Analysis

Category Package Started Completed Duration Options Log(s)
FILE exe 2025-06-12 04:01:12 2025-06-12 04:32:02 1850 seconds Show Options Show Analysis Log
procmemdump=1
import_reconstruction=1
unpacker=2
norefer=1
no-iat=1
2024-11-25 13:37:15,116 [root] INFO: Date set to: 20250611T16:55:40, timeout set to: 1800
2025-06-11 17:55:40,815 [root] DEBUG: Starting analyzer from: C:\tmp_gell1p8
2025-06-11 17:55:40,815 [root] DEBUG: Storing results at: C:\uyHCokWh
2025-06-11 17:55:40,815 [root] DEBUG: Pipe server name: \\.\PIPE\IpEgLKC
2025-06-11 17:55:40,815 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32
2025-06-11 17:55:40,815 [root] INFO: analysis running as an admin
2025-06-11 17:55:40,815 [root] INFO: analysis package specified: "exe"
2025-06-11 17:55:40,815 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-06-11 17:55:41,096 [root] DEBUG: imported analysis package "exe"
2025-06-11 17:55:41,096 [root] DEBUG: initializing analysis package "exe"...
2025-06-11 17:55:41,096 [lib.common.common] INFO: wrapping
2025-06-11 17:55:41,096 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation
2025-06-11 17:55:41,096 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\WFS.exe
2025-06-11 17:55:41,096 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-06-11 17:55:41,111 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-06-11 17:55:41,127 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-06-11 17:55:41,127 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-06-11 17:55:41,393 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-06-11 17:55:41,440 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2025-06-11 17:55:41,471 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-06-11 17:55:41,471 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-06-11 17:55:41,487 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-06-11 17:55:41,487 [lib.api.screenshot] ERROR: No module named 'PIL'
2025-06-11 17:55:41,487 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-06-11 17:55:41,487 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-06-11 17:55:41,487 [root] DEBUG: Initialized auxiliary module "Browser"
2025-06-11 17:55:41,487 [root] DEBUG: attempting to configure 'Browser' from data
2025-06-11 17:55:41,502 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-06-11 17:55:41,502 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-06-11 17:55:41,502 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-06-11 17:55:41,502 [root] DEBUG: Initialized auxiliary module "DigiSig"
2025-06-11 17:55:41,502 [root] DEBUG: attempting to configure 'DigiSig' from data
2025-06-11 17:55:41,502 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2025-06-11 17:55:41,502 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2025-06-11 17:55:41,502 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2025-06-11 17:55:41,643 [modules.auxiliary.digisig] DEBUG: File is not signed
2025-06-11 17:55:41,643 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2025-06-11 17:55:41,643 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2025-06-11 17:55:41,643 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-06-11 17:55:41,643 [root] DEBUG: attempting to configure 'Disguise' from data
2025-06-11 17:55:41,643 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-06-11 17:55:41,643 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-06-11 17:55:41,643 [modules.auxiliary.disguise] INFO: Disguising GUID to 9b7cdcea-e4d9-4c24-8a0c-bc615bd315ed
2025-06-11 17:55:41,643 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-06-11 17:55:41,643 [root] DEBUG: Initialized auxiliary module "Human"
2025-06-11 17:55:41,643 [root] DEBUG: attempting to configure 'Human' from data
2025-06-11 17:55:41,643 [root] DEBUG: module Human does not support data configuration, ignoring
2025-06-11 17:55:41,643 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-06-11 17:55:41,643 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-06-11 17:55:41,643 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-06-11 17:55:41,643 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-06-11 17:55:41,643 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-06-11 17:55:41,643 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-06-11 17:55:41,643 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2025-06-11 17:55:41,643 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-06-11 17:55:41,643 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-06-11 17:55:41,643 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-06-11 17:55:41,643 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-06-11 17:55:41,643 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-06-11 17:55:41,643 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696
2025-06-11 17:55:41,674 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmp_gell1p8\dll\696.ini
2025-06-11 17:55:41,674 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2025-06-11 17:55:41,674 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2025-06-11 17:55:41,674 [lib.api.process] INFO: Option 'unpacker' with value '2' sent to monitor
2025-06-11 17:55:41,674 [lib.api.process] INFO: Option 'norefer' with value '1' sent to monitor
2025-06-11 17:55:41,674 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2025-06-11 17:55:41,674 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-06-11 17:55:41,674 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp_gell1p8\dll\pQxbIz.dll, loader C:\tmp_gell1p8\bin\EPCPTrhb.exe
2025-06-11 17:55:41,737 [root] DEBUG: Loader: IAT patching disabled.
2025-06-11 17:55:41,737 [root] DEBUG: Loader: Injecting process 696 with C:\tmp_gell1p8\dll\pQxbIz.dll.
2025-06-11 17:55:41,752 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'.
2025-06-11 17:55:41,768 [root] INFO: Disabling sleep skipping.
2025-06-11 17:55:41,768 [root] DEBUG: 696: Full process memory dumps enabled.
2025-06-11 17:55:41,768 [root] DEBUG: 696: Import reconstruction of process dumps enabled.
2025-06-11 17:55:41,768 [root] DEBUG: 696: Active unpacking of payloads enabled
2025-06-11 17:55:41,768 [root] DEBUG: 696: CAPE debug - unrecognised key norefer.
2025-06-11 17:55:41,768 [root] DEBUG: 696: TLS secret dump mode enabled.
2025-06-11 17:55:41,768 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542
2025-06-11 17:55:41,784 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable
2025-06-11 17:55:41,784 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0
2025-06-11 17:55:41,784 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF8247F0000, thread 3468, image base 0x00007FF60D500000, stack from 0x0000008EFAA74000-0x0000008EFAA80000
2025-06-11 17:55:41,784 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe
2025-06-11 17:55:41,799 [root] DEBUG: 696: Hooked 5 out of 5 functions
2025-06-11 17:55:41,799 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-06-11 17:55:41,799 [root] DEBUG: Successfully injected DLL C:\tmp_gell1p8\dll\pQxbIz.dll.
2025-06-11 17:55:41,799 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe>
2025-06-11 17:55:41,799 [root] DEBUG: S <truncated>

    

    

    

Machine

Name Label Manager Started On Shutdown On Route
win10-2 win10-2 KVM 2025-06-12 04:01:12 2025-06-12 04:31:42 none

File Details

File Name
WFS.exe
File Type PE32+ executable (GUI) x86-64, for MS Windows
File Size 928768 bytes
MD5 8e8507b0c0c16f1698a24bfd038ea54d
SHA1 75e7b9572eba6c56b471f77d312ee5109942fbec
SHA256 8fbac98180bcf2d79ccea364f3d7e1301e1592727b99c712b1db5e2e50a7bf25 [VT] [MWDB] [Bazaar]
SHA3-384 386972be224ccb303d604ee5ab3bf1d9dbe9c1c67ff2d4ffbe3d16281ab2d6de1c1d7058cafb648ff0e93cac86473bd4
CRC32 64EF75B4
TLSH T1AF154BC9F79C80D4D86AC13A85179B5AE672BC151F6183CB1235B63E2F33AE64E39311
Ssdeep 12288:p1rNsTOtu0K0ZNY2cXxnedaK5Hp5GUlDY+xt4vFe:X05BU5G+evFe
File BinGraph Vba2Graph VirusTotal

E9,$v8H
fD9$Fu
MemAlloc() failed, size=%d
l$ VWATAVAWH
x0x#g
KJdA>z
@.data
D$hE3
}GGM~~
GdipGetImageHeight
%wgSrRA
HrNewFaxComposeUIFromFile failed with %d
SVWATAVAWH
D$,D+
MemAlloc failed with 0x%08x
D$0A9x
RevertToSelf
IsDlgButtonChecked
.?AVCServerNode@@
CAuthorizationDlg
_cS0'*
5TT@951'!
AddItem
.?AVCAuthorizationDlg@@
GetMenuStringW
ReleaseMutex
GetStartupInfoW
x ATAUAWH
U9=TTJr@TTLLLLLTLTrL
wwvwp
3?<:p<==
RK^;%
;@GGGGGG
CMainFrame::CreateDynamicView (Inbox)
fD9DDPt&A
CreateSemaphoreExW
UHsuuyuuuu~vtvtttttttrr
{RXT*KkV
.?AVCInboxDetailsPg@@
u*9Q<|%
+FGFMQK3I.DGDD9
fxsutility.DLL
f;\$ u/
CheckRadioButton
_wsplitpath_s
trRRPswx
InboxView
SHGetDesktopFolder
HrFreeDraftsListViewInfo
ScanView
w;<$5-
Or/dg
gwswW
F0A9x<
CString::operator=
EndDialog
__RTDynamicCast
LX)W0
SetCursor
RegSetValueExW
s(y8696>6>
PrintDlgExW
wvRRSgGu45
StatusBar
CopyFileExW
$4yJ(RFs
L$HE3
WFS.hlp
H9G8H
Wxwgww|wwwwww
list<T> too long
</security>
!!'1(5222(!
|$ ATAUAVH
GdipGetDpiX
L$2E3
DeleteFile failed with %d
SUB_ITEM
HcD$@H;E
y<<9T
SendToFaxRecipient
9D$0u
GdipGetDpiY
4!&YB
+J}x,,9899999=
H!\$ E3
xgwwwwp
H AVH
CMainFrame::CreateDynamicView (Incoming)
FGetComponentPath
-&!UU
CFaxAccounts::SetDefault failed
VWAVH
m_cpList.GetHeaderCtrl
PA_A^A]A\_^[
H!\$XH
L$xH3
5X)Y)W
f94Gu
J,89=<=<==<===
o\$PH
1l2~A
x]E;V
.?AV?$CList@VCFilterInfo@CTablePanView@@AEAV12@@@
StiEvent:
Microsoft Corporation
fD9,Qu
.?AVCSecureSimpleString@@
StringDup failed
D!t$$H
type="win32"
Bd@`<
u%A8h)t
OutputDebugStringA
SortAscending
_XcptFilter
9_8vVL
wwwwwx
_lock
image/tiff
98<=====A=A=AA<A
GetNameInfoW
USVWATAUAVAWH
.?AVCFolder@@
CListView::InsertItem
.?AVCTablePanView@@
FormatMessage
FaxUnregisterForServerEvents
CRenameFileDlg
25&Y&
G(9X@t3
.?AVCScanFolderDialog@@
SysListView32
FaxRegisterForServerEventsEx
wO&82@
ClientToScreen
WS2_32.dll
t.HcC<
vxvwwwwwwwww
@SUVWATAUAWH
CListBox::GetSelItems
D$pJ9
%s %s
ATL.DLL
G__N_z`N_YYY}Y
_initterm
Initialization of CFaxAccountConfigUI failed!
.?AVCMenu@@
.?AVlogic_error@std@@
WSAStringToAddressW
CFaxAccounts::Delete failed
tdD8i
.idata$5
X,133<3=v
Preview
LoadLibraryW
AddLocalFaxPrinter failed
T .SVY#sX
inbox
AfxGetMainWnd failed
*.xps
CFolderListView::SaveLayout
LoadDIBImageList
t99uot4H
InvalidateSubFolders
h UAVAWH
k(fD9l$@t
CServerNode::GetActivity
xgwwwwwww
.pdata
wcschr
Microsoft
_wcsnset
image/jpeg
GetNumberFormat
e@S"0F
l$ VWATH
wwwwww
I9:u)A8h)t
CListView::SetItemText
gJJV>V{
ListCtrl::SetItemText
H$3U}K,8699999<8v
5EN(566
OR`pi0SG
GdipDeleteGraphics
Scanned Documents\
.didat$2
?trrxrntn
E(A=~9z
IsItalic
AddPrinterForAccount failed
SetMenu
629oy
E;~8r
Invalid item
.?AVCAtlException@ATL@@
A^A\_
0A_A^A]A\_H
CFolder::Refresh
89=@J@T=L@L@L@AAAT
I~~~{~x{
cTSUU
.data$r$brc
A^A]_^]
D;|$8H
9\$htQH
D;d$x
GetMessageW
DeletePrinter
ScanSetting.DLL
wwwpwpxx
LoadLibraryA
e0L9a
TIFImage.Document\shell\printto\command
GKNNNNNNYY_YY
SetEvent
CopyFile
wxVwwwww
SleepConditionVariableSRW
_exit
},89<=<=<=<====
bqeI|
H_^][
fxscover.exe
PathIsUNCServerShareW
SHFileOperationW
$483A
0A^_^
.?AVCOutBarCtrl@@
uys39
<6i.H
.?AV?$CArray@PEBGPEBG@@
gwvww
GetSpecialPath failed dwRes=%d
.?AVCCmdLineInfo@@
wCListCtrl::InsertColumn
GetFileTime
OutboxView
%hs!%p:
.?AVCDialogBar@@
wwgwV
MSIOfficeLCID
K SVWH
)=rwH
Allocation of CFaxAccountConfigUI failed!
)HwI3
D9t$T~
0A_A^A\_^
LoadIcon
wxgwx
SOFTWARE\Clients\Mail
p WAVAWH
map::operator []
M9,$t,L
L#1,(5
i3@PE>
%SystemRoot%\system32\fxsresm.dll
;\$Hr
RegQueryInfoKey() failed, ec=%d
.tls$ZZZ
.?AVCRenameFileDlg@@
CoCreateInstance
vxwwwwwww
GetCommandLineW
6L9uht
t!@8y
$|=Kg
pA^A]A\_^[]
wwwwwwp
!t$xH
GetSpecialPath failed err=%ld
GetMenuItemCount
uK!D$ A
CMainFrame::OnToolsOptions
GetFileAttributesW
.?AVCPropertyPage@@
A_A^^
lxvvbljjJRPP!
t"L9q
DLLPathEx
aEMM_NNNNNNYN
AddStrToList
0x%016I64x
.rdata$r
f9,Ku
]GR`:
.?AVCIncomingDetailsPg@@
xxxxwt
SortAscendingScan
$,U}}83998<8<=<<=<z
ImageList_ReplaceIcon
wvwap
t"D8y
CIncomingDetailsPg
q/,*-
.CRT$XIA
@8j)t
GdipDisposeImage
A\_^][
@A^^[
Archive
|$(E3
H!\$HH
DispatchMessageW
D$DDtRH
hA_A^A]A\_^][
xxxwxw
W=Js}
C$9GH
fA9,Au
CFolderListView::AddMsgMapToView
f;|$`u
wgwwwgwwwp
-q)9h
DestroyIcon
9HrrrUrrrrsrrrrrrrrrr
45AAAE
Explorer
ImpersonateLoggedOnUser
x UAVAWH
LoadMenuW
.?AVCFrameWnd@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
{H0tQ
SetWindowLong
XA_A^A]A\_^][
t$ UWATH
-cNre
FileDescription
n==n}
3fIZf6
GetLocaleInfoEx
1S0z=[n.
