>A
/6656?
A_A^A\
9}wt*
DestroyWindow
=>DZ{u
/RUNONCELAUNCH
SxLoadSystem32LibraryEx
H9t$@t
SystemRestoreTracingFlags
@USVWATAVAWH
"ACEis
ExtTextOutW
c)*IM
SetWindowTextW
DeleteDC
CBlockingTaskExec::EnableCancel
@h!&`
ReportEventW
ozzZN
m"6vgbc#
8388838A
777469
fD94{u
ht]i-
=7XZZ
tk]RMk
RtlLookupFunctionEntry
MsgWaitForMultipleObjectsEx
OMNabz
GetTraceEnableFlags
_MsgSortVolumePicker
CSrGuiCallback::_Init
m#W(`
QueryPerformanceCounter
L$0H+
t$0E3
CreateCheckBoxImagelist
pqqp,
%ic`\&
fA90u
msvcrt.dll
\$ UVWATAUAVAWH
RtlDeleteElementGenericTableAvl
D9o(tbL
StringFileInfo
ole32.dll
u]LLL`||\!
DDvPPPDC
tDDDD
EQ"K%
SxMergeExtraLogs
Z3bc8
SxCheckRebootRequired
.text$mn
\$(fD
D$XE3
e2++E\
EnableTraceEx2
,(((1100///7774446665=
/3:z/
, ((*&&,'
11+233,
H!M8H
/RECOMMEND:
000/3
B@I9@@s
&&'71>1jr
m%:E;
delh`c}
,',,))(((
DecodePointer
LaunchControlPanel
InitCommonControlsEx
_GetSrDelayedErrorString
F.[TAh
?$)((11100///7774446656p
SxFindTopLevelWindow
bd`~tkw#B
dHxVUXWV
CSxApp::InitAccessLevel
UpdateWindow
L$ SWH
SxGetBootVolume
eqspy{^h~oocE
HB*A*
_DisplayStatus
BackgroundFetchDriverWU
]wD;`
fNBW%
A^A\_^]
HB!91u
&&&P,
RtlVirtualUnwind
%s.0.?.%s
|$ UH
pA_A^_^]
qE@.=<<;d
!Q7pI;
D9@Dt
uOD9k(uIH
Iv%*w1h
_Mount
9?=K?
yyydHxVUTcc!b
f*90BBA@?=
M4;-4
.CRT$XCA
%s.0.%d.%s
cA@pe
fD9;t/H
KERNEL32.dll
E9}ou
A^A]A\_]
M9fPt
U((09:;1
<windowsSettings>
*)(((
c||<1
^/#I}
UnhandledExceptionFilter
GetWindowsDirectoryW
CSrGuiCallback::UpdateProgress
,))((111
%s.0.1.%s
SxTracerDebuggerBreak
}MCkK
ZZZ:{
SxQueryTraceSession
GetSystemDirectoryW
ydHxU
udD9ot
VS_VERSION_INFO
CreateWellKnownSid
n/cq1A
&))(((111
_MsgErrorDialogInit
x UATAUAVAWH
</dependency>
A_A^_^]
_MsgProgressDialogUpdate
u8D9g
.CRT$XCZ
AF m&
_MsgRestorePointPageOnCommand
zqkk34L
1Q<Nkt=
\$ UVWATAVH
/RUNONCE
SendMessageW
778;;;<;<;
Pu;D9
;|$8r
L$pE3
.data
$aX_T
\9:065=?FIIGMZ2elszylg
_LogStatus
L$ UVWH
yddxU
GetVolumePathNameW
9|$0t
wbengine
xwwww
B$'..-*(11100///777
<application xmlns="urn:schemas-microsoft-com:asm.v3">
memset
_DoSystemRestore
ydHxVUXc b
GetThemePartSize
SetFocus
9A98u6A9x
level="requireAdministrator"
aT )I
GetProcAddress
H!D$tE3
</trustInfo>
ProductName
_FakeupSnapshotName
GetClassNameW
!M9HXI
DuplicateTokenEx
t^D9e
CreateCompatibleDC
L9}wu
.idata$6
fA9<Qu
SxTracerGetThreadContextRetail
e00nv
SxSetRichEditUnicodeText
$,:=3.*
S[Mwy
D$$9{
9s(tGH
a|<F
GetParent
TWVV6
InitRPfromBackup
D$HE3
spp.dll
E)(11100///77
type="win32"
SxCompressLogFile
D$ 9D$xt
t$ UWAVH
#>;7&|J
FileVersion
fD9$Au
D9k(t
A0H;E
J}kJ|
t$ E3
CreateDialogParamW
::DeviceIoControl( shVolume, FSCTL_IS_VOLUME_DIRTY, NULL, 0, &dwResult, sizeof(dwResult), &cbReturned, NULL)
UAVAWH
J cGP
wwwwxp
1860yJyTH
</dependentAssembly>
USVWATAVAWH
<requestedPrivileges>
DeregisterEventSource
K_dbl
FileTimeToLocalFileTime
&o`dt3
idCreate
Zmlvff
CoInitializeSecurity
@2d89^
2+20=
RtlLookupElementGenericTableAvl
SppFreeExternalGroupPropArray
+SxIsLocaleBiDi
/>
_SetWizStateSuggest
e;5/|
@`D9n(t?H
CoTaskMemAlloc
SxInitializeCOMSecurityForSPP
bSxGetPresentableVolumeName
%,..'((11000///77744466555q
SxTracerShouldTrackFailure
'@e$I
fA90t
H9L$@u
?R#H}(
A_A^_^]
DeleteFileW
CoInitializeEx
*9:9-6=?>JJICPYDS[eepce[
GDI32.dll
SYSTEM\CurrentControlSet\Control\MiniNT
FindNextVolumeW
B0H+A0u
D$TD9y
BackgroundInitRP
]S56+
*))(((
.$'.---&)(((111000/7774466558<=v
A_A^A\_^
G|H9]
7p&"g@
@USVH
omma}}}
$'R;R
i*#&&&###,,65=?ACLLLLLLLL3
?.HC|
5SS[[[[[[
K_z/-DC
.data$brc
yydHV
H@!1#
mJy}_'
[wmAe
H3E H3E
InternalName
GetAncestor
g2Y0&
](((((.,65=?<JCOOOOOVVVMZi
yHxVW{
?vvvPPN{
malloc
E@9]0
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
D$lE3
f94HA
Dv?PNPv
srcore.dll
</application>
.rsrc$02
L!u7H
_unlock
xxxxw
wDLDld
GetDC
SetTextColor
%(11000//777446
`hsgc
kilh`bb
HxVUX
AssertPrivilegeOnToken
RegisterApplicationRestart
runas
en-US
FindNextFileW
LogSrCommon
:9%=<JIGHHKD_ssqtx{|~hU
E`I;G@
.text$di
hVolume != INVALID_HANDLE_VALUE
FindClose
$GD9g0
CBlockingTaskExec::SetMarqueeProgress
VWATAVAWH
_SetupVolumePickerColumns
</requestedPrivileges>
_DoRunOnce
RtlGetLastNtStatus
(((*+2&
_GetBootVolumeProp
\$0E3
GetCurrentProcessId
L$XH3
+.,((1110
_PopulateDetailsList
_SetupRestorePointPickerColumns
<assemblyIdentity
aeiouyAEIOUY
GetAndEnsureTracingDirectory
name="Microsoft.Windows.Rstrui"
.)((opoo
DD.@}UR
language="*"
+0MMLH
MapWindowPoints
d$(E3
#GM}`
GetSystemMetrics
!]HH!]
@)(11100///7774446656P
EtwTraceMessage
<.AH
}hk#k
dHHxVU
_SetFinalPageHeaderFont
SxIsUserDefaultLocaleBiDi
@USWH
ShutdownSystem
@USVWH
CoTaskMemFree
GetDlgItem
processorArchitecture="amd64"
GetDesktopWindow
DvvDD
"ABEJ
_SetIntroPageHeaderFont
.CRT$XIZ
FAILED[TRACK]
CBlockingTaskExec::SetTitle
xS9\$XuM
EncodePointer
!This program cannot be run in DOS mode.
n&''Y
A_A^A]_^[]
f96`.|
SxEnableTraceCustom
-%u9QX
GetLocaleInfoW
t$@E3
L$0uDH
$,--1>>
JJJ|hhh
D$xE3
USER32.dll
SxAllocateEventTraceProp
_MsgVolumePickerPageInitDlg
OpenServiceW
::GetVolumeNameForVolumeMountPoint( wszRootPath, STRING_CCH_PARAM( wszVolume ) )
_GetFocusedVolume
#ACEG
OF8:o
Pv?PPNN{{AA
%SystemRoot%\Logs\SystemRestore
ry\OZ
CreateFontIndirectW
HeapSetInformation
KPL+@@I
f9H\u
EnterCriticalSection
.CRT$XCU
CSharedWizData::Initialize
\$ E3
ConvertStringSecurityDescriptorToSecurityDescriptorW
%%-'-'-'&)(((111
system32\rstrui.exe /RUNONCE
_MsgSuggestPageInitDlg
%s%s(0x%08X[0x%08X])
`A_A^_^]
GetCurrentProcess
,[uXB
System Restore
d&PIa[o
_vscwprintf
9A5?>JIGHH:ajpssuxz|bhh~gcl
dwErr
Cgald
K L9s
CSrGuiCallback::CreateInstance
SysLink
LocalFree
7769=
%systemroot%\system32\rstrui.exe
</assembly>
TargetOS
<description>manifest file for rstrui</description>
Translation
^wjzvuuruyo
{LAL$
Software\Microsoft\RecoveryEnvironment
RegisterTraceGuidsW
idSysRestoreOnOff
IsTokenMember
\.((..&,,65=?<KNNNNMMMMMR
ProductVersion
238'8'
D9ott]D9n
xxxxxxwttDDDL|V
ju&^39n
gePP"
_ParseCommandLine
y;w&:
ShowWindow
_onexit
^J,--bvn
.CRT$XIAA
Wu00 b
7W4xDWL
CHnb"HW
SafeSetWindowLongPtr
A_A^A\_^[]
_ShowDetails
dHHxU
$qb;I
Windows
CBlockingTaskExec::Execute
D$0E3
fff0??
{SxRegReadDWORD
_GetSPPExternalGroups
.idata$2
fA94Cu
x AVH
lzG3
lQ?wEk
|$PE3
5H@JM
D;mgs
l$<fD
R=v|{N
ls_0;;k
Bjq@?
LookupPrivilegeValueW
SxIsCalendarRtl
53gN_
.xdata
E#'..-&((11000///77744466655:
.gfids
K+]llq
$1K"BA
$$&,,,
>3ZiT
FindVolumeClose
Operating System
0A^A]A\_^][
FAILED
L$49}`v;
IDAT^
_cexit
SystemRestore{B03D8975-C55C-411d-A198-BA9DD6342261}
RB[;'
#n]$;2
SetInitialFocus
<xtlll<
xVUUX
UVWAUAVH
CenterDialog
[5@Z9
D$$E3
p]7AT
GetLastError
@USVWATAUAVAWH
UWAWH
_commode
SxUTCFileTimeToStringFormatted
_amsg_exit
fD9$Gu
p WATAUAVAWH
?terminate@@YAXXZ
<dependency>
#oX}+CP
HandleHelpSysLink
CommandLineToArgvW
V@"6l
_UpdateCurrentlyProtectedVolumes
BuiltInRestoreUITracing
TaskDialogDirtyVolumeCallbackProc
_FillWinDir
pA_A^A]A\_^]
wwttD
SrFreeRpPropArray
EwA96
name="Microsoft.Windows.Common-Controls"
DrawFrameControl
P:UEm
)5RV%o
A_A^A]A\]
A_A^A]_]
#VJA)
`.rdata
t$4;}`r
f9<Bu
CBlockingTaskExec::SetDetails
mnldsop
RegQueryInfoKeyW
RegCloseKey
&,.-&(111000///7774446655-
NtShutdownSystem
&*)))((
SxUTCFileTimeToString
0'T E

PE Information

Image Base Entry Point Reported Checksum Actual Checksum Minimum OS Version PDB Path Compile Time Import Hash Icon Icon Exact Hash Icon Similarity Hash Icon DHash
0x140000000 0x00020320 0x000478be 0x000478be 10.0 rstrui.pdb 2045-04-14 18:33:16 a8e60315ec8f851d650c69e54ca360bc 8525027f27717745be9a752e1e751c78 7fd1e05d4f0eeddcc5b8dba858db1bea c28084c68ea6f2e0

Version Infos

CompanyName Microsoft Corporation
FileDescription Microsoftร‚ยฎ Windows System Restore
FileVersion 10.0.17763.1 (WinBuild.160101.0800)
InternalName rstrui.exe
LegalCopyright ร‚ยฉ Microsoft Corporation. All rights reserved.
OriginalFilename rstrui.exe
ProductName Microsoftร‚ยฎ Windowsร‚ยฎ Operating System
ProductVersion 10.0.17763.1
Translation 0x0409 0x04b0

Sections

Name RAW Address Virtual Address Virtual Size Size of Raw Data Characteristics Entropy
.text 0x00000400 0x00001000 0x0001fe0c 0x00020000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.27
.rdata 0x00020400 0x00021000 0x000060f4 0x00006200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.21
.data 0x00026600 0x00028000 0x00000838 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.47
.pdata 0x00026800 0x00029000 0x00000fd8 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.30
.rsrc 0x00027800 0x0002a000 0x0001a0f0 0x0001a200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7.37
.reloc 0x00041a00 0x00045000 0x0000005c 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 1.19

Name Offset Size Language Sub-language Entropy File type
MUI 0x00044010 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US 2.62 None
RT_BITMAP 0x0002a8f8 0x00000e1e LANG_ENGLISH SUBLANG_ENGLISH_US 6.04 None
RT_BITMAP 0x0002b718 0x00003746 LANG_ENGLISH SUBLANG_ENGLISH_US 6.58 None
RT_ICON 0x0002f210 0x00000668 LANG_ENGLISH SUBLANG_ENGLISH_US 3.64 None
RT_ICON 0x0002f878 0x000002e8 LANG_ENGLISH SUBLANG_ENGLISH_US 3.71 None
RT_ICON 0x0002fb60 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US 3.37 None
RT_ICON 0x0002fc88 0x00000ea8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.62 None
RT_ICON 0x00030b30 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.86 None
RT_ICON 0x000313d8 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US 4.38 None
RT_ICON 0x00031940 0x0000eb7c LANG_ENGLISH SUBLANG_ENGLISH_US 7.98 None
RT_ICON 0x000404c0 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.26 None
RT_ICON 0x00042a68 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.19 None
RT_ICON 0x00043b10 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 5.57 None
RT_GROUP_ICON 0x00043f78 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US 2.90 None
RT_VERSION 0x0002ee60 0x000003b0 LANG_ENGLISH SUBLANG_ENGLISH_US 3.43 None
RT_MANIFEST 0x0002a3b0 0x00000542 LANG_ENGLISH SUBLANG_ENGLISH_US 4.90 None

Imports

Name Address
TraceMessage 0x140021238
GetTraceLoggerHandle 0x140021240
GetTraceEnableLevel 0x140021248
GetTraceEnableFlags 0x140021250
RegisterTraceGuidsW 0x140021258
UnregisterTraceGuids 0x140021260
ConvertStringSecurityDescriptorToSecurityDescriptorW 0x140021268
RegOpenKeyExW 0x140021270
InitiateShutdownW 0x140021278
OpenSCManagerW 0x140021280
OpenServiceW 0x140021288
ControlService 0x140021290
OpenProcessToken 0x140021298
RegCloseKey 0x1400212a0
CloseServiceHandle 0x1400212a8
CreateWellKnownSid 0x1400212b0
CheckTokenMembership 0x1400212b8
LookupPrivilegeValueW 0x1400212c0
AdjustTokenPrivileges 0x1400212c8
GetTokenInformation 0x1400212d0
EnableTraceEx2 0x1400212d8
StartTraceW 0x1400212e0
ControlTraceW 0x1400212e8
RegQueryInfoKeyW 0x1400212f0
InitializeSecurityDescriptor 0x1400212f8
SetEntriesInAclW 0x140021300
SetSecurityDescriptorOwner 0x140021308
SetSecurityDescriptorGroup 0x140021310
SetSecurityDescriptorDacl 0x140021318
DuplicateToken 0x140021320
DuplicateTokenEx 0x140021328
RegisterEventSourceW 0x140021330
ReportEventW 0x140021338
DeregisterEventSource 0x140021340
RegQueryValueExW 0x140021348
Name Address
CreateProcessW 0x140021420
LeaveCriticalSection 0x140021428
EnterCriticalSection 0x140021430
InitializeCriticalSectionAndSpinCount 0x140021438
GetTimeZoneInformation 0x140021440
SetThreadPreferredUILanguages 0x140021448
OpenProcess 0x140021450
FileTimeToSystemTime 0x140021458
FileTimeToLocalFileTime 0x140021460
GetTimeFormatW 0x140021468
GetDateFormatW 0x140021470
GlobalFree 0x140021478
GetLocaleInfoW 0x140021480
GetLocaleInfoEx 0x140021488
FindVolumeClose 0x140021490
FindNextVolumeW 0x140021498
FindFirstVolumeW 0x1400214a0
CloseHandle 0x1400214a8
GetWindowsDirectoryW 0x1400214b0
GetVolumeNameForVolumeMountPointW 0x1400214b8
GetVolumePathNameW 0x1400214c0
GetVolumePathNamesForVolumeNameW 0x1400214c8
LoadLibraryExW 0x1400214d0
LocalAlloc 0x1400214d8
GetSystemDirectoryW 0x1400214e0
ExpandEnvironmentStringsW 0x1400214e8
GetVolumeInformationW 0x1400214f0
GetDriveTypeW 0x1400214f8
MoveFileExW 0x140021500
DeviceIoControl 0x140021508
FindClose 0x140021510
FindNextFileW 0x140021518
FindFirstFileW 0x140021520
FormatMessageW 0x140021528
TerminateProcess 0x140021530
UnhandledExceptionFilter 0x140021538
GetTickCount 0x140021540
GetCurrentThreadId 0x140021548
GetCurrentProcessId 0x140021550
GetCurrentProcess 0x140021558
RegisterApplicationRestart 0x140021560
QueryPerformanceCounter 0x140021568
GetModuleHandleW 0x140021570
SetUnhandledExceptionFilter 0x140021578
GetStartupInfoW 0x140021580
Sleep 0x140021588
InitializeCriticalSection 0x140021590
CreateFileW 0x140021598
SetEvent 0x1400215a0
WaitForSingleObject 0x1400215a8
CreateThread 0x1400215b0
GetSystemTimeAsFileTime 0x1400215b8
FreeLibrary 0x1400215c0
LocalFree 0x1400215c8
GetLastError 0x1400215d0
CreateDirectoryW 0x1400215d8
DeleteFileW 0x1400215e0
GetFileAttributesW 0x1400215e8
GetCommandLineW 0x1400215f0
EncodePointer 0x1400215f8
DecodePointer 0x140021600
GetProcAddress 0x140021608
DeleteCriticalSection 0x140021610
SetLastError 0x140021618
HeapSetInformation 0x140021620
SetErrorMode 0x140021628
CreateEventW 0x140021630
GetUserDefaultLCID 0x140021638
Name Address
SetBkMode 0x1400213b0
DeleteDC 0x1400213b8
GdiFlush 0x1400213c0
SelectObject 0x1400213c8
SetLayout 0x1400213d0
CreateCompatibleDC 0x1400213d8
ExtTextOutW 0x1400213e0
SetBkColor 0x1400213e8
CreateDIBSection 0x1400213f0
GetDeviceCaps 0x1400213f8
CreateFontIndirectW 0x140021400
SetTextColor 0x140021408
DeleteObject 0x140021410
Name Address
UpdateWindow 0x1400216a8
GetDlgItem 0x1400216b0
SystemParametersInfoW 0x1400216b8
LoadIconW 0x1400216c0
SetForegroundWindow 0x1400216c8
CreateDialogParamW 0x1400216d0
ShowWindow 0x1400216d8
DestroyWindow 0x1400216e0
DialogBoxParamW 0x1400216e8
GetSystemMetrics 0x1400216f0
RegisterWindowMessageW 0x1400216f8
GetDC 0x140021700
ReleaseDC 0x140021708
SetWindowLongPtrW 0x140021710
PostMessageW 0x140021718
MsgWaitForMultipleObjectsEx 0x140021720
DispatchMessageW 0x140021728
PeekMessageW 0x140021730
SetWindowPos 0x140021738
CopyRect 0x140021740
GetDesktopWindow 0x140021748
MessageBoxW 0x140021750
EnumWindows 0x140021758
SendMessageTimeoutW 0x140021760
GetWindowTextW 0x140021768
GetWindowThreadProcessId 0x140021770
EndPaint 0x140021778
MapWindowPoints 0x140021780
GetWindowRect 0x140021788
BeginPaint 0x140021790
GetAncestor 0x140021798
GetClassNameW 0x1400217a0
LoadStringW 0x1400217a8
GetParent 0x1400217b0
GetWindowLongW 0x1400217b8
GetSysColor 0x1400217c0
InflateRect 0x1400217c8
OffsetRect 0x1400217d0
DrawFrameControl 0x1400217d8
SendMessageW 0x1400217e0
CallWindowProcW 0x1400217e8
IsWindow 0x1400217f0
GetWindowLongPtrW 0x1400217f8
SetClassLongPtrW 0x140021800
SetWindowTextW 0x140021808
SetWindowLongW 0x140021810
GetSysColorBrush 0x140021818
EndDialog 0x140021820
SetFocus 0x140021828
GetKeyState 0x140021830
EnableWindow 0x140021838
GetClientRect 0x140021840
Name Address
wcschr 0x140021850
_wcsnicmp 0x140021858
_wcsicmp 0x140021860
__C_specific_handler 0x140021868
free 0x140021870
malloc 0x140021878
_callnewh 0x140021880
_XcptFilter 0x140021888
_amsg_exit 0x140021890
__getmainargs 0x140021898
__set_app_type 0x1400218a0
exit 0x1400218a8
_exit 0x1400218b0
_cexit 0x1400218b8
_ismbblead 0x1400218c0
__setusermatherr 0x1400218c8
_initterm 0x1400218d0
_acmdln 0x1400218d8
_fmode 0x1400218e0
_commode 0x1400218e8
_lock 0x1400218f0
_unlock 0x1400218f8
__dllonexit 0x140021900
_onexit 0x140021908
?terminate@@YAXXZ 0x140021910
memset 0x140021918
memmove 0x140021920
memcpy 0x140021928
memcmp 0x140021930
iswspace 0x140021938
_vscwprintf 0x140021940
_vsnwprintf 0x140021948
strchr 0x140021950
wcsstr 0x140021958
wcscmp 0x140021960
Name Address
SHGetStockIconInfo 0x140021648
CommandLineToArgvW 0x140021650
ShellExecuteExW 0x140021658
Name Address
CoInitializeSecurity 0x1400219f0
CoTaskMemRealloc 0x1400219f8
CoTaskMemAlloc 0x140021a00
CoUninitialize 0x140021a08
CoCreateInstance 0x140021a10
CoInitializeEx 0x140021a18
CoTaskMemFree 0x140021a20
CLSIDFromString 0x140021a28
Name Address
PropertySheetW 0x140021358
DestroyPropertySheetPage 0x140021360
InitCommonControlsEx 0x140021370
ImageList_Create 0x140021378
ImageList_Add 0x140021380
ImageList_AddMasked 0x140021388
CreatePropertySheetPageW 0x140021390
ImageList_Destroy 0x1400213a0
Name Address
SrFreeRpPropArray 0x140021690
SrFreeRestoreStatus 0x140021698


Reports: JSON

Usage


Processing ( 370.37 seconds )

  • 327.975 ProcessMemory
  • 23.482 CAPE
  • 18.9 BehaviorAnalysis
  • 0.015 AnalysisInfo
  • 0.001 Debug

Signatures ( 0.40 seconds )

  • 0.045 masquerade_process_name
  • 0.043 antiav_detectreg
  • 0.041 ransomware_files
  • 0.031 ransomware_extensions
  • 0.023 antiav_detectfile
  • 0.022 infostealer_ftp
  • 0.018 territorial_disputes_sigs
  • 0.015 infostealer_bitcoin
  • 0.013 infostealer_im
  • 0.012 antianalysis_detectfile
  • 0.012 antidebug_devices
  • 0.01 antivm_vbox_files
  • 0.009 antianalysis_detectreg
  • 0.009 infostealer_mail
  • 0.006 poullight_files
  • 0.005 cryptbot_files
  • 0.004 antivm_vbox_keys
  • 0.004 echelon_files
  • 0.003 antivm_vmware_files
  • 0.003 antivm_vmware_keys
  • 0.003 geodo_banking_trojan
  • 0.003 ursnif_behavior
  • 0.002 antivm_generic_diskreg
  • 0.002 antivm_parallels_keys
  • 0.002 antivm_vbox_devices
  • 0.002 antivm_xen_keys
  • 0.002 ketrican_regkeys
  • 0.002 darkcomet_regkeys
  • 0.002 driver_filtermanager
  • 0.002 qulab_files
  • 0.002 revil_mutexes
  • 0.002 modirat_behavior
  • 0.002 rat_pcclient
  • 0.002 recon_fingerprint
  • 0.001 accesses_netlogon_regkey
  • 0.001 accesses_sysvol
  • 0.001 antiemu_windefend
  • 0.001 antisandbox_fortinet_files
  • 0.001 antisandbox_sunbelt_files
  • 0.001 antisandbox_threattrack_files
  • 0.001 antivm_bochs_keys
  • 0.001 antivm_hyperv_keys
  • 0.001 antivm_vpc_files
  • 0.001 antivm_vpc_keys
  • 0.001 banker_cridex
  • 0.001 bitcoin_opencl
  • 0.001 browser_security
  • 0.001 bypass_firewall
  • 0.001 file_credential_store_access
  • 0.001 file_credential_store_write
  • 0.001 registry_credential_store_access
  • 0.001 disables_backups
  • 0.001 disables_browser_warn
  • 0.001 disables_power_options
  • 0.001 downloader_cabby
  • 0.001 apocalypse_stealer_file_behavior
  • 0.001 arkei_files
  • 0.001 azorult_mutexes
  • 0.001 network_tor_service
  • 0.001 packer_armadillo_regkey
  • 0.001 persistence_ads
  • 0.001 persistence_shim_database
  • 0.001 medusalocker_regkeys
  • 0.001 dcrat_files
  • 0.001 limerat_regkeys
  • 0.001 obliquerat_files
  • 0.001 warzonerat_files
  • 0.001 warzonerat_regkeys
  • 0.001 remcos_files
  • 0.001 remcos_regkeys
  • 0.001 spicyhotpot_behavior
  • 0.001 sniffer_winpcap
  • 0.001 targeted_flame
  • 0.001 lokibot_mutexes
  • 0.001 web_shell_files
  • 0.001 suspicious_command_tools
  • 0.001 uses_windows_utilities

