What is winrar-5-50-beta-1-x86.exe?

winrar-5-50-beta-1-x86.exe is digitally signed by win.rar GmbH.

winrar-5-50-beta-1-x86.exe is usually located in the 'c:\downloads\' folder.

Some of the anti-virus scanners at VirusTotal detected winrar-5-50-beta-1-x86.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

winrar-5-50-beta-1-x86.exe does not have any version or vendor information.

Digital signatures [?]

winrar-5-50-beta-1-x86.exe has a valid digital signature.

PropertyValue
Signer namewin.rar GmbH
Certificate issuer nameCOMODO RSA Code Signing CA
Certificate serial number00fe46a10ad94269c3dd225c13645352e4

VirusTotal report

1 of the 66 anti-virus programs at VirusTotal detected the winrar-5-50-beta-1-x86.exe file. That's a 2% detection rate.

ScannerDetection Name
Zillya Trojan.GenericKD.Win32.52733
1 of the 66 anti-virus programs detected the winrar-5-50-beta-1-x86.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_created": [
        "C:\\Program Files (x86)\\WinRAR\\Uninstall.lst",
        "C:\\Program Files (x86)\\WinRAR\\WhatsNew.txt",
        "C:\\Program Files (x86)\\WinRAR\\Uninstall.exe",
        "C:\\Program Files (x86)\\WinRAR\\UnRAR.exe",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
        "C:\\Program Files (x86)\\WinRAR\\RarExt.dll",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
        "C:\\Program Files (x86)\\WinRAR\\ReadMe.txt",
        "C:\\Program Files (x86)\\WinRAR\\UNACEV2.DLL",
        "C:\\Program Files (x86)\\WinRAR\\__tmp_rar_sfx_access_check_27698812",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
        "C:\\Program Files (x86)\\WinRAR\\Rar.txt",
        "C:\\Program Files (x86)\\WinRAR\\RarExt64.dll",
        "C:\\Program Files (x86)\\WinRAR\\Default.SFX",
        "C:\\Program Files (x86)\\WinRAR\\Descript.ion",
        "C:\\Program Files (x86)\\WinRAR\\WinRAR.chm",
        "C:\\Program Files (x86)\\WinRAR\\rarnew.dat",
        "C:\\Program Files (x86)\\WinRAR\\zipnew.dat",
        "C:\\Program Files (x86)\\WinRAR\\WinCon.SFX",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
        "C:\\Program Files (x86)\\WinRAR\\Rar.exe",
        "C:\\Program Files (x86)\\WinRAR\\WinRAR.exe",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
        "C:\\Program Files (x86)\\WinRAR\\Order.htm",
        "C:\\Program Files (x86)\\WinRAR\\RarFiles.lst",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
        "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
        "C:\\Program Files (x86)\\WinRAR\\License.txt",
        "C:\\Program Files (x86)\\WinRAR\\Zip.SFX",
        "C:\\Program Files (x86)\\WinRAR\\7zxa.dll",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk"
    ],
    "regkey_written": [
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r29\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shell\\open\\command\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r19\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r09\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\WinRAR32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\VersionMinor",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links\\Desktop",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\ContextMenuHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cab\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r22\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\RegisteredApplications\\WinRAR",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.rar\\ShellNew\\FileName",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zipx\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r16\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.REV\\shell\\open\\command\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\UninstallString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tbz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zip\\ShellNew\\FileName",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\DisplayName",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\InstallLocation",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.zipx",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\NoModify",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bz2\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r03\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r10\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\InProcServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shell\\open\\command\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tlz\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r02\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\WinRAR.exe\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r20\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.lz",
        "HKEY_CURRENT_USER\\Software\\WinRAR SFX\\C%%Program Files (x86)%WinRAR",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.001",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.uu",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\WinRAR32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.bz2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\WinRAR32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\WinRAR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.uu\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lzh\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\DisplayVersion",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r18\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.lha",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.iso\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r15\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.001\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tbz2\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\ApplicationDescription",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.7z",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\exe32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lha\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\DragDropHandlers\\WinRAR32\\(Default)",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r07\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.xz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.rar",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\DefaultIcon\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.jar\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r24\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bz\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.rev\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r27\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r04\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.z",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r01\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.lzh",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.zip",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r11\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zip\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\GlobalAssocChangedCounter",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links\\StartMenu",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\WinRAR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.rar\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\ShellExt",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r26\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.xxe\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r00\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\DropHandler\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\WinRAR.exe\\Path",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.taz\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.z\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r13\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links\\Programs",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tlz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.7z\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r28\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.jar",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\ShellNew",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\DragDropHandlers\\WinRAR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\Language",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.cab",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\ContextMenuHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.uue",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tgz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.txz\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r17\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