CJob::UpdateStatus
ConfirmItemDelete
ttppnki[
CFolderListView::OpenSelectColumnsDlg
*.dib
wwwwpww
yi>1..11#
FXSTIFF.dll
CryptProtectData
\$ VWAVH
UWATAVAWH
PlaySoundW
</asmv3:application>
}TT4V
RefreshServerList
9\$Hv#
ntdll.dll
0A_A]A\_^][
{hU>##
MSFaxConsoleTempPreview-#
10.0.17763.1
SetWindowPlacement
CSetUpRoutingDlg
Created new fax registry key, ec=%d
InitializeCriticalSection
WakeAllConditionVariable
A_A^A\_^
xxwwp
SetWindowLongPtrW
AAjTjTjj
.?AV_com_error@@
{(f9|$ t
CDraftsFolder::GetDraftsFileName
CFolder::InvalidateContents
D$TE3
SetWindowLongW
CreateFolders
new CPropertyPage
gwwWww
F8EGEGG
A_A\_
LoadImage
Fax Save Path
version="6.0.0.0"
?;KO}
@0CwWwx
L9gPH
.?AVCFont@@
D$(E3
C$u'H
.?AVCFaxDoc@@
xghtTw
=+386869=y
message
originatingContextName
0A_A^_^]
.?AVTraceLoggingProvider@wil@@
Allocation of pFaxAccounts failed
)t$@H
D$(H!|$ E
pH@gg
WinHelpContextPopup
wwxww
g`ier
CStringArray::Add
http://schemas.microsoft.com/cdo/configuration/sendusing
CHeaderCtrl::SetItem
C0-1U:!
memmove_s
t=D8x
Microsoft.Windows.Shell.FaxScanApp
Microsoft-Windows-Fax-Common-EnableServerPolicy
.rdata$zETW9
%d.%d
CString::Format
.?AVCClientConsoleApp@@
.?AVCErrorDlg@@
UVWAVAWH
GetSysColor
L$0E3
L$8H3
H9X t
L9t$`
919gz
tJ@8x
FontColor
UATAWH
A_A^A\_]
H9t$Pu
;|?f((
H9w H
wwwwwwwwwwp
OBj6R~cd
CMainFrame::SaveSenderInfo
FaxGetQueueStates
xwge456wu'%
GC%$&&J\\
LoadResourceString
.?AVCListView@@
977m%##
TerminateProcess
t'@8y
There's already a connection with this name
wwwxw
f9,Au
D;|$@|
}Lr`@
*.tiff
@8x)t
9GGHGGGKG
qhhjq
.?AVCGdiObject@@
new CSingleDocTemplate
D$J9]
.?AVCViewRow@@
%s %s %s
CViewRow::InitExtStatusStr
Server
UpdateLineTextAndIcon
\$ A;
.?AVCListBox@@
|$$E3
rttt<61
.?AVCPersonalInfoPg@@
PathRemoveFileSpecW
CFolderListView::RemoveItem
Active
SHSetLocalizedName
(373(
Failed to open Simple MAPI registry key
CViewRow::AttachToMsg
CreateFile failed: %d
VGGH**
b8"M((a
FindNextFile failed
@A_A^A]A\_^[
UpdateData
0A^A\_
PA_A^A\_^
CFaxMsg::GetTIFF
F0~`\
GetModuleHandleA
.text$x
%systemroot%\system32\
AfxGetApp failed
CListCtrl::SetItem
CServerNode::OnNotificationMessage
T$ E3
_wtoi
CIncomingGeneralPg
-:(}@
wwwwxx
CFolderListView::GetSelectedItem
CoverPageDir
wwgwg7wwV6
SetDlgItemTextW
Send to fax recipient: Invalid command specified
[I7`BM
.xdata$x
L$HH3
t$ UWATAUAVH
uj9qDteH
WATAWH
6((('<
Can't create DefaultValue since it's NULL
A^_^
CListCtrl::InsertItem
GetModuleHandleW
Wvwvwgww
(<Uy}
MoveFile
FaxSetJob
GetTimeFormatW
.?AVCNavigationBar@@
.?AVCWaitDlgThread@@
RegQueryValueEx() failed, ec=%d
COutBarCtrl::Create
RefreshState
L$ E3
H!w H!w
``@@`Dt0Q
CTreeCtrl::InsertItem
.CRT$XLZ
.giats
kernelbase.dll
VAVAWH
.rsrc
L2(16LL@o>z
!t$ L
%I64d
SystemTimeToFileTime
v,(1((@
#!Lr+
gxwgwwwwwwp
(-8U
SHRFAX:
A^A]A\_^
%d%s%02d%s%02d
0A_A^_
OriginalFilename
D;d$X
CServerNode::InvalidateSubFolders
Software\Microsoft\Fax\Setup
DefaultAccount
d$0E3
r9<Lt
xwxxwxp
H9t$@u
GdipDrawImageRectRect
y[B0W
FileTimeToSystemTime
\$PH;_
D$0+D$(
ToolBar
H!\$xH
Server =
FaxRemoveMessage
FindFirstFile
t'@8x
OE@e@
fD94Au
A_A^A]_^][
GwvWuvugp
pnOrderCheck = new int[m_dwListSize]
D!D$HH
%I64x
PCTreeNode
G'O;xn
GetFullPathNameW
a(H,Js
wwwwwwvRx
txwwwwxwww
a_}{{{{{~{}}}`}}
k(fD9l$Pt
wwwwp
EnableWindow
pFJ0`
L$0t=
GetFileType
||||yyyvvyv
PropertySheetW
map::erase
UVWATAUAVAWH
a9EGGGGG
CreatePropertySheetPageW
.?AVCOutboxDetailsPg@@
ImageList_LoadImage
CloseHandle
L$8E3
@A__^
H9\$Ht
xxwxwxww
ta@8x
CFaxDoc::RefreshServersList
@.reloc
CMessageFolder::Init
swscanf
t&@8y
@`5`U
CServerNode::Disconnect
0A_A^A]_^
HA_A^A]A\_^[]
ReceiptAddress
0x%08X
FaxGetMessageTiffW
<||{$
VirtualProtect
_purecall
AfxFormatString2
i@Yy0F
hA^_^[
D9K(t
failureCount
GetSystemTimeAsFileTime
SHGetValueW
.?AVCControlBar@@
m_SentItems.StopBuildThread
HUyyyyyyy|yyyyvyvvvvvvtv
,H}x,,98999=89<z
A__^[]
A^_]
mshelp://windows/?id=68991cc9-cb2b-45c5-9c7b-6ad629e39a4d
t/@8x
F,9^(t
IsIconic
SendTo
Inbox
H!|$
fD;tDNu
.?AVCDialog@@
:9@E@@
H!\$(H
xrgcstrAttachments.Add failed
L______L
g;.O}
qy2$y
CListView::InsertColumn
G855G
NULL pComposeUIArgs passed
??0exception@@QEAA@AEBQEBDH@Z
.?AVCPreviewPaneView@@
CQueueFolder::Init
CharNextW
%s (%d)
SetUnhandledExceptionFilter
wcscmp
xxggwv
~e,VB#H
GlobalActive
"]8sN&
D$ E3
.text
%TEMP%
%s\shell\printto\command
MAPISendMail
wvvvvw
.?AVCLeftView@@
NG>Gzz}}
wxxwxxwwwxw
Alternate
AddPrinterConnection failed
SendMessageToElevatedFirstInstance failed with 0x%08x
.rdata$brc
d$XA;
SetWindowPos
@USVWATAUAVH
SystemTray_Main
Error in allocating m_scstrDraftsFolder
vwwwgwwevp
olqqqqqnnniw
I48:AA
originatingContextId
&'A.f
bSucceeded
.?AVCFaxTime@@
xxxxxx
WAUAVH
GetDlgItemTextW
Error %d: new failed for pFaxReassignUI in OnFolderItemReassign.
WinHelpW
.?AVCClientConsoleDoc@@
!3Ab`w
9|$@~=H
D$@fD90t
t'@8h
|$@H!t$8!t$0!t$(!t$ E3
COMDLG32.DLL
D9t$T
Can't read 64-bits message id from input string
A_A^A]A\_[]
s WAVAWH
wwwwwxx
n<f9]
u-I9q
Scanned Documents
FaxRegisterForServerEvents
FaxFreeSenderInformation
D9u0v(H
SVWATAUAWH
%s\%s%s%I64X.%s
A_A^A]_^[
LocalAlloc
D$HFt5H
(377(((3s
9\$pu
.idata$4
%s.%d.bmp
new CString[dwCount]
FaxAccessCheckEx
! I7d
A_A^A]A\^[]
FaxEnumAccounts
.?AVCProgressBar@@
xwwwwwwww
C_PrintDialogEx
YoeCOutBarCtrl
.rdata$T$brc
GdipGetImageVerticalResolution
n"Pu`
.?AVCListCtrl@@
__dllonexit
NormalPosTop
D8A)t
D8X(uTE
C(L9%A
RegEnumKeyExW
D$pEk
GetStringTypeExW
D$XA9X
MFC42u.dll
.?AVCFaxDuration@@
87u$ew
ZW-fmllflfffecbaa^^ONEd
wxwwxwwxw
mmKK|
T$PI+
`Mccn#f
SHGetMalloc
L9 t"H
COMCTL32.dll
vJRR3
9D$pt
,$($-HH7$*U
InSendMessage
L5((5<o@<<<@T
sJuyyyyyyu|uy~vvvvvttrtt
gwwwwww
HcD$ H
o{{{{{zzzsszz
>(aPQ
Kernel32.dll
=.#1=n
.?AVCIncomingGeneralPg@@
__C_specific_handler
@USVWAVAWH
f9<Au
.?AVCTime@@
FaxAccessCheckEx2
F+55}
CFaxDoc::Init
TraceMessage
fhfcb`^]NNDEM
tsqlkih[Od
m_Outbox.StopBuildThread
a5@E@}
text/plain
xvwWp
0A_A^A]A\_^]
InstalledComponents
OpenPrinter failed
@SUVWAUAVAWH
6>=G=KGG=
9|$4u
t"@8y
wwwwwwwwwww
K/wD5
H!\$P
D$p;t$xr
MakeDirectory failed dwRes=%d
|$@E3
D$PH!\$X!\$`!\$hH
fD90t
.?AVCPrintDialog@@
d$8A9
onnnn
%s\%s
CoGetObject
.?AVCFaxOptionsUI@@
xxxxwpp
CreateEventW
H!\$@H
wpt5!@4w
*.tif
+T$hL
|$ AVH
LoadLibraryExA
|$xL!t$`L!t$XH
DeleteObject
Allocation of FAX_ACCOUNT failed!
.text$mn$00
t$ WH
fD91t+f
guwWwwwp
SetLastError
xxxxww
xhwwwx
CListBox::InsertString
H95Eq
L9g@H
fA9,Su
.rsrc$01
|<v<m"
CallContext:[%hs]
}oHcO
DebugBreak
vxwwwwgw
t f99t
USVWAWH
wwvwwp
f9l$0uGH
tG!\$8L
CFaxMsg::DoOperation
OinS|<
A_A^A]A\_^[]
<26ry
L!0L!p
Authenticate
A_A^A]
:}L2XT\)y
WfsR.dll
L9gHH
D;u0r
*.jpe
L9g`H
rCFolder::StopBuildThread
u!D9E,u
FindNode failed
CoInitialize
8Y)u 9y
H9w`H
RegEnumKeyW
N;GGGGGGff
zi92#####
GetWindowRect
GetTraceEnableLevel
wwwwwrwWsp
.?AVCHostApp@@
http://schemas.microsoft.com/cdo/configuration/sendpassword
ServerCoverPageDir
Memory allocation failed for composeUIArgs.lpwszAccountServerName
Vk=Gf
_CxxThrowException
D$xfD
WINSPOOL.DRV
SHFileOperation
D95q!
IsWindow
GdipGetPropertyItem
.?AVFaxScanAppLogging@@
Software\Microsoft\Fax\FaxAccounts
'/0/!H
.?AVCButton@@
LeaveCriticalSection
L$ USVWAVH
tW@8y
EnumUILanguagesW
FaxGetSenderInfoW
wvRSWe4
z|%CDraftsMsg
bUpxwwvuummjj[Z
<'&$r`[W
LaunchComposeForm::OleInitialize
t*H;]
StringDup() failed.
|$ AWH
ReceiptType
GetTraceLoggerHandle
S(u&H;
SplitterPos
.?AV?$CArray@VCScanInfo@CSetUpRoutingDlg@@V12@@@
LaunchFaxConfigUI failed with 0x%08x
Microsoft Corporation. All rights reserved.
f{,aN
CredUIParseUserNameW
.?AVexception@@
+eRh4~
FaxConnectFaxServer
callContext
L$PH3
RegQueryValueW
U5?_~
0A_A]A\
CListBox::DeleteString
http://schemas.microsoft.com/cdo/configuration/urlgetlatestversion
.?AVCInboxGeneralPg@@
wwwwV
GetDateFormatW
9T$0H
t$ UATAUAVAWH
^(f9\$ t
.text$yd
IsWindowVisible
9{0v1H
L9|$HtH
<226LrrT@@@A
@A^A]A\_^
GetWindowLongPtrW
CreateDirectoryW
m_pMainWnd is NULL: %0x
CListBox::SetItemData
(26623
L$@H!\$ L
D$P;|$Xr
X7 U57
GroupBroadcastReceipts
WATAVH
hz_T>
FaxEndMessagesEnum
comctl32.dll
LcA<E3
@USVWAUAVAWH
;t$(|
wwxxwww
9\$xv
CFolderListView::UpdateSortedItem
CServerNode::StopBuildThread
D;t$T|
SetCapture
VirtualInbox\WelcomeFax.tif
GdipImageGetFrameDimensionsList
g1.1=i}
Vw||V
AcquireSRWLockExclusive
<;CArchiveMsg
.?AVCFaxAccountManagerUI@@
Folder
`A_A^A]A\_^]
MsgWaitForMultipleObjects
l$ E3
GdipGetImageEncoders
EpHcH
GetAccountManager()->CreateAccount failed
.?AVCServerStatusDlg@@
e+jux
CFaxAccounts::Create failed
LegalCopyright
nR Q<
!"#&-!