Reporting ( 12.20 seconds )

  • 11.266 CAPASummary
  • 0.934 JsonDump

Signatures

Checks available memory
Dynamic (imported) function loading detected
DynamicLoader: ntdll.dll/RtlWow64GetCurrentMachine
DynamicLoader: ntdll.dll/RtlWow64IsWowGuestMachineSupported
DynamicLoader: ntdll.dll/RtlWow64GetCurrentMachine
DynamicLoader: ntdll.dll/RtlWow64IsWowGuestMachineSupported
DynamicLoader: ntdll.dll/RtlWow64GetCurrentMachine
DynamicLoader: ntdll.dll/RtlWow64IsWowGuestMachineSupported
DynamicLoader: ntdll.dll/RtlWow64GetCurrentMachine
DynamicLoader: ntdll.dll/RtlWow64IsWowGuestMachineSupported
DynamicLoader: ntdll.dll/RtlWow64GetCurrentMachine
DynamicLoader: ntdll.dll/RtlWow64IsWowGuestMachineSupported
Queries the keyboard layout
The PE file contains a PDB path
pdbpath: rstrui.pdb
SetUnhandledExceptionFilter detected (possible anti-debug)
At least one process apparently crashed during execution
Possible date expiration check, exits too soon after checking local time
process: dllhost.exe, PID 4792
A process attempted to delay the analysis task.
note: wermgr.exe tried to sleep 420.0 seconds, actually delayed analysis time by 0.0 seconds
Resumed a thread in another process
thread_resumed: Process svchost.exe with process ID 808 resumed a thread in another process with the process ID 4100
thread_resumed: Process mousocoreworker.exe with process ID 2512 resumed a thread in another process with the process ID 2512
thread_resumed: Process svchost.exe with process ID 1348 resumed a thread in another process with the process ID 7048
thread_resumed: Process taskhostw.exe with process ID 3940 resumed a thread in another process with the process ID 3940
thread_resumed: Process mousocoreworker.exe with process ID 5688 resumed a thread in another process with the process ID 5688
thread_resumed: Process taskhostw.exe with process ID 6276 resumed a thread in another process with the process ID 6276
thread_resumed: Process mousocoreworker.exe with process ID 6108 resumed a thread in another process with the process ID 6108
thread_resumed: Process mousocoreworker.exe with process ID 3292 resumed a thread in another process with the process ID 3292
thread_resumed: Process mousocoreworker.exe with process ID 1012 resumed a thread in another process with the process ID 1012
thread_resumed: Process taskhostw.exe with process ID 3700 resumed a thread in another process with the process ID 3700
Terminates another process
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
process: svchost.exe
The binary likely contains encrypted or compressed data
section: {'name': '.rsrc', 'raw_address': '0x00027800', 'virtual_address': '0x0002a000', 'virtual_size': '0x0001a0f0', 'size_of_data': '0x0001a200', 'characteristics': 'IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ', 'characteristics_raw': '0x40000040', 'entropy': '7.37'}
Tries to unhook or modify Windows functions monitored by CAPE
unhook: function_name: ShellExecuteExW, type: removal
Checks the system manufacturer, likely for anti-virtualization
Process: FileCoAuth.exe (728)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (7048)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6904)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (2272)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (6396)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (5652)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: FileCoAuth.exe (3968)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: FileCoAuth.exe (5020)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (292)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: wermgr.exe (836)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: FileCoAuth.exe (1488)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Process: FileCoAuth.exe (6532)
registry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
Yara detections observed in process dumps, payloads or dropped files
Hit: PID 6388 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 880 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 832 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 59 }']'
Hit: PID 1380 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 6536 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 1056 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 6532 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 728 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 4788 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 1488 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 5020 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 3968 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Hit: PID 3760 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 58 }']'
Anomalous binary characteristics
anomaly: Entrypoint of binary is located outside of any mapped sections
Binary compilation timestomping detected
anomaly: Compilation timestamp is in the future
Enumerates physical drives
physical drive access: \??\PHYSICALDRIVE0
physical drive access: \??\PhysicalDrive0
Attempts to interact with an Alternate Data Stream (ADS)
file: C:\$Extend\$Quota:$Q:$INDEX_ALLOCATION
file: \??\Volume{01989354-0000-0000-0000-100000000000}\$Extend\$Quota:$Q:$INDEX_ALLOCATION
file: \??\Volume{01989354-0000-0000-0000-300300000000}\$Extend\$Quota:$Q:$INDEX_ALLOCATION
file: \??\Volume{01989354-0000-0000-0000-10e03f000000}\$Extend\$Quota:$Q:$INDEX_ALLOCATION

Screenshots

No screenshots available.

Hosts

No hosts contacted.

DNS

No domains contacted.