.bz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\WinRAR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.xz\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.arj\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tbz\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.iso",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lz\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\\JvaENE\\Havafgnyy.rkr",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tar\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\Set",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tar",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\InProcServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.taz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r25\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\Publisher",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\CascadedMenu",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r08\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r05\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r14\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\DropHandler\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tgz\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.REV\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ace\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz\\Type",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\NoRepair",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gz\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\MenuIcons",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r06\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz\\Exist",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\VersionMajor",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\ContextMenuHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.ace",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.gz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.arj",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.uue\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\ContextMenuHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.REV\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r23\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\DefaultIcon\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r12\\(Default)",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\Set",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\Type",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\DisplayIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r21\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.txz",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.xxe",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\Exist",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tbz2",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\ShellNew",
        "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\Type"
    ],
    "dll_loaded": [
        "IEFRAME.dll",
        "ext-ms-win-kernel32-package-current-l1-1-0",
        "C:\\Windows\\system32\\riched20.dll",
        "urlmon.dll",
        "kernel32",
        "POWRPROF.DLL",
        "srvcli.dll",
        "apphelp.dll",
        "api-ms-win-core-localization-l1-2-1",
        "kernel32.dll",
        "UxTheme.dll",
        "C:\\Windows\\system32\\rsaenh.dll",
        "C:\\Windows\\system32\\ole32.dll",
        "C:\\Windows\\system32\\sfc_os.dll",
        "dwmapi.dll",
        "slc.dll",
        "C:\\Windows\\system32\\DXGIDebug.dll",
        "profapi.dll",
        "mshtml.dll",
        "

Dropped

[
    {
        "yara": [],
        "sha1": "7dc007338abcf2946b09a07aabf8f0f03d2451d4",
        "name": "7d914ad5ba894cfb_unrar.exe",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\UnRAR.exe",
        "type": "PE32 executable (console) Intel 80386, for MS Windows",
        "sha256": "7d914ad5ba894cfbedf822f546ef604c787944df8980990d182b4fc1b921d3d3",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "0E4E90EF",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/7d914ad5ba894cfb_unrar.exe",
        "ssdeep": null,
        "size": 366856,
        "sha512": "aca16e246db5742b1f14d3c74712e110053b3d1f0041dc2f575a0273bccc2504fc2112df689d6b42c224ccf16a9cb54376b103f8db1c7158510cf3e3d94c5fe0",
        "pids": [
            2460
        ],
        "md5": "f676620b4f3d488798fb307c3e24774f"
    },
    {
        "yara": [],
        "sha1": "a5f66d420b6a6ebb04242fb85ca462a99dbf89b6",
        "name": "c9d28800e740a156_unacev2.dll",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\UNACEV2.DLL",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "c9d28800e740a1569aec8fe27df10ef186d883f94cec15a5c228826b45a24f9d",
        "urls": [],
        "crc32": "FBD107E5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/c9d28800e740a156_unacev2.dll",
        "ssdeep": null,
        "size": 77312,
        "sha512": "32b22966ecec433636f927dc7b27cf782271b36169a9fdd50aa99a4d8cf14496ac3948a3747b7b7680d2d472f6af714e640b05c29194e8f2db92b21619b09c11",
        "pids": [
            2460
        ],
        "md5": "de02c4d04088b69e64ecc30a3d9e22e5"
    },
    {
        "yara": [],
        "sha1": "45e117fda98d04669df00f593b179d088367942b",
        "name": "9f535d22754a5910_uninstall.exe",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Uninstall.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "9f535d22754a591001622f4c1c5264ad6ac916f15f1677f23e8a8eef1ed443f2",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "0B6B823B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/9f535d22754a5910_uninstall.exe",
        "ssdeep": null,
        "size": 200976,
        "sha512": "a85914fb835e5073f087f666e59ff6c711514ee9058cf4cfac5a7bee98ad1ecf8094be31fc68c36d737272ecd1d14e1b1591a9e85ae51deff257c946a9b86e45",
        "pids": [
            2460
        ],
        "md5": "e76b82cef16b6ac3e07161166b403c7b"
    },
    {
        "yara": [],
        "sha1": "7ccb8bdaaee66d512577dccf66dd3ecc7daabc60",
        "name": "12787f8204eedb0b_rarfiles.lst",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\RarFiles.lst",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "12787f8204eedb0b8bdabf5d68d557334fddb2d70b46e1422510713dda5e6a01",
        "urls": [],
        "crc32": "BE6FFB35",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/12787f8204eedb0b_rarfiles.lst",
        "ssdeep": null,
        "size": 1268,
        "sha512": "93ccf9a6db360fada6507ef8a4a893fd7e7d92178984b99cee11f22090a9c1293b5367fe25ea8301e317e743f6e987eb4406af8ee76073662e2c2f8005e98d51",
        "pids": [
            2460
        ],
        "md5": "08ea0309d72a874c182f08cbf9da2cc3"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "36f7bfad8b54f1991f60c17d2bd2bbe05cf486eb",
        "name": "9d12ed0108593b14_winrar.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Mon Apr 24 17:46:34 2017, length=1517320, window=hide",
        "sha256": "9d12ed0108593b148c1bfa5ea0da94a71892b9b316a92e14c897a9245de21e12",
        "urls": [],
        "crc32": "2F8394F7",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/9d12ed0108593b14_winrar.lnk",
        "ssdeep": null,
        "size": 1023,
        "sha512": "b5292cdac14a3bf7d3f127e93717709cb27cc95128aeca3650870a97f929feb5eb67f67e4a1b95b2ee85b4a60f03faf454ee07c62c017139f96ff5f706a6d8e5",
        "pids": [
            2096
        ],
        "md5": "afeb2b89cf970f1039cb56dc7e6a8e54"
    },
    {
        "yara": [],
        "sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709",
        "name": "e3b0c44298fc1c14___tmp_rar_sfx_access_check_27698812",
        "type": "empty",
        "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
        "urls": [],
        "crc32": "00000000",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/e3b0c44298fc1c14___tmp_rar_sfx_access_check_27698812",
        "ssdeep": null,
        "size": 0,
        "sha512": "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e",
        "md5": "d41d8cd98f00b204e9800998ecf8427e"
    },
    {
        "yara": [],
        "sha1": "786adb4e4802488cf79da9c2887e47a7b034db72",
        "name": "64eee728f38a3657_whatsnew.txt",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\WhatsNew.txt",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "64eee728f38a3657c0b5ce35c8979153f5d3bd412ce33b804a0b263009b32639",
        "urls": [
            "http:\/\/rarlab.com\/vuln_sfx_html2.htm",
            "https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms14-064.aspx",
            "https:\/\/blake2.net"
        ],
        "crc32": "37B0AC31",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/64eee728f38a3657_whatsnew.txt",