CMainFrame
function
hyUS~h
td%#Wa
L22<LvvvToTt
GdipImageGetFrameDimensionsCount
D$ 9X
Software\Microsoft\DocCenter\Settings
@USWATAUAVAWH
GetSystemTime
GetSaveFileNameW
;KLgKKgggg
GJGMMG-->>7,
VirtualQuery
wsvwp
FaxTimeFormat
,B`v"
<dependentAssembly>
CArchiveMsg::Init
L$ USWH
Error %d: CFaxReassignUI::Open failed!
{9&!!"#!-M
H9Q r!H
UAUAVH
Hc|$X
vwwwx
UnicodeStringToAnsiString failed, hr=%x
@8j(uVD
H!\$0D
H UVWATAUAVAWH
xwwwp
GdipDeleteBrush
@A_A^A]A\_^]
There's already a connection to this server
L$0H3
9\$pt
%s%s%08x%08x.%s
WUUQ)HEE
=TssUssuussrrstrrtrrto
GetMessagePos
CListCtrl::DeleteAllItems
NormalPosLeft
CCoverPagesDlg::DoModal
.rdata$zzzdbg
_vsnprintf_s
Columns
@8j(uYD
xigg_
hA_A]A\_^[
E[$`^
LoadString
LoadStringW
@8h)u
D!d$PL
WAVAWH
"+8K}
realloc
.rdata
FontSize
??1type_info@@UEAA@XZ
??0exception@@QEAA@XZ
RegDeleteKeyW
StiDevice:
A_A^_^[]
wGwwp
xwxwxw
CClientConsoleApp::SendMail
%d pt. %s, %s
ShellAboutW
wcsstr
D$$I;
.?AVCStatusBar@@
<assemblyIdentity
~K85*%?
x AWH
fD9,Au
pA_A^A]A\_^[
H;\$h
ImageList_Create
t9li3]
xxxxxw
GdiplusStartup
CPreviewPaneView
L$ H!\$X
t$HE;
WaitForSingleObject
D$@A9X
RtlInitUnicodeString
Lqssqqwnnnqn
HrDeInitAddressBook
GetRegistryString returned NULL
CListBox::GetCount
.?AVCMessageFolder@@
PostMessage of WM_DO_PUSHSCAN Failed
A__]
CNavigationBar
@VWAUAVAWH
wvwCW
4~,W4
vtTrv
@A_A^]
HrInitAddressBook failed: %0x
GetModuleFileNameA
D8p)t
H!\$@D
x;L!t$ L
CReBar::Create or CReBar::GetReBarCtrl().GetBandInfo
qgH@G
MessageBoxW
.?AVCFaxClientDlg@@
SVWATAUAVAWH
OpenRegistryKey
CString operator =
D|$0H
0A_A^A\
wwwwwp
aK{}}_Y``}N}N_Y
\*.tif
print
H!0H!p
CMenu::TrackPopupMenu
DeleteMenu
HrInitAddressBook
ffcfggpuqmmjj[s
t]D8y
memcpy
SetForegroundWindow
.idata$3
.?AVCWnd@@
[Y71|
H!\$0H
wvpqcw%
<GfD97t
GdipSaveImageToFile
yy|||yyyyvvvvtttv
.?AVCColumnSelectDlg@@
.?AVCStringArray@@
GenerateUniqueFileName failed
utf-8
.?AVCDraftsMsg@@
u7`98Qfe
.didat$5
outbox
xxwxwp
RtlDllShutdownInProgress
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
CTablePanView
YB822>>B>B>0#
H98u0A8h)t
xwxww
t7D!g
\Fax\Inbox
string too long
i )p7
SHGetFolderPathW
.?AVCOutboxGeneralPg@@
SyncFolderNode
FindInsertionIndex
k VWAVH
F09x@t3
.?AVCSetUpRoutingDlg@@
GetDefaultProfileScan
ExpandEnvironmentStringsW
l{zzzssssnqn
'wuw5cWp
@8=>W
DeleteFile
.?AVCCmdTarget@@
+$%#cTST
SetFileTime
(_^][
|$0+H
__setusermatherr
UATAUAVAWH
@8=bW
fA91t
xxxwt0
HeapFree
invalid string position
UWATAUAVH
CItemPropSheet
@A_A^A\_^
PA^_^[]
HrNewFaxComposeUI
~~~~}}
currentContextId
http://schemas.microsoft.com/cdo/configuration/smtpserver
GetTickCount
D9t$4t
Hvwwwp
T~~~~~
B9\$`H
sJ93($$3J
fD9,_u
A^_^H
@8|$0
L$@E3
$pwwx
OJ6@@Z
DebugLevel
.CRT$XIY
hhhcac``^^]NY
9|$pu
A^A]A\_^
CToolBar::CreateEx or CToolBar::LoadToolBar
.?AUIHostApp@@
L$@H3
PostMessageW
.1,"#,12>.#
CListCtrl::SetColumnOrderArray
V(ZB`L
.?AVCJob@@
CMainFrame::OnToolsAccounts
D9t$8
GdiplusShutdown
zvrrL
U-<====A==A=A=AAA
[IG,8<T
D$p+L$XL
D$@L#
`A_A^A]A\^
T$`H+
xw9\$huwI
CViewRow::InitStatusStr
|$4D;
new CArchiveMsg
a:KM_KKKLLLN
GdipDrawImageRect
T$`E3
!#>N~
UWAVH
]'wD5
.?AVCMainFrame@@
MultiByteToWideChar
agwwww
AfxFormatString1
A_A^A\
@VWAVH
/vT2*Bi/
\$PH;
WinPrint
EventSetInformation
Software\Microsoft\Fax
MessageId
Order
GdipCloneImage
"+8U}
43AE?SD
L9ghH
UWAUAVAWH
!\$(E3
OutputDebugStringW
%s\%s\%02d
Memory allocation failed for lpszTemp2
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
UnregisterTraceGuids
CreateProgressBar failed with 0x%08x
@A_A^A]_^
hcPFB
L;P@u
@SVWAVAWH
~}YNKGG>>
fD9$Qu
pFaxAccountConfigUI->Open failed
ReturnHr
_itow
=,<========A=AAz
SHELL32.dll
StringCbCopy failed, hr = 0x%x
CReBar::Create or CReBar::GetReBarCtrl().SetBandInfo
D8`)t
D$0H9
hjllq^^
IJG<4
Communications
SortColumn
FaxAccountName
t$hI;
vJr]j
!')1121)
@A^_]
GetY2KCompliantDate()
/A" #1
",8U}
A^A\]
CopyTiffFromServer
ZCOutboxDetailsPg
c0?1M'
H! zQPP
U,+8vv
.?AVCWinApp@@
~~~~~~
0123456789 -.#$*,?@!AaBbCcDdPpTtWw()
H;\$P}h
@8,1u
CreateProcessW
=9<n}
NormalPosBottom
A]A\_^]
@SUVWATAVAWH
UWATAUAWH
WATAUAVAWH
VWATAUAVH
\$`D;d$XH
.?AVCTreeViewEx@@
ShellExecuteW
fD9t]
CFrameWnd::LoadFrame
HcD$`E3
j{:;k
&9~n;
A_A^A]A\_
|$ E3
.CRT$XCAA
s25)5
@yxx5rqq&A??
9.4gw}
RegOpenKeyEx() failed, ec=%d
\$ UH
9t$(~GL
CSentItemsDetailsPg
H9w0H
CServerNode::Destructor exception
ADVAPI32.dll
H!\$p!\$xH
L9|$H
.?AVCWinThread@@
Error in allocating szDefaultDir
@SWAVH
@8j(uUD
CreateThread
L9{0t#H
.00cfg
D$@H;G
StringCchCopy
_wcsicmp
%s\CurVer
.?AVCAboutDlg@@
DialogBoxParamW
FreeLibrary
nBPbp
m_pdwColumnsOrder = new int[dwCount]
@SUVWH
MessagesPerCall
<Q|YD
FailFast
w``vwww
GetDraftsFileName failed with %d
lstrlenA
vL6LAL<9<3
T$0E3
DuplicateToken
UVWATAVH
\CServerNode
ATAVAWH
EDKKKKNKLNK
%SystemRoot%\system32\wfsr.dll
@A_A]_
SafeGetModuleFileName
y>31((1,21262<551)!
CompanyName
invalid map/set<T> iterator
D$`I;
trtt5
O8D9a4u>H
GetCurrentThreadId
@A_A^_
xxwxw
IsUnderline
FaxSetJobW
4eP]
aGNNzN_YYYYYYY
GetFrm
_wcsicoll
!!!#!!>
0A_A^A]A\]H
*.jpeg
u HcA<H
@SVWATAUAVAWH
FreeAddrInfoW
C 9GD
.?AVCDocument@@
wxxxw
@@DiN
GetProcessHeap
V9GGGGKGN
Sleep
CFolderListView::AddReassignInContextMenu
ONM<jjiw
LoadString(IDS_PROGRESS_NUMBER)
SetDefaultAccount failed
L56Lv
SOFTWARE\Clients\Mail\Microsoft Outlook
GetTextExtentPoint32W
@A_A^A]A\_
GetFocus
L$`;t$T|
t$ UWATAVAWH
.?AUIProgressBar@@
wwwt7
%+%)g
H9_ s
ShellExecuteExW
A9~8v%I
!\$hL
$6Www
GdipGetImageWidth
StrTrimW
{ AVH
vwwrvwwwp
7f@o,V
ChooseFontW
`A_A^A\^[
T$0H+
WSAAddressToStringW
oT$@f
RefreshFolder
Microsoft Outlook
fD9$wu
RegOpenKeyExW
iswalpha
H9_Hs<
0A_A^A]
ReleaseSemaphore
(%d)
l$@E3
vwxwwwwwww
Wfs.pdb
!-.77E{
H!\$pH
t$PH9
wxwww
FindFirstFileW
_wcsnicmp
AfxFindResourceHandle
Failed to create toolbar
~~~~~~}
L9gpH
.?AUIUnknown@@
h~0COutboxGeneralPg
PA_A^A]A\_^]
fB94@u
0A_A\_
GetObjectW
SHGetFolderPathAndSubDir failed dwRes=%d
l$ VWAVH
name="Microsoft.Windows.FaxAndScan"
LaunchComposeForm::(GetActiveDocument())->GetFaxDocument
CSplitterHorWnd::CreateStatic
FreeMessageId
Global
?what@exception@@UEBAPEBDXZ
USVWAVH
D$8H;
f9;ty
.?AVCStatic@@
A^_^][
CString::operator =
ShowReassign
L$ SUVWH
Microsoft-Windows-Fax-Common-DeviceLimit
HcL$P
GetNumberFormatW
CListBox::GetSelCount
MSIApplicationLCID
image/png
FontFaceName
AddSortedItem
FaxEnumJobsEx2
??0exception@@QEAA@AEBQEBD@Z
SHGetPathFromIDListW
wcsrchr
hhhaa_OC
CListCtrl::FindItem
e7:/9
0A^A]A\_]
WaitForMultipleObjects
L9t$hu
YG8.-.2>AB>0#
UATAVH
=M&ca
D$PE3
C_PrintDialogEx::DoModal
@USVATAUAVAWH
AddPrinterConnectionW
Gmmmlnnmgiw
new failed for pdwlMsgIdArray!
wxxxww
CListView::DeleteAllItems
StgOpenStorageEx
U3==@==L=L@LLLALLL
.didat$7
CMainFrame::SetWindowPlacement
(caller: %p)
|ye5f
printto
.?AVCSentItemsGeneralPg@@
y||y|||yyyyvyvvtv
FaxGetSenderInformation
image/bmp
_callnewh
D8X u
StringFromGUID2
@8|$0t
HrInitComposeFormDll
__set_app_type
X UWAVH
9}(vuH
GetListCtrl::GetHeaderCtrl
Width
9GKKKKKKKN
wwwpp`
.?AVCView@@
+D$ H
LoadIconW
MemAlloc failed
GG>BNYYz
.?AVCListViewEx@@
)Eo/86F99
twvugwvp
-138683=v
GetTempPath
AddPrinterW
040904B0
#nmmW
incoming
.?AVCProgressCtrl@@
"=GV#
FaxMonWinClass{3FD224BA-8556-47fb-B260-3E451BAE2793}
=jMg::S
.rdata$zETW2
TiffPrintToAnyPrinter
%s\%I64X.%s
GetFrm returned NULL
fD9$ru
D9|$ t
GdipCreateBitmapFromFile
@USVWAVH
\*.eml
ReleaseDC
wwwww
SetClientCpDir
GetCurrentObject
HcA<H
FT-FJ
`Y3NO4
.?AVbad_alloc@std@@
A_A^A]A\_^]
D9|$@
=IK~#
LoadString(IDS_ERR_MAPI_SEND_FAILED) failed
}}:sqq&caa
PeekMessageW
A_A^]
fA9<Au
T61((('(1(516622(!
SetPrinterW
RedrawWindow
Software\Microsoft\Fax\Client
.?AVCFixedSplitter@@
ParseArguments failed
DetachFromMsg
SHLWAPI.dll
xwwwxp
GetComputerNameW
TranslateMessage
GdipFillRectangle
*.bmp
U=Urstrttrsrrrrrrrrrrr
CUserInfoDlg::DoModal
scansetting.dll
CWnd::GetDlgItem
fA9,Ju
.?AVCSortStringArray@@
GetClientRect
\\%s\FxsSrvCp$
GetLocaleInfo
GetWindowLong
:z\V
{ ATAVAWH
edaNY
wcscat_s
InitOnceComplete
H9whL
L$ +D$XE3
RtlEqualDomainName
wD:H=
81DnDx
ReadFile
.?AVCScrollView@@
nFG`5
U,-383=yz
WideCharToMultiByte
tO@8x
RegQueryValueExW
CFaxMsg::GetTiff
)'15511!
u%o22668
A_A^_^[
@SVWH
VWAUAVAWH
9>vIH
GdipGetImageRawFormat
VarFileInfo
NormalPosRight
_fmode
GetLastActivePopup
SetWindowTheme
&1(|J
$[v^^
ImageList_Destroy
DrawTextW
SUVWAUAVAWH
D$PM+
fD9:t
D$DI!
wwwwwwx
tVD8q
FreePropVariantArray
.?AVCClientConsoleView@@
x,9==========:A=
MyEnumPrinters() failed.