Summary

C:\Windows\System32\kernel.appcore.dll
\Device\CNG
C:\Windows\System32\ntmarta.dll
C:
\??\MountPointManager
\??\Volume{01989354-0000-0000-0000-100000000000}
\??\Volume{01989354-0000-0000-0000-100000000000}\
\??\Volume{01989354-0000-0000-0000-300300000000}
\??\Volume{01989354-0000-0000-0000-300300000000}\
\??\Volume{01989354-0000-0000-0000-10e03f000000}
\??\Volume{01989354-0000-0000-0000-10e03f000000}\
C:\Users\Packager\AppData\Local\Temp\rstrui.exe
C:\Windows\System32\en-US\ntdll.dll.mui
C:\Windows\System32\en-US\KERNELBASE.dll.mui
C:\Windows\
C:\Windows\ServiceProfiles\
\??\PhysicalDrive0
C:\Windows\System32\wbem\WmiPrvSE.exe
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe
C:\Windows\System32\mousocoreworker.exe
C:\Windows\System32\SecurityHealthHost.exe
C:\Windows\System32\smartscreen.exe
C:\Windows\SysWOW64\smartscreen.exe
C:\Windows\System32\CompPkgSrv.exe
C:\Windows\SysWOW64\CompPkgSrv.exe
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\domgmt*.etl
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\domgmt.20241122_223814_928.etl
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\domgmt.20241125_171546_223.etl
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\domgmt.20250614_045229_461.etl
C:\Windows\System32\en-US\domgmt.dll.mui
C:\Windows\System32\policymanager.dll
C:\Windows\System32\msvcp110_win.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\SystemResources\USER32.dll.mun
C:\Windows\System32\en-US\USER32.dll.mui
C:\Windows\System32\rpcss.dll
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\System32\wtsapi32.dll
C:\Windows\System32\winsta.dll
C:\Windows\System32\tzres.dll
C:\Windows\System32\en-US\tzres.dll.mui
C:\Windows\System32\wmiclnt.dll
\??\WMIDataDevice
C:\Windows\System32\samcli.dll
C:\Windows\System32\srvcli.dll
C:\Windows\System32\netutils.dll
C:\Windows\System32\logoncli.dll
C:\Windows\System32\schedcli.dll
C:\Windows\System32\wkscli.dll
C:\Windows\System32\dsrole.dll
\??\PIPE\lsarpc
\??\PIPE\srvsvc
C:\Windows\System32\OemInfo.Ini
C:\Windows\System32\OemLogo.Bmp
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\CRYPTSP.dll
C:\Windows\System32\cryptsp.dll
C:\Windows\System32\windows.storage.dll
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\Wldp.dll
C:\Windows\System32\wldp.dll
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0456.6388.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth*.aodl
C:\Windows\sysnative\en-US\tzres.dll.mui
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0456.6388.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth*.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1741.6072.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1816.5756.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1845.6048.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1854.2316.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1913.1964.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2028.1120.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2052.6960.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2125.4072.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2133.5764.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth*.odlsent
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth*.odlgz
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0457.728.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0457.728.1.odl
C:\Program Files (x86)
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json
C:\Windows\System32\UsoSelfhost.dll
C:\ProgramData
C:\ProgramData\USOShared
C:\ProgramData\USOShared\Logs
C:\ProgramData\USOShared\Logs\System
C:\ProgramData\USOShared\Logs\System\*
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.2d772dc0-c22a-4b40-938b-a68ba55e5af7.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.5d67a91a-ef75-4681-85c0-1e0b11915cde.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.860111d2-db04-47d4-b948-9ba07339cd38.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.27243f9b-c04b-4c86-a877-7b4ce2e5550c.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.6b1b6c5f-fb27-4f57-bb8f-ef34e6dbccc4.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.81d3c983-0642-42ac-b0d8-521d06f7fcb7.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.be8815e4-ea09-4783-a4de-ed7022efe7f8.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.d7e9bd53-543d-4caa-933f-3e4957d4c5f7.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.af42ac84-6afc-41d1-bc6e-306f9e52bc09.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.a76d6bcb-aa07-44fc-bc30-b7ad467c4924.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.23c61ab0-7c6c-4a75-a81a-c30bf8181075.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.da029ca8-f908-4cdb-9fea-6b7e18db9e14.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.52080c9a-8af3-4f79-b739-04bdaeb427e7.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.a9bafe91-b938-4292-b720-785a1ad6e6a2.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.2c7b07f2-21ce-4c49-90aa-97c3ebe03baa.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.ad0941b5-0cfc-4426-80ff-dcb792c6a09d.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.f7b3ca06-8c06-461c-a090-8a6f98111f9f.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.7bce75d9-39ab-4514-b1b2-2aa3dc37c97c.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.90125552-a64e-4d22-828b-6d82b81ddec8.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.09b9c2cc-3dba-49b8-8443-69ca1cfad81d.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.d813753c-a9a9-4213-ba06-e477c1e3b4b6.1.etl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.da2ccfa2-332d-474c-859f-2513f30f04a1.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.ac1a6ba2-0620-4bdf-be7e-cefd1950af6c.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.7f8cb04b-8731-4025-96df-70b03a7760a5.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.b5b65b76-91b7-4af6-83a3-c80061ab650d.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.dfc8fe7b-a502-44f3-a7c8-596952c959d1.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.847e58c5-e854-40e2-bfad-c3ecf0b0780e.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.e73b7513-df84-44a1-9108-607624955d4e.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.2216c7b1-0c98-4356-a00e-e2c34a0e5f7d.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.8f156d09-bdf1-4e78-9519-85eec85a024f.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.f4b9f9cd-b8a8-4f6b-b2ee-a512e8509795.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.2bcf30b7-64a2-458e-849f-ca162447f3f3.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.1cb4e393-5110-45a0-99e2-22e56e8fbd24.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.015cd1c3-8179-429a-bb1b-0b3f610f3c2c.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.ceff177b-9cf0-4361-83f8-b0806ee1aaa0.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.be4f2a2b-0152-48f7-984d-36882f5bc4ec.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.6352827e-9e4e-46a2-91d5-6ad25222a92c.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.7a72a457-f93e-47f6-b0a1-248fbb5b954f.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.01d7708a-5097-4126-afe9-a645178b1fe2.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.543e8032-12c6-429e-9e9a-08cf41a43ed9.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.f920561d-8586-49f0-847c-821bbc7b1617.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.ca66d67f-1473-4d65-acd8-277482eaa9f7.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.a1808283-d076-4213-891e-77c10d23455f.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.e1d7ed34-ac5c-4efd-b07a-e2877546b62a.1.etl
C:\ProgramData\USOPrivate
C:\ProgramData\USOPrivate\UpdateStore
C:\ProgramData\USOPrivate\UpdateStore\store.db
C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
C:\ProgramData\USOPrivate\UpdateStore\store.db-wal
C:\Windows\System32\upshared.dll
C:\Windows\System32\winhttp.dll
C:\Windows\System32\dpapi.dll
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work
C:\Windows\System32\compattelrunner.exe
C:\Windows\System32\en-US\compattelrunner.exe.mui
C:\Windows\System32\en\compattelrunner.exe.mui
C:\Windows\System32\sppc.dll
C:\Windows\System32\en-US\sppc.dll.mui
C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
C:\Windows\System32\msdrm.dll
C:\Windows\System32\en-US\msdrm.dll.mui
C:\Windows\System32\ApplockerCsp.dll
C:\Windows\System32\en-US\ApplockerCsp.dll.mui
C:\Windows\System32\appidsvc.dll
C:\Windows\System32\en-US\appidsvc.dll.mui
C:\Windows\System32\invagent.dll
C:\Windows\System32\en-US\invagent.dll.mui
C:\Windows\System32\en\invagent.dll.mui
C:\Windows\System32\Startupscan.dll
C:\Windows\System32\en-US\Startupscan.dll.mui
C:\Windows\System32\AppHostRegistrationVerifier.exe
C:\Windows\System32\en-US\AppHostRegistrationVerifier.exe.mui
C:\Windows\System32\Windows.Storage.ApplicationData.dll
C:\Windows\System32\en-US\Windows.Storage.ApplicationData.dll.mui
C:\Windows\System32\dssvc.dll
C:\Windows\System32\en-US\dssvc.dll.mui
C:\Windows\System32\acproxy.dll
C:\Windows\System32\en-US\acproxy.dll.mui
C:\Windows\System32\BthUdTask.exe
C:\Windows\System32\en-US\BthUdTask.exe.mui
C:\Windows\System32\bisrv.dll
C:\Windows\System32\en-US\bisrv.dll.mui
C:\Windows\System32\ngctasks.dll
C:\Windows\System32\en-US\ngctasks.dll.mui
C:\Windows\System32\dimsjob.dll
C:\Windows\System32\en-US\dimsjob.dll.mui
C:\Windows\System32\pstask.dll
C:\Windows\System32\en-US\pstask.dll.mui
C:\Windows\System32\ClipUp.exe
C:\Windows\System32\wsqmcons.exe
C:\Windows\System32\en-US\wsqmcons.exe.mui
C:\Windows\System32\usbceip.dll
C:\Windows\System32\en-US\usbceip.dll.mui
C:\Windows\System32\discan.dll
C:\Windows\System32\en-US\discan.dll.mui
C:\Windows\System32\defragsvc.dll
C:\Windows\System32\en-US\defragsvc.dll.mui
C:\Windows\System32\DeviceSetupManager.dll
C:\Windows\System32\en-US\DeviceSetupManager.dll.mui
C:\Windows\System32\mitigationclient.dll
C:\Windows\System32\en-US\mitigationclient.dll.mui
C:\Windows\System32\sdiagschd.dll
C:\Windows\System32\en-US\sdiagschd.dll.mui
C:\Windows\System32\cleanmgr.exe
C:\Windows\System32\en-US\cleanmgr.exe.mui
C:\Windows\System32\dfdts.dll
C:\Windows\System32\en-US\DFDTS.dll.mui
C:\Windows\System32\mitigationconfiguration.dll
C:\Windows\System32\en-US\mitigationconfiguration.dll.mui
C:\Windows\System32\dmclient.exe
C:\Windows\System32\srm.dll
C:\Windows\System32\en-US\srm.dll.mui
C:\Windows\System32\fhtask.dll
C:\Windows\System32\en-US\fhtask.dll.mui
C:\Windows\System32\fcon.dll
C:\Windows\System32\en-US\fcon.dll.mui
C:\Windows\System32\wosc.dll
C:\Windows\System32\en-US\wosc.dll.mui
C:\Windows\System32\CoreGlobConfig.Dll
C:\Windows\System32\LanguageComponentsInstaller.Dll
C:\Windows\System32\en-US\LanguageComponentsInstaller.Dll.mui
C:\Windows\System32\LanguageOverlayServer.dll
C:\Windows\System32\en-US\LanguageOverlayServer.dll.mui
C:\Windows\System32\TempSignedLicenseExchangeTask.dll
C:\Windows\System32\LocationNotificationWindows.exe
C:\Windows\System32\en-US\LocationNotificationWindows.exe.mui
C:\Windows\System32\WindowsActionDialog.exe
C:\Windows\System32\en-US\WindowsActionDialog.exe.mui
C:\Windows\System32\winsatapi.dll
C:\Windows\System32\en-US\winsatapi.dll.mui
C:\Windows\System32\mapstoasttask.dll
C:\Windows\System32\en-US\mapstoasttask.dll.mui
C:\Windows\System32\mapsupdatetask.dll
C:\Windows\System32\en-US\mapsupdatetask.dll.mui
C:\Windows\System32\MemoryDiagnostic.dll
C:\Windows\System32\en-US\MemoryDiagnostic.dll.mui
C:\Windows\System32\MbaeParserTask.exe
C:\Windows\System32\en-US\MbaeParserTask.exe.mui
C:\Windows\System32\lpremove.exe
C:\Windows\System32\en-US\lpremove.exe.mui
C:\Windows\System32\PlaySndSrv.Dll
C:\Windows\System32\en-US\PlaySndSrv.Dll.mui
C:\Windows\System32\nettrace.dll
C:\Windows\System32\en-US\nettrace.dll.mui
C:\Windows\System32\wifitask.exe
C:\Windows\System32\en-US\wifitask.exe.mui
C:\Windows\System32\cscui.dll
C:\Windows\System32\en-US\cscui.dll.mui
C:\Windows\System32\TpmTasks.dll
C:\Windows\System32\en-US\TpmTasks.dll.mui
C:\Windows\System32\pnppolicy.dll
C:\Windows\System32\en-US\pnppolicy.dll.mui
C:\Windows\System32\pnpui.dll
C:\Windows\System32\en-US\pnpui.dll.mui
C:\Windows\System32\sppnp.dll
C:\Windows\System32\en-US\sppnp.dll.mui
C:\Windows\System32\energytask.dll
C:\Windows\System32\en-US\energytask.dll.mui
C:\Windows\System32\rasmbmgr.dll
C:\Windows\System32\en-US\rasmbmgr.dll.mui
C:\Windows\System32\ReAgentTask.dll
C:\Windows\System32\en-US\ReAgentTask.dll.mui
C:\Windows\System32\regidle.dll
C:\Windows\System32\en-US\regidle.dll.mui
C:\Windows\System32\msra.exe
C:\Windows\System32\en-US\msra.exe.mui
C:\Windows\System32\WpcMon.exe
C:\Windows\System32\en-US\wpcmon.exe.mui
C:\Windows\System32\WpcRefreshTask.dll
C:\Windows\System32\en-US\WpcRefreshTask.dll.mui
C:\Windows\System32\srchadmin.dll
C:\Windows\System32\en-US\srchadmin.dll.mui
C:\Windows\System32\SpaceAgent.exe
C:\Windows\System32\en-US\SpaceAgent.exe.mui
C:\Windows\System32\spaceman.exe
C:\Windows\System32\Windows.StateRepositoryClient.dll
C:\Windows\System32\en-US\Windows.StateRepositoryClient.dll.mui
C:\Windows\System32\en\Windows.StateRepositoryClient.dll.mui
C:\Windows\System32\TieringEngineService.exe
C:\Windows\System32\en-US\TieringEngineService.exe.mui
C:\Windows\System32\ClipRenew.exe
C:\Windows\System32\sysmain.dll
C:\Windows\System32\en-US\sysmain.dll.mui
C:\Windows\System32\srrstr.dll
C:\Windows\System32\en-US\srrstr.dll.mui
C:\Windows\System32\wdc.dll
C:\Windows\System32\en-US\wdc.dll.mui
C:\Windows\System32\MsCtfMonitor.dll
C:\Windows\System32\en-US\MsCtfMonitor.dll.mui
C:\Windows\System32\TimeSyncTask.dll
C:\Windows\System32\en-US\TimeSyncTask.dll.mui
C:\Windows\System32\w32time.dll
C:\Windows\System32\en-US\w32time.dll.mui
C:\Windows\System32\tzsyncres.dll
C:\Windows\System32\en-US\tzsyncres.dll.mui
C:\Windows\System32\usosvc.dll
C:\Windows\System32\en-US\usosvc.dll.mui
C:\Windows\System32\upnphost.dll
C:\Windows\System32\en-US\upnphost.dll.mui
C:\Windows\System32\UsbTask.dll
C:\Windows\System32\en-US\usbtask.dll.mui
C:\Windows\System32\profsvc.dll
C:\Windows\System32\en-US\profsvc.DLL.mui
C:\Windows\System32\WaasMedicSvc.dll
C:\Windows\System32\en-US\WaasMedicSvc.dll.mui
C:\Windows\System32\dps.dll
C:\Windows\System32\en-US\dps.dll.mui
C:\Windows\System32\wer.dll
C:\Windows\System32\en-US\wer.dll.mui
C:\Windows\System32\BFE.DLL
C:\Windows\System32\en-US\bfe.dll.mui
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\en-US\wmpnscfg.exe.mui
C:\Windows\System32\mscms.dll
C:\Windows\System32\en-US\mscms.dll.mui
C:\Windows\System32\wininet.dll
C:\Windows\System32\en-US\wininet.dll.mui
C:\Windows\System32\WofTasks.dll
C:\Windows\System32\en-US\WofTasks.dll.mui
C:\Windows\System32\WorkFoldersShell.dll
C:\Windows\System32\en-US\WorkFoldersShell.dll.mui
C:\Windows\System32\dsregcmd.exe
C:\Windows\System32\en-US\dsregcmd.exe.mui
C:\Windows\System32\dsregtask.dll
C:\Windows\System32\en-US\dsregtask.dll.mui
C:\Windows\System32\wer.dll.3.Manifest
C:\ProgramData\Microsoft\Windows\WER
C:\ProgramData\Microsoft\Windows\WER\ReportQueue
C:\ProgramData\Microsoft\Windows\WER\Temp
C:\ProgramData\Microsoft\Windows\WER\Temp\e9dad848-595e-4873-8503-27708eb9acd0
C:\ProgramData\Microsoft\Windows\WER\ReportArchive
C:\ProgramData\Microsoft\Windows\WER\Temp\d7184265-7711-49b8-87fb-03acb7edb57c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\*_*_*_*_*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78
C:\Windows\System32\usermgrcli.dll
C:\ProgramData\Microsoft\Windows\WER\Temp\bcab8f00-2c72-4578-b340-66ce01e488e0
C:\ProgramData\Microsoft\Windows\WER\Temp\7373f3af-d0c7-4990-aa8f-41d622d73f0b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\dcf2b97e-e240-43fe-addd-7c838c048f6d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\885cc5a3-492b-40cd-9255-60f9e44c6e54
C:\Windows\System32\umpdc.dll
C:\Windows\System32\rmclient.dll
C:\Windows\System32\netapi32.dll
C:\Windows\System32\dsreg.dll
C:\Windows\System32\profapi.dll
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Windows\System32\xmllite.dll
C:\Windows\System32\drivers\*.mrk
\Device\RasAcd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\4f5189ed-034a-4496-9f64-4ab2cb87f998
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326
C:\ProgramData\Microsoft\Windows\WER\Temp\60eacdec-4a0d-4e09-b02f-f75aeda2426c
C:\ProgramData\Microsoft\Windows\WER\Temp\732eeae2-97d6-4744-8f74-7d5e378095e1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\997a8a1c-3386-4396-90a9-163cd30bb6b2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\688b1d74-b47e-4f68-9da3-b00a830843b0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\a1b6b1e7-670e-4871-9bf1-e2577352a6ea
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\WER13F2.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089
C:\ProgramData\Microsoft\Windows\WER\Temp\2c94d629-7abd-4dc8-83ed-e1e56b510dea
C:\ProgramData\Microsoft\Windows\WER\Temp\ac20fe12-09b7-4b41-a658-5cb8e904d474
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f612892d-6d61-4852-9862-b52c3e2e7f52
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\93855010-d61c-4d55-a6ed-128459932be0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\3c034a96-2f7b-44f8-b614-62a0fa25e2a0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\WER152A.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4
C:\ProgramData\Microsoft\Windows\WER\Temp\dd22590b-7899-4f62-9b82-07a5cf15e2c2
C:\ProgramData\Microsoft\Windows\WER\Temp\235f2a0a-15c5-4c45-b3dc-21612f2584a5
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c0b95e9f-15ed-4439-8993-21b392d1ca09
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2510edd0-2c63-4e30-95b1-4b97ffe18409
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\392781c6-b0f5-460e-9316-83c988553135
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\WERF3D2.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543
C:\ProgramData\Microsoft\Windows\WER\Temp\da0020af-e41e-461b-875d-90634dfe9516
C:\ProgramData\Microsoft\Windows\WER\Temp\877aa596-b750-411c-9e08-78a946752b87
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1171b8ee-a241-4643-b570-267cd725f12a
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e5acc319-6fca-425e-9a3b-0613963d13b4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\81c20a53-9f40-4e0b-a319-785405b3be70
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\WERF588.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8
C:\ProgramData\Microsoft\Windows\WER\Temp\7e950d2d-b54b-49b9-87b9-5d07161c824f
C:\ProgramData\Microsoft\Windows\WER\Temp\d85a2e73-02aa-4c5b-aaf5-0f002b914279
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a83c8ac8-6a7b-4b06-8f77-eace6bbe5b45
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e6be0fcf-6a93-4be5-81f3-1f68f585fe2f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\2ac2dbcd-06b7-4a3c-bba7-010c8d31c328
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0
C:\ProgramData\Microsoft\Windows\WER\Temp\744297a1-9b9c-42b5-a397-75986c3d3d67
C:\ProgramData\Microsoft\Windows\WER\Temp\207fb8dd-f91c-4b9a-b385-1b59d659e12e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2ceecc04-b692-4f64-af22-419b8233284e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\30c025d2-512b-4f22-bee9-e35f975485c4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\03167b2b-037d-416a-9fdf-74881d455322
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d
C:\ProgramData\Microsoft\Windows\WER\Temp\9717e5e9-17cb-47c3-9401-f57b49039ba9
C:\ProgramData\Microsoft\Windows\WER\Temp\1cee0e0b-8423-4e02-872c-d5954305f7d6
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b8c31b68-1462-4150-9fcb-3832bfd042b7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9d5621c3-a026-44da-86be-88f542fa7aa0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\4cabafdf-dcbd-4cd5-abbd-5b27ed6b0910
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba
C:\ProgramData\Microsoft\Windows\WER\Temp\a1aa6ab4-9d6e-416e-830a-ed9d7e3e1d8d
C:\ProgramData\Microsoft\Windows\WER\Temp\ea6962ca-df51-4f49-bafe-4534c5cf2a99
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\14b734bd-586d-4178-ac83-3c048497e905
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\dfbb56ce-faef-4893-9fcb-05460cc90327
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\abb1891f-94f7-4aee-888d-c40c685428d0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978
C:\ProgramData\Microsoft\Windows\WER\Temp\7adc2317-bfa9-4235-8a7b-541ed924a922
C:\ProgramData\Microsoft\Windows\WER\Temp\243c4484-37d5-4b7a-b3a5-416e6b48d29f
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\eacb53fe-158b-4e5f-9e3a-8adbab486655
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\86ef8182-1c60-4db4-8c51-397c3f6d5af8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\d272d083-9e73-4aa6-bdc3-0754b421aed1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec
C:\ProgramData\Microsoft\Windows\WER\Temp\c3dd8148-4487-4698-9a9d-717d31c00c43
C:\ProgramData\Microsoft\Windows\WER\Temp\7b0e2d40-76dc-4065-8376-959632f26dd9
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a995868d-257e-4a00-b867-05acb73b93fa
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\34604d03-fc65-4ce5-93b1-e959fb29e4a0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\4d37ffad-27bb-47bf-8369-667793bfb95f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3
C:\ProgramData\Microsoft\Windows\WER\Temp\8b78e135-63c3-4eba-9758-8870717830e4
C:\ProgramData\Microsoft\Windows\WER\Temp\0ef019eb-d35a-4651-a817-7214366ff8f0
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c0754d41-a8ea-4a5e-a084-a33b0f41b9a7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ad4db298-f247-409f-8f1e-33f72ac5f9e9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\a5db7820-61f5-4126-8101-fd5c5f32dd67
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270
C:\ProgramData\Microsoft\Windows\WER\Temp\9e261ed7-2425-4021-871a-5b65785b7d95
C:\ProgramData\Microsoft\Windows\WER\Temp\fd72fbde-5cee-43b3-99bf-5180684a9fb9
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\341b70a0-df59-4aad-8a07-ce067feaa9c0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\6d612b14-bc92-4e06-9d04-e019ef0a8aa1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\b8c5b657-34e1-4e24-9d85-ad6a1a620fc1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa
C:\ProgramData\Microsoft\Windows\WER\Temp\2c0c012c-6d98-4a00-be62-9ec6986b559b
C:\ProgramData\Microsoft\Windows\WER\Temp\4887d440-d357-43f5-aa4e-430e21e85305
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\3ff6920d-7514-48cf-a33d-cdb1cb13e20b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ceee58d5-610c-4422-9d36-81e5da912bf3
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4CDC.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4CDC.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\0d1accb0-6e6f-453d-b34d-0e2b9e96b4be
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\Report.wer.tmp
\\?\C:\ProgramData\Microsoft\Windows\WER\ReportQueue
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\*
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\*_*_*_*_*
C:\ProgramData\Microsoft\Windows\WER\Temp\*
C:\ProgramData\Microsoft\Windows\WER\Temp\d1649359-d6cb-4221-80bc-8c4438c59194
C:\ProgramData\Microsoft\Windows\WER\Temp\c795f028-b4c9-4604-98ce-5ab2daf82ca8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\3aba0db1-22e4-4003-85f1-1aa5763b1a35
C:\ProgramData\Microsoft\Windows\WER\Temp\a32092d0-db7c-4e44-a9ce-620596fb1259
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c35aebb4-9c46-4bf8-85dc-a7eb83e9c1dc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\88bd7f04-f215-4e50-9885-93d2617eb60f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\9d2ba87d-85d7-4704-9483-4bd3f106ea3d
C:\ProgramData\Microsoft\Windows\WER\Temp\a476cb2b-cf3c-42a9-9b60-a0e21c031dca
C:\ProgramData\Microsoft\Windows\WER\Temp\1109e652-6a34-48e2-b60f-afa4a574a1e7
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\bfe3459b-d76c-4fce-927b-076e68ae6491
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3681c203-ca9a-4f37-b0a7-67dbcc43830f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\eed5e41d-9894-4168-b9fd-3caabc8b2168
C:\ProgramData\Microsoft\Windows\WER\Temp\acdc6bc8-4c00-4640-b08b-90c0af9a4eee
C:\ProgramData\Microsoft\Windows\WER\Temp\456353a8-9a84-4a6f-a44b-d13777b91a3c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a4f8b77e-cd23-4bc1-b61b-314b0a5ebb4e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5f7101ec-0114-446f-a0f2-bc9341877ada
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\25cc640e-3665-438e-831e-217900b7af72
C:\ProgramData\Microsoft\Windows\WER\Temp\e38416f2-f530-4b74-a451-a551518e45fd
C:\ProgramData\Microsoft\Windows\WER\Temp\9509242e-08b4-4726-9918-87b9675aca86
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\bba8f2a9-d64a-4398-825a-d01e272ed89b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a76eb39b-988a-4368-a2a0-bf9a3dab637c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\21bf49d8-4434-4dd3-afc9-ea6df2c31cc5
C:\ProgramData\Microsoft\Windows\WER\Temp\a23cd13c-e15b-400d-be9c-f8b845b1f08b
C:\ProgramData\Microsoft\Windows\WER\Temp\c366f261-df1d-4486-b8a2-7a43bf9f1015
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\482f071a-de63-454b-8617-8096242b68b7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9958b409-aefd-445d-9988-c7325afc823e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\8fcbb065-67bc-4b4f-89b5-91b2c3b4174b
C:\ProgramData\Microsoft\Windows\WER\Temp\71493e72-e899-43d3-952d-7509a4400148
C:\ProgramData\Microsoft\Windows\WER\Temp\a3191c95-8d90-4679-b420-7787e6eff736
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\489b29b1-f257-499b-80a8-46cd7d32d7d0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9137a1f2-3b5a-4385-ad59-45bf95131169
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\380fa896-ff4b-43d6-bcef-e8f78ca66f63
C:\ProgramData\Microsoft\Windows\WER\Temp\809c6590-861c-4b66-b735-fcc92a230ff7
C:\ProgramData\Microsoft\Windows\WER\Temp\2aa98408-2215-4f45-9a3d-d1fcb7abc72e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4998cede-9b58-4125-9311-0e426c5e95d4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c36885ac-e7ce-42f6-915b-0a141cbc06f0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\4002b8a3-6127-44a7-a116-20bb1fca8221
C:\ProgramData\Microsoft\Windows\WER\Temp\fe2e5aba-3bb4-4a8d-b7fc-8d558abf0f36
C:\ProgramData\Microsoft\Windows\WER\Temp\d4dffd9e-23e5-45b3-a9a1-2377fbc38e4c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\abfe7a04-5cdf-4e9a-93be-b79b6c1ed474
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\393d0f26-b431-4a64-9642-f5e0f8f859b3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\feaa6e25-ffc0-4d0b-a0af-536e8577d7b4
C:\ProgramData\Microsoft\Windows\WER\Temp\925cd51f-21c4-4d4d-9a74-d0fe9c561ae6
C:\ProgramData\Microsoft\Windows\WER\Temp\e9688031-acb2-4fe9-b378-43ee86b2db23
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e4ada5fe-e302-499c-aab3-ba430c6a62fd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\d5abb1a2-2da8-4093-9a51-60feb8e2e5ab
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\15106b8d-c9da-4c13-8b97-2f2f6865d185
C:\ProgramData\Microsoft\Windows\WER\Temp\6a82b907-d1f2-4632-aa8d-a5dc87d5519b
C:\ProgramData\Microsoft\Windows\WER\Temp\b2b78f6d-cee6-42dc-8bab-5392d4cf888b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ba83b77e-bb13-4509-b70a-0cf337f24deb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c55f7b96-d39f-460e-92e4-e8b1741d2bbb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\af798486-fc7d-4b75-938f-f2fda90aaf0b
C:\ProgramData\Microsoft\Windows\WER\Temp\8c502474-0826-4043-97e0-70a28a76f861
C:\ProgramData\Microsoft\Windows\WER\Temp\c10dc88f-f5eb-4090-b903-e13cc0e8d8c1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\feea0f68-cc0c-4d2e-9899-998fa9941b30
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5127c870-4ee5-4838-8ef7-4a0e2421102c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\13c82a8c-f9c1-4d2a-ba35-8830b6d6c269
C:\ProgramData\Microsoft\Windows\WER\Temp\6c0e5c82-d18e-4a38-8692-d97b79df91b2
C:\ProgramData\Microsoft\Windows\WER\Temp\08fa8cd1-50bf-4d17-a171-77f39106e0da
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\20950766-e0ef-4ce6-8269-8696dee0cb84
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0454fcc6-a758-4d25-a297-78881e659b38
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\153a733d-6802-4b5b-af13-06bc76ac38ea
C:\ProgramData\Microsoft\Windows\WER\Temp\c2c4d011-a198-4429-b731-e111ef55c941
C:\ProgramData\Microsoft\Windows\WER\Temp\ed34ccf5-c9a0-48aa-a2fc-813317158444
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4f1a5248-9622-40e3-b52e-f80c6342df00
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c3dc3942-5585-41cf-98d9-c3e670670adf
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\3acb737f-90af-4856-879d-570e52477713
C:\ProgramData\Microsoft\Windows\WER\Temp\e7256d10-3b11-4c3d-8efa-49245951dcae
C:\ProgramData\Microsoft\Windows\WER\Temp\1fc846f0-a3f8-4b80-b5c5-196b9cee9031
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ede10e6a-18c1-4554-8fbb-054752d38f4a
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3a4a13eb-d5a3-4093-9621-65f6cc7b2e6e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\6529d6bc-d28d-4c03-840b-4e3dc00e3e4e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0
C:\ProgramData\Microsoft\Windows\WER\Temp\eef83a82-fdb0-43eb-9c30-9ebdcf8fccf7
C:\ProgramData\Microsoft\Windows\WER\Temp\c8c7eefa-b514-4c1e-b406-11df3ecab1c4
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f4752bee-12f7-4a7d-aefa-03a2cee268de
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\18fb7aea-e44b-4aff-bcad-10971e70ba43
C:\ProgramData\Microsoft\Windows\WER\Temp\WER500.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER500.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\fae5ec24-26ff-467d-af46-03bc422c1596
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\*
C:\ProgramData\Microsoft\Windows\WER\Temp\3ef95f0c-b8cf-47d4-8f1d-d5a198a0afb0
C:\ProgramData\Microsoft\Windows\WER\Temp\934f2673-d94a-432e-9eb9-a8ecdc67bfd2
C:\ProgramData\Microsoft\Windows\WER\Temp\40a72e08-811f-486b-801b-392c301ac78b
C:\ProgramData\Microsoft\Windows\WER\Temp\115ef9dc-3402-46ff-89f1-ce54f6e02373
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\5668b7dc-6715-4d84-b5da-a840abb1928c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\cfcbef2f-650b-4b04-b4ec-28cb2ae0a9f2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\963cbfa0-c56d-4473-bf88-ae0265f95997
C:\ProgramData\Microsoft\Windows\WER\Temp\19a24906-5116-45e6-ab81-380bd4a902b8
C:\ProgramData\Microsoft\Windows\WER\Temp\9a03da4a-ad9e-40ee-9b31-038f3ca83444
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\6620124e-f846-4a6f-b788-16d9d0f3a366
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\4d2683df-76cb-4d74-98c9-42a71bba9cba
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\4f2657fe-2909-4549-93e8-060b6639a1ef
C:\ProgramData\Microsoft\Windows\WER\Temp\00df8a7d-8b1c-4d5f-93c6-1402ec05920d
C:\ProgramData\Microsoft\Windows\WER\Temp\c4463b56-480e-4166-9a0c-44165305824a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\00b26dcd-200a-47cf-9c98-f78864465e38
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5fbfb57e-9e58-4c61-958b-19ce584922a2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\c320ebea-0a93-44b1-9632-c6af8328ae7b
C:\ProgramData\Microsoft\Windows\WER\Temp\7c3aded6-04b5-478e-acef-56c0c1637537
C:\ProgramData\Microsoft\Windows\WER\Temp\d16afb34-a2a9-40ba-a6f9-f27e86e734e2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\97c34b45-e6d6-4574-bf34-3e5565ad10d7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\45bc4b37-26cf-4f20-a258-15c90fbd3d1b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\2a19b57c-d221-4e72-b816-e3f76d12cc4c
C:\ProgramData\Microsoft\Windows\WER\Temp\a2c2a70c-36d5-4bf5-b06a-d7279ab112cf
C:\ProgramData\Microsoft\Windows\WER\Temp\e5e1791f-6938-421a-a71b-b7117d0d6f31
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1a8256a8-2ba1-4655-aa62-ff5f254b937f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\02ab0ca9-0540-4f6a-b5a7-2b0201ec6f15
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\94b75ba5-068e-4966-a3a9-99fe23d2b88e
C:\ProgramData\Microsoft\Windows\WER\Temp\e84d5ea0-8b81-4019-9e43-a01327b361cd
C:\ProgramData\Microsoft\Windows\WER\Temp\f84a3199-d4b2-4016-b6e3-79c88d1e4438
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\68778cc0-88e2-44d3-840e-fc041c15dddc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\588ec950-3620-48a7-a3ba-bc0358c5c5ce