        "ssdeep": null,
        "size": 63389,
        "sha512": "0d3d2fb16da4a121af5915136ffdc5392f8c32983276dc97bf27045311315fb7f32ea417a9801879d95736bd4eb9c5dec579e41c3468ee9e995256f2f175d109",
        "pids": [
            2460
        ],
        "md5": "515ce3456b83f991fa2cf4c3de7ca78b"
    },
    {
        "yara": [],
        "sha1": "07c731b7cbd1019eb047af826872e9c13eb236c5",
        "name": "dbfde3d73f18217d_winrar.exe",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\WinRAR.exe",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "dbfde3d73f18217d615b412b05c08e6f8a1b6cd521fd56b5be03dc94b6e20a11",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "AE99A058",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/dbfde3d73f18217d_winrar.exe",
        "ssdeep": null,
        "size": 1517320,
        "sha512": "7c9c37091ddd3a399447845451f2f9074167fc4d268fbb2939bebe81261a496c0bc9e1b49bad222e07ca8382229322faafc15ac2cd1286c2e5ef9d437afbbf09",
        "pids": [
            2460
        ],
        "md5": "73f4da56283ad873137e19ffd345c1d8"
    },
    {
        "yara": [],
        "sha1": "6233724f8b3ac18649dc248d1c778e2bca78a7f2",
        "name": "4301ec2e9592e7a2_rarnew.dat",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\rarnew.dat",
        "type": "RAR archive data, flags: Archive volume, Commented, Locked, Solid,",
        "sha256": "4301ec2e9592e7a22262d1c046954545033b73be322b33a8117d201556c4254b",
        "urls": [],
        "crc32": "2E7BD620",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/4301ec2e9592e7a2_rarnew.dat",
        "ssdeep": null,
        "size": 24,
        "sha512": "2e8945172ef567d4ae84d6317efce63502a6d9496caa48b8dc09cf12d1ceec3e89d033d6d9fceeba82f403107d15341bcdb72b4a6f60ba3e6df4d2a2cb6e48cd",
        "pids": [
            2096
        ],
        "md5": "c69d0b5902a959577c02e9dcdda77de0"
    },
    {
        "yara": [],
        "sha1": "b362897dcaf86db8a85ba3d21905ffbd4f5d4115",
        "name": "49f34467654d78a1_winrar.chm",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\WinRAR.chm",
        "type": "MS Windows HtmlHelp Data",
        "sha256": "49f34467654d78a1c9c5f3be6ea5e1d842dfea1005c4711597b8a0b0e4ffa033",
        "urls": [],
        "crc32": "BDA9F52B",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/49f34467654d78a1_winrar.chm",
        "ssdeep": null,
        "size": 310804,
        "sha512": "2e6cabcf1c7b1e6ce3ed93f9d2711a6c058e1f92a84eab3bcf4dd91ef43e39e71eb4fa50188e3750e233ebc8c80b208fce48f7d54213b74cc73b7ac343cec4b9",
        "pids": [
            2460
        ],
        "md5": "23e6bde58c0a7376eefbbe5502770b0c"
    },
    {
        "yara": [],
        "sha1": "b381e3756ae55c119996f8a4b4fa65e86bef0ccd",
        "name": "4cd8627d48333b2e_rarext.dll",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\RarExt.dll",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "4cd8627d48333b2e46a5106a8c72c897abf2849487aa2bfae6898d9314b89d87",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "73AE0918",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/4cd8627d48333b2e_rarext.dll",
        "ssdeep": null,
        "size": 366344,
        "sha512": "edd83402c415e389097512a1bfcc08f04f92c446179be43ffd153130ecdee5cd904229340db71550b640215485a9e21c32e2ba051025e6312a33ffa3d2045762",
        "pids": [
            2460
        ],
        "md5": "2a200d1da7569cb90465bc0d7e3986d8"
    },
    {
        "yara": [],
        "sha1": "579a9ca74cd0d1242556f38a5b471f2c28d49889",
        "name": "1b725fdf19ad3897_order.htm",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Order.htm",
        "type": "HTML document, ASCII text, with CRLF line terminators",
        "sha256": "1b725fdf19ad3897fc20d3464c2393a1fb53117dc4c945b8c91a2280d7735bed",
        "urls": [
            "http:\/\/www.rarlab.com\/registration.php",
            "http:\/\/www.rarlab.com"
        ],
        "crc32": "FB7594F7",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/1b725fdf19ad3897_order.htm",
        "ssdeep": null,
        "size": 3229,
        "sha512": "3543f6f06fe9dd2c442bf4d2704b47aed4ad8ac330061ba52b085bf2176c62d85d457935a7bf02c6d17d3cf3acd35c618433ebbda579bb2a2b06a81e76b47296",
        "pids": [
            2460
        ],
        "md5": "5bfbad2b771c10c15d9a64f46ee72dd6"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "0fded0a7d2fdaa5edb51d33a9020c5e3e7dd6096",
        "name": "1fe46bf36cb591af_winrar help.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Mon Apr 24 17:46:05 2017, length=310804, window=hide",
        "sha256": "1fe46bf36cb591af283ee13bbbf76d6206bc16a046904eee39e764a930d826aa",
        "urls": [],
        "crc32": "19070B69",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/1fe46bf36cb591af_winrar help.lnk",
        "ssdeep": null,
        "size": 1023,
        "sha512": "04c87fbe40ff02b31186c371299b487c01b86602ad09a6dda914e6cebf596eb8a51479070554990549c2a6611583925d2c8e035d10f1733f9e310791b8d06529",
        "pids": [
            2096
        ],
        "md5": "c92ada8525a6bb9218d530d342672fa9"
    },
    {
        "yara": [],
        "sha1": "93db55ae5e29052c526d06175eae1ed33cb5db61",
        "name": "7ddb23fc019323ab_rar.exe",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Rar.exe",
        "type": "PE32 executable (console) Intel 80386, for MS Windows",
        "sha256": "7ddb23fc019323abf8f1e7567b806bc889007c3846b2b2aed9e3c9aae36a019f",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "B33987AC",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/7ddb23fc019323ab_rar.exe",
        "ssdeep": null,
        "size": 562448,
        "sha512": "57bdc901bfa870db84dea7d322e57c9656e640a107805fe73054026e84601edd4f8c11ec6ac41bcd601bd69095e286ea740e47a57d58fa0fc1c8f88104d0f42b",
        "pids": [
            2460
        ],
        "md5": "272cc74ed05256a3f89209deceb6a936"
    },
    {
        "yara": [],
        "sha1": "26a0350afc712d1e4d16d70589ba323b7f9894b9",
        "name": "0971037a31e532e6_zip.sfx",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Zip.SFX",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "0971037a31e532e6c76c5ba5d9c84e8018975efd5a49ef72e8957bd898cd7eef",
        "urls": [],
        "crc32": "1CDCE39D",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/0971037a31e532e6_zip.sfx",
        "ssdeep": null,
        "size": 212480,
        "sha512": "03974ecfcc5d94e06620660bd57b5fc437977284a4d98ea576e0dc0419e2fb2f2d06dba55ddf197924cacc521f0a5e2929d74e9a7a6a2967c9f08f96b30d851e",
        "pids": [
            2460
        ],
        "md5": "54ce22d1918d61f4ef6c60f0a294f011"
    },
    {
        "yara": [],
        "sha1": "b04f3ee8f5e43fa3b162981b50bb72fe1acabb33",
        "name": "8739c76e681f9009_zipnew.dat",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\zipnew.dat",
        "type": "Zip archive data (empty)",
        "sha256": "8739c76e681f900923b900c9df0ef75cf421d39cabb54650c4b9ad19b6a76d85",
        "urls": [],
        "crc32": "D7CBC50E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/8739c76e681f9009_zipnew.dat",
        "ssdeep": null,
        "size": 22,
        "sha512": "5e2f959f36b66df0580a94f384c5fc1ceeec4b2a3925f062d7b68f21758b86581ac2adcfdde73a171a28496e758ef1b23ca4951c05455cdae9357cc3b5a5825f",
        "pids": [
            2096
        ],
        "md5": "76cdb2bad9582d23c1f6f4d868218d6c"
    },
    {
        "yara": [],
        "sha1": "24a63401aa8aad3dd50e84bf53be4026e3743388",
        "name": "190ddef85c19a121_rarext64.dll",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\RarExt64.dll",
        "type": "PE32+ executable (DLL) (GUI) x86-64, for MS Windows",
        "sha256": "190ddef85c19a12146b3af2119b8eb00c1363388246c379c83f41f7bb6437849",
        "urls": [
            "http:\/\/www.usertrust.com1",
            "http:\/\/ocsp.comodoca.com0",
            "http:\/\/crl.usertrust.com\/UTN-USERFirst-Object.crl05",
            "http:\/\/crl.comodoca.com\/COMODORSACertificationAuthority.crl0q",
            "http:\/\/crl.comodoca.com\/COMODORSACodeSigningCA.crl0t",
            "https:\/\/secure.comodo.net\/CPS0C",
            "http:\/\/ocsp.usertrust.com0",
            "http:\/\/crt.comodoca.com\/COMODORSACodeSigningCA.crt0",
            "http:\/\/crt.comodoca.com\/COMODORSAAddTrustCA.crt0"
        ],
        "crc32": "FD9047CD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/190ddef85c19a121_rarext64.dll",
        "ssdeep": null,
        "size": 435976,
        "sha512": "5fa6948c29f26f22ad491403f6ee4b6182fe7d236138fb49eb0ef1ffa46fb9f17fc3dd1e54a5ffd6b15242885e20b33ee63675f66c050b30bf31148ffc261b40",
        "pids": [
            2460
        ],
        "md5": "2704a4be8666a6bbf104e430ac99bc1a"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "9db96874e5fa4814d55863f3eade4d03a9337604",