;`pQ]
VWAWH
LcE(3
K4#cgHbr*
CFaxAccounts::GetDefault
CommandLineToArgv
.tiff
FaxGetMessageW
_vsnwprintf
tLD8p
Ikrrnnnnn
D$@Hc
D$(HcH
ResumeThread
PreviewSplitterPos
CScanLeftView
S~&LE
.?AVCItemPropSheet@@
$''+)
0A_A^A]_^][
CreateFileW
FxsCompose.dll
Error in allocating cstrTiffLocation
CopyFileW
CMainFRame::CreateFolderViews
Local\SM0:%d:%d:%hs
MemAlloc for subject failed, hr=%x
InputValidate
vtwwp
%s KB
SUVWAVH
YuH"*
wwwvw7PGvvGxwxhww
USVWATAUAVH
L$PE3
;-IR
2.aCJ#
}}}}}
UxTheme.dll
SLGetWindowsInformationDWORD
SetRect
Memory allocation failed for AfxFormatString1
A^A]]
FormatMessageW
xwxwwwCB
SVWAUAVAWH
version="5.1.0.0"
processorArchitecture="amd64"
}GG1!",.8>8,
:-WKR
Microsoft Shared Fax Driver
module
r(1'12)!
_wcstoui64
FXSAPI.dll
@WAVAWH
wwwt0
base64
<security>
)d[jW
-~}}$[YY
CListCtrl::GetNextItem
CSplitterFixedWnd::AddView
CoUninitialize
<!-- Copyright (c) Microsoft Corporation -->
lgbkztp
ShellExecuteEx
wxwvswswp
A_Yi@
Cp9GL
A_A^A]A\_
gwgwWw
IsBold
10.0.17763.1 (WinBuild.160101.0800)
u'!D$ A
.?AVCPropertySheet@@
9>vCH
~}NYNGA2,!
DeleteCriticalSection
FXSRESM.DLL
CImageList::Attach
RaiseException
GetWindowLongW
Disconnect
.?AVCCoverPagesDlg@@
\fyi.cov
CDraftsFolder::Init
U+3868989<
RtlCaptureContext
b A8$a
K VWATAVAWH
0CFaxDoc
N@`/=Wf
T$HH+
GetClientCpDir
CSplitterHorWnd::AddView
9\$Pv2D
x ATAVAWH
map::operator[]
D$PL+
\Fax\Personal CoverPages
.CRT$XLA
CFaxAccounts::GetAccountList
SetDefault failed
FaxGetGeneralConfiguration
GetCursorPos
CServerStatusDlg::DoModal
UserInfo1
HA_A^A\_^[
Memory allocation failed for composeUIArgs.lplpwszAttachments
<=93,(7y
wwwVp
%s (%s)
.?AUIFailureCallback@details@wil@@
GetDeviceCaps
DestroyMenu
U,89<8<<98=<=z
%oN5989;9>
` UAVAWH
DrawMenuBar
D953t
[XXZ[\\hefkkjjjbb____N
HeapReAlloc
hxxxxxxxxxwp
\Fax\Drafts
CListCtrl::DeleteItem
RegQueryValueEx() failed[%s], ec=%d
StringDup failed!
Memory Allocation Failed
GetUserPreferredUILanguages
StringDup
application/octet-stream
publicKeyToken="6595b64144ccf1df"
UpdateReassignStatus failed
WinSqmIncrementDWORD
LogonUserW
A_A^_
G>>GJMM~
xxxxxxxxww
UnregisterClassW
<dpiAware>true</dpiAware>
89==T=@L=L<AAAAAA
WriteFile
E 9x8t
CTime::GetAsSystemTime
-+*$A
A_A^A\
H!\$XA
<6,3;@
DestroyWindow
D$0H;
A8h)u
CInboxDetailsPg
t6D8i
}wHcO
68;>>>>>
Invalid folder type
x AUAVAWH
u )X)Mr!905IB
MailFrom
GdipSaveAdd
FaxConnectFaxServerW
@USVWATAVAWH
@@I9F@
FaxSetMessage
GetVersion
Memory allocation failed for composeUIArgs.lplpwszAttachments[i]
CFolder::RebuildContents
OpenPrinterW
(t$@H
T$(E3
wwGWw
wuxwwVw
9|$4t
'!hPR
9]@u_D
xwxwxww
U+,39<vv
CPersonalInfoPg
@8j(uXD
D$8HcH
wwxx
.?AVCMultiViewSplitter@@
LcD$hE3
GdipAlloc
wwwp@
.CFolderListView
t:f9/t5f9.t
__wgetmainargs
ReleaseSRWLockExclusive
PathIsContentTypeW
GetAccountInternal failed
EnableMenuItem
LoadCursorW
SHGetSpecialFolderLocation
StringDup failed with %d
m_Incoming.StopBuildThread
u$L97t
RtlLookupFunctionEntry
D;|$8
_5?@a
LFKp[
F!M(j
internal\sdk\inc\wil\resource.h
M0L9(t
CopyPage
0B)dam
GetTraceEnableFlags
[%hs(%hs)]
"X2`F
QueryPerformanceCounter
CTreeCtrl::Select
?..^h
hhcc``]N
MainFrame
threadId
t$0E3
Message is not available
t<2(#'#')'1126521'
%d %%
msvcrt.dll
UserInfoDisplayed
\$ UVWATAUAVAWH
StringFileInfo
.?AVCScanLeftView@@
oD$ f
t$ WAVAWH
srand
t$ UWATAUAWH
gdiplus.dll
0A_A^A]A\_
ole32.dll
AllocateNewMessageId
D$hH;
SHBrowseForFolderW
sent_items
CMenu::LoadMenu
CFolderListView::AddItem
CFrameWnd::PreCreateWindow
.?AVCCommonDialog@@
xxxwp
CMainFrame::OnCopyData returned NULL
*.jfif
NE26666
GetOpenFileNameW
MyFaxEnumMessagesEx
ClosePrinter
.?AVBitmap@Gdiplus@@
GetColumnHeaderString
.?AVCTreeNode@@
9{0v%H
.?AVXPrintDialogCallback@C_PrintDialogEx@@
CScanDocument::ScanToFile failed with 0x%08x
t)@8x
E11j{
@A_A^A]
.text$mn
l$ VWAUAVAWH
FaxGetReportedServerAPIVersion
!1121'
D$XE3
D!L$8D!L$0L;
txgWgvW
*.png
failureId
m_Outbox.InvalidateContents
L9 t%I
x@%f'0
CFolderListView::FetchTiff
FaxComposeFreeBuffer
/'3'-
GdipGetImageEncodersSize
x ATAUAVH
QueueUserWorkItem
L$XH+
MailTo
f9<Cu
cgfb^F]
D8X(uWE
OnToolsFaxProperties failed with 0x%08x
SUVWATAUAVAWH
MyFaxGetMessageEx
CClientConsoleView
%s%s%s
CString operation
.?AVCUserInfoDlg@@
AC661
EventWriteTransfer
6wuu!
T$8H!t$8H
XXXZW[\\ghcbbb__Oa
InitCommonControlsEx
f94_u
PathAppendW
f9l$ t;H
CQueueFolder
LoadLibrary(ScanSettings)
we%56wvu% P
SHSetLocalizedName failed dwRes=%d
oL$0f
tA!]@L
EHMKMM_NNNNN
T$@E3
CClientConsoleDoc
CFolderListView::AddSortedItem
+T$@E3
L$`H3
CLeftView::OpenSelectColumnsDlg
CPersonalInfoPg::Init
R$97Z
D$@E3
CryptUnprotectData
</asmv3:windowsSettings>
=189<89=<9=<y
HrFaxComposePreTranslateAccelerator
PhoneNos
UpdateWindow
H!\$H
BooleanSearchInsertionPoint
pppt7x
###-#
A_A\]
fxsadmin.msc
new CServerNode
L$ SWH
CFaxOptions::Load
HrNewTiffViewUIFromFile
WelcomeFaxCopied
CSentItemsGeneralPg
.didat$6
D$4+D$,
@A^_[
9\$Xv
wwwwwww
FaxEnumMessagesEx
toiPR
0,#69C
G@H9h
FaxGetMessageEx
8A^_^[
wCFaxClientPg
IsDebuggerPresent
wtwwp
I"CJob
Tk{{{r{t{{
bm$")deeI
.rdata$zETW1
.?AVCDraftsFolder@@
Software\Microsoft\Fax\UserInfo
A^A\_^]
??1exception@@UEAA@XZ
.?AV?$CArray@UtagLVITEMW@@U1@@@
HrInitComposeFormDll failed: %0x
@A_A^A\
xwwwxxx
ReleaseCapture
MSIComponentID
RtlVirtualUnwind
_wcmdln
CMsgPropertyPg
,sVsz
*.rle
devices
GetModuleFileNameW
|$PD8
RaiseFailFastException
X83vvv
GetUniqueFileName
A_A^A]_^
FaxReAssignMessage
L9gXH
_wcsupr
GdipGetImageHorizontalResolution
Win32Error2String
EnumPrintersW
fE98t
D9k@u8A
@SUVWATH
SHChangeNotify
RegEnumKey() failed, ec=%d
,F=B!
CTreeCtrl::SetItem
t&D8q
.CRT$XCA
wp66Rpw
lstrcmpW
LaunchComposeForm::HrNewFaxComposeUI
D$p+D$X
POV22
D8A)u
KERNEL32.dll
OleInitialize
DraftsView
A^A]A\_]
rrToATo><5v
Z5?A%
list::push_back
GetSubMenu
GetThemeSysFont
<description>Microsoft Windows Fax and Scan</description>
FindFirstFile failed
.?AVCShellFileHandling@@
U8==T@J@JL@LLLLATAT
%s"%s" "%s"
T$8H!\$8
UnhandledExceptionFilter
IncomingView
Af6wwx
@SVATAVAWH
VVyVz
|Jyy||y
CJob::InitStrings
fD9 t
DefWindowProcW
HrNewFaxComposeUIFromFile
EventUnregister
\[ZYG
%PROGRAMDATA%\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
6;:"A
kHS~X
wcscpy_s
zvvrLL@<66551(!(
Allocation of ppFaxAccounts failed
PlaySound
currentContextName
GetVersionExW
ort@u
!.11,
@SUVWATAUAVAWH
StringCbCopy failed, hr: 0x%x
cCreateEvent
CMainFrame::CreateDynamicView (SentItems)
.?AVCDirTreeCtrl@@
m_Inbox.InvalidateContents
VS_VERSION_INFO
.?AVCFaxStatusBar@@
9xvv0ecc#USS
tYf9)tT
r2rr==ry}
@A^A]_
i"R=U
U&`iG*
x UATAUAVAWH
</dependency>
7a56577c-6143-43d9-bdcb-bcf234d86e98
A_A^_^]
HrGetDraftsListViewInfo
Awww4B@@
!\$@H!\$P!
.CRT$XCZ
image/gif
.?AVCTreeView@@
http://schemas.microsoft.com/cdo/configuration/smtpserverport
ExpandEnvironmentStrings() failed, ec=%d
map/set<T> too long
currentContextMessage
.?AVCSentItemsDetailsPg@@
Exception
E;,$r
GdipSaveAddImage
DllGetVersion
b`[UTQH
SendMessageW
!D$ L
H9w(H
NTTTTj
L$pE3
ItemDeletion
ZKIlmlllkffeebbb__^ON]
.data
E8Y(u
.?AUIFaxReassignUI@@
l}{}{|{{zzz}n
CFolderListView::ReadLayout
CRYPT32.dll
CSenderInfo::LoadSenderInfo
D8B)u
9|$0t
2#<#:UUUUUU
T$$D!t$ H
xwwww
PathFileExistsW
slc.dll
COMDLG32.dll
oGlllglgggi
StringCchCat
H!\$83
memset
2=FQF"F
D95Aa
[%hs]
GetActiveWindow
0A_A^A\_^][
xwxwp
8<AL@JT@T@LLLLoAATT
SetFocus
Rtwwx
CListBox::GetItemData
CMainFrame::CreateDynamicView (Outbox)
\$ UVWAVAWH
GetProcAddress
GdipGetPropertyItemSize
Software\Microsoft\Windows Messaging Subsystem
;D$@|
</trustInfo>
JX__\ZVSIU
pwwwppausapp@
drafts
ProductName
*.cov
new CJob
HrSelectEmailRecipient
wDGsw
s2((('@
CImageViewer
zigf9-
PlaySoundOnNewMessage
InsertMenuW
ReadFile failed: %d
.idata$6
U5"8I
D95ra
D$`E3
Account was not found
D$8L+
Invalid parameter passed to C runtime function.
GetParent
GdipFree
{ f9|$ tIH
N6>>>>==K
m_Incoming.InvalidateContents
t^@8=
@A_A^_^]
D$HE3
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0">
)t$0H
rN!+I
FaxFreeBuffer
.?AVSolidBrush@Gdiplus@@
type="win32"
GdipCreateSolidFill
}qnng<
PA^_^
\Documents
t$ UWAVH
MoveFileW
LoadResourceString faield for IDS_FORWARDPREFIX, dwError=%d
FileVersion
R(>_s
.?AVCMyFolderDialog@@
fD9$Au
L$hH3
<226LrvroL@t
.?AVlength_error@std@@
RegQueryValueEx() failed, ec=%d - and no default value was specified
FaxSetSenderInformation
SVWAVH
p AWH
SendMessageToFirstWFSInstance failed with 0x%08x
T1O{q
.?AVCSortHeader@@
t$ E3
r93112225(655<651(#
CreateDialogParamW
wilResult
AttachFaxToReceipt
CFolderListView::InitColumns
CreateAccount called for existing account
http://schemas.microsoft.com/cdo/configuration/smtpauthenticate
GdipGetImagePixelFormat
6226LrTo><<A
UAVAWH
A_A^_
memcpy_s
FaxGetSenderInfo
A_A^A\_]
wwwwxp
Delete
A9_@uxH
!|udpI
</dependentAssembly>
StringCchPrintf() failed.