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\ec22efd5-71ab-4312-8858-65fa12eea828
C:\ProgramData\Microsoft\Windows\WER\Temp\b508a165-f971-456a-84cd-e8ca5c0a5e5a
C:\ProgramData\Microsoft\Windows\WER\Temp\a4ed0f59-3400-473d-93b6-b9d7dc6c6914
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ae3f8d46-0c55-4548-9210-17a6f8cb6a5c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\104dd1df-fb39-4f81-bb3f-4227f0e5a6d2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\fb52a3a5-7397-4fac-b9e2-acd73ea743b0
C:\ProgramData\Microsoft\Windows\WER\Temp\10440f15-d565-4dcb-a45a-bb7545314f8f
C:\ProgramData\Microsoft\Windows\WER\Temp\aa013658-db4d-4d68-894e-2a2079b18590
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9552ca9a-7a5d-4ad6-b8f7-2a0f3041dd86
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\92c247bd-7ca6-421c-be0a-b66ed975ef9f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\1abe32ae-2379-47ed-af80-c8b3b33b21a0
C:\ProgramData\Microsoft\Windows\WER\Temp\5df93b2a-2817-4bf5-b549-0ac85d90173d
C:\ProgramData\Microsoft\Windows\WER\Temp\70403755-dfa7-4c1c-b33c-b367259c9ead
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9e74d0c0-a082-48bd-b767-e93f6c938d5e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\78b713d5-724c-44f4-8999-d3bd8e4112b6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\ab0ece60-e8df-4484-b04d-e425ce232b9f
C:\ProgramData\Microsoft\Windows\WER\Temp\313d1355-7a48-4167-b3be-15fee5e71268
C:\ProgramData\Microsoft\Windows\WER\Temp\c5267c5b-d47e-451f-a803-6aad9153e8e8
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e83a2954-70f3-40f8-a01b-66eb907b9302
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\12bc41f8-2904-42ed-a33f-caf220f51445
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\06670560-5ce1-465c-aef8-224d31fedb3a
C:\ProgramData\Microsoft\Windows\WER\Temp\e5f88077-6012-468e-91ca-dda020b295ed
C:\ProgramData\Microsoft\Windows\WER\Temp\b4381a1e-ad83-436a-a526-fad3611692f7
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\6c55adad-5d9c-4d28-8a18-b74627e5a8fc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\4166bb8a-5805-4557-8f54-1d3a4c6c431e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\00ff5250-7bca-47cb-8540-8eebad853bc7
C:\ProgramData\Microsoft\Windows\WER\Temp\e0f30c60-d4d1-47ba-9d42-ed7bc101dfbc
C:\ProgramData\Microsoft\Windows\WER\Temp\88dddb4d-6690-4249-b551-2b7a03977459
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e6d0fd6f-d0f7-4b21-b594-542e07f22d62
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9b6ad1a5-6a88-4849-aa2f-4d7f6de66a86
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\02397b65-b769-4f00-999d-aaa180ef2c93
C:\ProgramData\Microsoft\Windows\WER\Temp\900612ea-4447-47b6-a5c2-f3a9d57442cf
C:\ProgramData\Microsoft\Windows\WER\Temp\68396835-e8a8-47a0-8d39-78544f9d81e1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\92686bbc-7732-4f98-b921-b027f73a3dca
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\90be3da8-9df9-4f4b-aad3-c2517cf2b327
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\76bb6f1b-9adf-444d-be17-e5ba25954cf2
C:\ProgramData\Microsoft\Windows\WER\Temp\49c686e7-7a39-4b7f-bb9b-7d90dc16b0af
C:\ProgramData\Microsoft\Windows\WER\Temp\856798a2-6d86-41ac-be75-02a3b2377cf2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\73f22d1a-a6d6-4b81-84aa-cc41560fcf68
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a8af954f-51d6-411d-a2b8-a91c4c0d0cc1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\abb053a2-1802-43fa-bd13-6b8b0aa5c23d
C:\ProgramData\Microsoft\Windows\WER\Temp\a67ab964-e261-47b9-b02f-166fa8dbd567
C:\ProgramData\Microsoft\Windows\WER\Temp\b835510d-3b8e-4d2c-9f39-50365f18d09a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\bc02ac5f-e410-498c-a68c-751b313c1243
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9a48e11f-8331-41a9-9629-f630a67fb9db
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\c5ae1d82-dfc5-4395-8bd9-3387060f30c7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52
C:\ProgramData\Microsoft\Windows\WER\Temp\a83556e7-326d-44cc-8738-9f67899f16c7
C:\ProgramData\Microsoft\Windows\WER\Temp\ecaa692f-e352-4dc6-9ad0-abd725c565fa
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\071a1509-2367-410f-9268-3222c6450751
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\887ce1fb-1855-4f4a-bed7-f3dbc45f3a6f
C:\ProgramData\Microsoft\Windows\WER\Temp\WER440D.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER440D.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\d5aae025-4700-4521-838d-8ac93f9f2ed4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\Report.wer.tmp
C:\Windows\System32\wbem\en-US\cimwin32.dll.mui
C:\
C:\Windows\System32
C:\Windows\System32\
C:\Windows
C:\$Extend\$Quota:$Q:$INDEX_ALLOCATION
\??\GLOBALROOT\Device\HarddiskVolume1
\??\Volume{01989354-0000-0000-0000-100000000000}\$Extend\$Quota:$Q:$INDEX_ALLOCATION
\??\GLOBALROOT\Device\HarddiskVolume2
\??\Volume{01989354-0000-0000-0000-300300000000}\$Extend\$Quota:$Q:$INDEX_ALLOCATION
\??\GLOBALROOT\Device\HarddiskVolume3
\??\Volume{01989354-0000-0000-0000-10e03f000000}\$Extend\$Quota:$Q:$INDEX_ALLOCATION
\??\scsi#disk&ven_qemu&prod_harddisk#4&35424867&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
\??\PHYSICALDRIVE0
C:\Windows\System32\clusapi.dll
C:\Windows\System32\dnsapi.dll
C:\Windows\System32\IPHLPAPI.DLL
\??\Nsi
\??\PIPE\wkssvc
C:\Windows\System32\iologmsg.dll
C:\Windows\System32\en-US\iologmsg.dll.mui
C:\Windows\System32\slc.dll
C:\Windows\System32\en-US\slc.dll.mui
C:\Windows\System32\en-US\storagewmi.dll.mui
C:\Windows\System32\Syncreg.dll
C:\Windows\System32\en-US\Syncreg.dll.mui
C:\Windows\System32\tapi3.dll
C:\Windows\System32\en-US\tapi3.dll.mui
C:\Windows\System32\vdsutil.dll
C:\Windows\System32\en-US\vdsutil.dll.mui
C:\Windows\System32\vsstrace.dll
C:\Windows\System32\en-US\vsstrace.dll.mui
C:\Windows\System32\wbem\en-US\wmiutils.dll.mui
C:\Windows\System32\msasn1.dll
C:\Windows\System32\dhcpcsvc6.DLL
C:\Windows\System32\dhcpcsvc.dll
\DEVICE\NETBT_TCPIP_{CC6EEB36-5AE2-46BE-81A9-5F0B62ECF81F}
\DEVICE\NETBT_TCPIP_{27E3D6D8-A922-11EF-90C1-806E6F6E6963}
\Device\Afd\Endpoint
C:\Windows\System32\perfc009.dat
C:\Windows\System32\drivers\Synth3dVsc.sys
C:\Windows\System32\SystemResources\Synth3dVsc.sys.mun
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WorkflowServiceHostPerformanceCounters.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\WorkflowServiceHostPerformanceCounters.dll.mui
C:\Windows\System32\lsm.dll
C:\Windows\System32\en-US\lsm.dll.mui
C:\Windows\System32\HvHostSvc.dll
C:\Windows\System32\en-US\HvHostSvc.dll.mui
C:\Windows\System32\drivers\pacer.sys
C:\Windows\System32\drivers\en-US\pacer.sys.mui
C:\Windows\System32\FWPUCLNT.DLL
C:\Windows\System32\en-US\fwpuclnt.dll.mui
C:\Windows\System32\pnrpsvc.dll
C:\Windows\System32\en-US\pnrpsvc.dll.mui
C:\Windows\System32\azroles.dll
C:\Windows\System32\en-US\AzRoles.dll.mui
C:\Windows\System32\FXSRESM.dll
C:\Windows\System32\en-US\fxsresm.dll.mui
C:\Windows\System32\drivers\afd.sys
C:\Windows\System32\drivers\en-US\afd.sys.mui
C:\Windows\System32\drivers\fvevol.sys
C:\Windows\System32\drivers\en-US\fvevol.sys.mui
C:\Windows\System32\drivers\spaceport.sys
C:\Windows\System32\drivers\en-US\spaceport.sys.mui
C:\Windows\System32\drivers\refs.sys
C:\Windows\System32\drivers\en-US\refs.sys.mui
C:\Windows\System32\mispace.dll
C:\Windows\System32\en-US\mispace.dll.mui
C:\Windows\System32\drivers\vmbkmcl.sys
C:\Windows\System32\drivers\en-US\vmbkmcl.sys.mui
C:\Windows\System32\drivers\en\vmbkmcl.sys.mui
C:\Windows\System32\drivers\smbdirect.sys
C:\Windows\System32\drivers\en-US\smbdirect.sys.mui
C:\Windows\System32\cscsvc.dll
C:\Windows\System32\en-US\cscsvc.dll.mui
C:\Windows\System32\iphlpsvc.dll
C:\Windows\System32\en-US\iphlpsvc.dll.mui
C:\Windows\System32\drivers\dmvsc.sys
C:\Windows\System32\drivers\en-US\dmvsc.sys.mui
C:\Windows\System32\bthserv.dll
C:\Windows\System32\en-US\bthserv.dll.mui
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelPerformanceCounters.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\ServiceModelPerformanceCounters.dll.mui
C:\Windows\System32\umpoext.dll
C:\Windows\System32\en-US\umpoext.dll.mui
C:\Windows\System32\drivers\tcpip.sys
C:\Windows\System32\drivers\en-US\tcpip.sys.mui
C:\Windows\System32\drivers\winnat.sys
C:\Windows\System32\drivers\en-US\winnat.sys.mui
C:\Windows\System32\drivers\http.sys
C:\Windows\System32\drivers\en-US\http.sys.mui
C:\Windows\System32\WindowsPowerShell\v1.0\PSEvents.dll
C:\Windows\System32\WindowsPowerShell\v1.0\en-US\PSEvents.dll.mui
C:\Windows\System32\drivers\dxgmms2.sys
C:\Windows\System32\drivers\en-US\dxgmms2.sys.mui
C:\Windows\System32\drivers\en\dxgmms2.sys.mui
C:\Windows\System32\wmp.dll
C:\Windows\System32\rdpcorets.dll
C:\Windows\System32\en-US\rdpcorets.dll.mui
C:\Windows\System32\drivers\srv2.sys
C:\Windows\System32\drivers\en-US\srv2.sys.mui
C:\Windows\System32\netlogon.dll
C:\Windows\System32\en-US\NetLogon.dll.mui
C:\Windows\System32\drivers\USBXHCI.SYS
C:\Windows\System32\drivers\en-US\usbxhci.sys.mui
C:\Windows\System32\drt.dll
C:\Windows\System32\en-US\drt.dll.mui
C:\Windows\System32\drivers\ndis.sys
C:\Windows\System32\drivers\en-US\ndis.sys.mui
C:\Windows\System32\advapi32res.dll
C:\Windows\System32\en-US\advapi32res.dll.mui
C:\Windows\System32\drivers\mrxsmb.sys
C:\Windows\System32\drivers\en-US\mrxsmb.sys.mui
C:\Windows\System32\appvetwclientres.dll
C:\Windows\System32\wevtsvc.dll
C:\Windows\System32\en-US\wevtsvc.dll.mui
C:\Windows\System32\PeerDistSvc.dll
C:\Windows\System32\en-US\PeerDistSvc.dll.mui
C:\Windows\System32\WsmRes.dll
C:\Windows\System32\en-US\WsmRes.dll.mui
C:\Windows\System32\vid.dll
C:\Windows\System32\en-US\vid.dll.mui
C:\Windows\System32\mprddm.dll
C:\Windows\System32\en-US\mprddm.dll.mui
C:\Windows\System32\perfh009.dat
\??\UNC\WORKGROUP*\MAILSLOT\NET\NETLOGON
C:\Windows\System32\en-US\ACTIVEDS.dll.mui
C:\Windows\System32\powrprof.dll
C:\Windows\System32\en-US\powrprof.dll.mui
C:\Windows\System32\dusmapi.dll
C:\ProgramData\Microsoft\Windows\OneSettings
C:\ProgramData\Microsoft\Windows\OneSettings\config.json
C:\Windows\System32\OneSettingsClient.dll
C:\Windows\System32\netmsg.dll
C:\Windows\System32\en-US\netmsg.dll.mui
C:\Windows\System32\en\netmsg.dll.mui
C:\Windows\System32\twinapi.appcore.dll
C:\Windows\ImmersiveControlPanel\images\logo.png
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.a017b90e-4c4f-45cf-bd78-d9d533e8c38e.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.8be52fb9-77fb-43e3-8170-c81b7e6c8c98.1.etl
C:\ProgramData\Microsoft\Windows\WER\Temp\ccfb3c9d-1c9c-4a28-ab97-79a0485044ff
C:\ProgramData\Microsoft\Windows\WER\Temp\1f13a608-7d8a-464e-ba02-64e43a7a6c49
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\801e5901-2be1-49ec-9834-6b23c98b2c99
C:\ProgramData\Microsoft\Windows\WER\Temp\6a81e6f6-0ae6-41c6-8181-4b84ad985c26
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\702efa4c-c21c-4ab4-b326-7469a2bb811e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\41630a53-7227-4ec6-b5d3-f6b03813474b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\2fbe7cc5-85ab-4e22-9cee-7fa7d975c4d0
C:\ProgramData\Microsoft\Windows\WER\Temp\ee1cc283-b16b-461a-8c8d-cfa8ec26c043
C:\ProgramData\Microsoft\Windows\WER\Temp\ba5e6688-89d7-4b2e-a5f5-aa8a5454898a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\d6730272-4a2c-4160-82a9-57394758b34e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2d529f19-a8a3-4fd2-8878-f5a5f45919ff
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\0610a571-d86b-4550-a78e-ac9293f760b8
C:\ProgramData\Microsoft\Windows\WER\Temp\f2d1ec52-e12d-4474-ac5d-41c79e574d8a
C:\ProgramData\Microsoft\Windows\WER\Temp\77101115-4e74-4b0f-be4d-63a8e1c6949d
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\696b5530-03fe-4fb3-a725-7deff06c745d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\61d3a684-310f-4028-a956-492d221d8714
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\a73021db-ca2e-4737-bff3-9889278770b8
C:\ProgramData\Microsoft\Windows\WER\Temp\6112fa7c-3523-4096-8efb-f1aa5d9d9745
C:\ProgramData\Microsoft\Windows\WER\Temp\039b23a3-fd6d-43f4-9b56-32eb18e7cc1e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\3e9209d3-a3dc-4bcb-acf3-476b4c416648
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\7f8aea12-7bbe-4690-befa-4ccc57291e50
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\11d0ab8c-ce29-4e0e-b6d8-410f31a0eb5a
C:\ProgramData\Microsoft\Windows\WER\Temp\b1729862-d020-4287-af5f-417571024b10
C:\ProgramData\Microsoft\Windows\WER\Temp\c0ccc400-f473-4c5c-b0a6-5f9b13b27a68
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\57fb1c2e-6610-4cb8-bd49-e5e529fe472d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5723a1b9-8cb5-4bd9-b3bc-09478d5deaf2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\b71a69c4-2747-4c99-b53a-c1d501f67c3b
C:\ProgramData\Microsoft\Windows\WER\Temp\6a5e8be1-66ae-41fb-ada5-44da40aec583
C:\ProgramData\Microsoft\Windows\WER\Temp\74c88e35-f7df-485d-8d85-c7ad5aeb9277
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\13d80c02-6012-40b0-a1f0-b60d703891ea
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b33c36a7-996c-4dd3-ae97-2dedcf6dfd67
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\bf7c0df4-630c-4fb0-97b6-f0cf144da83f
C:\ProgramData\Microsoft\Windows\WER\Temp\d9719e75-afc6-4458-a318-72b18086910c
C:\ProgramData\Microsoft\Windows\WER\Temp\cc5ce0a6-7f7b-4441-88f9-29c9f4e5e6d3
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\916dafcb-8bf7-4b13-a49c-697d1ecdbeae
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\be03eb2f-edd0-4453-b40b-1fe897feba3b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\14565abe-0d71-4959-8cc4-7ef0d149cb7c
C:\ProgramData\Microsoft\Windows\WER\Temp\ae6e9fdd-ea7d-4f77-925f-724ac624b8ad
C:\ProgramData\Microsoft\Windows\WER\Temp\ffeeffcd-2de4-4325-8d7e-646541e8f8e1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\669c5daa-e5ed-4683-84d1-47562067e6b5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\582c1958-1fa6-4349-b54e-f1fda0808284
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\3e78605d-6afa-48c4-806c-2fb6c52eaddc
C:\ProgramData\Microsoft\Windows\WER\Temp\526acef5-7c3e-4de5-8404-6ac1cd8b078b
C:\ProgramData\Microsoft\Windows\WER\Temp\bb617e56-cf2a-4de1-955b-0994bca216e2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\dde2c523-7506-43e8-b7e7-79af2e03d5ef
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c0c100be-018d-4f21-bf53-951d67ce4407
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\11d7c32f-f060-414b-b748-6c42e3ab9900
C:\ProgramData\Microsoft\Windows\WER\Temp\11e57c72-f68f-485d-a3a4-c1f990818124
C:\ProgramData\Microsoft\Windows\WER\Temp\ce0b5008-abe5-4bca-bf5b-611cef498e44
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2841f96f-a7b1-45b2-95c0-00e89581e29c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\afa8dbe2-dcfb-4310-9fd8-7dfe04f21c1d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\b4ec8fa0-8a60-482a-bd16-f20805c50cce
C:\ProgramData\Microsoft\Windows\WER\Temp\83f069d5-7714-4d49-aa05-1546e2c72933
C:\ProgramData\Microsoft\Windows\WER\Temp\31db8716-a02d-434c-ac6e-722a21ef604a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\7623b5a0-e450-4bd1-8439-67c11e2a4f1f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0804766a-3a1f-4e32-9eab-59e032bb8251
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\48afbf20-e1c4-424d-ba12-b362117266eb
C:\ProgramData\Microsoft\Windows\WER\Temp\95cd10f5-5bae-42f3-ae64-e5841d335609
C:\ProgramData\Microsoft\Windows\WER\Temp\be0bab84-badc-4a28-a7cc-10085c44edea
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\59de9b60-6883-45d8-b9d4-9aa424af0bbc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a6264ac5-2f99-4bed-8e6c-117835819343
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\3d2a8a0e-10f1-4db9-b859-be174d8102af
C:\ProgramData\Microsoft\Windows\WER\Temp\945ced0e-701c-4ad2-911a-c5b41c911433
C:\ProgramData\Microsoft\Windows\WER\Temp\e275839a-f943-4cb2-8d9e-731f0c95e8be
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\7037dd82-16d7-42d1-8776-b015fdfe35dc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b50d4620-542a-4cb3-abcc-edc89bcce0b2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\1da90243-107b-411d-a5a7-0652d6f3a530
C:\ProgramData\Microsoft\Windows\WER\Temp\85ad08e8-12b7-49a9-8e25-831ee68c6ae3
C:\ProgramData\Microsoft\Windows\WER\Temp\fcc3bb69-3f54-4ef4-8ae3-30c8e16a4535
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\5bcc0442-c45e-45a1-bec1-f36c14dd6d0b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c11ce6df-0b02-43cd-86ea-f3a537fd5efa
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\627a7504-a8ea-4ef3-bba0-fe15a2746db7
C:\ProgramData\Microsoft\Windows\WER\Temp\0ca69f76-49d0-4d88-8057-4bb6503aa33d
C:\ProgramData\Microsoft\Windows\WER\Temp\c878fe47-ba54-4a7b-9533-8895ea7c4e69
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0c96bdb0-c843-4999-a908-160232b1ef6e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\772c9362-d47e-45d8-83f6-e00625a090c9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\d7f0fd10-3240-443d-b95a-b038a858d0fd
C:\ProgramData\Microsoft\Windows\WER\Temp\30d345d1-b216-48d8-9015-2bf562b38085
C:\ProgramData\Microsoft\Windows\WER\Temp\a52aae0e-b20a-457e-9fc1-f34a79341289
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\dfc2352e-fd8b-4eb5-b6e1-e23cf58b1946
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\6c7a976c-d778-4846-8e6a-801647a47865
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\ae6ed8ce-ed45-4993-924d-c30e017fcc32
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e
C:\ProgramData\Microsoft\Windows\WER\Temp\0a74fb24-58cc-4bd2-8ea3-49b79c6caaa0
C:\ProgramData\Microsoft\Windows\WER\Temp\c3de6bd1-1df2-4656-9d85-5c4adce93551
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c85a8dcd-3b9a-42c8-99f2-898101333e7b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\07b8128c-9fba-442a-af03-c770d6d9956f
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D50.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D50.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\8e27d8a1-f654-4fab-99da-9321040c5950
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\*
C:\ProgramData\Microsoft\Windows\WER\Temp\64b8ebf5-f962-42ba-a10d-d0b081177e24
C:\ProgramData\Microsoft\Windows\WER\Temp\6e52899c-b4c9-4189-be39-f53b40d0f0dd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\b3e4fb18-beba-424b-a7a5-33273e8fcde4
C:\ProgramData\Microsoft\Windows\WER\Temp\20c27c22-16fd-4e07-81bd-30850eec2f69
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ab80d052-4307-41db-9a68-a670dc3a6cef
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b0c06e23-409a-4a88-b8b5-57bc5850dd1a
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\44a17d0c-1fef-41ac-a36e-e2b980ba75b5
C:\ProgramData\Microsoft\Windows\WER\Temp\683ddc7f-9312-4740-b4f9-096b74e2d884
C:\ProgramData\Microsoft\Windows\WER\Temp\b1c788f3-e649-4e10-9be2-fae41facfa5a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0e5845c0-4d43-4e4e-bfa4-f10d2ab7f456
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\aaf94ea3-15e4-4833-b0a6-e7f2c3c567c0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\eeb33c2f-aae0-4638-b18d-6482703d6312
C:\ProgramData\Microsoft\Windows\WER\Temp\25b28594-6e3f-4f43-ac00-63190de4de4d
C:\ProgramData\Microsoft\Windows\WER\Temp\ec4ec7d8-d4fb-45b3-ba43-17ce8ede5eed
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\14f03354-7268-468c-a0cc-6ed74382bf5e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b96a1761-508d-4a77-9002-6a28069635e4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\880354f7-9728-4ac1-8449-777fda15bb9e
C:\ProgramData\Microsoft\Windows\WER\Temp\0816d6a6-0803-425d-a3a7-04bee067620e
C:\ProgramData\Microsoft\Windows\WER\Temp\311fad48-6200-4562-b20e-5aee4e40fc3f
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\3faa4a86-3e8d-4e5d-8f99-ad3b5f7ea749
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2f7cf03a-8aca-49a3-add5-655719ab561e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\342ea154-5d21-445b-9e5e-70396b1c5560
C:\ProgramData\Microsoft\Windows\WER\Temp\4b2424a1-11c0-4baa-952d-8515508004da
C:\ProgramData\Microsoft\Windows\WER\Temp\7a650dbe-7c60-4924-af85-98f01fe32479
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f32cd806-aaee-4d24-a33e-94ea7a10de79
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\1f5a3587-6b3e-4826-abe4-95fcde6fd2d5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\c6665ab7-85e0-42dd-9d9a-65f71227887f
C:\ProgramData\Microsoft\Windows\WER\Temp\a2b8d1f7-71d9-4b85-add8-8a4f88c94ca6
C:\ProgramData\Microsoft\Windows\WER\Temp\4f4daf35-6c9e-4488-a5ad-a8e64dd6a039
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b9690290-667e-4edf-9242-410d2b0b3366
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\f344492c-f7a5-476b-888c-220ab286aa9c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\96dea8b2-9069-4cad-a6c7-3d359a742f2a
C:\ProgramData\Microsoft\Windows\WER\Temp\1c4840ef-b62c-4f74-8b4a-62f012d68f4e
C:\ProgramData\Microsoft\Windows\WER\Temp\34129842-7be3-432d-9d2a-c3625a3c5c7e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\8f510d3c-36ed-4965-ae94-be6b65d29fd6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a6ea6c47-bb29-466b-abc8-28dc9172e702
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\aace3312-43cb-49ef-aea8-038f889b5ca6
C:\ProgramData\Microsoft\Windows\WER\Temp\84ccc7eb-b685-4d98-94e5-6c15d0ce96f9
C:\ProgramData\Microsoft\Windows\WER\Temp\013b7a3e-ced1-409e-a9f5-e59067c0f8de
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0059cd3f-def3-44ce-a852-38148f72a533
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9c6da26f-73f9-4acd-9337-84e8ad0f91ed
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\9ba96a3d-e10e-42e8-9018-659a346e1785
C:\ProgramData\Microsoft\Windows\WER\Temp\9720e6fe-c9e5-4652-90b9-a53e094e245a
C:\ProgramData\Microsoft\Windows\WER\Temp\134b942d-c827-4507-a46b-c95236381b86
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b6ff5018-f631-4bfe-9f3c-9c41c8a14283
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\86c2486b-9dbd-4b93-8d51-ca7b25399610
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\c5c4094e-63c7-4e05-80c1-d84e43736136
C:\ProgramData\Microsoft\Windows\WER\Temp\68662616-57b7-4ffc-9c44-8944156cbe86
C:\ProgramData\Microsoft\Windows\WER\Temp\844911fb-b3a2-48e0-a048-c02e16de6c3d
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ef73187f-8f00-4713-9f76-3dad052ceed9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\38f6eb69-02bd-4f54-bef7-fc03520a4a36
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\7eb51c00-84b9-40c2-8a31-81146d4b02ed
C:\ProgramData\Microsoft\Windows\WER\Temp\50968a87-3303-4253-a1bf-b6f2febb7ad3
C:\ProgramData\Microsoft\Windows\WER\Temp\de3e7429-62dc-4870-9566-f683ccff6749
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\7a6b0280-bd78-4bd0-adfe-4dba5b74e721
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\30aa32e7-7314-4e3c-9641-612716a0d7c7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\93a11392-eae9-4913-a4ff-7d8aa7569159
C:\ProgramData\Microsoft\Windows\WER\Temp\76828054-cb55-4dd6-898a-625571abfb1a
C:\ProgramData\Microsoft\Windows\WER\Temp\492efc2b-8f00-4b59-8c63-e43ce37cd79e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\236f6a63-7189-489c-aeb1-f51686b98322
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\d56631cc-435a-4c06-b6a0-fd6b547f3093
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\9ac9cf14-6e79-4039-acf1-4045b6e5acc2
C:\ProgramData\Microsoft\Windows\WER\Temp\329c6666-991b-442b-a502-afc2af57bbdb
C:\ProgramData\Microsoft\Windows\WER\Temp\bc13c39d-5bcf-4bbe-8cdb-421cbfde868e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\09fb6b89-b935-42c2-a28a-b57d59390ab0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ccca980f-c42e-4843-901b-64155fc12cf8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\be818d8e-f7e9-437b-b508-a9f15a9cd115
C:\ProgramData\Microsoft\Windows\WER\Temp\40be500a-f3da-4343-805d-0a4cd90c5582
C:\ProgramData\Microsoft\Windows\WER\Temp\de106a57-be9b-4ac9-bf98-8465339af15b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e67f88e3-b4c5-4cb2-82a2-f6f86f9fc8ca
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0ee20b94-bd2b-4506-b82f-e5178257a15b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\967a06d1-438e-4d20-bf1d-9576bf41d9c7
C:\ProgramData\Microsoft\Windows\WER\Temp\f358e887-f7ab-416f-9694-57cc189cbf37
C:\ProgramData\Microsoft\Windows\WER\Temp\e0b4af49-d816-4771-a7d2-e5e21569ae4c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f1c43bd8-654f-4395-9bc2-9ba1e29aa8c0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\20566a11-9572-4782-91a2-375faff4bc78
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\0e694e83-b862-4682-aa35-f987bbc5652d
C:\ProgramData\Microsoft\Windows\WER\Temp\470a92b8-b936-4737-bc44-4425765f9232
C:\ProgramData\Microsoft\Windows\WER\Temp\79f9516d-29b1-42f3-9e7a-b2f09d7683c0
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\cf4c5238-b077-4552-b78b-0fdb3189d6e6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ca3e3f18-3f55-417e-a6d1-f4aa22ac4f0b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\829c893c-ae1e-495f-9d8e-17e63f60be03
C:\ProgramData\Microsoft\Windows\WER\Temp\c9802fc3-76b0-4ca0-8354-1154bb31563f
C:\ProgramData\Microsoft\Windows\WER\Temp\6db69f28-fdf1-4824-839e-6e4d68792f98
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\88aa117c-ddf2-480a-badd-f1e9549b4bb3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9cf35c8a-612e-4ff1-8c4f-f71e2d1162df
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\47496ebb-3e70-489b-bf07-169f80fa4898
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287
C:\ProgramData\Microsoft\Windows\WER\Temp\f4e96b87-a696-4c8f-8071-ea27981befcc
C:\ProgramData\Microsoft\Windows\WER\Temp\31baa8ea-3c64-4f75-adf3-be5e8a076436
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\98e09bb5-0945-4bda-84d4-18e06bdb5189
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5cdd7680-d158-4749-a2df-37ced24d4353
C:\ProgramData\Microsoft\Windows\WER\Temp\WER7F26.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER7F26.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\e7197e09-bfd9-41b4-8a4d-fa3b579f1bb7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\*
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.664aae87-ec2e-42d2-88e6-929a86587279.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.eaaeb978-fc0a-4a94-838b-b2ff97d3bded.1.etl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.3968.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.3968.1.odl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.45dfe0c1-1dab-4d7f-9030-1205a3d3102b.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.5fbd21e7-5d85-463d-8627-8ff8d46309aa.1.etl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.5020.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.5020.1.odl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.ef7451d8-bb1a-4842-86f0-0faa9a634377.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.3fc10395-12ad-4849-baa4-9cde6775020f.1.etl
C:\ProgramData\Microsoft\Windows\WER\Temp\0824bd4f-cdad-4e0f-bcbf-b0d456025bac
C:\ProgramData\Microsoft\Windows\WER\Temp\b3492820-4ea8-4a16-8525-3bf2d8c2bbb0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\23c2aa24-0607-461b-9188-e737de26b8e0
C:\ProgramData\Microsoft\Windows\WER\Temp\b27a6e55-13e1-49d3-8b46-17bfdd6f3e92
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\403c9931-3cb7-4204-972e-2d6bad0a2b49
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e0d98955-c097-4943-9f11-652615dbd842
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\1acc9970-12ab-4481-9560-1b30b1eb1993
C:\ProgramData\Microsoft\Windows\WER\Temp\8be0d2cb-a401-45be-b46a-1e397486edbb
C:\ProgramData\Microsoft\Windows\WER\Temp\90f1b236-8b2d-4a58-bd54-bcf6a30c4499
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1d24c144-5e8b-436e-812a-0011141878ad
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\52f773cb-01f4-44db-bd89-53e1c8558510
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\ffb11e99-66cb-4940-b558-5d432f97a393
C:\ProgramData\Microsoft\Windows\WER\Temp\3f6842b0-1a0c-428e-b327-fedd055cb453
C:\ProgramData\Microsoft\Windows\WER\Temp\5b950499-572c-4b46-bfce-91559e2baa49
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\12f62db8-14f4-42e7-b5e5-6c80d1e778fd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3d0cd0a6-19df-435f-8e63-a523385b7b1c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\3a852232-9989-45ae-9b07-6de403b85dda
C:\ProgramData\Microsoft\Windows\WER\Temp\bcb7547d-13a6-4881-9d11-467241e39a9c
C:\ProgramData\Microsoft\Windows\WER\Temp\2dea5e17-46b5-464d-a906-5fa5461d17d5
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b88f5036-a4ae-4407-ba62-d3ea4c44c4d4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e3c2b34d-79fa-45e0-8648-26d65a46e94c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\3e3ba975-7ead-482e-843c-99680dde8024
C:\ProgramData\Microsoft\Windows\WER\Temp\12be36b9-37be-49bc-aedf-545617c3ee0b
C:\ProgramData\Microsoft\Windows\WER\Temp\3bb92578-fe8c-4c45-9d95-1900d02293ff
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\933c3231-c052-4c3c-80d8-313952228ef6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e424454b-ed10-419f-b07e-b795e597ebdb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\82a39648-1056-487a-97ce-3ca5bf8e9308
C:\ProgramData\Microsoft\Windows\WER\Temp\95b99827-11e3-4057-93a0-5100ba9d8b33
C:\ProgramData\Microsoft\Windows\WER\Temp\74981166-163c-46b6-8054-5f568c7471ad
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\5bf23806-aca9-4b45-aa96-68dceffec998
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\45e7fc5f-053d-4dac-a0c3-6f41e4fea242
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\2f2cef1f-4e2a-458e-8678-0a440a7b2394
C:\ProgramData\Microsoft\Windows\WER\Temp\7cdf6711-584f-4d2b-8d87-8364b25e8b13
C:\ProgramData\Microsoft\Windows\WER\Temp\ba23f212-7169-436a-b449-bf1ce1864e09
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\44afd72b-f62f-44be-ac16-c7a07b7cb4b0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\d491e6f4-6bef-4359-b72d-631660bb83e9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\7f2837ce-ee7b-4f86-a345-9eee7785123f
C:\ProgramData\Microsoft\Windows\WER\Temp\95c20b21-aeb2-4ae0-94e3-570de0faa818
C:\ProgramData\Microsoft\Windows\WER\Temp\ec43824c-ad6c-4ab9-8e73-6feca19cafca
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\d7fb31bd-f3c4-4517-b9b2-1c750b2b2d77
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\754eb9cc-e1b1-49c5-94ee-0d820f130bd4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\aeaa52d9-d336-47cf-863f-c0d39c61e736
C:\ProgramData\Microsoft\Windows\WER\Temp\ed6c2868-831c-4f32-b07d-b082d7fb206b
C:\ProgramData\Microsoft\Windows\WER\Temp\35e3bb79-c0b2-4757-89b6-d770b3838ff6
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0cca5ce1-d8c6-44ee-ae25-64cfd3c93888
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\64876d78-97b5-4a4a-a0e6-48680472782c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\74f29ebf-e4bc-43dc-8692-d75de11e76a5
C:\ProgramData\Microsoft\Windows\WER\Temp\e062894b-c6db-4899-bc9a-717e93d72335
C:\ProgramData\Microsoft\Windows\WER\Temp\2d4a1827-88c5-421c-b54f-979376660a73
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b054de80-51ca-463f-94fc-d1bc585bb631
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\cad824f5-16fd-43fc-aef5-99af24a93035
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\4f91cce8-68e8-4840-9f61-4dc2fab504a3
C:\ProgramData\Microsoft\Windows\WER\Temp\482e6b42-e6de-4866-a9e5-4048a062d4f7
C:\ProgramData\Microsoft\Windows\WER\Temp\b8ab82ed-d1d6-4550-94e6-6d0809296a6e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\8932b557-6604-4ff6-a724-19647317034c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\dfed3310-73db-4101-851b-b2f39538517b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\9560aa0a-aebb-4a84-ab81-4cfd85549b85
C:\ProgramData\Microsoft\Windows\WER\Temp\773077a2-20f7-465a-bffe-3d174e80dec4
C:\ProgramData\Microsoft\Windows\WER\Temp\0f935146-613f-4261-ba1c-995203c086c2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0b2d15f9-952d-4dae-a288-413258d96fda
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\16b5cb4c-9406-4f76-8b77-49aac50ae051
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\b73537fa-74d4-4955-96d0-dc515c4ef769
C:\ProgramData\Microsoft\Windows\WER\Temp\b5d0e209-a07a-49ad-9f8f-7e69fa946e7d
C:\ProgramData\Microsoft\Windows\WER\Temp\8db4ff45-4bc6-46b4-8d8d-d865d5c42c37