        "name": "9c7ff98109316944_what is new in the latest version.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Thu Apr 13 10:12:00 2017, length=63389, window=hide",
        "sha256": "9c7ff9810931694408c6f73a01367b08406ecbd20f24630e1fb40bda29e1eaa2",
        "urls": [],
        "crc32": "848EC95D",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/9c7ff98109316944_what is new in the latest version.lnk",
        "ssdeep": null,
        "size": 1035,
        "sha512": "8f58ef5b5918f47872170987ba3bf54bf2d79f9ef23f1e9df8928b4ba3be5e2f4831b186290f2a015fd7411cb6967ebe79fdf117ed926c89eb66e775f8fe9a78",
        "pids": [
            2096
        ],
        "md5": "8284e2d38ae6e2140b4b45064ab34317"
    },
    {
        "yara": [],
        "sha1": "f91e7ecaa1418c4594aa21a909380d3ab76cb766",
        "name": "9e0f4043fbb548be_default.sfx",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Default.SFX",
        "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
        "sha256": "9e0f4043fbb548be8bdfdf011ca9fd6d9935f7a768f23e3443d430aa54bbf3f0",
        "urls": [],
        "crc32": "26DD9017",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/9e0f4043fbb548be_default.sfx",
        "ssdeep": null,
        "size": 259072,
        "sha512": "fc95065111389c13137980921480ec93d5ccb5b9c28f01052a034a335bd100e73431817af18729d855fcc2dd312f52cb018716ffef4f5e111ebc6fa690aaa732",
        "pids": [
            2460
        ],
        "md5": "fd82da0ada311ecd8a37bd7c3739b6c1"
    },
    {
        "yara": [],
        "sha1": "8a6a0c657af3bf729551c422eacad08ccb2e8261",
        "name": "10a1d803683e5a69_rar.txt",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Rar.txt",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "10a1d803683e5a69de2eb84f5f4d8a9c5558ea3628ab92b3d6bb026ecd0d5a7b",
        "urls": [],
        "crc32": "3FE2A89A",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/10a1d803683e5a69_rar.txt",
        "ssdeep": null,
        "size": 101948,
        "sha512": "da19c477e560579b0102788c349bc5ce50c915138d8597c7dc02a67b0f91858c1c0821ed30ab196df15c15d11c0a56bbf20e8476798dee331928df969d9e6f02",
        "pids": [
            2460
        ],
        "md5": "0645bde6b77b094ffef31d08dad7adb1"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "8fe9dac167b6300d0f7a1babc271c5720956c565",
        "name": "53e23672be2a94f5_winrar.lnk",
        "filepath": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Mon Apr 24 17:46:34 2017, length=1517320, window=hide",
        "sha256": "53e23672be2a94f5d5637472cf604d3200550e552e7ff4b460e33fb8928c0f55",
        "urls": [],
        "crc32": "FF4F0630",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/53e23672be2a94f5_winrar.lnk",
        "ssdeep": null,
        "size": 1041,
        "sha512": "6ad6162d4d319ff649716e97c3188be92eb5ff3613592d09207fa11d575bb3ffe40541384619ec3776068394eb321d6acd9a461a086f9a6a9b80df9ba8a87140",
        "pids": [
            2096
        ],
        "md5": "663e22a2fadd2f1e12f898b87a61bb4c"
    },
    {
        "yara": [],
        "sha1": "5f7824667f902ae3f76d7acd17ace20860979256",
        "name": "29bf0e22ba729921_descript.ion",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Descript.ion",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "29bf0e22ba729921958bbe4dc42d8bf688cccfbfeac6ef68b79674023b05d01f",
        "urls": [],
        "crc32": "5A70AADD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/29bf0e22ba729921_descript.ion",
        "ssdeep": null,
        "size": 948,
        "sha512": "170dc562603e6690180fea934801c064c0128b5ec027c01ab3f45ca2b5f297d70200481b8f95e7d250f110bbe9b88623ff4e5b067acd8fc332bddc535b24fb05",
        "pids": [
            2460
        ],
        "md5": "73e2e911b7730a92c04298ec770b0ab6"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "44144ecb848be46d913331d1f2dc10905935e9b6",
        "name": "ce1e874c1f3c20e0_winrar.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Mon Apr 24 17:46:34 2017, length=1517320, window=hide",
        "sha256": "ce1e874c1f3c20e07954f6a5714b148b264aa23bf75a72e1bd8252e48c254006",
        "urls": [],
        "crc32": "2018E621",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/ce1e874c1f3c20e0_winrar.lnk",
        "ssdeep": null,
        "size": 1011,
        "sha512": "80aaced1de9b1f2f8bb981514f62f6bf450a4fba600652bf877b0f57ea612a8ec78a32f8625942ca414fe7555c2df2c09768e9e0ebcc47939e8ea2cb5dc16e9d",
        "pids": [
            2096
        ],
        "md5": "aaf21d4a7c2b7d8344c4d8c7cf5a272c"
    },
    {
        "yara": [],
        "sha1": "f79ebe52f1ec543c5528759489c8c196ff5d9a8b",
        "name": "6b20e182c4f31bd8_wincon.sfx",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\WinCon.SFX",
        "type": "PE32 executable (console) Intel 80386, for MS Windows",
        "sha256": "6b20e182c4f31bd80a80b59ad68389d881585a79993e647b4c6a5425af770996",
        "urls": [],
        "crc32": "5BE67DF5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/6b20e182c4f31bd8_wincon.sfx",
        "ssdeep": null,
        "size": 260608,
        "sha512": "5486e7c0cea39b174b8b01c6ab8cc7e6197f60277c888c39dc0a8b2e6d7f77b63b184f264c83e0df74f3d798863b28d5c4657823ef86196381c9e737cccdce97",
        "pids": [
            2460
        ],
        "md5": "73f0f3d1e2bbb7554e9fcaf7cbcf64f1"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "b4a041b85b0a41345522d8f569f94cf5edb48644",
        "name": "9b6aa14900154bb0_console rar manual.lnk",
        "filepath": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Thu Apr 20 08:40:37 2017, length=101948, window=hide",
        "sha256": "9b6aa14900154bb0842f22089fe606879f90922df4a1b2e9905d127f23fc55d7",
        "urls": [],
        "crc32": "6E281FC3",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/9b6aa14900154bb0_console rar manual.lnk",
        "ssdeep": null,
        "size": 1022,
        "sha512": "a224877df39b2c48510ab34064add8b0ee14db00da88bcbaf562e3783e9c2d50dc407853b173d7e22fbff682e350187cd464fec891544a25b31735574419e7a2",
        "pids": [
            2096
        ],
        "md5": "3a9a1cc465d9a25d7ea23714b49dd0df"
    },
    {
        "yara": [],
        "sha1": "9a2ee5d73f4cdbe44f136adaf4ca4a1142082edc",
        "name": "548291ec78a04cb9_uninstall.lst",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\Uninstall.lst",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "548291ec78a04cb9b1606858a6913eccf215c5b57f05e510ec82b4a1bdcfef8c",
        "urls": [],
        "crc32": "20052ADD",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/548291ec78a04cb9_uninstall.lst",
        "ssdeep": null,
        "size": 372,
        "sha512": "2e951b193ff6dc46769f4fa374b4f389d604dba5ed38d996a402156c616101e066afc2c3ad3de32db4d4f487a8a384b3a99f7c36b068319bc32d466bb77827d1",
        "pids": [
            2460
        ],
        "md5": "dc20a41dd5976945ad2ff6a742bc26dd"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "cf85ae4d712a9277e87770ea180b1dadc3022bc0",
        "name": "1002832164a455bd_what is new in the latest version.lnk",
        "filepath": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Thu Apr 13 10:12:00 2017, length=63389, window=hide",
        "sha256": "1002832164a455bdb93fd65ef990599b7efb5706afac11a3cc30aea9bbded64f",
        "urls": [],
        "crc32": "CCE80C22",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/1002832164a455bd_what is new in the latest version.lnk",
        "ssdeep": null,
        "size": 1053,
        "sha512": "c38a59f5d94990c135dc6787af641c13e82f3d8b0993075f870e365f10ed141997403f754867a75316c4f258f8eba6c20088e37b6824494fb46973a8431140ff",
        "pids": [
            2096
        ],
        "md5": "30c63cbd4eae293f6282915cd244579b"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "b89a87eca29037703b78f7c454aea981a6e23ba0",
        "name": "cd3c07af7f274447_winrar help.lnk",
        "filepath": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Mon Apr 24 17:46:05 2017, length=310804, window=hide",
        "sha256": "cd3c07af7f274447e84d1e2c2d2b7deaf26357790ddc8cce46f36ac696f41192",
        "urls": [],
        "crc32": "5660DFC5",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/cd3c07af7f274447_winrar help.lnk",
        "ssdeep": null,
        "size": 1041,
        "sha512": "6bf9e3a3007b48445a26e34d5b18a3c7711822fe5827d3f939af1964b8073657abab45cbb1fb07330d7c529b050ae48f9bd3a5d694e574e73ec232810810c84d",
        "pids": [
            2096
        ],
        "md5": "6953f850bfa161f0bf2594e954d6f050"
    },
    {
        "yara": [],
        "sha1": "c07c12ad0f8d39d5d26c708fc132469d5570aada",