.?AUIFaxOptionsUI@@
<requestedPrivileges>
FXdca\WRIA
0ScRpzo
G5P9X
GdipGetDC
MemAlloc
@8h)t
D$8I;E
CDraftsFolder::GetDraftsFileName failed with %d
xugwvwwwp
e8Cbcc=
r!!D$
FileTimeToLocalFileTime
%s\%s%08x*.%s
A^A]A\
3mgN|/
.?AVCFaxAccountConfigWizard@@
WAUAWH
\Fax\Personal Coverpages\
ugxguwuwwwvp
.?AVC_PrintDialogEx@@
,\\,q
HrGetDraftsListViewInfo failed with %d
A8h)t
.?AVCWaitDlg@@
T$p!\$hE3
GdipCreateBitmapFromScan0
SortColumnScan
)37>{
/>
SVAVH
FaxEnumMessagesW
CheckDlgButton
wxwwww
3erx4
t$ WATAWH
wcstok
(7ed/
Ef)aN6
CFolder::GetConnectionHandle
GetWindowContextHelpId
CreateMutexExW
FaxGetMessageTiff
SetActiveWindow
GdipCreateFromHDC
cHRM
SentItemsView
EventRegister
CMainFrame::UpdateFaxPreview
FaxGetJobEx
_wcsdup
FaxBeep
PropVariantClear
Error %d: DeletePrinterConnection failed
@UVWH
DeleteFileW
GdipReleaseDC
CoInitializeEx
GetSendToFaxRecipientArgs failed
GDI32.dll
Software\Microsoft\Fax\FaxOptions
H USWH
CreateFile
.?AVout_of_range@std@@
CInboxGeneralPg
l-)lA
L9t$h
InvalidateRect
Confirm
wxhwxw
7OF5>
H9_ uG
HeapAlloc
A_A^A\_^
CSplitterFixedWnd::CreateStatic
qkqqqo
StringCchCat failed, hr=%x
cZ@M,
.?AVCmdWaitDialog@@
0A__^
T$pE3
F@GKGKKKKK
PtInRect
GdipGetImageGraphicsContext
m_Drafts.InvalidateContents
SetItemText failed
hQ@RHHH
L9g8H
GdipCloneBrush
L1(1@T
Account not found
GetFaxPrinterNameOnServer() failed.
new CDraftsMsg
ZHGmllliiffeecba^]NNND
9|$@~LD
t$D8q
.data$brc
t#@8y
^(f9\$0t
wwgwe6q%
LLLLLLLL
H3E H3E
InternalName
Location
CommDlgExtendedError
malloc
WINMM.dll
CreateDialog
xxxxxp
FaxEnumPortsExW
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
FaxClose
D!t$ L
.rsrc$02
GdipImageSelectActiveFrame
=Tsuuuuuuuuuvvttvttrttt
5@E@G`
_unlock
xxxxw
+99LL
AppendLocalizedDirName failed!
wgvu5cWV
GetDC
.Gmwv
(t$0H
vBRCWx
.?AVCCommandLineInfo@@
FindNextFileW
+SSNa
A8x)t
HrInvokeAddressBook
OLEAUT32.dll
Null arguments
.?AVCEdit@@
@_^[H
.text$di
GetReadFaxArgs failed with %d
FindClose
tNLcG
@8j)u
originatingContextMessage
6(26@ro@<5<o
t'D8i
TL<93539>>
VATAUAVAWH
K8HcC
FaxGetRecipientInfoW
VWATAVAWH
MulDiv
UVWATAUH
</requestedPrivileges>
DeletePrinter failed
GetTempPathW
FaxSizeFormat
l$0H;
vDVwp0ex
D8p)H
GetCurrentProcessId
Error in allocating cstrTempFileName
L$XH3
ag^~'
!pN;W:q
RegCreateKeyExW
.?AVCTimeSpan@@
.?AUIFaxAccountConfigUI@@
.rdata$zETW0
b),4VPP
Maximized
4`ggwwtwx
CListBox::SetSel
StringCchPrintf
<assemblyIdentity
;|$Pr
.?AVCObject@@
\$ UVWAUAVH
SetProcessDefaultLayout
GetViewportOrgEx
]d4[ b
0A^_^][
language="*"
Switch
WaitForSingleObjectEx
GetPrinterNameFromAccount failed
t$HH9.t
list::remove
]f%%IyE
;\$@|
ROFP^_Q
AppModeChanged
GetPrinterW
GetSystemMetrics
fE9$~u
W`CU$@9
U<TTrrrTTTrTTrTTrrrrr
uwwggg
Hsy||||
.?AVCMsgPropertyPg@@
`eQaQ
FindNextFile
>>>:542.(%
@USVWH
CoTaskMemFree
+-K}
GetDlgItem
GdipLoadImageFromFile
PostThreadMessageW
.?AVCCustomView@@
processorArchitecture="amd64"
'%#e]XT
text/html
wwwwwwvu
TttLy
.?AVCTreeCtrl@@
.CRT$XIZ
68A!8EJ6
8("*8J}
C(H95
yto@<5(
G(A9X<
U^xwwvupqlki[Z\
.?AVBrush@Gdiplus@@
!This program cannot be run in DOS mode.
StartEditor
Msg:[%ws]
@A^_^
A_A^A]_^[]
vwwxx
MMMU"
CFrameWnd::OnCreate
Lct$$H
D$PH+
A_A^A]A\_^[
RegCreateKeyEx() failed, ec=%d
GetLocaleInfoW
OleInitialize failed with %d
A_A^A\_^H
G27BMMN}
%s ( %s )
HrAddressBookPreTranslateAccelerator
}G8-&,)8>>>2,
m_SentItems.InvalidateContents
D$xE3
A^_^[]
StringCchCopy failed hr=%x
USER32.dll
xxwwg
A^A\_
6ivBz\
LU@up
t"D8=
IDATx^
.?AV?$CSimpleStringBase@G@@
ClientConsole.EXE
|D>\t
HrDeinitComposeFormDll
*.gif
G1**0*1G
D$ fD
L$TE3
FreeLibrary (MAPI32.DLL)
H!|$PI9~
L9{@u
OpenSemaphoreW
Gxwgwwwwwwwp
ODPvfN
StrChrW
yupqrko{
ShellAbout
.?AVImage@Gdiplus@@
Ff&&9
H!|$HE3
CreateFontIndirectW
FallbackError
HeapSetInformation
\$(E3
!\$ H
.?AVCQueueFolder@@
f9H\u
EnterCriticalSection
folder
.CRT$XCU
fG9<Fu
\$ E3
WgWww
f9<ku
k76oD>
_errno
ProgDlgTakeFgIfShowing
[a7:d
t6L;?u
LoadImageW
5khkd
RemoveServerNode failed
twwcgp
FaxGetJobExW
CListBox::AddString
.?AVCFaxMsg@@
m_Drafts.StopBuildThread
SendDlgItemMessageW
E2t*:
+D$@E3
%hs(%d) tid(%x) %08X %ws
wwgvw
8A_A^A]A\_^[]
A(H90u
)X\$3g&J
fD;1t
<asmv3:application>
GetCurrentProcess
L$HD+
wcsspn
V/rk0[
GetMenu
H16=(
`f2R!
f%V+r|
D$@A#
SHGetFileInfoW
_vscwprintf
fileName
d$ E3
MemReAlloc() failed, src=%x, size=%d
@hh`j
}R9-V
xxxvx
LocalFree
D$8E3
L9o@t
.?AVResultException@wil@@
Fbad allocation
CMainFrame::FindMenuItem
</assembly>
.didat$3
ImageList_LoadImageW
Account
CJob::Init
Translation
ScreenToClient
!!1111)!
N8iLOU%j
(8Lo(o
D8@)t
FindWindowW
fE9$Gu
,qlqY
http://schemas.microsoft.com/cdo/configuration/sendusername
OleUninitialize
DeletePrinterConnectionW
L1'(5Lro@<5@y
WilError_02
WaitForThreadDeathOrShutdown
CFaxAccounts::Load failed
RegisterTraceGuidsW
wcsncmp
CFaxMsg::Print
gFaxGetRecipientInfo
}&NlZ
.PEAVCMemoryException@@
GetTempFileNameW
http://schemas.microsoft.com/cdo/configuration/smtpconnectiontimeout
ProductVersion
FlushFileBuffers
H!]XH
.?AUIPrintDialogCallback@@
AuthType
Secur32.dll
GdipSetPropertyItem
0A^A]A\_^[]
.?AVCFolderListView@@
CSplitterVerWnd::CreateStatic
.didat$4
SHGetFolderPathAndSubDirW
__CxxFrameHandler3
FaxStartMessagesEnumEx
.?AUIImageViewer@@
ImageList_GetIcon
ShowWindow
_onexit
B_Db1]
H!\$PE3
` UAUAVH
.CRT$XIAA
?+<>MRs
fD9<Au
AddServerNode failed
EHFt1H
A_A^A\_^[]
failureType
f9l$ t4H
/-+a\XT
GetUserNameExW
Windows
multipart/mixed; charset=utf-8
cdosys.dll
D8X!u
D8X(u
!\$lA
hresult
H!w(H
.?AVCHeaderCtrl@@
D$0E3
9K8t;
TiffPrintDC
GdipImageGetFrameCount
CMenu :: InsertMenu
.idata$2
WelcomeFax.tif
D$HFt
CReBar::Create or CReBar::AddBar
x AVH
AA%g0w
~8kkkjjjn
FaxStartMessagesEnum
.CRT$XCL
LoadLibrary("MAPI32.DLL")
yz|}{}|}{{}
iJtI>
UserInfo2
.?AVCImageViewer@@
xxxxwp
Microsoft Windows Fax and Scan
.tls$
credui.dll
8=TTTJrTTTTTTTToToTr
U,,,=vv
SysTreeView32
D$0
GetAppLoadPath
@VWATAVAWH
}_rVr
.xdata
.PEAVCException@@
{j:11(
.gfids
FaxScanAppLaunched
.?AUIFaxAccountManagerUI@@
hiiQ5
.?AVCFaxReassignUI@@
CMainFrame::GetWindowPlacement
AccessCheckAndElevate failed! 0x%x
??0exception@@QEAA@AEBV0@@Z
%hs(%d)\%hs!%p:
t$$E3
Operating System
wxxxx
vector<T> too long
@.didat
}q"333
t4A9~
GetModuleHandleExW
wwwwx
RegSetValueEx() failed[%s], ec=%d
'D9|$`t
_cexit
.?AVGdiplusBase@Gdiplus@@
@VWAWH
818999:999A
.?AVCFaxClientPg@@
C_PrintDialogEx::GetPrinterDC
OleRun
GetFileMUIPath
CString::Empty
.?AUIAccountManager@@
@Y5Nh
GetWindowPlacement
.?AVCArchiveMsg@@
t$ WATAUAVAWH
9CFolder
CString exception
GetLastError
_commode
@USVWATAUAVAWH
UWAWH
CDraftsMsg::Init
\$@H;
*.jpg
L8@L+
IsFaxPrinterShared
LogHr
wwwwwwwwww
_amsg_exit
%s(%ld, %02ld%08ld)
SHSetValueW
fD9$Gu
ewwgwwwww
p WATAUAVAWH
vhkzn
CStatusBar::CreateEx or CStatusBar::SetIndicators
A_A]A\_]
?terminate@@YAXXZ
G>>BN
D8X)u
AUAVAWH
NJGJY}~
4ESEEEJ
xwxxp
<dependency>
|$ UAVAWH
.?AVCSplitterWnd@@
Drafts
T$@H+
CommandLineToArgvW
mapistub.dll
Elevation:Administrator!new:%s
CString::operator+
"?;7WSQN
ExpandEnvironmentStrings failed: %d
A_A]A\
m_Inbox.StopBuildThread
.?AVCCtrlView@@
GetAddrInfoW
pA_A^A]A\_^]
GwwWvwgugwp
1NW]T
name="Microsoft.Windows.Common-Controls"
IncludeOriginalMessageInReply
sXnI{
gxxwp
CServerNode::GetConnectionHandle
A_A^A]A\]
A_A^A]_]
D$0H!t$(H!t$ E3
f9,~u
T$HH!\$H3
CanSendToFaxRecipient
InitOnceBeginInitialize
GetSystemInfo
xxxwppCCBVwx
CWaitDlgThread
SafeCreateFile failed with %d
H`{{{~}}}`}_}}}
`.rdata
vvrrL@951()!
NewFaxScanAction
AfxRegisterClass
l$$E3
CDraftsFolder::ReadConfiguration failed: %0x
RegQueryInfoKeyW
D$@H;
l$ WH
H!\$`H
RegCloseKey
GetFileAttributesExW
GetSystemMenu
CheckReassignPermissions
.?AVCSubItemEditCtrl@@
|$ UATAUAVAWH
LM%!p
Allocation of ppFaxAccounts member failed
|$ ATAUAWH
MAPI32.DLL
lineNumber
AddServerNode
CLeftView

PE Information

Image Base Entry Point Reported Checksum Actual Checksum Minimum OS Version PDB Path Compile Time Import Hash Icon Icon Exact Hash Icon Similarity Hash Icon DHash
0x140000000 0x00065db0 0x000eac6b 0x000eac6b 10.0 Wfs.pdb 2096-05-20 04:44:04 c987cf564df7a02af3d7a1c59523a3de 68f56c3aa2b0d1cdae49586659e001b8 c302df79e1599d54c39bc2171fc409a5 c880b0ece2eee020

Version Infos

CompanyName Microsoft Corporation
FileDescription Microsoft Windows Fax and Scan
FileVersion 10.0.17763.1 (WinBuild.160101.0800)
InternalName ClientConsole.EXE
LegalCopyright ร‚ยฉ Microsoft Corporation. All rights reserved.