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9d47bbda-9491-4021-99ed-60e003dca2df
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\75d3fc79-06b4-44fa-a74c-1be2374a5f1c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\83328372-d2c4-4dff-befe-b69bb5ddf861
C:\ProgramData\Microsoft\Windows\WER\Temp\3ba5acd1-a2e4-4fef-895f-342aa0abb153
C:\ProgramData\Microsoft\Windows\WER\Temp\eecb6f49-e398-4c35-992f-203d5d817f9c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\51ef653b-8b36-4ecb-a536-6456227710c3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\7918b014-9335-43cb-b80f-a599726fe73d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\a4ba8d60-23a7-4837-9d22-5b3eb8719617
C:\ProgramData\Microsoft\Windows\WER\Temp\0254c96f-45a2-40ea-b1ce-f3e467d91158
C:\ProgramData\Microsoft\Windows\WER\Temp\45ffc5e4-1452-42a1-b45c-f21c1fd9dd8d
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a8fe641c-5c04-4b06-93c7-46bc72a7f200
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\32403e2f-e985-4577-9118-3cdddd53ecf8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\82146ec1-ad29-49a0-bbc1-6e12731ea559
C:\ProgramData\Microsoft\Windows\WER\Temp\5586e7bb-05db-4e68-b46a-734091f4dc96
C:\ProgramData\Microsoft\Windows\WER\Temp\8b59e893-7235-4e49-a194-49565ad4dd2c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\54c62453-1a71-45a3-b9ce-14632b93a3ef
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0e772b64-4a0b-470d-904d-fbed82443e92
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\2581c0c0-5feb-49da-becc-bb04ae9fba43
C:\ProgramData\Microsoft\Windows\WER\Temp\a90fbd65-20b7-4fb9-b35d-7ca4c1032bf9
C:\ProgramData\Microsoft\Windows\WER\Temp\8f18dbba-644a-40b2-af6d-bb56ba2502e5
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\849abb44-33c1-42a1-85b4-fc5377312d46
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ee317768-8142-4caa-b515-e4c8c15f8d97
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\fd69f262-8583-4fb4-b396-f4f638e1d2f7
C:\ProgramData\Microsoft\Windows\WER\Temp\daa53604-ee4b-48ce-bdbc-77ba3f1b8f63
C:\ProgramData\Microsoft\Windows\WER\Temp\0d4a4a43-be3b-4a7d-bbf1-3c3dcd475e7b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4999e3ef-5038-4359-aa79-efdf94dee3cb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3df42fa3-e5a3-49a3-82a2-c68a6535c8c3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\a6ba4e11-5e7f-427b-a42d-471a401a72bd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192
C:\ProgramData\Microsoft\Windows\WER\Temp\6b6e78ee-b9a5-4491-8b1b-da3a3ca0a963
C:\ProgramData\Microsoft\Windows\WER\Temp\9f999aac-e40c-4213-9615-524737049be1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a3b2d87b-9946-4f47-ae95-35af0c4486f5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\116ca581-c466-4e97-a8b6-dc201e399a2d
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1FD.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1FD.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\10d4b10d-ffaf-44c1-a35f-61f82452a448
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\*
C:\ProgramData\Microsoft\Windows\WER\Temp\fee30ab5-7abc-4d96-a846-cca5f0aeaedf
C:\ProgramData\Microsoft\Windows\WER\Temp\41f59a50-2e19-4b09-a0bb-70c3147ef5b0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\1141a71a-ece2-4327-b92f-2186dbbbcd64
C:\ProgramData\Microsoft\Windows\WER\Temp\1aa3981d-894f-45b2-b305-fc5832ee44bf
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\785c1a36-0639-4d06-8952-3713e42b867b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9b9ae052-c3f9-4561-868d-499299445055
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\d9b3ac32-25e8-477a-8923-2833a2739891
C:\ProgramData\Microsoft\Windows\WER\Temp\003a4421-5979-458d-a982-5993114432ba
C:\ProgramData\Microsoft\Windows\WER\Temp\9082e886-facd-4a68-96bb-5105a778a733
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2a74e684-5f3a-4c1b-8371-ab9c96830556
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\afb44274-5093-4fea-8316-5f784c7a3cd3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\fd55d2bf-984c-4869-a288-75cf23bed450
C:\ProgramData\Microsoft\Windows\WER\Temp\98383aaa-85e7-4eb8-a883-11cc625a0ce9
C:\ProgramData\Microsoft\Windows\WER\Temp\42009691-a48e-4c7a-b97d-33b60c13eb50
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\53c8fea2-99d0-44ff-9791-ce27616061f2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\749ded7d-cfd0-4869-af49-adb8065bf7b2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\889daf7c-e8b6-41ea-9134-2e9772fc7b88
C:\ProgramData\Microsoft\Windows\WER\Temp\88ea0537-493c-405d-a95f-f8764b56b7d6
C:\ProgramData\Microsoft\Windows\WER\Temp\80c55aa8-35bb-4de4-9a6f-50a91455b445
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\af3c7fb8-4133-4f8f-b020-c4708cc19575
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a395706b-f1fa-4de2-8cce-cd3b09356fb8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\84266304-881f-4dd0-be4d-38e75af93893
C:\ProgramData\Microsoft\Windows\WER\Temp\12df1fb7-ead2-4c9e-ad9e-a29731b5fdc6
C:\ProgramData\Microsoft\Windows\WER\Temp\2d8b9016-d125-4de2-a94a-e556144726a6
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e203da33-56a8-4fa8-8393-0a37a1946b0c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\de2387ab-48af-45c7-aa47-7d97ba2c8837
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\f46faf06-32b0-4b67-88fb-8ebc5396084c
C:\ProgramData\Microsoft\Windows\WER\Temp\41606878-b0bd-4525-8c56-f417de24c492
C:\ProgramData\Microsoft\Windows\WER\Temp\afd414ec-2812-4fc1-8011-b624971ec505
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ef5d8bb3-cb4a-4aec-8c3b-5554348a045f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2aa1d75c-1956-4e50-bff2-87b9104419ae
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\e761c96d-fe29-4fa4-8d03-9a23a19fc73e
C:\ProgramData\Microsoft\Windows\WER\Temp\b2811f5a-2723-4112-959f-8a6da8d22be9
C:\ProgramData\Microsoft\Windows\WER\Temp\ea5a4740-d0fb-4cb4-a411-0ce91bf37cb4
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\aacc913f-a96a-43d8-83e1-cd140e649935
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5e007094-5969-44f2-a966-68c57b1ec52e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\a4cd838a-7e91-4f34-a959-c727df567aa8
C:\ProgramData\Microsoft\Windows\WER\Temp\31fb2fa9-81fe-4f2b-ba9d-6538f71a3a4b
C:\ProgramData\Microsoft\Windows\WER\Temp\31aece71-8225-424a-9035-9731b3ca67f2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\08d6abfa-c17f-45f8-872f-33884c852cb0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\78a8de27-6842-44e3-91bb-d3a23e0538a5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\94269bd7-033a-46a7-844d-1fbfffa7cd63
C:\ProgramData\Microsoft\Windows\WER\Temp\aa46d960-1b08-4873-967a-607644fa57b7
C:\ProgramData\Microsoft\Windows\WER\Temp\daeb8a0f-f706-474e-b281-bbe30b5ba18a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2f091af1-e0b2-4706-9c2f-b4fda8b4c339
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\71d14e4f-0a13-48bb-a147-7c8393c28231
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\e7a2dd31-33ab-46ac-9a44-e64abe177345
C:\ProgramData\Microsoft\Windows\WER\Temp\328309a1-18ab-4223-bbff-7cf535ac59be
C:\ProgramData\Microsoft\Windows\WER\Temp\2f593e8c-4038-46c6-85bc-c1e5098e42c4
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\cedd77c4-291c-4556-ae47-caf6fcf0f5a2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\496d443c-846a-4e61-9982-6b37566e2144
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\54045340-ca0d-466b-ba72-b163a1d6591a
C:\ProgramData\Microsoft\Windows\WER\Temp\72b862b7-dc07-4d63-99d3-a477cde242dd
C:\ProgramData\Microsoft\Windows\WER\Temp\a81803cc-90d2-4f9f-84df-7e193b0d16fd
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\97982a73-e173-468d-942b-bcc5cf2aea92
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0898bdad-4196-4e15-9569-ef1a48423524
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\837a7e8c-afd9-43ce-a3b6-8d50c92eacbd
C:\ProgramData\Microsoft\Windows\WER\Temp\f8cf2b29-d712-4199-9c29-c84c73a47bd7
C:\ProgramData\Microsoft\Windows\WER\Temp\9f464074-9343-4eaf-95af-f0319c2ec142
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\90dfd3fa-6388-415a-b9be-013f5e2e3d89
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\65846ec2-c070-411d-9df5-2d3155a68dad
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\b21af807-1dca-4050-b555-a9d44710b96c
C:\ProgramData\Microsoft\Windows\WER\Temp\e1ff20a4-d9c8-4bb9-a566-72376c24cd3c
C:\ProgramData\Microsoft\Windows\WER\Temp\4dd62641-db82-4922-a50d-2cc043008d63
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\d03d83ea-c891-4080-9270-60389aba901c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2b6c2511-6fdf-44bf-9ddb-6aca63e9c693
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\cd5d146e-98e9-42cf-9994-efa86e60a8bb
C:\ProgramData\Microsoft\Windows\WER\Temp\441f8b95-4957-4eab-bf1e-4400ae3631cc
C:\ProgramData\Microsoft\Windows\WER\Temp\105dbe84-2966-46ee-bc36-c9871fd61a5c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\57f52fcf-f686-4192-9b47-bfbb1e3d92c1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ee183bd1-58d7-448c-804b-e6cc268e0477
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\4e08ec69-024d-4a88-80c3-e0c27f689c94
C:\ProgramData\Microsoft\Windows\WER\Temp\cefec80b-2218-48bb-af72-ff03800cadbc
C:\ProgramData\Microsoft\Windows\WER\Temp\f7bc51a6-8454-4eab-88bd-887e1110b949
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a93fd6e6-43c1-4b8a-94b3-3b323e5588d8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a1672920-f06f-4f9b-b987-71992521a015
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\a5044130-d9f3-433b-9d7e-b05ecf3e28ab
C:\ProgramData\Microsoft\Windows\WER\Temp\9670feaf-0a33-40bc-a024-876bf7f8d0af
C:\ProgramData\Microsoft\Windows\WER\Temp\9008b10e-560c-4ed8-a773-17abdc6d5a2b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1328f99b-90ca-43a4-be69-9c5b9f753782
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\37982eb4-f54a-4a1a-abe0-217a06e75099
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\b9c56713-3a83-4b7c-b283-7786d44911fb
C:\ProgramData\Microsoft\Windows\WER\Temp\6b82370b-50eb-4ed5-a2bf-bc88826268b4
C:\ProgramData\Microsoft\Windows\WER\Temp\62dc31d9-a167-4568-bde6-dbb8aa075118
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4f19eee7-31aa-4b93-ba4a-63fcf8c47683
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\bd260e56-9d56-470a-b2cb-254031c262a2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\ac4de274-6e3f-4a20-8630-84c1a7746a6e
C:\ProgramData\Microsoft\Windows\WER\Temp\681fbcf5-b889-417b-9b29-3311b014367c
C:\ProgramData\Microsoft\Windows\WER\Temp\8f0370ee-b947-47c5-984e-fc5b3893bdb8
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9b812701-1f6a-45a1-961c-3d525c928a3d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\8a45776d-845c-41cb-891e-121980bb3154
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\ddb4ebbd-3023-41ca-9e01-ef27f9840463
C:\ProgramData\Microsoft\Windows\WER\Temp\012c9aac-2420-4b55-b9e6-853b395f525a
C:\ProgramData\Microsoft\Windows\WER\Temp\a154bb06-f5a2-4a9c-b169-3633a6fadf76
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0a34f610-06d3-4092-a99e-af9ebf673121
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ffbdc62e-f610-4ef7-a63b-929ca91e1ee2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\1732f344-cee9-4109-bb30-100af21a9eb1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f
C:\ProgramData\Microsoft\Windows\WER\Temp\3f9b8d66-8b4f-440b-af82-da1882021a1c
C:\ProgramData\Microsoft\Windows\WER\Temp\dd910702-84fb-472e-9704-9ef720bf3dce
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\8cd2ba2e-6e9d-443b-9ba7-0230f5509579
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e6a057da-ecc8-4780-9709-5e3c96431abf
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD868.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD868.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\b98c548b-c468-431e-87f4-48c1b067271f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\*
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0519.1488.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0519.1488.1.odl
C:\Windows\Web\Wallpaper\Windows\img0.jpg
C:\Windows\Web\Wallpaper\Theme1\img1.jpg
C:\Windows\Web\Wallpaper\Theme1\img13.jpg
C:\Windows\Web\Wallpaper\Theme1\img2.jpg
C:\Windows\Web\Wallpaper\Theme1\img3.jpg
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0520.6532.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0520.6532.1.odl
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
\??\PIPE\lsarpc
\??\PIPE\srvsvc
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0456.6388.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0456.6388.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0457.728.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0457.728.1.odl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.da2ccfa2-332d-474c-859f-2513f30f04a1.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.e1d7ed34-ac5c-4efd-b07a-e2877546b62a.1.etl
C:\ProgramData\USOPrivate\UpdateStore\store.db
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Work
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work
C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work
C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
C:\ProgramData\Microsoft\Windows\WER\Temp
C:\ProgramData\Microsoft\Windows\WER\Temp\e9dad848-595e-4873-8503-27708eb9acd0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue
C:\ProgramData\Microsoft\Windows\WER\Temp\d7184265-7711-49b8-87fb-03acb7edb57c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive
C:\ProgramData\Microsoft\Windows\WER\Temp\bcab8f00-2c72-4578-b340-66ce01e488e0
C:\ProgramData\Microsoft\Windows\WER\Temp\7373f3af-d0c7-4990-aa8f-41d622d73f0b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\dcf2b97e-e240-43fe-addd-7c838c048f6d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\885cc5a3-492b-40cd-9255-60f9e44c6e54
\Device\RasAcd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\4f5189ed-034a-4496-9f64-4ab2cb87f998
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\60eacdec-4a0d-4e09-b02f-f75aeda2426c
C:\ProgramData\Microsoft\Windows\WER\Temp\732eeae2-97d6-4744-8f74-7d5e378095e1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\997a8a1c-3386-4396-90a9-163cd30bb6b2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\688b1d74-b47e-4f68-9da3-b00a830843b0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\a1b6b1e7-670e-4871-9bf1-e2577352a6ea
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\2c94d629-7abd-4dc8-83ed-e1e56b510dea
C:\ProgramData\Microsoft\Windows\WER\Temp\ac20fe12-09b7-4b41-a658-5cb8e904d474
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f612892d-6d61-4852-9862-b52c3e2e7f52
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\93855010-d61c-4d55-a6ed-128459932be0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\3c034a96-2f7b-44f8-b614-62a0fa25e2a0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\dd22590b-7899-4f62-9b82-07a5cf15e2c2
C:\ProgramData\Microsoft\Windows\WER\Temp\235f2a0a-15c5-4c45-b3dc-21612f2584a5
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c0b95e9f-15ed-4439-8993-21b392d1ca09
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2510edd0-2c63-4e30-95b1-4b97ffe18409
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\392781c6-b0f5-460e-9316-83c988553135
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\da0020af-e41e-461b-875d-90634dfe9516
C:\ProgramData\Microsoft\Windows\WER\Temp\877aa596-b750-411c-9e08-78a946752b87
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1171b8ee-a241-4643-b570-267cd725f12a
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e5acc319-6fca-425e-9a3b-0613963d13b4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\81c20a53-9f40-4e0b-a319-785405b3be70
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\7e950d2d-b54b-49b9-87b9-5d07161c824f
C:\ProgramData\Microsoft\Windows\WER\Temp\d85a2e73-02aa-4c5b-aaf5-0f002b914279
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a83c8ac8-6a7b-4b06-8f77-eace6bbe5b45
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e6be0fcf-6a93-4be5-81f3-1f68f585fe2f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\2ac2dbcd-06b7-4a3c-bba7-010c8d31c328
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\744297a1-9b9c-42b5-a397-75986c3d3d67
C:\ProgramData\Microsoft\Windows\WER\Temp\207fb8dd-f91c-4b9a-b385-1b59d659e12e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2ceecc04-b692-4f64-af22-419b8233284e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\30c025d2-512b-4f22-bee9-e35f975485c4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\03167b2b-037d-416a-9fdf-74881d455322
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\9717e5e9-17cb-47c3-9401-f57b49039ba9
C:\ProgramData\Microsoft\Windows\WER\Temp\1cee0e0b-8423-4e02-872c-d5954305f7d6
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b8c31b68-1462-4150-9fcb-3832bfd042b7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9d5621c3-a026-44da-86be-88f542fa7aa0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\4cabafdf-dcbd-4cd5-abbd-5b27ed6b0910
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\a1aa6ab4-9d6e-416e-830a-ed9d7e3e1d8d
C:\ProgramData\Microsoft\Windows\WER\Temp\ea6962ca-df51-4f49-bafe-4534c5cf2a99
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\14b734bd-586d-4178-ac83-3c048497e905
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\dfbb56ce-faef-4893-9fcb-05460cc90327
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\abb1891f-94f7-4aee-888d-c40c685428d0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\7adc2317-bfa9-4235-8a7b-541ed924a922
C:\ProgramData\Microsoft\Windows\WER\Temp\243c4484-37d5-4b7a-b3a5-416e6b48d29f
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\eacb53fe-158b-4e5f-9e3a-8adbab486655
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\86ef8182-1c60-4db4-8c51-397c3f6d5af8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\d272d083-9e73-4aa6-bdc3-0754b421aed1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\c3dd8148-4487-4698-9a9d-717d31c00c43
C:\ProgramData\Microsoft\Windows\WER\Temp\7b0e2d40-76dc-4065-8376-959632f26dd9
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a995868d-257e-4a00-b867-05acb73b93fa
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\34604d03-fc65-4ce5-93b1-e959fb29e4a0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\4d37ffad-27bb-47bf-8369-667793bfb95f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\8b78e135-63c3-4eba-9758-8870717830e4
C:\ProgramData\Microsoft\Windows\WER\Temp\0ef019eb-d35a-4651-a817-7214366ff8f0
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c0754d41-a8ea-4a5e-a084-a33b0f41b9a7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ad4db298-f247-409f-8f1e-33f72ac5f9e9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\a5db7820-61f5-4126-8101-fd5c5f32dd67
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\9e261ed7-2425-4021-871a-5b65785b7d95
C:\ProgramData\Microsoft\Windows\WER\Temp\fd72fbde-5cee-43b3-99bf-5180684a9fb9
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\341b70a0-df59-4aad-8a07-ce067feaa9c0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\6d612b14-bc92-4e06-9d04-e019ef0a8aa1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\b8c5b657-34e1-4e24-9d85-ad6a1a620fc1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\2c0c012c-6d98-4a00-be62-9ec6986b559b
C:\ProgramData\Microsoft\Windows\WER\Temp\4887d440-d357-43f5-aa4e-430e21e85305
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\3ff6920d-7514-48cf-a33d-cdb1cb13e20b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ceee58d5-610c-4422-9d36-81e5da912bf3
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4CDC.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\0d1accb0-6e6f-453d-b34d-0e2b9e96b4be
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\d1649359-d6cb-4221-80bc-8c4438c59194
C:\ProgramData\Microsoft\Windows\WER\Temp\c795f028-b4c9-4604-98ce-5ab2daf82ca8
C:\ProgramData\Microsoft\Windows\WER\Temp\3aba0db1-22e4-4003-85f1-1aa5763b1a35
C:\ProgramData\Microsoft\Windows\WER\Temp\a32092d0-db7c-4e44-a9ce-620596fb1259
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c35aebb4-9c46-4bf8-85dc-a7eb83e9c1dc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\88bd7f04-f215-4e50-9885-93d2617eb60f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\9d2ba87d-85d7-4704-9483-4bd3f106ea3d
C:\ProgramData\Microsoft\Windows\WER\Temp\a476cb2b-cf3c-42a9-9b60-a0e21c031dca
C:\ProgramData\Microsoft\Windows\WER\Temp\1109e652-6a34-48e2-b60f-afa4a574a1e7
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\bfe3459b-d76c-4fce-927b-076e68ae6491
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3681c203-ca9a-4f37-b0a7-67dbcc43830f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\eed5e41d-9894-4168-b9fd-3caabc8b2168
C:\ProgramData\Microsoft\Windows\WER\Temp\acdc6bc8-4c00-4640-b08b-90c0af9a4eee
C:\ProgramData\Microsoft\Windows\WER\Temp\456353a8-9a84-4a6f-a44b-d13777b91a3c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a4f8b77e-cd23-4bc1-b61b-314b0a5ebb4e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5f7101ec-0114-446f-a0f2-bc9341877ada
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\25cc640e-3665-438e-831e-217900b7af72
C:\ProgramData\Microsoft\Windows\WER\Temp\e38416f2-f530-4b74-a451-a551518e45fd
C:\ProgramData\Microsoft\Windows\WER\Temp\9509242e-08b4-4726-9918-87b9675aca86
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\bba8f2a9-d64a-4398-825a-d01e272ed89b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a76eb39b-988a-4368-a2a0-bf9a3dab637c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\21bf49d8-4434-4dd3-afc9-ea6df2c31cc5
C:\ProgramData\Microsoft\Windows\WER\Temp\a23cd13c-e15b-400d-be9c-f8b845b1f08b
C:\ProgramData\Microsoft\Windows\WER\Temp\c366f261-df1d-4486-b8a2-7a43bf9f1015
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\482f071a-de63-454b-8617-8096242b68b7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9958b409-aefd-445d-9988-c7325afc823e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\8fcbb065-67bc-4b4f-89b5-91b2c3b4174b
C:\ProgramData\Microsoft\Windows\WER\Temp\71493e72-e899-43d3-952d-7509a4400148
C:\ProgramData\Microsoft\Windows\WER\Temp\a3191c95-8d90-4679-b420-7787e6eff736
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\489b29b1-f257-499b-80a8-46cd7d32d7d0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9137a1f2-3b5a-4385-ad59-45bf95131169
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\380fa896-ff4b-43d6-bcef-e8f78ca66f63
C:\ProgramData\Microsoft\Windows\WER\Temp\809c6590-861c-4b66-b735-fcc92a230ff7
C:\ProgramData\Microsoft\Windows\WER\Temp\2aa98408-2215-4f45-9a3d-d1fcb7abc72e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4998cede-9b58-4125-9311-0e426c5e95d4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c36885ac-e7ce-42f6-915b-0a141cbc06f0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\4002b8a3-6127-44a7-a116-20bb1fca8221
C:\ProgramData\Microsoft\Windows\WER\Temp\fe2e5aba-3bb4-4a8d-b7fc-8d558abf0f36
C:\ProgramData\Microsoft\Windows\WER\Temp\d4dffd9e-23e5-45b3-a9a1-2377fbc38e4c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\abfe7a04-5cdf-4e9a-93be-b79b6c1ed474
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\393d0f26-b431-4a64-9642-f5e0f8f859b3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\feaa6e25-ffc0-4d0b-a0af-536e8577d7b4
C:\ProgramData\Microsoft\Windows\WER\Temp\925cd51f-21c4-4d4d-9a74-d0fe9c561ae6
C:\ProgramData\Microsoft\Windows\WER\Temp\e9688031-acb2-4fe9-b378-43ee86b2db23
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e4ada5fe-e302-499c-aab3-ba430c6a62fd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\d5abb1a2-2da8-4093-9a51-60feb8e2e5ab
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\15106b8d-c9da-4c13-8b97-2f2f6865d185
C:\ProgramData\Microsoft\Windows\WER\Temp\6a82b907-d1f2-4632-aa8d-a5dc87d5519b
C:\ProgramData\Microsoft\Windows\WER\Temp\b2b78f6d-cee6-42dc-8bab-5392d4cf888b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ba83b77e-bb13-4509-b70a-0cf337f24deb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c55f7b96-d39f-460e-92e4-e8b1741d2bbb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\af798486-fc7d-4b75-938f-f2fda90aaf0b
C:\ProgramData\Microsoft\Windows\WER\Temp\8c502474-0826-4043-97e0-70a28a76f861
C:\ProgramData\Microsoft\Windows\WER\Temp\c10dc88f-f5eb-4090-b903-e13cc0e8d8c1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\feea0f68-cc0c-4d2e-9899-998fa9941b30
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5127c870-4ee5-4838-8ef7-4a0e2421102c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\13c82a8c-f9c1-4d2a-ba35-8830b6d6c269
C:\ProgramData\Microsoft\Windows\WER\Temp\6c0e5c82-d18e-4a38-8692-d97b79df91b2
C:\ProgramData\Microsoft\Windows\WER\Temp\08fa8cd1-50bf-4d17-a171-77f39106e0da
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\20950766-e0ef-4ce6-8269-8696dee0cb84
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0454fcc6-a758-4d25-a297-78881e659b38
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\153a733d-6802-4b5b-af13-06bc76ac38ea
C:\ProgramData\Microsoft\Windows\WER\Temp\c2c4d011-a198-4429-b731-e111ef55c941
C:\ProgramData\Microsoft\Windows\WER\Temp\ed34ccf5-c9a0-48aa-a2fc-813317158444
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4f1a5248-9622-40e3-b52e-f80c6342df00
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c3dc3942-5585-41cf-98d9-c3e670670adf
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\3acb737f-90af-4856-879d-570e52477713
C:\ProgramData\Microsoft\Windows\WER\Temp\e7256d10-3b11-4c3d-8efa-49245951dcae
C:\ProgramData\Microsoft\Windows\WER\Temp\1fc846f0-a3f8-4b80-b5c5-196b9cee9031
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ede10e6a-18c1-4554-8fbb-054752d38f4a
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3a4a13eb-d5a3-4093-9621-65f6cc7b2e6e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\6529d6bc-d28d-4c03-840b-4e3dc00e3e4e
C:\ProgramData\Microsoft\Windows\WER\Temp\eef83a82-fdb0-43eb-9c30-9ebdcf8fccf7
C:\ProgramData\Microsoft\Windows\WER\Temp\c8c7eefa-b514-4c1e-b406-11df3ecab1c4
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f4752bee-12f7-4a7d-aefa-03a2cee268de
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\18fb7aea-e44b-4aff-bcad-10971e70ba43
C:\ProgramData\Microsoft\Windows\WER\Temp\WER500.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\fae5ec24-26ff-467d-af46-03bc422c1596
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\3ef95f0c-b8cf-47d4-8f1d-d5a198a0afb0
C:\ProgramData\Microsoft\Windows\WER\Temp\934f2673-d94a-432e-9eb9-a8ecdc67bfd2
C:\ProgramData\Microsoft\Windows\WER\Temp\40a72e08-811f-486b-801b-392c301ac78b
C:\ProgramData\Microsoft\Windows\WER\Temp\115ef9dc-3402-46ff-89f1-ce54f6e02373
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\5668b7dc-6715-4d84-b5da-a840abb1928c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\cfcbef2f-650b-4b04-b4ec-28cb2ae0a9f2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\963cbfa0-c56d-4473-bf88-ae0265f95997
C:\ProgramData\Microsoft\Windows\WER\Temp\19a24906-5116-45e6-ab81-380bd4a902b8
C:\ProgramData\Microsoft\Windows\WER\Temp\9a03da4a-ad9e-40ee-9b31-038f3ca83444
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\6620124e-f846-4a6f-b788-16d9d0f3a366
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\4d2683df-76cb-4d74-98c9-42a71bba9cba
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\4f2657fe-2909-4549-93e8-060b6639a1ef
C:\ProgramData\Microsoft\Windows\WER\Temp\00df8a7d-8b1c-4d5f-93c6-1402ec05920d
C:\ProgramData\Microsoft\Windows\WER\Temp\c4463b56-480e-4166-9a0c-44165305824a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\00b26dcd-200a-47cf-9c98-f78864465e38
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5fbfb57e-9e58-4c61-958b-19ce584922a2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\c320ebea-0a93-44b1-9632-c6af8328ae7b
C:\ProgramData\Microsoft\Windows\WER\Temp\7c3aded6-04b5-478e-acef-56c0c1637537
C:\ProgramData\Microsoft\Windows\WER\Temp\d16afb34-a2a9-40ba-a6f9-f27e86e734e2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\97c34b45-e6d6-4574-bf34-3e5565ad10d7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\45bc4b37-26cf-4f20-a258-15c90fbd3d1b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\2a19b57c-d221-4e72-b816-e3f76d12cc4c
C:\ProgramData\Microsoft\Windows\WER\Temp\a2c2a70c-36d5-4bf5-b06a-d7279ab112cf
C:\ProgramData\Microsoft\Windows\WER\Temp\e5e1791f-6938-421a-a71b-b7117d0d6f31
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1a8256a8-2ba1-4655-aa62-ff5f254b937f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\02ab0ca9-0540-4f6a-b5a7-2b0201ec6f15
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\94b75ba5-068e-4966-a3a9-99fe23d2b88e
C:\ProgramData\Microsoft\Windows\WER\Temp\e84d5ea0-8b81-4019-9e43-a01327b361cd
C:\ProgramData\Microsoft\Windows\WER\Temp\f84a3199-d4b2-4016-b6e3-79c88d1e4438
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\68778cc0-88e2-44d3-840e-fc041c15dddc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\588ec950-3620-48a7-a3ba-bc0358c5c5ce
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\ec22efd5-71ab-4312-8858-65fa12eea828
C:\ProgramData\Microsoft\Windows\WER\Temp\b508a165-f971-456a-84cd-e8ca5c0a5e5a
C:\ProgramData\Microsoft\Windows\WER\Temp\a4ed0f59-3400-473d-93b6-b9d7dc6c6914
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ae3f8d46-0c55-4548-9210-17a6f8cb6a5c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\104dd1df-fb39-4f81-bb3f-4227f0e5a6d2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\fb52a3a5-7397-4fac-b9e2-acd73ea743b0
C:\ProgramData\Microsoft\Windows\WER\Temp\10440f15-d565-4dcb-a45a-bb7545314f8f
C:\ProgramData\Microsoft\Windows\WER\Temp\aa013658-db4d-4d68-894e-2a2079b18590
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9552ca9a-7a5d-4ad6-b8f7-2a0f3041dd86
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\92c247bd-7ca6-421c-be0a-b66ed975ef9f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\1abe32ae-2379-47ed-af80-c8b3b33b21a0
C:\ProgramData\Microsoft\Windows\WER\Temp\5df93b2a-2817-4bf5-b549-0ac85d90173d
C:\ProgramData\Microsoft\Windows\WER\Temp\70403755-dfa7-4c1c-b33c-b367259c9ead
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9e74d0c0-a082-48bd-b767-e93f6c938d5e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\78b713d5-724c-44f4-8999-d3bd8e4112b6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\ab0ece60-e8df-4484-b04d-e425ce232b9f
C:\ProgramData\Microsoft\Windows\WER\Temp\313d1355-7a48-4167-b3be-15fee5e71268
C:\ProgramData\Microsoft\Windows\WER\Temp\c5267c5b-d47e-451f-a803-6aad9153e8e8
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e83a2954-70f3-40f8-a01b-66eb907b9302
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\12bc41f8-2904-42ed-a33f-caf220f51445
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\06670560-5ce1-465c-aef8-224d31fedb3a
C:\ProgramData\Microsoft\Windows\WER\Temp\e5f88077-6012-468e-91ca-dda020b295ed
C:\ProgramData\Microsoft\Windows\WER\Temp\b4381a1e-ad83-436a-a526-fad3611692f7
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\6c55adad-5d9c-4d28-8a18-b74627e5a8fc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\4166bb8a-5805-4557-8f54-1d3a4c6c431e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\00ff5250-7bca-47cb-8540-8eebad853bc7
C:\ProgramData\Microsoft\Windows\WER\Temp\e0f30c60-d4d1-47ba-9d42-ed7bc101dfbc
C:\ProgramData\Microsoft\Windows\WER\Temp\88dddb4d-6690-4249-b551-2b7a03977459
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e6d0fd6f-d0f7-4b21-b594-542e07f22d62
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9b6ad1a5-6a88-4849-aa2f-4d7f6de66a86
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\02397b65-b769-4f00-999d-aaa180ef2c93
C:\ProgramData\Microsoft\Windows\WER\Temp\900612ea-4447-47b6-a5c2-f3a9d57442cf
C:\ProgramData\Microsoft\Windows\WER\Temp\68396835-e8a8-47a0-8d39-78544f9d81e1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\92686bbc-7732-4f98-b921-b027f73a3dca
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\90be3da8-9df9-4f4b-aad3-c2517cf2b327
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\76bb6f1b-9adf-444d-be17-e5ba25954cf2
C:\ProgramData\Microsoft\Windows\WER\Temp\49c686e7-7a39-4b7f-bb9b-7d90dc16b0af
C:\ProgramData\Microsoft\Windows\WER\Temp\856798a2-6d86-41ac-be75-02a3b2377cf2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\73f22d1a-a6d6-4b81-84aa-cc41560fcf68
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a8af954f-51d6-411d-a2b8-a91c4c0d0cc1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\abb053a2-1802-43fa-bd13-6b8b0aa5c23d