        "name": "25c6c5f336b40457_readme.txt",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\ReadMe.txt",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "25c6c5f336b404579889549b10a45f5e32ce5844a5a5a29075168d460d025bd2",
        "urls": [],
        "crc32": "7DB6D9F0",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/25c6c5f336b40457_readme.txt",
        "ssdeep": null,
        "size": 1284,
        "sha512": "01a923ebb8bb23aa1f37947af04b08b424631dff1003d9cdd63abe25a8c164d347de72214a0f8613d600819fa2eb151d92a29573af24bdd05435534bdee552fa",
        "pids": [
            2460
        ],
        "md5": "6a697fe386885ea78ab05ad1bd4a96eb"
    },
    {
        "yara": [],
        "sha1": "30f5bc5e12279859043c43a2dbe6a97f57bfebf8",
        "name": "dbe966226d1df41c_7zxa.dll",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\7zxa.dll",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "dbe966226d1df41c9ab854da3897c0fa99858d8848dd23470edb4974f256c2fa",
        "urls": [],
        "crc32": "86F59C88",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/dbe966226d1df41c_7zxa.dll",
        "ssdeep": null,
        "size": 141312,
        "sha512": "f66fc1244078bf1ba259b87f83d92a35226aa99dbb4c253c62443bc71c54dba155e10b1f781fbbd7c31f48a528821bc588da24d853fdee17cd75ecf8fcb7e35e",
        "pids": [
            2460
        ],
        "md5": "ae27db1a0e1e2b338c79af9d74967b7d"
    },
    {
        "yara": [],
        "sha1": "c200c77558ca77c044a2c2d794c98f8437ffd2b4",
        "name": "9fc8aa33ccafa04c_license.txt",
        "filepath": "C:\\Program Files (x86)\\WinRAR\\License.txt",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "9fc8aa33ccafa04c1ce4c0a61047b341297d720adab1b77f67b5fe59f43bb59f",
        "urls": [],
        "crc32": "90B8F090",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/9fc8aa33ccafa04c_license.txt",
        "ssdeep": null,
        "size": 6880,
        "sha512": "a016b287b6d1a4320bd5ab5790163f837a28b54d8bcca56a51dc8b6a50374aacb35c0341d42915cd97d3b135dbf1f363087a4631deb69f82811d41db2f78a0a8",
        "pids": [
            2460
        ],
        "md5": "672064cf19db0b083b981cf0be7662b0"
    },
    {
        "yara": [
            {
                "meta": {
                    "description": "(no description)"
                },
                "name": "LnkHeader",
                "offsets": {
                    "guid": [
                        [
                            4,
                            0
                        ]
                    ],
                    "signature": [
                        [
                            0,
                            1
                        ]
                    ]
                },
                "strings": [
                    "ARQCAAAAAADAAAAAAAAARg==",
                    "TAAAAA=="
                ]
            }
        ],
        "sha1": "59a7b7943c1caa3ae1d34e2709fc4e659b6c2866",
        "name": "a16a6b56f65147fb_console rar manual.lnk",
        "filepath": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
        "type": "MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Wed Sep  2 19:53:08 2020, mtime=Wed Sep  2 19:53:08 2020, atime=Thu Apr 20 08:40:37 2017, length=101948, window=hide",
        "sha256": "a16a6b56f65147fb7115e3430fd3cf4a3debabe2c574d0115c6e5e77bc8b4ae1",
        "urls": [],
        "crc32": "5A86C02E",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/9274\/files\/a16a6b56f65147fb_console rar manual.lnk",
        "ssdeep": null,
        "size": 1004,
        "sha512": "c4732802f0b348f32d81aafaf88e7b40b3e2431b2a2ee651b42207424f96ea2a994aca3d2994ab58308c5a969f0b6a2dd5e5d32985cf89d1f13c5a6c30b4a581",
        "pids": [
            2096
        ],
        "md5": "e416779e72380e62cfcc7aae4873074b"
    }
]

Generic

[
    {
        "process_path": "C:\\Program Files (x86)\\WinRAR\\uninstall.exe",
        "process_name": "uninstall.exe",
        "pid": 2096,
        "summary": {
            "file_created": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
                "C:\\Program Files (x86)\\WinRAR\\rarnew.dat",
                "C:\\Program Files (x86)\\WinRAR\\zipnew.dat",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk"
            ],
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r29\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shell\\open\\command\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r19\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r09\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\WinRAR32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\VersionMinor",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links\\Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\ContextMenuHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cab\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\Set",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r22\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\RegisteredApplications\\WinRAR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.rar\\ShellNew\\FileName",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zipx\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r16\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.REV\\shell\\open\\command\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\UninstallString",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tbz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zip\\ShellNew\\FileName",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\DisplayName",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\InstallLocation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.zipx",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\NoModify",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bz2\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r03\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r10\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\InProcServer32\\ThreadingModel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shell\\open\\command\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tlz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r02\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\WinRAR.exe\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r20\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.lz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.001",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.uu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\WinRAR32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.bz2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\WinRAR32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\Set",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\WinRAR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.uu\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lzh\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\DisplayVersion",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r18\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.lha",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.iso\\Set",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r15\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.001\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tbz2\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\ApplicationDescription",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.7z",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\exe32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lha\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\DragDropHandlers\\WinRAR32\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\Set",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r07\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.xz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.rar",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\DefaultIcon\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.jar\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r24\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.bz\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.rev\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r27\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r04\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.z",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r01\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.lzh",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.zip",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r11\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zip\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\GlobalAssocChangedCounter",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links\\StartMenu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\WinRAR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.rar\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\ShellExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r26\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.xxe\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r00\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\DropHandler\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\WinRAR.exe\\Path",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.taz\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links\\Programs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.z\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r13\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tlz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.7z\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r28\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.jar",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\DragDropHandlers\\WinRAR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\Language",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.cab",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\Set",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.uue",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tgz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.txz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r17\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.bz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\WinRAR\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.xz\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.arj\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tbz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.iso",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR\\shellex\\ContextMenuHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tar\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\Set",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tar",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\InProcServer32\\ThreadingModel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.taz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r25\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\Publisher",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\CascadedMenu",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r08\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r05\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r14\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\DropHandler\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tgz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.REV\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.ace\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz\\Type",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\NoRepair",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gz\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\MenuIcons",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r06\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz\\Exist",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\VersionMajor",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\ContextMenuHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.ace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.gz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.arj",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.uue\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\shellex\\ContextMenuHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.REV\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r23\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\WinRAR.ZIP\\DefaultIcon\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r12\\(Default)",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z\\Set",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace\\Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver\\DisplayIcon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.r21\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.txz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.xxe",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar\\Exist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\WinRAR\\Capabilities\\FileAssociations\\.tbz2",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx\\Type"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\riched20.dll",
                "kernel32",
                "srvcli.dll",
                "LINKINFO.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "dwmapi.dll",
                "slc.dll",
                "api-ms-win-core-synch-l1-2-0",
                "PROPSYS.dll",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "OLEAUT32.DLL",
                "comctl32",
                "ole32.dll",
                "SHLWAPI.dll",
                "USER32.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "api-ms-win-core-localization-l1-2-1",
                "profapi.dll",
                "comctl32.dll",
                "api-ms-win-core-fibers-l1-1-1",
                "rpcrt4.dll",
                "SETUPAPI.dll",
                "ntshrui.dll"
            ],
            "file_failed": [
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk\\desktop.ini",
                "C:\\Program Files (x86)\\WinRAR\\uninstall.lng",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "C:\\Program Files (x86)\\WinRAR",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk"
            ],
            "regkey_opened": [
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.txz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz2",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Paths",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}",
                "HKEY_CLASSES_ROOT\\.txz",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.arj",
                "HKEY_CLASSES_ROOT\\WinRAR.REV\\DefaultIcon",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
                "HKEY_CLASSES_ROOT\\.r10",
                "HKEY_CLASSES_ROOT\\.r09",
                "HKEY_CLASSES_ROOT\\.r08",
                "HKEY_CLASSES_ROOT\\.r07",
                "HKEY_CLASSES_ROOT\\.r06",
                "HKEY_CLASSES_ROOT\\.r05",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.r03",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
                "HKEY_CLASSES_ROOT\\.r00",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xxe",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\Software\\WinRAR\\Capabilities",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.zip\\ShellNew",
                "HKEY_CLASSES_ROOT\\.z\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.xz",
                "HKEY_CLASSES_ROOT\\WinRAR\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.iso",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\General",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Folder\\shellex\\ContextMenuHandlers\\WinRAR",
                "HKEY_CLASSES_ROOT\\.taz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}",
                "HKEY_CLASSES_ROOT\\.taz",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
                "HKEY_CLASSES_ROOT\\.gz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.7z",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}",
                "HKEY_CLASSES_ROOT\\.tar",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_CLASSES_ROOT\\.txz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.7z\\ShellNew",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved",
                "HKEY_CLASSES_ROOT\\*\\shellex\\ContextMenuHandlers\\WinRAR",
                "HKEY_CLASSES_ROOT\\.jar\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
                "HKEY_CLASSES_ROOT\\WinRAR\\DefaultIcon",
                "HKEY_CLASSES_ROOT\\.cab\\ShellNew",
                "HKEY_CLASSES_ROOT\\.tbz\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
                "HKEY_CLASSES_ROOT\\.bz",
                "HKEY_CLASSES_ROOT\\WinRAR\\shell\\open\\command",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.ace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}",
                "HKEY_CLASSES_ROOT\\.uu\\ShellNew",
                "HKEY_LOCAL_MACHINE\\Software\\RegisteredApplications",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.z",
                "HKEY_CLASSES_ROOT\\.xz\\ShellNew",
                "HKEY_CLASSES_ROOT\\.uue\\ShellNew",
                "HKEY_CLASSES_ROOT\\.tbz2",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.zipx",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_CLASSES_ROOT\\.r04",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\uninstall.exe",