OriginalFilename ClientConsole.EXE
ProductName Microsoftร‚ยฎ Windowsร‚ยฎ Operating System
ProductVersion 10.0.17763.1
Translation 0x0409 0x04b0

Sections

Name RAW Address Virtual Address Virtual Size Size of Raw Data Characteristics Entropy
.text 0x00000400 0x00001000 0x0006b482 0x0006b600 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.27
.rdata 0x0006ba00 0x0006d000 0x0002c4e8 0x0002c600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.30
.data 0x00098000 0x0009a000 0x00002f24 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3.51
.pdata 0x0009a000 0x0009d000 0x00004134 0x00004200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.74
.didat 0x0009e200 0x000a2000 0x000001c0 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2.94
.rsrc 0x0009e400 0x000a3000 0x00042500 0x00042600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.50
.reloc 0x000e0a00 0x000e6000 0x00002048 0x00002200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5.38

Name Offset Size Language Sub-language Entropy File type
RT_ICON 0x000a3db0 0x00002868 LANG_ENGLISH SUBLANG_ENGLISH_US 2.97 None
RT_ICON 0x000a6618 0x000016e8 LANG_ENGLISH SUBLANG_ENGLISH_US 2.69 None
RT_ICON 0x000a7d00 0x00000a68 LANG_ENGLISH SUBLANG_ENGLISH_US 2.92 None
RT_ICON 0x000a8768 0x00000668 LANG_ENGLISH SUBLANG_ENGLISH_US 2.91 None
RT_ICON 0x000a8dd0 0x000002e8 LANG_ENGLISH SUBLANG_ENGLISH_US 3.07 None
RT_ICON 0x000a90b8 0x000001e8 LANG_ENGLISH SUBLANG_ENGLISH_US 3.10 None
RT_ICON 0x000a92a0 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US 3.13 None
RT_ICON 0x000a93c8 0x00004c28 LANG_ENGLISH SUBLANG_ENGLISH_US 4.70 None
RT_ICON 0x000adff0 0x00002ca8 LANG_ENGLISH SUBLANG_ENGLISH_US 4.23 None
RT_ICON 0x000b0c98 0x00001628 LANG_ENGLISH SUBLANG_ENGLISH_US 4.84 None
RT_ICON 0x000b22c0 0x00000ea8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.01 None
RT_ICON 0x000b3168 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.49 None
RT_ICON 0x000b3a10 0x000006c8 LANG_ENGLISH SUBLANG_ENGLISH_US 5.15 None
RT_ICON 0x000b40d8 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US 3.74 None
RT_ICON 0x000b4640 0x0000ea46 LANG_ENGLISH SUBLANG_ENGLISH_US 7.95 None
RT_ICON 0x000c3088 0x00010828 LANG_ENGLISH SUBLANG_ENGLISH_US 4.51 None
RT_ICON 0x000d38b0 0x000094a8 LANG_ENGLISH SUBLANG_ENGLISH_US 3.95 None
RT_ICON 0x000dcd58 0x00004228 LANG_ENGLISH SUBLANG_ENGLISH_US 4.29 None
RT_ICON 0x000e0f80 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US 4.40 None
RT_ICON 0x000e3528 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US 4.36 None
RT_ICON 0x000e45d0 0x00000988 LANG_ENGLISH SUBLANG_ENGLISH_US 4.72 None
RT_ICON 0x000e4f58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 4.93 None
RT_GROUP_ICON 0x000e53c0 0x0000013a LANG_ENGLISH SUBLANG_ENGLISH_US 3.35 None
RT_VERSION 0x000a39e8 0x000003c4 LANG_ENGLISH SUBLANG_ENGLISH_US 3.44 None
RT_MANIFEST 0x000a3520 0x000004c7 LANG_ENGLISH SUBLANG_ENGLISH_US 5.00 None

Imports

Name Address
TraceMessage 0x1400769d8
GetTraceLoggerHandle 0x1400769e0
GetTraceEnableLevel 0x1400769e8
GetTraceEnableFlags 0x1400769f0
RegisterTraceGuidsW 0x1400769f8
UnregisterTraceGuids 0x140076a00
RegCloseKey 0x140076a08
EventUnregister 0x140076a10
EventRegister 0x140076a18
EventSetInformation 0x140076a20
EventWriteTransfer 0x140076a28
RegQueryValueExW 0x140076a30
RegOpenKeyExW 0x140076a38
RegSetValueExW 0x140076a40
RegEnumKeyExW 0x140076a48
RegCreateKeyExW 0x140076a50
RegDeleteKeyW 0x140076a58
RegQueryInfoKeyW 0x140076a60
RegEnumKeyW 0x140076a68
LogonUserW 0x140076a70
DuplicateToken 0x140076a78
RegQueryValueW 0x140076a80
ImpersonateLoggedOnUser 0x140076a88
RevertToSelf 0x140076a90
Name Address
CreateMutexExW 0x140076b80
GetCurrentProcessId 0x140076b88
InitOnceComplete 0x140076b90
CreateSemaphoreExW 0x140076b98
GetCommandLineW 0x140076ba0
WakeAllConditionVariable 0x140076ba8
SleepConditionVariableSRW 0x140076bb0
MulDiv 0x140076bb8
VirtualQuery 0x140076bc0
GetSystemInfo 0x140076bc8
AcquireSRWLockExclusive 0x140076bd0
ReleaseSRWLockExclusive 0x140076bd8
LoadLibraryExA 0x140076be0
VirtualProtect 0x140076be8
ResumeThread 0x140076bf0
WaitForMultipleObjects 0x140076bf8
RaiseException 0x140076c00
CopyFileExW 0x140076c08
GetFileAttributesExW 0x140076c10
QueueUserWorkItem 0x140076c18
FileTimeToLocalFileTime 0x140076c20
MoveFileW 0x140076c28
GetFileTime 0x140076c30
CreateProcessW 0x140076c38
InitOnceBeginInitialize 0x140076c40
CreateThread 0x140076c48
SetFileTime 0x140076c50
SetEvent 0x140076c58
CreateEventW 0x140076c60
LeaveCriticalSection 0x140076c68
EnterCriticalSection 0x140076c70
GetNumberFormatW 0x140076c78
GetModuleFileNameW 0x140076c80
ReadFile 0x140076c88
WriteFile 0x140076c90
GetDateFormatW 0x140076c98
GetComputerNameW 0x140076ca0
MultiByteToWideChar 0x140076ca8
GetLocaleInfoW 0x140076cb0
CreateDirectoryW 0x140076cb8
GetVersion 0x140076cc0
GetVersionExW 0x140076cc8
FlushFileBuffers 0x140076cd0
GetSystemTime 0x140076cd8
GetFileType 0x140076ce0
CopyFileW 0x140076ce8
SystemTimeToFileTime 0x140076cf0
FileTimeToSystemTime 0x140076cf8
GetFileAttributesW 0x140076d00
CreateFileW 0x140076d08
FindClose 0x140076d10
FindNextFileW 0x140076d18
GetFullPathNameW 0x140076d20
FindFirstFileW 0x140076d28
HeapReAlloc 0x140076d30
GetTempFileNameW 0x140076d38
DeleteFileW 0x140076d40
GetTempPathW 0x140076d48
ExpandEnvironmentStringsW 0x140076d50
GetTimeFormatW 0x140076d58
GetUserPreferredUILanguages 0x140076d60
EnumUILanguagesW 0x140076d68
GetLocaleInfoEx 0x140076d70
GetStringTypeExW 0x140076d78
GetTickCount 0x140076d80
GetSystemTimeAsFileTime 0x140076d88
QueryPerformanceCounter 0x140076d90
TerminateProcess 0x140076d98
GetCurrentProcess 0x140076da0
SetUnhandledExceptionFilter 0x140076da8
UnhandledExceptionFilter 0x140076db0
OutputDebugStringA 0x140076db8
GetStartupInfoW 0x140076dc0
Sleep 0x140076dc8
InitializeCriticalSection 0x140076dd0
OpenSemaphoreW 0x140076dd8
WaitForSingleObject 0x140076de0
LocalAlloc 0x140076de8
DeleteCriticalSection 0x140076df0
WaitForSingleObjectEx 0x140076df8
ReleaseMutex 0x140076e00
ReleaseSemaphore 0x140076e08
CloseHandle 0x140076e10
SetLastError 0x140076e18
OutputDebugStringW 0x140076e20
IsDebuggerPresent 0x140076e28
DebugBreak 0x140076e30
GetModuleFileNameA 0x140076e38
GetModuleHandleExW 0x140076e40
HeapAlloc 0x140076e48
GetProcessHeap 0x140076e50
HeapFree 0x140076e58
GetCurrentThreadId 0x140076e60
FormatMessageW 0x140076e68
GetModuleHandleW 0x140076e70
WideCharToMultiByte 0x140076e78
GetProcAddress 0x140076e80
LoadLibraryA 0x140076e88
LocalFree 0x140076e90
FreeLibrary 0x140076e98
LoadLibraryW 0x140076ea0
lstrlenA 0x140076ea8
lstrcmpW 0x140076eb0
GetLastError 0x140076eb8
HeapSetInformation 0x140076ec0
GetModuleHandleA 0x140076ec8
Name Address
GetTextExtentPoint32W 0x140076b40
GetViewportOrgEx 0x140076b48
DeleteObject 0x140076b50
GetCurrentObject 0x140076b58
GetObjectW 0x140076b60
CreateFontIndirectW 0x140076b68
GetDeviceCaps 0x140076b70
Name Address
GetDlgItem 0x1400781a0
LoadMenuW 0x1400781a8
InSendMessage 0x1400781b0
DrawMenuBar 0x1400781b8
GetCursorPos 0x1400781c0
GetWindowRect 0x1400781c8
IsIconic 0x1400781d0
GetLastActivePopup 0x1400781d8
IsWindowVisible 0x1400781e0
SetWindowLongPtrW 0x1400781e8
InsertMenuW 0x1400781f0
MessageBoxW 0x1400781f8
SetProcessDefaultLayout 0x140078200
GetDlgItemTextW 0x140078208
SetDlgItemTextW 0x140078210
LoadStringW 0x140078218
WinHelpW 0x140078220
ShowWindow 0x140078228
MsgWaitForMultipleObjects 0x140078230
GetMessageW 0x140078238
TranslateMessage 0x140078240
GetSubMenu 0x140078248
SetWindowLongW 0x140078250
DeleteMenu 0x140078258
GetSysColor 0x140078260
GetWindowLongW 0x140078268
LoadImageW 0x140078270
GetDC 0x140078278
ReleaseDC 0x140078280
ClientToScreen 0x140078288
CreateDialogParamW 0x140078290
SendDlgItemMessageW 0x140078298
PeekMessageW 0x1400782a0
DestroyWindow 0x1400782a8
GetWindowLongPtrW 0x1400782b0
GetMenu 0x1400782b8
GetSystemMenu 0x1400782c0
EnableMenuItem 0x1400782c8
SetWindowPos 0x1400782d0
SetActiveWindow 0x1400782d8
ReleaseCapture 0x1400782e0
SetFocus 0x1400782e8
SetCapture 0x1400782f0
FindWindowW 0x1400782f8
UnregisterClassW 0x140078300
SetForegroundWindow 0x140078308
UpdateWindow 0x140078310
LoadIconW 0x140078318
DialogBoxParamW 0x140078320
GetSystemMetrics 0x140078328
EndDialog 0x140078330
CheckDlgButton 0x140078338
IsDlgButtonChecked 0x140078340
CheckRadioButton 0x140078348
GetActiveWindow 0x140078350
GetMenuStringW 0x140078358
GetMenuItemCount 0x140078360
DestroyMenu 0x140078368
DispatchMessageW 0x140078370
SetMenu 0x140078378
DefWindowProcW 0x140078380
GetWindowContextHelpId 0x140078388
SetCursor 0x140078390
ScreenToClient 0x140078398
GetMessagePos 0x1400783a0
InvalidateRect 0x1400783a8
DestroyIcon 0x1400783b0
IsWindow 0x1400783b8
DrawTextW 0x1400783c0
GetParent 0x1400783c8
PostMessageW 0x1400783d0
PtInRect 0x1400783d8
SetRect 0x1400783e0
SendMessageW 0x1400783e8
LoadCursorW 0x1400783f0
GetClientRect 0x1400783f8
EnableWindow 0x140078400
GetFocus 0x140078408
RedrawWindow 0x140078410
CharNextW 0x140078418
PostThreadMessageW 0x140078420
Name Address
Name Address
wcsrchr 0x140078648
time 0x140078650
srand 0x140078658
_vsnwprintf 0x140078660
??0exception@@QEAA@XZ 0x140078668
memmove_s 0x140078670
??0exception@@QEAA@AEBQEBD@Z 0x140078678
??1exception@@UEAA@XZ 0x140078680
?what@exception@@UEBAPEBDXZ 0x140078688
_wsplitpath_s 0x140078690
memcpy_s 0x140078698
??0exception@@QEAA@AEBV0@@Z 0x1400786a0
__CxxFrameHandler3 0x1400786a8
__RTDynamicCast 0x1400786b0
memcpy 0x1400786b8
iswalpha 0x1400786c0
memset 0x1400786c8
_errno 0x1400786d0
_callnewh 0x1400786d8
??0exception@@QEAA@AEBQEBDH@Z 0x1400786e0
realloc 0x1400786e8
_wcsupr 0x1400786f0
_wcstoui64 0x1400786f8
_wcsicoll 0x140078700
_itow 0x140078708
wcschr 0x140078710
malloc 0x140078718
wcscat_s 0x140078720
wcscpy_s 0x140078728
_vscwprintf 0x140078730
wcsstr 0x140078738
rand 0x140078740
_wtoi 0x140078748
wcsncmp 0x140078750
_wcsnset 0x140078758
wcsspn 0x140078760
free 0x140078768
_wcsdup 0x140078770
_vsnprintf_s 0x140078778
swscanf 0x140078780
_purecall 0x140078788
_onexit 0x140078790
__dllonexit 0x140078798
_unlock 0x1400787a0
_lock 0x1400787a8
??1type_info@@UEAA@XZ 0x1400787b0
?terminate@@YAXXZ 0x1400787b8
_commode 0x1400787c0
_fmode 0x1400787c8
_wcmdln 0x1400787d0
__C_specific_handler 0x1400787d8
wcstok 0x1400787e0
_wcsnicmp 0x1400787e8
_wcsicmp 0x1400787f0
_CxxThrowException 0x1400787f8
_initterm 0x140078800
__setusermatherr 0x140078808
_cexit 0x140078810
_exit 0x140078818
exit 0x140078820
__set_app_type 0x140078828
__wgetmainargs 0x140078830
_amsg_exit 0x140078838
_XcptFilter 0x140078840
wcscmp 0x140078848
Name Address
RtlInitUnicodeString 0x140078858
RtlCaptureContext 0x140078860
RtlLookupFunctionEntry 0x140078868
RtlVirtualUnwind 0x140078870
WinSqmIncrementDWORD 0x140078878
RtlEqualDomainName 0x140078880
Name Address
StrTrimW 0x140078150
PathIsContentTypeW 0x140078158
PathIsUNCServerShareW 0x140078160
PathAppendW 0x140078168
PathFileExistsW 0x140078170
StrChrW 0x140078178
SHSetValueW 0x140078180
SHGetValueW 0x140078188
PathRemoveFileSpecW 0x140078190
Name Address
StringFromGUID2 0x140078890
CoCreateInstance 0x140078898
CoInitialize 0x1400788a0
CoInitializeEx 0x1400788a8
CoUninitialize 0x1400788b0
OleRun 0x1400788b8
FreePropVariantArray 0x1400788c0
StgOpenStorageEx 0x1400788c8
CoTaskMemFree 0x1400788d0
PropVariantClear 0x1400788d8
OleUninitialize 0x1400788e0
OleInitialize 0x1400788e8
CoGetObject 0x1400788f0
Name Address
CommandLineToArgvW 0x1400780c8
ShellAboutW 0x1400780d0
SHGetMalloc 0x1400780d8
SHBrowseForFolderW 0x1400780e0
ShellExecuteExW 0x1400780e8
SHGetFolderPathAndSubDirW 0x1400780f0
ShellExecuteW 0x1400780f8
SHGetFolderPathW 0x140078100
SHSetLocalizedName 0x140078108
SHChangeNotify 0x140078110
SHGetSpecialFolderLocation 0x140078118
SHGetPathFromIDListW 0x140078120
SHFileOperationW 0x140078128
SHGetFileInfoW 0x140078138
SHGetDesktopFolder 0x140078140
Name Address
DeletePrinter 0x140078458
AddPrinterConnectionW 0x140078460
EnumPrintersW 0x140078468
DeletePrinterConnectionW 0x140078470
AddPrinterW 0x140078478
GetPrinterW 0x140078480
SetPrinterW 0x140078488
OpenPrinterW 0x140078490
ClosePrinter 0x140078498
Name Address
PropertySheetW 0x140076ab0
CreatePropertySheetPageW 0x140076ab8
ImageList_Create 0x140076ac0
ImageList_LoadImageW 0x140076ac8
InitCommonControlsEx 0x140076ad0
ImageList_GetIcon 0x140076ae0
ImageList_Destroy 0x140076ae8
ImageList_ReplaceIcon 0x140076af0
Name Address
SetWindowTheme 0x140078430
GetThemeSysFont 0x140078438
Name Address
CryptProtectData 0x140076b28
CryptUnprotectData 0x140076b30
Name Address
GetOpenFileNameW 0x140076b00
GetSaveFileNameW 0x140076b08
CommDlgExtendedError 0x140076b10
ChooseFontW 0x140076b18
Name Address
SysAllocStringLen 0x140078090
SysFreeString 0x140078098
GetErrorInfo 0x1400780a0
VariantClear 0x1400780a8
SysStringLen 0x1400780b0
SysAllocString 0x1400780b8
Name Address
GdipGetImagePixelFormat 0x140078500
GdipCreateBitmapFromScan0 0x140078508
GdipDrawImageRect 0x140078510
GdipGetImageGraphicsContext 0x140078518
GdipImageSelectActiveFrame 0x140078520
GdipDrawImageRectRect 0x140078528
GdipDeleteBrush 0x140078530
GdipSaveAddImage 0x140078538
GdipSaveAdd 0x140078540
GdipCreateSolidFill 0x140078548
GdipGetDpiY 0x140078550
GdipGetDpiX 0x140078558
GdipFillRectangle 0x140078560
GdipCloneBrush 0x140078568
GdipGetDC 0x140078570
GdipReleaseDC 0x140078578
GdipLoadImageFromFile 0x140078580
GdipGetImageHorizontalResolution 0x140078588
GdipGetImageHeight 0x140078590
GdipGetImageWidth 0x140078598
GdipCreateBitmapFromFile 0x1400785a0
GdipDeleteGraphics 0x1400785a8
GdipCreateFromHDC 0x1400785b0
GdipSaveImageToFile 0x1400785b8
GdipGetImageRawFormat 0x1400785c0
GdipGetImageEncoders 0x1400785c8
GdiplusShutdown 0x1400785d0
GdiplusStartup 0x1400785d8
GdipGetImageVerticalResolution 0x1400785e0
GdipFree 0x1400785e8
GdipAlloc 0x1400785f0
GdipCloneImage 0x1400785f8
GdipGetPropertyItemSize 0x140078600
GdipGetPropertyItem 0x140078608
GdipImageGetFrameDimensionsCount 0x140078610
GdipImageGetFrameDimensionsList 0x140078618
GdipImageGetFrameCount 0x140078620
GdipDisposeImage 0x140078628
GdipSetPropertyItem 0x140078630
GdipGetImageEncodersSize 0x140078638
Name Address
PlaySoundW 0x140078448
Name Address
GetNameInfoW 0x1400784a8
WSAStringToAddressW 0x1400784b0
FreeAddrInfoW 0x1400784b8
WSAAddressToStringW 0x1400784c0
WSAGetLastError 0x1400784c8
GetAddrInfoW 0x1400784d0
WSAStartup 0x1400784d8
WSACleanup 0x1400784e0
Name Address
CredUIParseUserNameW 0x1400784f0
Name Address


Reports: JSON

Usage


Processing ( 35.52 seconds )

  • 32.539 ProcessMemory
  • 2.518 CAPE
  • 0.442 BehaviorAnalysis
  • 0.021 AnalysisInfo
  • 0.001 Debug

Signatures ( 0.12 seconds )

  • 0.022 antiav_detectreg
  • 0.009 ransomware_files
  • 0.009 territorial_disputes_sigs
  • 0.008 infostealer_ftp
  • 0.006 antianalysis_detectfile
  • 0.006 ransomware_extensions
  • 0.005 antianalysis_detectreg
  • 0.005 infostealer_im
  • 0.004 antiav_detectfile
  • 0.004 infostealer_mail
  • 0.003 ursnif_behavior
  • 0.002 antivm_vbox_files
  • 0.002 antivm_vbox_keys
  • 0.002 antivm_vmware_keys
  • 0.002 geodo_banking_trojan
  • 0.002 browser_security
  • 0.002 infostealer_bitcoin
  • 0.002 poullight_files
  • 0.002 masquerade_process_name
  • 0.001 bot_drive
  • 0.001 antidebug_devices
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_parallels_keys
  • 0.001 antivm_vpc_keys
  • 0.001 antivm_xen_keys
  • 0.001 ketrican_regkeys
  • 0.001 browser_addon
  • 0.001 uac_bypass_cmstpcom
  • 0.001 darkcomet_regkeys
  • 0.001 disables_backups
  • 0.001 disables_browser_warn
  • 0.001 disables_power_options
  • 0.001 azorult_mutexes
  • 0.001 cryptbot_files
  • 0.001 echelon_files
  • 0.001 qulab_files
  • 0.001 modify_security_center_warnings
  • 0.001 revil_mutexes
  • 0.001 limerat_regkeys
  • 0.001 modirat_behavior
  • 0.001 warzonerat_regkeys
  • 0.001 recon_fingerprint