C:\ProgramData\Microsoft\Windows\WER\Temp\a67ab964-e261-47b9-b02f-166fa8dbd567
C:\ProgramData\Microsoft\Windows\WER\Temp\b835510d-3b8e-4d2c-9f39-50365f18d09a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\bc02ac5f-e410-498c-a68c-751b313c1243
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9a48e11f-8331-41a9-9629-f630a67fb9db
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\c5ae1d82-dfc5-4395-8bd9-3387060f30c7
C:\ProgramData\Microsoft\Windows\WER\Temp\a83556e7-326d-44cc-8738-9f67899f16c7
C:\ProgramData\Microsoft\Windows\WER\Temp\ecaa692f-e352-4dc6-9ad0-abd725c565fa
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\071a1509-2367-410f-9268-3222c6450751
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\887ce1fb-1855-4f4a-bed7-f3dbc45f3a6f
C:\ProgramData\Microsoft\Windows\WER\Temp\WER440D.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\d5aae025-4700-4521-838d-8ac93f9f2ed4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\Report.wer
C:\$Extend\$Quota:$Q:$INDEX_ALLOCATION
\??\PIPE\wkssvc
\Device\Afd\Endpoint
\??\UNC\WORKGROUP*\MAILSLOT\NET\NETLOGON
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.a017b90e-4c4f-45cf-bd78-d9d533e8c38e.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.8be52fb9-77fb-43e3-8170-c81b7e6c8c98.1.etl
C:\ProgramData\Microsoft\Windows\WER\Temp\ccfb3c9d-1c9c-4a28-ab97-79a0485044ff
C:\ProgramData\Microsoft\Windows\WER\Temp\1f13a608-7d8a-464e-ba02-64e43a7a6c49
C:\ProgramData\Microsoft\Windows\WER\Temp\801e5901-2be1-49ec-9834-6b23c98b2c99
C:\ProgramData\Microsoft\Windows\WER\Temp\6a81e6f6-0ae6-41c6-8181-4b84ad985c26
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\702efa4c-c21c-4ab4-b326-7469a2bb811e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\41630a53-7227-4ec6-b5d3-f6b03813474b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\2fbe7cc5-85ab-4e22-9cee-7fa7d975c4d0
C:\ProgramData\Microsoft\Windows\WER\Temp\ee1cc283-b16b-461a-8c8d-cfa8ec26c043
C:\ProgramData\Microsoft\Windows\WER\Temp\ba5e6688-89d7-4b2e-a5f5-aa8a5454898a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\d6730272-4a2c-4160-82a9-57394758b34e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2d529f19-a8a3-4fd2-8878-f5a5f45919ff
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\0610a571-d86b-4550-a78e-ac9293f760b8
C:\ProgramData\Microsoft\Windows\WER\Temp\f2d1ec52-e12d-4474-ac5d-41c79e574d8a
C:\ProgramData\Microsoft\Windows\WER\Temp\77101115-4e74-4b0f-be4d-63a8e1c6949d
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\696b5530-03fe-4fb3-a725-7deff06c745d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\61d3a684-310f-4028-a956-492d221d8714
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\a73021db-ca2e-4737-bff3-9889278770b8
C:\ProgramData\Microsoft\Windows\WER\Temp\6112fa7c-3523-4096-8efb-f1aa5d9d9745
C:\ProgramData\Microsoft\Windows\WER\Temp\039b23a3-fd6d-43f4-9b56-32eb18e7cc1e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\3e9209d3-a3dc-4bcb-acf3-476b4c416648
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\7f8aea12-7bbe-4690-befa-4ccc57291e50
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\11d0ab8c-ce29-4e0e-b6d8-410f31a0eb5a
C:\ProgramData\Microsoft\Windows\WER\Temp\b1729862-d020-4287-af5f-417571024b10
C:\ProgramData\Microsoft\Windows\WER\Temp\c0ccc400-f473-4c5c-b0a6-5f9b13b27a68
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\57fb1c2e-6610-4cb8-bd49-e5e529fe472d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5723a1b9-8cb5-4bd9-b3bc-09478d5deaf2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\b71a69c4-2747-4c99-b53a-c1d501f67c3b
C:\ProgramData\Microsoft\Windows\WER\Temp\6a5e8be1-66ae-41fb-ada5-44da40aec583
C:\ProgramData\Microsoft\Windows\WER\Temp\74c88e35-f7df-485d-8d85-c7ad5aeb9277
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\13d80c02-6012-40b0-a1f0-b60d703891ea
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b33c36a7-996c-4dd3-ae97-2dedcf6dfd67
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\bf7c0df4-630c-4fb0-97b6-f0cf144da83f
C:\ProgramData\Microsoft\Windows\WER\Temp\d9719e75-afc6-4458-a318-72b18086910c
C:\ProgramData\Microsoft\Windows\WER\Temp\cc5ce0a6-7f7b-4441-88f9-29c9f4e5e6d3
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\916dafcb-8bf7-4b13-a49c-697d1ecdbeae
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\be03eb2f-edd0-4453-b40b-1fe897feba3b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\14565abe-0d71-4959-8cc4-7ef0d149cb7c
C:\ProgramData\Microsoft\Windows\WER\Temp\ae6e9fdd-ea7d-4f77-925f-724ac624b8ad
C:\ProgramData\Microsoft\Windows\WER\Temp\ffeeffcd-2de4-4325-8d7e-646541e8f8e1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\669c5daa-e5ed-4683-84d1-47562067e6b5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\582c1958-1fa6-4349-b54e-f1fda0808284
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\3e78605d-6afa-48c4-806c-2fb6c52eaddc
C:\ProgramData\Microsoft\Windows\WER\Temp\526acef5-7c3e-4de5-8404-6ac1cd8b078b
C:\ProgramData\Microsoft\Windows\WER\Temp\bb617e56-cf2a-4de1-955b-0994bca216e2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\dde2c523-7506-43e8-b7e7-79af2e03d5ef
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c0c100be-018d-4f21-bf53-951d67ce4407
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\11d7c32f-f060-414b-b748-6c42e3ab9900
C:\ProgramData\Microsoft\Windows\WER\Temp\11e57c72-f68f-485d-a3a4-c1f990818124
C:\ProgramData\Microsoft\Windows\WER\Temp\ce0b5008-abe5-4bca-bf5b-611cef498e44
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2841f96f-a7b1-45b2-95c0-00e89581e29c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\afa8dbe2-dcfb-4310-9fd8-7dfe04f21c1d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\b4ec8fa0-8a60-482a-bd16-f20805c50cce
C:\ProgramData\Microsoft\Windows\WER\Temp\83f069d5-7714-4d49-aa05-1546e2c72933
C:\ProgramData\Microsoft\Windows\WER\Temp\31db8716-a02d-434c-ac6e-722a21ef604a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\7623b5a0-e450-4bd1-8439-67c11e2a4f1f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0804766a-3a1f-4e32-9eab-59e032bb8251
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\48afbf20-e1c4-424d-ba12-b362117266eb
C:\ProgramData\Microsoft\Windows\WER\Temp\95cd10f5-5bae-42f3-ae64-e5841d335609
C:\ProgramData\Microsoft\Windows\WER\Temp\be0bab84-badc-4a28-a7cc-10085c44edea
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\59de9b60-6883-45d8-b9d4-9aa424af0bbc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a6264ac5-2f99-4bed-8e6c-117835819343
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\3d2a8a0e-10f1-4db9-b859-be174d8102af
C:\ProgramData\Microsoft\Windows\WER\Temp\945ced0e-701c-4ad2-911a-c5b41c911433
C:\ProgramData\Microsoft\Windows\WER\Temp\e275839a-f943-4cb2-8d9e-731f0c95e8be
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\7037dd82-16d7-42d1-8776-b015fdfe35dc
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b50d4620-542a-4cb3-abcc-edc89bcce0b2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\1da90243-107b-411d-a5a7-0652d6f3a530
C:\ProgramData\Microsoft\Windows\WER\Temp\85ad08e8-12b7-49a9-8e25-831ee68c6ae3
C:\ProgramData\Microsoft\Windows\WER\Temp\fcc3bb69-3f54-4ef4-8ae3-30c8e16a4535
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\5bcc0442-c45e-45a1-bec1-f36c14dd6d0b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\c11ce6df-0b02-43cd-86ea-f3a537fd5efa
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\627a7504-a8ea-4ef3-bba0-fe15a2746db7
C:\ProgramData\Microsoft\Windows\WER\Temp\0ca69f76-49d0-4d88-8057-4bb6503aa33d
C:\ProgramData\Microsoft\Windows\WER\Temp\c878fe47-ba54-4a7b-9533-8895ea7c4e69
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0c96bdb0-c843-4999-a908-160232b1ef6e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\772c9362-d47e-45d8-83f6-e00625a090c9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\d7f0fd10-3240-443d-b95a-b038a858d0fd
C:\ProgramData\Microsoft\Windows\WER\Temp\30d345d1-b216-48d8-9015-2bf562b38085
C:\ProgramData\Microsoft\Windows\WER\Temp\a52aae0e-b20a-457e-9fc1-f34a79341289
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\dfc2352e-fd8b-4eb5-b6e1-e23cf58b1946
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\6c7a976c-d778-4846-8e6a-801647a47865
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\ae6ed8ce-ed45-4993-924d-c30e017fcc32
C:\ProgramData\Microsoft\Windows\WER\Temp\0a74fb24-58cc-4bd2-8ea3-49b79c6caaa0
C:\ProgramData\Microsoft\Windows\WER\Temp\c3de6bd1-1df2-4656-9d85-5c4adce93551
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\c85a8dcd-3b9a-42c8-99f2-898101333e7b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\07b8128c-9fba-442a-af03-c770d6d9956f
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D50.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\8e27d8a1-f654-4fab-99da-9321040c5950
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\64b8ebf5-f962-42ba-a10d-d0b081177e24
C:\ProgramData\Microsoft\Windows\WER\Temp\6e52899c-b4c9-4189-be39-f53b40d0f0dd
C:\ProgramData\Microsoft\Windows\WER\Temp\b3e4fb18-beba-424b-a7a5-33273e8fcde4
C:\ProgramData\Microsoft\Windows\WER\Temp\20c27c22-16fd-4e07-81bd-30850eec2f69
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ab80d052-4307-41db-9a68-a670dc3a6cef
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b0c06e23-409a-4a88-b8b5-57bc5850dd1a
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\44a17d0c-1fef-41ac-a36e-e2b980ba75b5
C:\ProgramData\Microsoft\Windows\WER\Temp\683ddc7f-9312-4740-b4f9-096b74e2d884
C:\ProgramData\Microsoft\Windows\WER\Temp\b1c788f3-e649-4e10-9be2-fae41facfa5a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0e5845c0-4d43-4e4e-bfa4-f10d2ab7f456
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\aaf94ea3-15e4-4833-b0a6-e7f2c3c567c0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\eeb33c2f-aae0-4638-b18d-6482703d6312
C:\ProgramData\Microsoft\Windows\WER\Temp\25b28594-6e3f-4f43-ac00-63190de4de4d
C:\ProgramData\Microsoft\Windows\WER\Temp\ec4ec7d8-d4fb-45b3-ba43-17ce8ede5eed
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\14f03354-7268-468c-a0cc-6ed74382bf5e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\b96a1761-508d-4a77-9002-6a28069635e4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\880354f7-9728-4ac1-8449-777fda15bb9e
C:\ProgramData\Microsoft\Windows\WER\Temp\0816d6a6-0803-425d-a3a7-04bee067620e
C:\ProgramData\Microsoft\Windows\WER\Temp\311fad48-6200-4562-b20e-5aee4e40fc3f
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\3faa4a86-3e8d-4e5d-8f99-ad3b5f7ea749
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2f7cf03a-8aca-49a3-add5-655719ab561e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\342ea154-5d21-445b-9e5e-70396b1c5560
C:\ProgramData\Microsoft\Windows\WER\Temp\4b2424a1-11c0-4baa-952d-8515508004da
C:\ProgramData\Microsoft\Windows\WER\Temp\7a650dbe-7c60-4924-af85-98f01fe32479
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f32cd806-aaee-4d24-a33e-94ea7a10de79
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\1f5a3587-6b3e-4826-abe4-95fcde6fd2d5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\c6665ab7-85e0-42dd-9d9a-65f71227887f
C:\ProgramData\Microsoft\Windows\WER\Temp\a2b8d1f7-71d9-4b85-add8-8a4f88c94ca6
C:\ProgramData\Microsoft\Windows\WER\Temp\4f4daf35-6c9e-4488-a5ad-a8e64dd6a039
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b9690290-667e-4edf-9242-410d2b0b3366
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\f344492c-f7a5-476b-888c-220ab286aa9c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\96dea8b2-9069-4cad-a6c7-3d359a742f2a
C:\ProgramData\Microsoft\Windows\WER\Temp\1c4840ef-b62c-4f74-8b4a-62f012d68f4e
C:\ProgramData\Microsoft\Windows\WER\Temp\34129842-7be3-432d-9d2a-c3625a3c5c7e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\8f510d3c-36ed-4965-ae94-be6b65d29fd6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a6ea6c47-bb29-466b-abc8-28dc9172e702
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\aace3312-43cb-49ef-aea8-038f889b5ca6
C:\ProgramData\Microsoft\Windows\WER\Temp\84ccc7eb-b685-4d98-94e5-6c15d0ce96f9
C:\ProgramData\Microsoft\Windows\WER\Temp\013b7a3e-ced1-409e-a9f5-e59067c0f8de
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0059cd3f-def3-44ce-a852-38148f72a533
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9c6da26f-73f9-4acd-9337-84e8ad0f91ed
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\9ba96a3d-e10e-42e8-9018-659a346e1785
C:\ProgramData\Microsoft\Windows\WER\Temp\9720e6fe-c9e5-4652-90b9-a53e094e245a
C:\ProgramData\Microsoft\Windows\WER\Temp\134b942d-c827-4507-a46b-c95236381b86
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b6ff5018-f631-4bfe-9f3c-9c41c8a14283
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\86c2486b-9dbd-4b93-8d51-ca7b25399610
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\c5c4094e-63c7-4e05-80c1-d84e43736136
C:\ProgramData\Microsoft\Windows\WER\Temp\68662616-57b7-4ffc-9c44-8944156cbe86
C:\ProgramData\Microsoft\Windows\WER\Temp\844911fb-b3a2-48e0-a048-c02e16de6c3d
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ef73187f-8f00-4713-9f76-3dad052ceed9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\38f6eb69-02bd-4f54-bef7-fc03520a4a36
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\7eb51c00-84b9-40c2-8a31-81146d4b02ed
C:\ProgramData\Microsoft\Windows\WER\Temp\50968a87-3303-4253-a1bf-b6f2febb7ad3
C:\ProgramData\Microsoft\Windows\WER\Temp\de3e7429-62dc-4870-9566-f683ccff6749
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\7a6b0280-bd78-4bd0-adfe-4dba5b74e721
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\30aa32e7-7314-4e3c-9641-612716a0d7c7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\93a11392-eae9-4913-a4ff-7d8aa7569159
C:\ProgramData\Microsoft\Windows\WER\Temp\76828054-cb55-4dd6-898a-625571abfb1a
C:\ProgramData\Microsoft\Windows\WER\Temp\492efc2b-8f00-4b59-8c63-e43ce37cd79e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\236f6a63-7189-489c-aeb1-f51686b98322
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\d56631cc-435a-4c06-b6a0-fd6b547f3093
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\9ac9cf14-6e79-4039-acf1-4045b6e5acc2
C:\ProgramData\Microsoft\Windows\WER\Temp\329c6666-991b-442b-a502-afc2af57bbdb
C:\ProgramData\Microsoft\Windows\WER\Temp\bc13c39d-5bcf-4bbe-8cdb-421cbfde868e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\09fb6b89-b935-42c2-a28a-b57d59390ab0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ccca980f-c42e-4843-901b-64155fc12cf8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\be818d8e-f7e9-437b-b508-a9f15a9cd115
C:\ProgramData\Microsoft\Windows\WER\Temp\40be500a-f3da-4343-805d-0a4cd90c5582
C:\ProgramData\Microsoft\Windows\WER\Temp\de106a57-be9b-4ac9-bf98-8465339af15b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e67f88e3-b4c5-4cb2-82a2-f6f86f9fc8ca
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0ee20b94-bd2b-4506-b82f-e5178257a15b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\967a06d1-438e-4d20-bf1d-9576bf41d9c7
C:\ProgramData\Microsoft\Windows\WER\Temp\f358e887-f7ab-416f-9694-57cc189cbf37
C:\ProgramData\Microsoft\Windows\WER\Temp\e0b4af49-d816-4771-a7d2-e5e21569ae4c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\f1c43bd8-654f-4395-9bc2-9ba1e29aa8c0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\20566a11-9572-4782-91a2-375faff4bc78
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\0e694e83-b862-4682-aa35-f987bbc5652d
C:\ProgramData\Microsoft\Windows\WER\Temp\470a92b8-b936-4737-bc44-4425765f9232
C:\ProgramData\Microsoft\Windows\WER\Temp\79f9516d-29b1-42f3-9e7a-b2f09d7683c0
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\cf4c5238-b077-4552-b78b-0fdb3189d6e6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ca3e3f18-3f55-417e-a6d1-f4aa22ac4f0b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\829c893c-ae1e-495f-9d8e-17e63f60be03
C:\ProgramData\Microsoft\Windows\WER\Temp\c9802fc3-76b0-4ca0-8354-1154bb31563f
C:\ProgramData\Microsoft\Windows\WER\Temp\6db69f28-fdf1-4824-839e-6e4d68792f98
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\88aa117c-ddf2-480a-badd-f1e9549b4bb3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9cf35c8a-612e-4ff1-8c4f-f71e2d1162df
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\47496ebb-3e70-489b-bf07-169f80fa4898
C:\ProgramData\Microsoft\Windows\WER\Temp\f4e96b87-a696-4c8f-8071-ea27981befcc
C:\ProgramData\Microsoft\Windows\WER\Temp\31baa8ea-3c64-4f75-adf3-be5e8a076436
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\98e09bb5-0945-4bda-84d4-18e06bdb5189
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5cdd7680-d158-4749-a2df-37ced24d4353
C:\ProgramData\Microsoft\Windows\WER\Temp\WER7F26.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\e7197e09-bfd9-41b4-8a4d-fa3b579f1bb7
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\Report.wer
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.664aae87-ec2e-42d2-88e6-929a86587279.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.eaaeb978-fc0a-4a94-838b-b2ff97d3bded.1.etl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.3968.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.3968.1.odl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.45dfe0c1-1dab-4d7f-9030-1205a3d3102b.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.5fbd21e7-5d85-463d-8627-8ff8d46309aa.1.etl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.5020.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.5020.1.odl
C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.ef7451d8-bb1a-4842-86f0-0faa9a634377.1.etl
C:\ProgramData\USOShared\Logs\System\WuProvider.3fc10395-12ad-4849-baa4-9cde6775020f.1.etl
C:\ProgramData\Microsoft\Windows\WER\Temp\0824bd4f-cdad-4e0f-bcbf-b0d456025bac
C:\ProgramData\Microsoft\Windows\WER\Temp\b3492820-4ea8-4a16-8525-3bf2d8c2bbb0
C:\ProgramData\Microsoft\Windows\WER\Temp\23c2aa24-0607-461b-9188-e737de26b8e0
C:\ProgramData\Microsoft\Windows\WER\Temp\b27a6e55-13e1-49d3-8b46-17bfdd6f3e92
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\403c9931-3cb7-4204-972e-2d6bad0a2b49
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e0d98955-c097-4943-9f11-652615dbd842
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\1acc9970-12ab-4481-9560-1b30b1eb1993
C:\ProgramData\Microsoft\Windows\WER\Temp\8be0d2cb-a401-45be-b46a-1e397486edbb
C:\ProgramData\Microsoft\Windows\WER\Temp\90f1b236-8b2d-4a58-bd54-bcf6a30c4499
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1d24c144-5e8b-436e-812a-0011141878ad
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\52f773cb-01f4-44db-bd89-53e1c8558510
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\ffb11e99-66cb-4940-b558-5d432f97a393
C:\ProgramData\Microsoft\Windows\WER\Temp\3f6842b0-1a0c-428e-b327-fedd055cb453
C:\ProgramData\Microsoft\Windows\WER\Temp\5b950499-572c-4b46-bfce-91559e2baa49
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\12f62db8-14f4-42e7-b5e5-6c80d1e778fd
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3d0cd0a6-19df-435f-8e63-a523385b7b1c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\3a852232-9989-45ae-9b07-6de403b85dda
C:\ProgramData\Microsoft\Windows\WER\Temp\bcb7547d-13a6-4881-9d11-467241e39a9c
C:\ProgramData\Microsoft\Windows\WER\Temp\2dea5e17-46b5-464d-a906-5fa5461d17d5
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b88f5036-a4ae-4407-ba62-d3ea4c44c4d4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e3c2b34d-79fa-45e0-8648-26d65a46e94c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\3e3ba975-7ead-482e-843c-99680dde8024
C:\ProgramData\Microsoft\Windows\WER\Temp\12be36b9-37be-49bc-aedf-545617c3ee0b
C:\ProgramData\Microsoft\Windows\WER\Temp\3bb92578-fe8c-4c45-9d95-1900d02293ff
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\933c3231-c052-4c3c-80d8-313952228ef6
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e424454b-ed10-419f-b07e-b795e597ebdb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\82a39648-1056-487a-97ce-3ca5bf8e9308
C:\ProgramData\Microsoft\Windows\WER\Temp\95b99827-11e3-4057-93a0-5100ba9d8b33
C:\ProgramData\Microsoft\Windows\WER\Temp\74981166-163c-46b6-8054-5f568c7471ad
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\5bf23806-aca9-4b45-aa96-68dceffec998
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\45e7fc5f-053d-4dac-a0c3-6f41e4fea242
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\2f2cef1f-4e2a-458e-8678-0a440a7b2394
C:\ProgramData\Microsoft\Windows\WER\Temp\7cdf6711-584f-4d2b-8d87-8364b25e8b13
C:\ProgramData\Microsoft\Windows\WER\Temp\ba23f212-7169-436a-b449-bf1ce1864e09
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\44afd72b-f62f-44be-ac16-c7a07b7cb4b0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\d491e6f4-6bef-4359-b72d-631660bb83e9
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\7f2837ce-ee7b-4f86-a345-9eee7785123f
C:\ProgramData\Microsoft\Windows\WER\Temp\95c20b21-aeb2-4ae0-94e3-570de0faa818
C:\ProgramData\Microsoft\Windows\WER\Temp\ec43824c-ad6c-4ab9-8e73-6feca19cafca
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\d7fb31bd-f3c4-4517-b9b2-1c750b2b2d77
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\754eb9cc-e1b1-49c5-94ee-0d820f130bd4
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\aeaa52d9-d336-47cf-863f-c0d39c61e736
C:\ProgramData\Microsoft\Windows\WER\Temp\ed6c2868-831c-4f32-b07d-b082d7fb206b
C:\ProgramData\Microsoft\Windows\WER\Temp\35e3bb79-c0b2-4757-89b6-d770b3838ff6
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0cca5ce1-d8c6-44ee-ae25-64cfd3c93888
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\64876d78-97b5-4a4a-a0e6-48680472782c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\74f29ebf-e4bc-43dc-8692-d75de11e76a5
C:\ProgramData\Microsoft\Windows\WER\Temp\e062894b-c6db-4899-bc9a-717e93d72335
C:\ProgramData\Microsoft\Windows\WER\Temp\2d4a1827-88c5-421c-b54f-979376660a73
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\b054de80-51ca-463f-94fc-d1bc585bb631
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\cad824f5-16fd-43fc-aef5-99af24a93035
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\4f91cce8-68e8-4840-9f61-4dc2fab504a3
C:\ProgramData\Microsoft\Windows\WER\Temp\482e6b42-e6de-4866-a9e5-4048a062d4f7
C:\ProgramData\Microsoft\Windows\WER\Temp\b8ab82ed-d1d6-4550-94e6-6d0809296a6e
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\8932b557-6604-4ff6-a724-19647317034c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\dfed3310-73db-4101-851b-b2f39538517b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\9560aa0a-aebb-4a84-ab81-4cfd85549b85
C:\ProgramData\Microsoft\Windows\WER\Temp\773077a2-20f7-465a-bffe-3d174e80dec4
C:\ProgramData\Microsoft\Windows\WER\Temp\0f935146-613f-4261-ba1c-995203c086c2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0b2d15f9-952d-4dae-a288-413258d96fda
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\16b5cb4c-9406-4f76-8b77-49aac50ae051
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\b73537fa-74d4-4955-96d0-dc515c4ef769
C:\ProgramData\Microsoft\Windows\WER\Temp\b5d0e209-a07a-49ad-9f8f-7e69fa946e7d
C:\ProgramData\Microsoft\Windows\WER\Temp\8db4ff45-4bc6-46b4-8d8d-d865d5c42c37
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9d47bbda-9491-4021-99ed-60e003dca2df
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\75d3fc79-06b4-44fa-a74c-1be2374a5f1c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\83328372-d2c4-4dff-befe-b69bb5ddf861
C:\ProgramData\Microsoft\Windows\WER\Temp\3ba5acd1-a2e4-4fef-895f-342aa0abb153
C:\ProgramData\Microsoft\Windows\WER\Temp\eecb6f49-e398-4c35-992f-203d5d817f9c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\51ef653b-8b36-4ecb-a536-6456227710c3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\7918b014-9335-43cb-b80f-a599726fe73d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\a4ba8d60-23a7-4837-9d22-5b3eb8719617
C:\ProgramData\Microsoft\Windows\WER\Temp\0254c96f-45a2-40ea-b1ce-f3e467d91158
C:\ProgramData\Microsoft\Windows\WER\Temp\45ffc5e4-1452-42a1-b45c-f21c1fd9dd8d
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a8fe641c-5c04-4b06-93c7-46bc72a7f200
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\32403e2f-e985-4577-9118-3cdddd53ecf8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\82146ec1-ad29-49a0-bbc1-6e12731ea559
C:\ProgramData\Microsoft\Windows\WER\Temp\5586e7bb-05db-4e68-b46a-734091f4dc96
C:\ProgramData\Microsoft\Windows\WER\Temp\8b59e893-7235-4e49-a194-49565ad4dd2c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\54c62453-1a71-45a3-b9ce-14632b93a3ef
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0e772b64-4a0b-470d-904d-fbed82443e92
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\2581c0c0-5feb-49da-becc-bb04ae9fba43
C:\ProgramData\Microsoft\Windows\WER\Temp\a90fbd65-20b7-4fb9-b35d-7ca4c1032bf9
C:\ProgramData\Microsoft\Windows\WER\Temp\8f18dbba-644a-40b2-af6d-bb56ba2502e5
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\849abb44-33c1-42a1-85b4-fc5377312d46
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ee317768-8142-4caa-b515-e4c8c15f8d97
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\fd69f262-8583-4fb4-b396-f4f638e1d2f7
C:\ProgramData\Microsoft\Windows\WER\Temp\daa53604-ee4b-48ce-bdbc-77ba3f1b8f63
C:\ProgramData\Microsoft\Windows\WER\Temp\0d4a4a43-be3b-4a7d-bbf1-3c3dcd475e7b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4999e3ef-5038-4359-aa79-efdf94dee3cb
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\3df42fa3-e5a3-49a3-82a2-c68a6535c8c3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\a6ba4e11-5e7f-427b-a42d-471a401a72bd
C:\ProgramData\Microsoft\Windows\WER\Temp\6b6e78ee-b9a5-4491-8b1b-da3a3ca0a963
C:\ProgramData\Microsoft\Windows\WER\Temp\9f999aac-e40c-4213-9615-524737049be1
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a3b2d87b-9946-4f47-ae95-35af0c4486f5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\116ca581-c466-4e97-a8b6-dc201e399a2d
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1FD.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\10d4b10d-ffaf-44c1-a35f-61f82452a448
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\Report.wer
C:\ProgramData\Microsoft\Windows\WER\Temp\fee30ab5-7abc-4d96-a846-cca5f0aeaedf
C:\ProgramData\Microsoft\Windows\WER\Temp\41f59a50-2e19-4b09-a0bb-70c3147ef5b0
C:\ProgramData\Microsoft\Windows\WER\Temp\1141a71a-ece2-4327-b92f-2186dbbbcd64
C:\ProgramData\Microsoft\Windows\WER\Temp\1aa3981d-894f-45b2-b305-fc5832ee44bf
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\785c1a36-0639-4d06-8952-3713e42b867b
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\9b9ae052-c3f9-4561-868d-499299445055
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\d9b3ac32-25e8-477a-8923-2833a2739891
C:\ProgramData\Microsoft\Windows\WER\Temp\003a4421-5979-458d-a982-5993114432ba
C:\ProgramData\Microsoft\Windows\WER\Temp\9082e886-facd-4a68-96bb-5105a778a733
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2a74e684-5f3a-4c1b-8371-ab9c96830556
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\afb44274-5093-4fea-8316-5f784c7a3cd3
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\fd55d2bf-984c-4869-a288-75cf23bed450
C:\ProgramData\Microsoft\Windows\WER\Temp\98383aaa-85e7-4eb8-a883-11cc625a0ce9
C:\ProgramData\Microsoft\Windows\WER\Temp\42009691-a48e-4c7a-b97d-33b60c13eb50
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\53c8fea2-99d0-44ff-9791-ce27616061f2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\749ded7d-cfd0-4869-af49-adb8065bf7b2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\889daf7c-e8b6-41ea-9134-2e9772fc7b88
C:\ProgramData\Microsoft\Windows\WER\Temp\88ea0537-493c-405d-a95f-f8764b56b7d6
C:\ProgramData\Microsoft\Windows\WER\Temp\80c55aa8-35bb-4de4-9a6f-50a91455b445
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\af3c7fb8-4133-4f8f-b020-c4708cc19575
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a395706b-f1fa-4de2-8cce-cd3b09356fb8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\84266304-881f-4dd0-be4d-38e75af93893
C:\ProgramData\Microsoft\Windows\WER\Temp\12df1fb7-ead2-4c9e-ad9e-a29731b5fdc6
C:\ProgramData\Microsoft\Windows\WER\Temp\2d8b9016-d125-4de2-a94a-e556144726a6
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\e203da33-56a8-4fa8-8393-0a37a1946b0c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\de2387ab-48af-45c7-aa47-7d97ba2c8837
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\f46faf06-32b0-4b67-88fb-8ebc5396084c
C:\ProgramData\Microsoft\Windows\WER\Temp\41606878-b0bd-4525-8c56-f417de24c492
C:\ProgramData\Microsoft\Windows\WER\Temp\afd414ec-2812-4fc1-8011-b624971ec505
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\ef5d8bb3-cb4a-4aec-8c3b-5554348a045f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2aa1d75c-1956-4e50-bff2-87b9104419ae
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\e761c96d-fe29-4fa4-8d03-9a23a19fc73e
C:\ProgramData\Microsoft\Windows\WER\Temp\b2811f5a-2723-4112-959f-8a6da8d22be9
C:\ProgramData\Microsoft\Windows\WER\Temp\ea5a4740-d0fb-4cb4-a411-0ce91bf37cb4
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\aacc913f-a96a-43d8-83e1-cd140e649935
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\5e007094-5969-44f2-a966-68c57b1ec52e
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\a4cd838a-7e91-4f34-a959-c727df567aa8
C:\ProgramData\Microsoft\Windows\WER\Temp\31fb2fa9-81fe-4f2b-ba9d-6538f71a3a4b
C:\ProgramData\Microsoft\Windows\WER\Temp\31aece71-8225-424a-9035-9731b3ca67f2
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\08d6abfa-c17f-45f8-872f-33884c852cb0
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\78a8de27-6842-44e3-91bb-d3a23e0538a5
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\94269bd7-033a-46a7-844d-1fbfffa7cd63
C:\ProgramData\Microsoft\Windows\WER\Temp\aa46d960-1b08-4873-967a-607644fa57b7
C:\ProgramData\Microsoft\Windows\WER\Temp\daeb8a0f-f706-474e-b281-bbe30b5ba18a
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\2f091af1-e0b2-4706-9c2f-b4fda8b4c339
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\71d14e4f-0a13-48bb-a147-7c8393c28231
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\e7a2dd31-33ab-46ac-9a44-e64abe177345
C:\ProgramData\Microsoft\Windows\WER\Temp\328309a1-18ab-4223-bbff-7cf535ac59be
C:\ProgramData\Microsoft\Windows\WER\Temp\2f593e8c-4038-46c6-85bc-c1e5098e42c4
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\cedd77c4-291c-4556-ae47-caf6fcf0f5a2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\496d443c-846a-4e61-9982-6b37566e2144
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\54045340-ca0d-466b-ba72-b163a1d6591a
C:\ProgramData\Microsoft\Windows\WER\Temp\72b862b7-dc07-4d63-99d3-a477cde242dd
C:\ProgramData\Microsoft\Windows\WER\Temp\a81803cc-90d2-4f9f-84df-7e193b0d16fd
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\97982a73-e173-468d-942b-bcc5cf2aea92
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\0898bdad-4196-4e15-9569-ef1a48423524
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\837a7e8c-afd9-43ce-a3b6-8d50c92eacbd
C:\ProgramData\Microsoft\Windows\WER\Temp\f8cf2b29-d712-4199-9c29-c84c73a47bd7
C:\ProgramData\Microsoft\Windows\WER\Temp\9f464074-9343-4eaf-95af-f0319c2ec142
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\90dfd3fa-6388-415a-b9be-013f5e2e3d89
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\65846ec2-c070-411d-9df5-2d3155a68dad
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\b21af807-1dca-4050-b555-a9d44710b96c
C:\ProgramData\Microsoft\Windows\WER\Temp\e1ff20a4-d9c8-4bb9-a566-72376c24cd3c
C:\ProgramData\Microsoft\Windows\WER\Temp\4dd62641-db82-4922-a50d-2cc043008d63
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\d03d83ea-c891-4080-9270-60389aba901c
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\2b6c2511-6fdf-44bf-9ddb-6aca63e9c693
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\cd5d146e-98e9-42cf-9994-efa86e60a8bb
C:\ProgramData\Microsoft\Windows\WER\Temp\441f8b95-4957-4eab-bf1e-4400ae3631cc
C:\ProgramData\Microsoft\Windows\WER\Temp\105dbe84-2966-46ee-bc36-c9871fd61a5c
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\57f52fcf-f686-4192-9b47-bfbb1e3d92c1
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ee183bd1-58d7-448c-804b-e6cc268e0477
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\4e08ec69-024d-4a88-80c3-e0c27f689c94
C:\ProgramData\Microsoft\Windows\WER\Temp\cefec80b-2218-48bb-af72-ff03800cadbc
C:\ProgramData\Microsoft\Windows\WER\Temp\f7bc51a6-8454-4eab-88bd-887e1110b949
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\a93fd6e6-43c1-4b8a-94b3-3b323e5588d8
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\a1672920-f06f-4f9b-b987-71992521a015
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\a5044130-d9f3-433b-9d7e-b05ecf3e28ab