                "HKEY_CLASSES_ROOT\\.rev",
                "HKEY_CLASSES_ROOT\\.r02",
                "HKEY_CLASSES_ROOT\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_CLASSES_ROOT\\.gz",
                "HKEY_CLASSES_ROOT\\.r01",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.001",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_CLASSES_ROOT\\Directory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
                "HKEY_CLASSES_ROOT\\.lha",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\WinRAR\\shellex\\ContextMenuHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\InProcServer32",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.cab",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_CLASSES_ROOT\\exefile\\shellex\\PropertySheetHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\Software\\WinRAR",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uu",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.taz",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
                "HKEY_CLASSES_ROOT\\.rar\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PropertyBag",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tar",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup",
                "HKEY_CLASSES_ROOT\\.lz",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
                "HKEY_CLASSES_ROOT\\Folder\\shellex\\ContextMenuHandlers\\WinRAR32",
                "HKEY_CLASSES_ROOT\\.xxe\\ShellNew",
                "HKEY_CLASSES_ROOT\\*\\shellex\\ContextMenuHandlers\\WinRAR32",
                "HKEY_CLASSES_ROOT\\.r12",
                "HKEY_CLASSES_ROOT\\.xz",
                "HKEY_CLASSES_ROOT\\.tlz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
                "HKEY_CLASSES_ROOT\\.r14",
                "HKEY_CLASSES_ROOT\\exefile\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}",
                "HKEY_CLASSES_ROOT\\Folder\\shellex\\DragDropHandlers\\WinRAR32",
                "HKEY_CLASSES_ROOT\\WinRAR\\shellex\\PropertySheetHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\DefaultIcon",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
                "HKEY_CLASSES_ROOT\\.ace\\ShellNew",
                "HKEY_CLASSES_ROOT\\.arj",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
                "HKEY_CLASSES_ROOT\\.lha\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.cab",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Interface\\Themes",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.gz",
                "HKEY_CLASSES_ROOT\\Folder\\shellex\\DragDropHandlers\\WinRAR",
                "HKEY_CLASSES_ROOT\\.001",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\WinRAR.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}",
                "HKEY_CLASSES_ROOT\\.jar",
                "HKEY_CLASSES_ROOT\\.zipx",
                "HKEY_CLASSES_ROOT\\WinRAR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.zipx\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_CLASSES_ROOT\\.zip",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tgz",
                "HKEY_CLASSES_ROOT\\.uu",
                "HKEY_LOCAL_MACHINE\\Software\\WinRAR\\Capabilities\\FileAssociations",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.rar",
                "HKEY_CLASSES_ROOT\\.xxe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_CLASSES_ROOT\\.7z",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}",
                "HKEY_CLASSES_ROOT\\.bz2",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.uue",
                "HKEY_CLASSES_ROOT\\.rar",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tlz",
                "HKEY_CLASSES_ROOT\\WinRAR.REV",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.bz2",
                "HKEY_CLASSES_ROOT\\.tbz",
                "HKEY_CLASSES_ROOT\\.lzh",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WinRAR archiver",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lha",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\DragDropHandlers\\WinRAR32",
                "HKEY_CLASSES_ROOT\\WinRAR.REV\\shell\\open\\command",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Interface\\Misc",
                "HKEY_CLASSES_ROOT\\.lz\\ShellNew",
                "HKEY_CLASSES_ROOT\\.bz2\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\uninstall.exe",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\shellex\\DropHandler",
                "HKEY_CLASSES_ROOT\\.r25",
                "HKEY_CLASSES_ROOT\\.r24",
                "HKEY_CLASSES_ROOT\\.r27",
                "HKEY_CLASSES_ROOT\\.r26",
                "HKEY_CLASSES_ROOT\\.r21",
                "HKEY_CLASSES_ROOT\\.r20",
                "HKEY_CLASSES_ROOT\\.r23",
                "HKEY_CLASSES_ROOT\\.r22",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.tbz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\WinRAR\\shellex\\DropHandler",
                "HKEY_CLASSES_ROOT\\.r28",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\Links",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.r29",
                "HKEY_CLASSES_ROOT\\.ace",
                "HKEY_CLASSES_ROOT\\.001\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}",
                "HKEY_CLASSES_ROOT\\.bz\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\Folder",
                "HKEY_CLASSES_ROOT\\AllFilesystemObjects",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\shellex\\ContextMenuHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lzh",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.jar",
                "HKEY_CLASSES_ROOT\\WinRAR.ZIP\\shellex\\ContextMenuHandlers\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}",
                "HKEY_CLASSES_ROOT\\.r11",
                "HKEY_CLASSES_ROOT\\CLSID\\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\\InProcServer32",
                "HKEY_CLASSES_ROOT\\.r13",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.r15",
                "HKEY_CLASSES_ROOT\\.r16",
                "HKEY_CLASSES_ROOT\\.r17",
                "HKEY_CLASSES_ROOT\\.r18",
                "HKEY_CLASSES_ROOT\\.r19",
                "HKEY_CLASSES_ROOT\\.tgz",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\uninstall.exe",
                "HKEY_CLASSES_ROOT\\.tbz2\\ShellNew",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.tgz\\ShellNew",
                "HKEY_CLASSES_ROOT\\.uue",
                "HKEY_CLASSES_ROOT\\.tlz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.tar\\ShellNew",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\DragDropHandlers\\WinRAR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CLASSES_ROOT\\.iso",
                "HKEY_CLASSES_ROOT\\.arj\\ShellNew",
                "HKEY_CURRENT_USER\\Software\\WinRAR\\Setup\\.lz",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\WinRAR\\shellex\\ContextMenuHandlers\\{B41DB860-64E4-11D2-9906-E49FADC173CA}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PropertyBag",
                "HKEY_CLASSES_ROOT\\.lzh\\ShellNew",
                "HKEY_CLASSES_ROOT\\.z",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"
            ],
            "file_written": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
                "C:\\Program Files (x86)\\WinRAR\\rarnew.dat",
                "C:\\Program Files (x86)\\WinRAR\\zipnew.dat",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk"
            ],
            "regkey_deleted": [
                "HKEY_CLASSES_ROOT\\.zip\\ShellNew",
                "HKEY_CLASSES_ROOT\\.rar\\ShellNew"
            ],
            "file_deleted": [
                "C:\\Users\\Public\\Desktop\\WinRAR.lnk",
                "C:\\Users\\cuck\\Desktop\\WinRAR.lnk"
            ],
            "file_exists": [
                "C:\\Program Files (x86)\\WinRAR\\WhatsNew.txt",
                "C:\\Program Files (x86)\\WinRAR\\rarreg.key",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\Users\\cuck\\Desktop",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "C:\\Program Files (x86)\\WinRAR\\RarExt.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\rarreg.key",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\rarreg.txt",
                "C:\\Users\\cuck\\AppData\\Roaming\\WinRAR",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\winrar.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "C:\\Program Files (x86)\\WinRAR\\Rar.txt",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.ini",
                "C:\\Program Files (x86)\\WinRAR\\RarExt64.dll",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.chm",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.exe",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR",