  • 0.001 remcos_regkeys
  • 0.001 removes_startmenu_defaults
  • 0.001 tampers_etw
  • 0.001 lokibot_mutexes

Reporting ( 0.32 seconds )

  • 0.299 CAPASummary
  • 0.021 JsonDump

Signatures

Queries the keyboard layout
The PE file contains a PDB path
pdbpath: Wfs.pdb
SetUnhandledExceptionFilter detected (possible anti-debug)
Resumed a thread in another process
thread_resumed: Process explorer.exe with process ID 640 resumed a thread in another process with the process ID 640
The binary contains an unknown PE section name indicative of packing
unknown section: {'name': '.didat', 'raw_address': '0x0009e200', 'virtual_address': '0x000a2000', 'virtual_size': '0x000001c0', 'size_of_data': '0x00000200', 'characteristics': 'IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE', 'characteristics_raw': '0xc0000040', 'entropy': '2.94'}
Yara detections observed in process dumps, payloads or dropped files
Hit: PID 2868 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 59 }']'
Anomalous binary characteristics
anomaly: Entrypoint of binary is located outside of any mapped sections
Binary compilation timestomping detected
anomaly: Compilation timestamp is in the future
Harvests information related to installed mail clients
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\(Default)
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail
Attempts to interact with an Alternate Data Stream (ADS)
file: C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA
file: C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:Docf_\x053or4kl4x13tuuug3Byamue2s4b:$DATA
file: C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:\x053or4kl4x13tuuug3Byamue2s4b:$DATA
file: C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:Updt_\x053or4kl4x13tuuug3Byamue2s4b:$DATA

Screenshots

No screenshots available.

Hosts

No hosts contacted.

DNS

No domains contacted.

Summary

C:\Windows\System32\kernel.appcore.dll
C:\Users\Packager\AppData\Local\Temp\profapi.dll
C:\Windows\System32\profapi.dll
C:\Users\Packager
C:\Users\Packager\Documents
C:\Users\Packager\Documents\Fax\Drafts
C:\Users
C:\Users\Packager\Documents\Fax
C:\
C:\Users\Packager\AppData\Local\Microsoft\Windows\Caches
C:\Users\Packager\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Packager\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db
C:\Users\desktop.ini
C:\Users\Packager\Documents\desktop.ini
\Device\DeviceApi\CMApi
C:\Users\Packager\AppData\Local\Temp\%SystemRoot%\system32\wfsr.dll
C:\Users\Packager\Documents\Fax\Drafts\desktop.ini
\??\MountPointManager
C:\Windows\Fonts\staticcache.dat
C:\Users\Packager\AppData\Local\Temp\TextShaping.dll
C:\Windows\System32\TextShaping.dll
C:\Users\Packager\Documents\Scanned Documents
C:\Users\Packager\Documents\Scanned Documents\desktop.ini
C:\Users\Packager\Documents\Scanned Documents\Documents
C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:Docf_\x053or4kl4x13tuuug3Byamue2s4b:$DATA
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:\x053or4kl4x13tuuug3Byamue2s4b:$DATA
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:Updt_\x053or4kl4x13tuuug3Byamue2s4b:$DATA
C:\Users\Packager\Documents\Scanned Documents\
C:\Users\Packager\Documents\Scanned Documents\*.*
C:\Users\Packager\Documents\Scanned Documents\Documents\
C:\Users\Packager\Documents\Scanned Documents\Documents\*.*
C:\Windows\System32\UxTheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\System32\textinputframework.dll
C:\Windows\System32\CoreUIComponents.dll
C:\Windows\System32\CoreMessaging.dll
C:\Windows\System32\WinTypes.dll
C:\Users\Packager\DOCUMENTS\SCANNED DOCUMENTS\nul
C:\Users\Packager\Documents\Scanned Documents\*.gif
C:\Users\Packager\Documents\Scanned Documents\*.bmp
C:\Users\Packager\Documents\Scanned Documents\*.dib
C:\Users\Packager\Documents\Scanned Documents\*.rle
C:\Users\Packager\Documents\Scanned Documents\*.jpg
C:\Users\Packager\Documents\Scanned Documents\*.jpe
C:\Users\Packager\Documents\Scanned Documents\*.jpeg
C:\Users\Packager\Documents\Scanned Documents\*.jfif
C:\Users\Packager\Documents\Scanned Documents\*.tif
C:\Users\Packager\Documents\Scanned Documents\*.tiff
C:\Users\Packager\Documents\Scanned Documents\*.png
C:\Users\Packager\Documents\Scanned Documents\*.xps
C:\Users\Packager\Documents\Fax\Inbox
C:\Users\Packager\Documents\Fax\Inbox\desktop.ini
C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\WelcomeFax.tif
C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
C:\Users\Packager\Documents\Fax\Inbox\WelcomeFax.tif
C:\Users\Packager\Documents\Fax\Inbox\*.tif
C:\Windows\System32\en-US\tzres.dll.mui
C:\Users\Packager\AppData\Local\Temp\MSFaxConsoleTempPreview-#00000b34dc8c5961.tif
C:\Users\Packager\Desktop\desktop.ini
C:\Users\Packager\Music\desktop.ini
C:\Users\Packager\Pictures\desktop.ini
C:\Users\Packager\Videos\desktop.ini
C:\Users\Packager\Downloads\desktop.ini
C:\Users\Packager\OneDrive\desktop.ini
C:\Users\Packager\AppData\Local\Temp\WFS.exe
C:\Users\Packager\AppData
C:\Users\Packager\AppData\Local
C:\Users\Packager\AppData\Local\Temp
\Device\Bam
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\IconCacheToDelete
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
C:\Users\Packager\AppData\Local\SystemResources\wfs.exe.mun
C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg
C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\WelcomeFax.tif
C:\Users\Packager\Documents\Fax\Inbox\WelcomeFax.tif
C:\Users\Packager\Documents\Fax\Drafts\desktop.ini
C:\Users\Packager\Documents\Scanned Documents\desktop.ini
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:\x053or4kl4x13tuuug3Byamue2s4b:$DATA
C:\Users\Packager\Documents\Scanned Documents\Welcome Scan.jpg\:Updt_\x053or4kl4x13tuuug3Byamue2s4b:$DATA
C:\Users\Packager\Documents\Fax\Inbox\desktop.ini
C:\Users\Packager\Documents\Fax\Inbox\WelcomeFax.tif
C:\Users\Packager\AppData\Local\Temp\MSFaxConsoleTempPreview-#00000b34dc8c5961.tif
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\software
HKEY_CURRENT_USER\SOFTWARE\Microsoft
HKEY_CURRENT_USER\SOFTWARE\Microsoft\WFS
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Archive
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Archive\MessagesPerCall
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Drafts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Drafts\Location
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\DefinitionFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-64934406-199802361-3218922526-1001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-64934406-199802361-3218922526-1001\ProfileImagePath
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WFS.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\WFS.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\FolderValueFlags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-300300000000}\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-300300000000}\Data
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-300300000000}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowStatusBar
HKEY_CLASSES_ROOT\Directory
HKEY_CURRENT_USER\Software\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_CURRENT_USER\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_CURRENT_USER\Software\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_CURRENT_USER\Software\Classes\Directory\AlwaysShowExt
HKEY_CURRENT_USER\Software\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-100000000000}\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-100000000000}\Generation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UseSystemForSystemFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Messaging Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Messaging Subsystem\MAPI
HKEY_LOCAL_MACHINE\Software\Microsoft\Fax\Client
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Client\DebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Fax\Compose\Fax
HKEY_CURRENT_USER\Software\Microsoft\Fax\Compose
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\Compose\JP_ISO_SIO_Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\3\KnownFolders
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\Tracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\WFS.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE\LaunchUserOOBE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\SplitterPos
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\SortAscendingScan
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\SortColumnScan
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosTop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosRight
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosBottom
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosLeft
HKEY_CURRENT_USER\Software\Microsoft\Fax\FaxOptions
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\PlaySoundOnNewMessage
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\ReceiptType
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\ReceiptAddress
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\GroupBroadcastReceipts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\AttachFaxToReceipt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IncludeOriginalMessageInReply
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsBold
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsItalic
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsUnderline
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontColor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontSize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontFaceName
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
HKEY_CURRENT_USER\Software\Microsoft\Fax\UserInfo
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\FullName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\FaxNumber
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Company
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Address
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\City
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\State
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\ZIP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Country
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Title
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Department
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Office
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\HomePhone
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\OfficePhone
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\BillingCode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Mailbox
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\TSID
HKEY_CURRENT_USER\Software\Microsoft\Fax
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\ShowReassign
HKEY_CLASSES_ROOT\CLSID\{A26CEC36-234C-4950-AE16-E34AACE71D0D}
HKEY_CLASSES_ROOT\CLSID\{E9A4A80A-44FE-4DE4-8971-7150B10A5199}
HKEY_CLASSES_ROOT\CLSID\{7693E886-51C9-4070-8419-9F70738EC8FA}
HKEY_CLASSES_ROOT\CLSID\{AC4CE3CB-E1C1-44CD-8215-5A1665509EC2}
HKEY_CLASSES_ROOT\CLSID\{0DBECEC1-9EB3-4860-9C6F-DDBE86634575}
HKEY_CLASSES_ROOT\CLSID\{72B624DF-AE11-4948-A65C-351EB0829419}
HKEY_CLASSES_ROOT\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}
HKEY_CLASSES_ROOT\CLSID\{E7E79A30-4F2C-4FAB-8D00-394F2D6BBEBE}
HKEY_CLASSES_ROOT\CLSID\{7F12E753-FC71-43D7-A51D-92F35977ABB5}
HKEY_CLASSES_ROOT\CLSID\{AA94DCC2-B8B0-4898-B835-000AABD74393}
HKEY_CLASSES_ROOT\CLSID\{1765E14E-1BD4-462E-B6B1-590BF1262AC6}
HKEY_CLASSES_ROOT\CLSID\{22C21F93-7DDB-411C-9B17-C5B7BD064ABC}
HKEY_CLASSES_ROOT\CLSID\{ED822C8C-D6BE-4301-A631-0E1416BAD28F}
HKEY_CLASSES_ROOT\CLSID\{6D68D1DE-D432-4B0F-923A-091183A9BDA7}
HKEY_CLASSES_ROOT\CLSID\{076C2A6C-F78F-4C46-A723-3583E70876EA}
HKEY_CLASSES_ROOT\CLSID\{C17CABB2-D4A3-47D7-A557-339B2EFBD4F1}
HKEY_CLASSES_ROOT\CLSID\{9CB5172B-D600-46BA-AB77-77BB7E3A00D9}
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_CLASSES_ROOT\CLSID\{05AF94D8-7174-4CD2-BE4A-4124B80EE4B8}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}\Containers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7E79A30-4F2C-4FAB-8D00-394F2D6BBEBE}\Containers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7F12E753-FC71-43D7-A51D-92F35977ABB5}\Containers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA94DCC2-B8B0-4898-B835-000AABD74393}\Containers
HKEY_CLASSES_ROOT\CLSID\{43324B33-A78F-480F-9111-9638AACCC832}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{43324B33-A78F-480F-9111-9638AACCC832}\Containers
HKEY_CLASSES_ROOT\CLSID\{DDE33513-774E-4BCD-AE79-02F4ADFE62FC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE33513-774E-4BCD-AE79-02F4ADFE62FC}\Containers
HKEY_CLASSES_ROOT\CLSID\{50D42F09-ECD1-4B41-B65D-DA1FDAA75663}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50D42F09-ECD1-4B41-B65D-DA1FDAA75663}\Containers
HKEY_CLASSES_ROOT\CLSID\{D9403860-297F-4A49-BF9B-77898150A442}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D9403860-297F-4A49-BF9B-77898150A442}\Containers
HKEY_CLASSES_ROOT\CLSID\{3697790B-223B-484E-9925-C4869218F17A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3697790B-223B-484E-9925-C4869218F17A}\Containers
HKEY_CLASSES_ROOT\CLSID\{03012959-F4F6-44D7-9D09-DAA087A9DB57}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03012959-F4F6-44D7-9D09-DAA087A9DB57}\Containers
HKEY_CLASSES_ROOT\CLSID\{D4DCD3D7-B4C2-47D9-A6BF-B89BA396A4A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4DCD3D7-B4C2-47D9-A6BF-B89BA396A4A3}\Containers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72B624DF-AE11-4948-A65C-351EB0829419}\Containers
HKEY_CLASSES_ROOT\CLSID\{B5C8B898-0074-459F-B700-860D4651EA14}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B5C8B898-0074-459F-B700-860D4651EA14}\Containers
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Schemas
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Namespaces
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\ResourcePolicies
HKEY_CURRENT_USER\Software\Microsoft\Fax\FaxAccounts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Inbox
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Inbox\Location
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\WelcomeFaxCopied
HKEY_LOCAL_MACHINE\Software\Microsoft\Fax\Client\ServiceStartup
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\en-US
HKEY_CLASSES_ROOT\CLSID\{AA7E3C50-864C-4604-BC04-8B0B76E637F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA7E3C50-864C-4604-BC04-8B0B76E637F6}\Containers
HKEY_CLASSES_ROOT\CLSID\{9F66347C-60C4-4C4D-AB58-D2358685F607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9F66347C-60C4-4C4D-AB58-D2358685F607}\Containers
HKEY_CLASSES_ROOT\CLSID\{50B1904B-F28F-4574-93F4-0BADE82C69E9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50B1904B-F28F-4574-93F4-0BADE82C69E9}\Containers
HKEY_CLASSES_ROOT\CLSID\{356F2F88-05A6-4728-B9A4-1BFBCE04D838}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{356F2F88-05A6-4728-B9A4-1BFBCE04D838}\Containers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\Maximized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\AppCompatClassName
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\IsVailContainer
HKEY_LOCAL_MACHINE\Software\Microsoft\Input
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\ResyncResetTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\MaxResyncAttempts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.
HKEY_CLASSES_ROOT\.
HKEY_CLASSES_ROOT\.\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\OpenWithProgids
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.
HKEY_CLASSES_ROOT\Unknown
HKEY_CURRENT_USER\Software\Classes\Unknown\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\ShellEx\IconHandler
HKEY_CLASSES_ROOT\SystemFileAssociations\.