C:\ProgramData\Microsoft\Windows\WER\Temp\9670feaf-0a33-40bc-a024-876bf7f8d0af
C:\ProgramData\Microsoft\Windows\WER\Temp\9008b10e-560c-4ed8-a773-17abdc6d5a2b
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\1328f99b-90ca-43a4-be69-9c5b9f753782
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\37982eb4-f54a-4a1a-abe0-217a06e75099
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\b9c56713-3a83-4b7c-b283-7786d44911fb
C:\ProgramData\Microsoft\Windows\WER\Temp\6b82370b-50eb-4ed5-a2bf-bc88826268b4
C:\ProgramData\Microsoft\Windows\WER\Temp\62dc31d9-a167-4568-bde6-dbb8aa075118
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\4f19eee7-31aa-4b93-ba4a-63fcf8c47683
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\bd260e56-9d56-470a-b2cb-254031c262a2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\ac4de274-6e3f-4a20-8630-84c1a7746a6e
C:\ProgramData\Microsoft\Windows\WER\Temp\681fbcf5-b889-417b-9b29-3311b014367c
C:\ProgramData\Microsoft\Windows\WER\Temp\8f0370ee-b947-47c5-984e-fc5b3893bdb8
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\9b812701-1f6a-45a1-961c-3d525c928a3d
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\8a45776d-845c-41cb-891e-121980bb3154
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\ddb4ebbd-3023-41ca-9e01-ef27f9840463
C:\ProgramData\Microsoft\Windows\WER\Temp\012c9aac-2420-4b55-b9e6-853b395f525a
C:\ProgramData\Microsoft\Windows\WER\Temp\a154bb06-f5a2-4a9c-b169-3633a6fadf76
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\0a34f610-06d3-4092-a99e-af9ebf673121
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\ffbdc62e-f610-4ef7-a63b-929ca91e1ee2
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\1732f344-cee9-4109-bb30-100af21a9eb1
C:\ProgramData\Microsoft\Windows\WER\Temp\3f9b8d66-8b4f-440b-af82-da1882021a1c
C:\ProgramData\Microsoft\Windows\WER\Temp\dd910702-84fb-472e-9704-9ef720bf3dce
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\8cd2ba2e-6e9d-443b-9ba7-0230f5509579
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\e6a057da-ecc8-4780-9709-5e3c96431abf
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD868.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\b98c548b-c468-431e-87f4-48c1b067271f
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\Report.wer
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0519.1488.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0519.1488.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0520.6532.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0520.6532.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0456.6388.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2133.5764.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2125.4072.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2052.6960.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.2028.1120.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1913.1964.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1854.2316.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1845.6048.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1816.5756.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2024-11-25.1741.6072.1.odl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0457.728.1.aodl
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_windows.immersiv_8252a9b726a2ca5168b11af40b319ab28e06656_31aeda3d_841fb045-354c-457d-9cb0-a7dda03e1d78\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_5ed5ec82a9b038a6cf1c6dde5247a22d3a43f7_00000000_d871f5e6-49e7-4785-b605-9ffc4964c326\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_37174847-3906-422e-b227-a20349c47089\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_c9ba984c1fb2f68b57c358b04812ef3133da8e9_00000000_e880c3f8-3ce8-491b-8b2a-08690bf988b4\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft_f56eeaf4c54df4517ca4f4ec62f6777f7adb93a0_00000000_99f0b73b-c8c4-41c1-9271-25b038d09543\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_a4488e19f39db737bbf3c629781316979543e6a_00000000_e42a7fa6-1cf7-4296-b2a8-f6367c9592e8\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_4ba8fe2c-cd5c-4e54-ab22-06c23564ece0\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_f824e6a4-40f6-471a-a442-89b13e78a66d\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Window_16827428572979ae8ccf6a4adfb6fb82df42c84_00000000_779d63e8-be23-4004-a2b8-3f441a53bbba\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_33b998188f678f96da3a8a0377712336947a156_00000000_96f26c02-a54b-41b3-b6b2-0187b5451978\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_41bd3d2fa18feb9f71aeedce9e9c879f5a6422e_00000000_2441405d-dc45-49a0-a06b-2f19b11a93ec\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Corpor_8f55e0a5fe5a4ace9ce4d7b3d11ec987f58c91_00000000_3a2b0db3-a593-430b-aad4-90a00f320cf3\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_8ffc1abdd2374b3843b3c7d54ffd8ce461c9_f237ee1c_82983da1-f57f-4308-a3b3-b799832bb270\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4CDC.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_fc9744e3-2740-4711-acb0-b35559ff0afa\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER500.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_OneDrive.exe_964a2733c5af6746b97d023226479c268542f_00000000_b5b13657-6e62-45ea-83d2-d941d97e8ec0\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER440D.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_a2ea31f3d29381d7e1168dcf941b6fc2ea543b0_f237ee1c_c295b834-32e0-4bcd-91e5-ea497bd2ad52\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D50.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_0c25183f-ec97-4180-9e55-33b26529925e\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WER7F26.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_7d33d272-a6a1-45be-a571-75d3d58db287\Report.wer.tmp
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.3968.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0517.5020.1.aodl
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1FD.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_2c628c892acff9f251c95527b4be783abbc9_f237ee1c_d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192\Report.wer.tmp
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD868.tmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_FileCoAuth.exe_644527c6ad208775a0796c9478da966c37a5ad_f237ee1c_c247b10f-4748-4c08-b20e-edba76013b6f\Report.wer.tmp
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0519.1488.1.aodl
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2025-06-14.0520.6532.1.aodl
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\STE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\StateSeparation\RedirectionMap\Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseActivationAuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\rstrui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MiniNT
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\SystemRestore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Setup\SetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\en-US
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableUmpdBufferSizeCheck
HKEY_CURRENT_USER\Software\Classes
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\MGOTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ProtectionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AccessPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DDA0424F-9478-40FF-9B21-099EC9FFCBAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DDA0424F-9478-40FF-9B21-099EC9FFCBAE}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DDA0424F-9478-40FF-9B21-099EC9FFCBAE}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\Elevation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\MajorVersion
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\UsagePolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\DeliveryOptimization
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\DownloadMode_BackCompat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\DODownloadMode
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateForegroundBps
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateForegroundPct
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateBackgroundBps
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateBackgroundPct
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\UpRatePctBandwidth
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\UpRatePctBandwidth
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\UploadLimitGBMonth
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\UploadLimitGBMonth
HKEY_CURRENT_USER\Software\Microsoft\OneDrive
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\FileCoAuthTelemetryRampStatus
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\FirstEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\LastEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2025
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2007
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2024
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_CURRENT_USER\Software\Classes\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\AppID\FileCoAuth.exe
HKEY_LOCAL_MACHINE\Software\Classes\AppID\FileCoAuth.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{389510B7-9E58-40D7-98BF-60B911CB0EA9}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}\ProxyStubClsid32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\TreatAs
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InprocHandler32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\LocalServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\AppID
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\LocalServer
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\LocalServer
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\Elevation
HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\MainAccount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\UserFolder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\cid
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\DisplayName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\UserEmail
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\Business
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\SharePointOnPrem
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\FirstRun
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\EdpManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\RootAddedToFavorites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\TenantAddedToFavorites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\HasMadeFirstUpload
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\IsUpgradeAvailable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\CrashDetectionKey
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\EnableADALForSilentBusinessConfig
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\LastKnownCloudFilesEnabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\WamWebAccountId
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\AuthenticationURLs
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\Tenants
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal\ScopeIdToMountPointPathCache
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Accounts\Personal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\LastMigrationScanResult
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\PreSignInRampOverrides
HKEY_CURRENT_USER\Software\Microsoft\OneDrive\PreSignInSettingsOverrides
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SQMClient\MSFTInternal
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SQMClient\IsTest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\DefinitionFlags
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\DefinitionFlags
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\UpdateRingPostAuthConditions
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\ClickToRun\Configuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\EnablePreviewBuilds
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\OneDrive
HKEY_CURRENT_USER\Software\Policies\Microsoft\OneDrive
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableEnterpriseUpdate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableOrgInternalUpdate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableTeamTier_Internal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableFasterRingUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MachineId
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsUpdate\Orchestrator\Configurations
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\TestHooks
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MiniNT
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TimeZoneInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\Bias
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\StandardName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\StandardBias
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\StandardStart
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DaylightName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DaylightBias
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DaylightStart
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerCorrelationId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\mousocoreworker.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\mousocoreworker.exe\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D726464B-98F1-4627-86CD-4A082A1E5307}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D726464B-98F1-4627-86CD-4A082A1E5307}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D726464B-98F1-4627-86CD-4A082A1E5307}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsUpdate\UX\RebootDowntime
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\PolicyTestHooks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Update\ActiveHoursStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ActiveHoursStart\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\Lus
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Update\ActiveHoursEnd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ActiveHoursEnd\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Update\SetEDURestart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\SetEDURestart\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B357F841-2130-454E-802C-5C398B549F8E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsSelfhost\ClientState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\ClientState\PilotInfoRing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\ClientState\ErrorState
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\Diagnosis
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5DF486F8-50EB-427E-8DA3-7122CCAF9415}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5DF486F8-50EB-427E-8DA3-7122CCAF9415}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5DF486F8-50EB-427E-8DA3-7122CCAF9415}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9844E0CA-F034-40A2-AADA-84671C0E21AB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9844E0CA-F034-40A2-AADA-84671C0E21AB}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9844E0CA-F034-40A2-AADA-84671C0E21AB}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE2F3CF5-D9CD-4284-ADA8-1EDB8A23FFA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE2F3CF5-D9CD-4284-ADA8-1EDB8A23FFA9}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE2F3CF5-D9CD-4284-ADA8-1EDB8A23FFA9}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{84D31176-4A5A-4419-B07F-809FBA936A0A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{84D31176-4A5A-4419-B07F-809FBA936A0A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{84D31176-4A5A-4419-B07F-809FBA936A0A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsSelfhost\Applicability
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\IsBuildFlightingEnabled
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsSelfhost\OneSettings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PreviewBuilds
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowBuildPreview
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\System
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsUpdate\Orchestrator
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\ShutdownFlyoutOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\EnhancedShutdownEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1E78367-46B7-4AC8-AFFA-D9F55645223B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1E78367-46B7-4AC8-AFFA-D9F55645223B}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1E78367-46B7-4AC8-AFFA-D9F55645223B}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C85C21BB-5CCF-412A-B0CC-059A8A6AD0DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C85C21BB-5CCF-412A-B0CC-059A8A6AD0DF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C85C21BB-5CCF-412A-B0CC-059A8A6AD0DF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\NewUserDefaultConsent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\AutoApproveOSDumps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LiveReportFlushInterval
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\ResourcePolicies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MinFreeDiskSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CabArchiveFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceHeapDump
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceMetadata
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Source
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\StorePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceEtw
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUploadOnFreeNetworksOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\UploadOnFreeNetworksOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CabArchiveSeparate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CabArchiveCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalCompression
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableWerUpload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableEnterpriseAuthProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ArchiveFolderCountLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueSizeMaxPercentFreeDisk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MinQueueSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxRetriesForSasRenewal
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoHeapDumpOnQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DeferCabUpload
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DataCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowTelemetry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection\Users
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowTelemetry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\RegValueNameRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowTelemetry_PolicyManager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection\AllowTelemetry
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MSFTInternal
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\IsTest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\SysprepLock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MachineID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\MoAppCrash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp\MoAppCrash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\SampleStore
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\MoAppCrash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\OobeCompleted
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\Debug
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\My\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\My
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\MY\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\MY\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\MY\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\MY\CTLs
HKEY_USERS\S-1-5-18
HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\My\PhysicalStores
HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\My
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\_Groups\UTCPartnerPrograms
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\_Groups\UTCPartnerPrograms\System
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowCommercialDataPipeline
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowDesktopAnalyticsProcessing
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowUpdateComplianceProcessing
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowWUfBCloudProcessing
HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityCRL\Trace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE363A51-A0DE-5827-80F4-961B407B40C2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE363A51-A0DE-5827-80F4-961B407B40C2}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE363A51-A0DE-5827-80F4-961B407B40C2}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityCRL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityCRL\ServiceEnvironment
HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\GipActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\ServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\ServerBaseName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\UrlPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\RequestUrl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\ServerPort
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\UseSecure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\DoNotRequireMsftRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\BypassProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\AzureBlockSizeInKb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\MaxBlobSizeInKb
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\ConfigureMicrosoft365UploadEndpoint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\8073
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\OEM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm
HKEY_LOCAL_MACHINE\SYSTEM\Platform\DeviceTargetingInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Product
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\10433
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\31
HKEY_LOCAL_MACHINE\Hardware\Description\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\4573
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\4572
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\4575
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\9290
HKEY_LOCAL_MACHINE\Hardware\Description\System\BIOS
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemSKU
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\ComputerHardwareId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\12728
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacSampleNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\OEMInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\CorporateSQMURL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\CommercialId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection\CommercialId
HKEY_LOCAL_MACHINE\Software\Microsoft\XboxLive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\12674
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableSmartNameResolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\QueryNetBTFQDN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableSmartProtocolReordering
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UdpRecvBufferSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableParallelAandAAAA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableCoalescing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\FilterVPNTrigger
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ForceQueriesOverTcp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ShareTcpConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableServerUnreachability
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableMulticast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableMDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\NewDhcpSrvRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DirectAccessPreferLocal
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableIdnEncoding
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableIdnMapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ShortnameProxyDefault
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableNRPTForAdapterRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\NetworkDiagnosticsFrameworkV3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp\NetworkDiagnosticsFrameworkV3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\NetworkDiagnosticsFrameworkV3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\ScriptedDiagFailure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp\ScriptedDiagFailure
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\ScriptedDiagFailure
HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Throttling\ScriptedDiagFailure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsUpdate\Orchestrator\Installation\Target
HKEY_LOCAL_MACHINE\Software\Microsoft\Shell\OOBE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\OOBE\Stats
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DAM\PowerEvents
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\State
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Windows Error Reporting\Throttling\SkyDriveClientError
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E245105B-B06E-11D0-AD61-00C04FD8FDFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E245105B-B06E-11D0-AD61-00C04FD8FDFF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E245105B-B06E-11D0-AD61-00C04FD8FDFF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD450835-CF1B-4C87-9FD2-5E0D42FDE081}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD450835-CF1B-4C87-9FD2-5E0D42FDE081}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD450835-CF1B-4C87-9FD2-5E0D42FDE081}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Elevation
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-15
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-14
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-13
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-12
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-11
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\taskhostw.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\EnableDebuggerBreakForTaskStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Update\UpdateServiceUrl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\UpdateServiceUrl\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\PreMigration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETagBackup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETagValidated
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETagAcknowledged
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastUpdated
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastRefreshAttempted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastRefreshByApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\RefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastHTTPCode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\QueryStringHash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastPayload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastNotification
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\WOSC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\OSDATA\Software\Microsoft\WindowsSelfhost\OneSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\Ring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\TestFlags
HKEY_LOCAL_MACHINE\%DiagtrackRegistryRoot%\TestHooks\Volatile
HKEY_LOCAL_MACHINE\%DiagtrackRegistryRoot%\TestHooks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\UBR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildBranch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectX\HybridDeviceApplicableForDxDbGpuPreferences
HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\Immersive\production\Token\{0CB4A94A-6E8C-477B-88C8-A3799FC97414}
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\RegValueNameRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\DisableOneSettingsDownloads
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\RegValueNameRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\EnableOneSettingsAuditing
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\en
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\EnableDebuggerBreakForTaskHang
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\DisableThresholdAppLaunchPerfFeature
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\MGOTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ProtectionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-E0D0-43E5-9380-1D80483ACF72}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-e0d0-43e5-9380-1d80483acf72}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-e0d0-43e5-9380-1d80483acf72}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000c-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000c-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA9812C4-0B34-47D0-9B0B-157FB5B5FDF2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA9812C4-0B34-47D0-9B0B-157FB5B5FDF2}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA9812C4-0B34-47D0-9B0B-157FB5B5FDF2}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFB02FED-4C71-40E1-B4F3-CE99C2FF0542}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFB02FED-4C71-40E1-B4F3-CE99C2FF0542}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFB02FED-4C71-40E1-B4F3-CE99C2FF0542}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68766F36-3808-42F9-A18F-0ABDE6391172}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68766F36-3808-42F9-A18F-0ABDE6391172}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68766F36-3808-42F9-A18F-0ABDE6391172}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{04C2542D-3C28-4510-A0C0-8DB0E0A3A526}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{04C2542D-3C28-4510-A0C0-8DB0E0A3A526}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{04C2542D-3C28-4510-A0C0-8DB0E0A3A526}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D4966FA-DBD1-4799-A07F-6A5E1991BDA4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D4966FA-DBD1-4799-A07F-6A5E1991BDA4}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D4966FA-DBD1-4799-A07F-6A5E1991BDA4}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F3CC02FB-7C40-443A-966E-D85196B36F21}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F3CC02FB-7C40-443A-966E-D85196B36F21}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F3CC02FB-7C40-443A-966E-D85196B36F21}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}\CLSID
HKEY_CLASSES_ROOT\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Author
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FriendlyName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SpecVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Vendor
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ContainerFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceManufacturer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceModels
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ColorManagementVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\MimeTypes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FileExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportChromakey
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportLossless
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportMultiframe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ArbitrationPriority
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Formats
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\CLSID
HKEY_CLASSES_ROOT\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Author
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\FriendlyName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SpecVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Vendor
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\ContainerFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\DeviceManufacturer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\DeviceModels