HKEY_CURRENT_USER\Software\Classes\.
HKEY_LOCAL_MACHINE\Software\Classes\.
HKEY_CURRENT_USER\Software\Classes\SystemFileAssociations\.
HKEY_LOCAL_MACHINE\Software\Classes\SystemFileAssociations\.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\NeverShowExt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{F42EE2D3-909F-4907-8871-4C22FC0BF756}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A0C69A99-21C8-4671-8703-7934162FCF1D}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{0DDD015D-B06C-45D5-8C4C-F59713854639}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}
HKEY_CLASSES_ROOT\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\FolderValueFlags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}
HKEY_CLASSES_ROOT\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\SortOrderIndex
HKEY_CLASSES_ROOT\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\CLSID
HKEY_CLASSES_ROOT\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\DescriptionID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\HelpTopic
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\AllowChildAliasRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\RecursiveSearch
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\TargetKnownFolder
HKEY_CURRENT_USER\Software\Classes\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}\Instance
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}\Instance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\3\ApplicationViewManagement\W32:000000000002017A
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\3\ApplicationViewManagement\W32:000000000002017A\VirtualDesktop
HKEY_CLASSES_ROOT\Applications\WFS.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\SortOrderIndex
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\FolderValueFlags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_CLASSES_ROOT\CLSID\{56AD4C5D-B908-4F85-8FF1-7940C29B3BCF}\Instance
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\Instance
HKEY_CLASSES_ROOT\CLSID\{4234D49B-0245-4DF3-B780-3893943456E1}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\LoadWithoutCOM
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedAppEvents
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Feeds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\IsFeedsAvailable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\HeadlinesOnboardingComplete
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\ShellFeedsTaskbarViewMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\ShellFeedsTaskbarContentUpdateMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ThumbnailCache
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\Value
HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\current\Device\DataProtection
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Programs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\Cnpxntre\NccQngn\Ybpny\Grzc\JSF.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYPHNPbhag:pgbe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Archive\MessagesPerCall
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Drafts\Location
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\DefinitionFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-64934406-199802361-3218922526-1001\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\FolderValueFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\ValidateRegItems
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\MonitorRegistry
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-300300000000}\Data
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-300300000000}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowStatusBar
HKEY_CURRENT_USER\Software\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_CURRENT_USER\Software\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_CURRENT_USER\Software\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_CURRENT_USER\Software\Classes\Directory\AlwaysShowExt
HKEY_CURRENT_USER\Software\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{01989354-0000-0000-0000-100000000000}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UseSystemForSystemFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Messaging Subsystem\MAPI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Client\DebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\Compose\JP_ISO_SIO_Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE\LaunchUserOOBE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\SortAscending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\SortColumn
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\SplitterPos
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04\Show
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04\Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04\Order
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\SortAscendingScan
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\SortColumnScan
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosTop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosRight
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosBottom
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\NormalPosLeft
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\PlaySoundOnNewMessage
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\ReceiptType
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\ReceiptAddress
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\GroupBroadcastReceipts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\AttachFaxToReceipt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IncludeOriginalMessageInReply
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsBold
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsItalic
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsUnderline
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontColor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontSize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontFaceName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\FullName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\FaxNumber
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Company
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Address
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\City
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\State
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\ZIP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Country
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Title
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Department
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Office
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\HomePhone
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\OfficePhone
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\BillingCode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Mailbox
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\TSID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\ShowReassign
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\ResourcePolicies
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Inbox\Location
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\WelcomeFaxCopied
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame\Maximized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\IsVailContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\ResyncResetTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\MaxResyncAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Unknown\NeverShowExt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{F42EE2D3-909F-4907-8871-4C22FC0BF756}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A0C69A99-21C8-4671-8703-7934162FCF1D}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{0DDD015D-B06C-45D5-8C4C-F59713854639}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{35286A68-3C57-41A1-BBB1-0EAE73D76C95}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{7D83EE9B-2244-4E70-B1F5-5393042AF1E4}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\ShellFolder\FolderValueFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{A8CDFF1C-4878-43BE-B5FD-F8091C1C60D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\DescriptionID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\HelpTopic
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\AllowChildAliasRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\RecursiveSearch
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}\Instance\InitPropertyBag\TargetKnownFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\ShellFolder\FolderValueFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{4234D49B-0245-4DF3-B780-3893943456E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4234d49b-0245-4df3-b780-3893943456e1}\InProcServer32\LoadWithoutCOM
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\IsFeedsAvailable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\HeadlinesOnboardingComplete
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\ShellFeedsTaskbarViewMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\ShellFeedsTaskbarContentUpdateMode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\PolicyType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\Behavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\MergeAlgorithm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\RegKeyPathRedirectMapped
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\RegKeyPathRedirect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\grouppolicyname
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\ADMXMetadataUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\ADMXMetadataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\ADMXMetadataBoth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\DataProtection\EDPShowIcons\Value
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Programs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\Cnpxntre\NccQngn\Ybpny\Grzc\JSF.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYPHNPbhag:pgbe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Archive
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Drafts
HKEY_CURRENT_USER\Software\Microsoft\Fax\Compose\Fax
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\IncomingView\Columns\16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\InboxView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\DraftsView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\17
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\18
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\19
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\21
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\SentItemsView\Columns\22
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\05
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\06
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\07
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\08
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\09
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\17
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\18
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\19
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\21
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\OutboxView\Columns\22
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\MainFrame
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\00
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\02
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\03
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\ScanView\Columns\04
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\PlaySoundOnNewMessage
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\ReceiptType
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\ReceiptAddress
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\GroupBroadcastReceipts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\AttachFaxToReceipt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IncludeOriginalMessageInReply
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsBold
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsItalic
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\IsUnderline
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontColor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontSize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\FaxOptions\FontFaceName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\FullName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\FaxNumber
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Company
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Address
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\City
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\State
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\ZIP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Country
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Title
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Department
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Office
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\HomePhone
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\OfficePhone
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\BillingCode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\Mailbox
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\TSID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\ShowReassign
HKEY_CURRENT_USER\Software\Microsoft\Fax\FaxAccounts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\wfs\Inbox
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fax\UserInfo\WelcomeFaxCopied
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\3\ApplicationViewManagement\W32:000000000002017A
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\3\ApplicationViewManagement\W32:000000000002017A\VirtualDesktop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\P:\Hfref\Cnpxntre\NccQngn\Ybpny\Grzc\JSF.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
Local\SM0:2868:304:WilStaging_02
Local\SM0:2868:120:WilError_03
Local\MSCTF.Asm.MutexDefault3
CicLoadWinStaWinSta0
Local\MSCTF.CtfMonitorInstMutexDefault3
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwWriterMutex
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_16.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_32.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_48.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_96.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_256.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_768.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_1280.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_1920.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_2560.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_sr.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_wide.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_exif.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_wide_alternate.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_custom_stream.db!dfMaintainer
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!IconCacheInit
Global\C::Users:Packager:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwReaderRefs
Fax
No results
Sorry! No behavior.
Sorry! No strace.
Sorry! No tracee.

No hosts contacted.

No TCP connections recorded.

No UDP connections recorded.

No domains contacted.

HTTP Requests

No HTTP(s) requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No Suricata Extracted files.
Sorry! No dropped files.
Sorry! No process dumps.
Sorry! No process dumps.