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\ColorManagementVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\MimeTypes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\FileExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportChromakey
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportLossless
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportMultiframe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\ArbitrationPriority
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Formats
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2168CAC-969E-43DD-A3AB-A4DD612E223D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2168CAC-969E-43DD-A3AB-A4DD612E223D}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2168CAC-969E-43DD-A3AB-A4DD612E223D}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Update\DetectionFrequency
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FindMyDevice
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Experience\AllowFindMyDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Experience\AllowFindMyDevice\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\Experience
HKEY_LOCAL_MACHINE\Software\Microsoft\Settings\FindMyPhone
HKEY_LOCAL_MACHINE\Software\Microsoft\MdmCommon\SettingValues
HKEY_LOCAL_MACHINE\Software\Microsoft\Settings\FindMyDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\IdentityStore\Providers\{D7F9888F-E3FC-49B0-9EA6-A85B5F392A4F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityStore\Providers\{D7F9888F-E3FC-49b0-9EA6-A85B5F392A4F}\Name
HKEY_USERS\S-1-5-18\Software\Microsoft\IdentityCRL\StoredIdentities
HKEY_LOCAL_MACHINE\Software\Microsoft\MdmCommon\Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\MdmCommon\Internal
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MdmCommon\Internal\RegisteredWithService
HKEY_CURRENT_USER\Software\Classes\AppID\{A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AccessPermission
HKEY_CURRENT_USER\Software\Classes\CLSID\{A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D}
HKEY_CURRENT_USER\Software\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{29A3AB33-0FD7-44F5-9BFF-C0B6C081FBFB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29A3AB33-0FD7-44F5-9BFF-C0B6C081FBFB}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29A3AB33-0FD7-44F5-9BFF-C0B6C081FBFB}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\MGOTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ProtectionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\Elevation
HKEY_CURRENT_USER\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF86E2E0-B12D-4c6a-9C5A-D7AA65101E90}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF86E2E0-B12D-4c6a-9C5A-D7AA65101E90}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{00000035-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000035-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000035-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{3474D734-3408-4471-A344-A3439343634A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3474d734-3408-4471-a344-a3439343634a}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3474d734-3408-4471-a344-a3439343634a}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\Browser\AllowSmartScreen
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Browser\AllowSmartScreen\Behavior
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\Browser
HKEY_LOCAL_MACHINE\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\MicrosoftEdge\PhishingFilter
HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\PhishingFilter
HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B357F841-2130-454E-802C-5C398B549F8E}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\DisablePersonalSync
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\DetectionFrequency\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A37467DB-1DE5-4A3E-B9E1-D010EBA71143}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C879DD73-4BD2-4B76-9DD8-3B96113A2130}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C879DD73-4BD2-4B76-9DD8-3B96113A2130}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C879DD73-4BD2-4B76-9DD8-3B96113A2130}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68DA530A-6DF6-438A-BF57-452EAD01C7CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68DA530A-6DF6-438A-BF57-452EAD01C7CC}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68DA530A-6DF6-438A-BF57-452EAD01C7CC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B357F841-2130-454E-802C-5C398B549F8E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PhotoPropertyHandler\ContainerAssociations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PhotoPropertyHandler\ContainerAssociations\{56C11740-CCD9-4cdd-9139-BD5F89299BA5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PhotoPropertyHandler\ContainerAssociations\{FE99CE60-F19C-433C-A3AE-00ACEFA9CA21}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\STE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseActivationAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableUmpdBufferSizeCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\MGOTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ProtectionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DDA0424F-9478-40FF-9B21-099EC9FFCBAE}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6FF50C0-56C0-71CA-5732-BED303A59628}\AppID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\MajorVersion
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\UsagePolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DODownloadMode\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\DownloadMode_BackCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitForegroundDownloadBandwidth\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxForegroundBandwidth\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxForegroundDownloadBandwidth\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateForegroundBps
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateForegroundPct
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOSetHoursToLimitBackgroundDownloadBandwidth\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOPercentageMaxBackgroundBandwidth\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMaxBackgroundDownloadBandwidth\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateBackgroundBps
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\DownloadRateBackgroundPct
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\UpRatePctBandwidth
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\UpRatePctBandwidth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DeliveryOptimization\DOMonthlyUploadDataCap\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings\UploadLimitGBMonth
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\UploadLimitGBMonth
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\FileCoAuthTelemetryRampStatus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\FirstEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\LastEntry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2025
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2007
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time\Dynamic DST\2024
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\InprocServer32
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\(Default)
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\AppID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\MainAccount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\UserFolder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\cid
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\DisplayName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\UserEmail
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\Business
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\SharePointOnPrem
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\FirstRun
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\EdpManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\RootAddedToFavorites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\TenantAddedToFavorites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\HasMadeFirstUpload
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\IsUpgradeAvailable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\CrashDetectionKey
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\EnableADALForSilentBusinessConfig
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\LastKnownCloudFilesEnabled
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\WamWebAccountId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\LastMigrationScanResult
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SQMClient\MSFTInternal
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SQMClient\IsTest
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\DefinitionFlags
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905e63b6-c1bf-494e-b29c-65b732d3d21a}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\DefinitionFlags
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\UpdateRingPostAuthConditions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\EnablePreviewBuilds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableEnterpriseUpdate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableOrgInternalUpdate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableTeamTier_Internal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\EnableFasterRingUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MachineId
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\Bias
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\StandardName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\StandardBias
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\StandardStart
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DaylightName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DaylightBias
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DaylightStart
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerCorrelationId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D726464B-98F1-4627-86CD-4A082A1E5307}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\mousocoreworker.exe\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D726464B-98F1-4627-86CD-4A082A1E5307}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D726464B-98F1-4627-86CD-4A082A1E5307}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{607C052E-2B08-4548-BD1D-EB7665A34788}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ActiveHoursStart\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ActiveHoursEnd\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\SetEDURestart\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11F11442-3359-410C-875E-D21984507B62}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\ClientState\PilotInfoRing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\ClientState\ErrorState
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformation\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Networking.Connectivity.NetworkInformationPrivate\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5DF486F8-50EB-427E-8DA3-7122CCAF9415}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9844E0CA-F034-40A2-AADA-84671C0E21AB}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE2F3CF5-D9CD-4284-ADA8-1EDB8A23FFA9}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{84D31176-4A5A-4419-B07F-809FBA936A0A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\IsBuildFlightingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\ManagePreviewBuilds\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowBuildPreview\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\ShutdownFlyoutOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1E78367-46B7-4AC8-AFFA-D9F55645223B}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C85C21BB-5CCF-412A-B0CC-059A8A6AD0DF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\NewUserDefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\AutoApproveOSDumps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LiveReportFlushInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\ResourcePolicies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MinFreeDiskSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CabArchiveFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceHeapDump
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceMetadata
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Source
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\StorePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceEtw
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUploadOnFreeNetworksOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\UploadOnFreeNetworksOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CabArchiveSeparate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CabArchiveCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalCompression
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableWerUpload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableEnterpriseAuthProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ArchiveFolderCountLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueSizeMaxPercentFreeDisk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MinQueueSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxRetriesForSasRenewal
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoHeapDumpOnQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DeferCabUpload
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowTelemetry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\RegValueNameRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowTelemetry\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowTelemetry_PolicyManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection\AllowTelemetry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MSFTInternal
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\IsTest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\MachineID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\MoAppCrash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp\MoAppCrash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\OobeCompleted
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Ids\en
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowCommercialDataPipeline\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowCommercialDataPipeline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowDesktopAnalyticsProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowDesktopAnalyticsProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowMicrosoftManagedDesktopProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowUpdateComplianceProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowUpdateComplianceProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\AllowWUfBCloudProcessing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowWUfBCloudProcessing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Security.WebAuthentication.AuthenticationManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Diagnostics.AsyncCausalityTracer\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE363A51-A0DE-5827-80F4-961B407B40C2}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityCRL\ServiceEnvironment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\GipActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\ServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\ServerBaseName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\UrlPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\RequestUrl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\ServerPort
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\UseSecure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\DoNotRequireMsftRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\BypassProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\AzureBlockSizeInKb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TelemetryClient\MaxBlobSizeInKb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicypath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicyismultisz
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\grouppolicymultiszSeparatorChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\ConfigureMicrosoft365UploadEndpoint\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\ConfigureMicrosoft365UploadEndpoint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\8073
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\10433
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\31
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\4573
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\4572
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\4575
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\9290
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemSKU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\ComputerHardwareId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\12728
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacSampleNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\CorporateSQMURL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\CommercialId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection\CommercialId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CommonDatapoints\12674
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableSmartNameResolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\QueryNetBTFQDN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableSmartProtocolReordering
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UdpRecvBufferSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableParallelAandAAAA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableCoalescing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\FilterVPNTrigger
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ForceQueriesOverTcp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ShareTcpConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableServerUnreachability
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableMulticast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableMDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\NewDhcpSrvRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DirectAccessPreferLocal
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableIdnEncoding
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\EnableIdnMapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\ShortnameProxyDefault
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DisableNRPTForAdapterRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\NetworkDiagnosticsFrameworkV3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp\NetworkDiagnosticsFrameworkV3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\ScriptedDiagFailure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BrokerUp\ScriptedDiagFailure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9F6C78EF-FCE5-42FA-ABEA-3E7DF91921DC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6C683A5C-32B8-47cd-AC28-4B292414D032}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E245105B-B06E-11D0-AD61-00C04FD8FDFF}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD450835-CF1B-4C87-9FD2-5E0D42FDE081}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\AppID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-15
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-14
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-13
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-12
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-11
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\EnableDebuggerBreakForTaskStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsManager\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.ClientAttributes\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\UpdateServiceUrl\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\PreMigration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETagBackup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETagValidated
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\ETagAcknowledged
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastUpdated
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastRefreshAttempted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastRefreshByApp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\RefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastHTTPCode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\QueryStringHash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastPayload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\LastNotification
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonObject\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.Flighting.OneSettings.OneSettingsPayload\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonValue\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.StringMap\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\Ring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\TestFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContainerID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\UBR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildBranch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectX\HybridDeviceApplicableForDxDbGpuPreferences
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\RegValueNameRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneSettingsDownloads\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\DisableOneSettingsDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\RegValueNameRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\EnableOneSettingsAuditing\Value
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\EnableOneSettingsAuditing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\EnableDebuggerBreakForTaskHang
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\DisableThresholdAppLaunchPerfFeature
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\MGOTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ProtectionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{75121952-e0d0-43e5-9380-1d80483acf72}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E357FCCD-A995-4576-B01F-234630154E96}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B824B49D-22AC-4161-AC8A-9916E8FA3F7F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000c-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA9812C4-0B34-47D0-9B0B-157FB5B5FDF2}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFB02FED-4C71-40E1-B4F3-CE99C2FF0542}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68766F36-3808-42F9-A18F-0ABDE6391172}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{04C2542D-3C28-4510-A0C0-8DB0E0A3A526}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D4966FA-DBD1-4799-A07F-6A5E1991BDA4}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F3CC02FB-7C40-443A-966E-D85196B36F21}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{41945702-8302-44A6-9445-AC98E8AFA086}\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Author
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FriendlyName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SpecVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Vendor
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ContainerFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceManufacturer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\DeviceModels
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ColorManagementVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\MimeTypes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\FileExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportChromakey
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportLossless
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\SupportMultiframe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\ArbitrationPriority
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\0\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\1\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\10\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\11\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\12\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\13\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\14\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\2\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\3\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\4\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\5\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\6\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\7\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\8\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\Patterns\9\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Author
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\FriendlyName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SpecVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Vendor
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\ContainerFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\DeviceManufacturer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\DeviceModels
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\ColorManagementVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\MimeTypes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\FileExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportChromakey
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportLossless
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\SupportMultiframe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\ArbitrationPriority
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\Pattern
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\0\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\1\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\10\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\11\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\12\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\2\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\3\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\4\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\5\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\6\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\7\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\8\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\Position
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\EndOfStream
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FDD51E2-A9D0-44CE-8C8D-162BA0C591A0}\Patterns\9\Mask
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2168CAC-969E-43DD-A3AB-A4DD612E223D}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Experience\AllowFindMyDevice\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Data.Json.JsonArray\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityStore\Providers\{D7F9888F-E3FC-49b0-9EA6-A85B5F392A4F}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MdmCommon\Internal\RegisteredWithService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29A3AB33-0FD7-44F5-9BFF-C0B6C081FBFB}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\MGOTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ProcessMitigationPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{a463fcb9-6b1c-4e0d-a80b-a2ca7999e25d}\ProtectionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF86E2E0-B12D-4c6a-9C5A-D7AA65101E90}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000035-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3474d734-3408-4471-a344-a3439343634a}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Browser\AllowSmartScreen\Behavior
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B357F841-2130-454E-802C-5C398B549F8E}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\DisablePersonalSync
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Update\DetectionFrequency\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C879DD73-4BD2-4B76-9DD8-3B96113A2130}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{68DA530A-6DF6-438A-BF57-452EAD01C7CC}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PhotoPropertyHandler\ContainerAssociations\{56C11740-CCD9-4cdd-9139-BD5F89299BA5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PhotoPropertyHandler\ContainerAssociations\{FE99CE60-F19C-433C-A3AE-00ACEFA9CA21}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\DownloadMode_BackCompat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\DODownloadMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\ShutdownFlyoutOptions
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-15
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-14
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-13
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-12
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-11
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\2\52C64B7E\@%SystemRoot%\system32\powrprof.dll,-10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState\WOSC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\Orchestrator\EnhancedShutdownEnabled
ntdll.dll.RtlWow64GetCurrentMachine
ntdll.dll.RtlWow64IsWowGuestMachineSupported
C:\Windows\system32\DllHost.exe /Processid:{AA65DD7C-83AC-48C0-A6FD-9B61FEBF8800}
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Users\Packager\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe -Embedding
C:\Windows\System32\mousocoreworker.exe -Embedding
C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
C:\Windows\system32\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
C:\Windows\System32\smartscreen.exe -Embedding
C:\Windows\System32\CompPkgSrv.exe -Embedding
C:\Windows\system32\wermgr.exe -upload
taskhostw.exe
taskhostw.exe -RegisterDevice -ProtectionStateChanged -FreeNetworkOnly
Local\SM0:832:120:WilError_03
Local\SM0:4792:304:WilStaging_02
Local\SM0:728:168:WilStaging_02
Global\MoUsoCoreworkerRunning
Local\SM0:2512:304:WilStaging_02
Local\SM0:7048:120:WilError_03
Global\WerMgrUploadingLock
Global\841fb045-354c-457d-9cb0-a7dda03e1d78
Local\SM0:7048:304:WilStaging_02
Global\d871f5e6-49e7-4785-b605-9ffc4964c326
Global\37174847-3906-422e-b227-a20349c47089
Global\e880c3f8-3ce8-491b-8b2a-08690bf988b4
Global\99f0b73b-c8c4-41c1-9271-25b038d09543
Global\e42a7fa6-1cf7-4296-b2a8-f6367c9592e8
Global\4ba8fe2c-cd5c-4e54-ab22-06c23564ece0
Global\f824e6a4-40f6-471a-a442-89b13e78a66d
Global\779d63e8-be23-4004-a2b8-3f441a53bbba
Global\96f26c02-a54b-41b3-b6b2-0187b5451978
Global\2441405d-dc45-49a0-a06b-2f19b11a93ec
Global\3a2b0db3-a593-430b-aad4-90a00f320cf3
Global\82983da1-f57f-4308-a3b3-b799832bb270
Global\fc9744e3-2740-4711-acb0-b35559ff0afa
Local\SM0:6904:120:WilError_03
Local\SM0:6904:304:WilStaging_02
Global\b5b13657-6e62-45ea-83d2-d941d97e8ec0
Local\SM0:2272:120:WilError_03
Local\SM0:2272:304:WilStaging_02
Global\c295b834-32e0-4bcd-91e5-ea497bd2ad52
Local\SM0:684:304:WilStaging_02
Local\SM0:3940:304:WilStaging_02
Local\SM0:3940:120:WilError_03
Local\SM0:4100:304:WilStaging_02
Local\SM0:5688:304:WilStaging_02
Local\SM0:6396:120:WilError_03
Local\SM0:6396:304:WilStaging_02
Global\0c25183f-ec97-4180-9e55-33b26529925e
Local\C9E8AF12-FA27-4748-EC04-38CA71239739_RegisterDevice
Local\SM0:5864:304:WilStaging_02
Local\SM0:5864:120:WilError_03
Local\SM0:5652:120:WilError_03
Local\SM0:5652:304:WilStaging_02
Global\7d33d272-a6a1-45be-a571-75d3d58db287
Local\SM0:6108:304:WilStaging_02
Local\SM0:3968:168:WilStaging_02
Local\SM0:3292:304:WilStaging_02
Local\SM0:5020:168:WilStaging_02
Local\SM0:1012:304:WilStaging_02
Local\SM0:3700:304:WilStaging_02
Local\SM0:3700:120:WilError_03
Local\SM0:292:120:WilError_03
Local\SM0:292:304:WilStaging_02
Global\d31a6aa3-12a8-4e4b-8264-1cbdf8bc0192
Local\SM0:836:120:WilError_03
Local\SM0:836:304:WilStaging_02
Global\c247b10f-4748-4c08-b20e-edba76013b6f
Local\SM0:1488:168:WilStaging_02
Local\SM0:1128:304:WilStaging_02
Local\SM0:6532:168:WilStaging_02
wbengine
wuauserv
lfsvc
camsvc
WaaSMedicSvc
BITS
wisvc
DevicesFlowUserSvc_1d7e26
smphost
No results
Sorry! No behavior.
Sorry! No strace.
Sorry! No tracee.

No hosts contacted.

No TCP connections recorded.

No UDP connections recorded.

No domains contacted.

HTTP Requests

No HTTP(s) requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No Suricata Extracted files.
Sorry! No dropped files.
Sorry! No CAPE files.
Sorry! No process dumps.
Sorry! No process dumps.