                "C:\\Users\\Public\\Desktop",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk"
            ],
            "file_opened": [
                "C:\\Program Files (x86)\\WinRAR\\WhatsNew.txt",
                "C:\\ProgramData",
                "C:\\",
                "C:\\Users\\cuck\\AppData",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu",
                "C:\\Users\\Public\\Desktop\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Users",
                "C:\\Program Files (x86)\\WinRAR\\Rar.txt",
                "C:\\Program Files (x86)\\WinRAR",
                "C:\\Users\\Public",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\ProgramData\\Microsoft",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows",
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Program Files (x86)\\WinRAR\\",
                "C:\\Users\\desktop.ini",
                "C:\\Windows\\win.ini",
                "C:\\Users\\cuck",
                "C:\\Program Files (x86)",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu",
                "C:\\ProgramData\\Microsoft\\Windows",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.exe",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Users\\Public\\desktop.ini",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.chm",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Program Files (x86)\\desktop.ini"
            ],
            "guid": [
                "{00021401-0000-0000-c000-000000000046}",
                "{000214f9-0000-0000-c000-000000000046}"
            ],
            "file_read": [
                "C:\\Users\\cuck\\Desktop\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Users\\desktop.ini",
                "C:\\Windows\\win.ini",
                "C:\\Users\\Public\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\desktop.ini",
                "C:\\Users\\Public\\Desktop\\desktop.ini",
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\desktop.ini",
                "C:\\Program Files (x86)\\desktop.ini"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollDelay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Favorites",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\ProgramFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.iso\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\CommonFilesDir",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Parameters\\RpcCacheTimeout",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Personal",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResourceType",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProfilesDirectory",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResource",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Pictures",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.zip\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{374DE290-123F-4565-9164-39C4925E467B}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tar\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Start Menu",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Programs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Music",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\My Video",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonMusic",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\GlobalAssocChangedCounter",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalRedirectOnly",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInterval",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\PreCreate",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Desktop",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Security",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InfoTip",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{56784854-C6CB-462B-8169-88E350ACB882}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Stream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonVideo",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\ScrollInset",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Roamable",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.cab\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.z\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Attributes",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\LocalizedName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Security",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\CommonPictures",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\LocalizedName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Programs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\LocalizedName",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalizedName",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Security",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\Public",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{33E28130-4E1E-4676-835A-98395C3BC3BB}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Startup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DFDF76A2-C82A-4D63-906A-5644AC457385}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B97D20BB-F46A-4C97-BA10-5E3608430854}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\User Shell Folders\\Common Documents",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{0762D272-C50A-4BB0-A382-697DCD729B80}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.tgz\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{2400183A-6185-49FB-A2D8-4A392A602BA3}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{374DE290-123F-4565-9164-39C4925E467B}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\Name",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragMinDist",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{56784854-C6CB-462B-8169-88E350ACB882}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{4BD8D571-6D19-48D3-BE97-422220080E43}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\\Category"
            ],
            "directory_enumerated": [
                "C:\\Program Files (x86)\\WinRAR\\rarnew.dat",
                "C:\\Program Files (x86)\\WinRAR\\zipnew.dat"
            ],
            "directory_created": [
                "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR"
            ]
        },
        "first_seen": 1599087189.09325,
        "ppid": 2460
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\83d80d034d31b88652506e88a1cd1f16472dc68e66eeaab48e7a355c09338077.bin",
        "process_name": "83d80d034d31b88652506e88a1cd1f16472dc68e66eeaab48e7a355c09338077.bin",
        "pid": 2460,
        "summary": {
            "file_created": [
                "C:\\Program Files (x86)\\WinRAR\\Uninstall.lst",
                "C:\\Program Files (x86)\\WinRAR\\RarExt64.dll",
                "C:\\Program Files (x86)\\WinRAR\\Order.htm",
                "C:\\Program Files (x86)\\WinRAR\\WhatsNew.txt",
                "C:\\Program Files (x86)\\WinRAR\\Descript.ion",
                "C:\\Program Files (x86)\\WinRAR\\Uninstall.exe",
                "C:\\Program Files (x86)\\WinRAR\\RarFiles.lst",
                "C:\\Program Files (x86)\\WinRAR\\UnRAR.exe",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.exe",
                "C:\\Program Files (x86)\\WinRAR\\License.txt",
                "C:\\Program Files (x86)\\WinRAR\\Zip.SFX",
                "C:\\Program Files (x86)\\WinRAR\\Rar.txt",
                "C:\\Program Files (x86)\\WinRAR\\WinRAR.chm",
                "C:\\Program Files (x86)\\WinRAR\\7zxa.dll",
                "C:\\Program Files (x86)\\WinRAR\\Default.SFX",
                "C:\\Program Files (x86)\\WinRAR\\WinCon.SFX",
                "C:\\Program Files (x86)\\WinRAR\\RarExt.dll",
                "C:\\Program Files (x86)\\WinRAR\\ReadMe.txt",
                "C:\\Program Files (x86)\\WinRAR\\UNACEV2.DLL",
                "C:\\Program Files (x86)\\WinRAR\\__tmp_rar_sfx_access_check_27698812",
                "C:\\Program Files (x86)\\WinRAR\\Rar.exe"
            ],
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
                "HKEY_CURRENT_USER\\Software\\WinRAR SFX\\C%%Program Files (x86)%WinRAR"
            ],
            "dll_loaded": [
                "IEFRAME.dll",
                "ext-ms-win-kernel32-package-current-l1-1-0",
                "C:\\Windows\\system32\\riched20.dll",
                "urlmon.dll",
                "kernel32",
                "mshtml.dll",
                "apphelp.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "C:\\Windows\\system32\\rsaenh.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "C:\\Windows\\system32\\sfc_os.dll",
                "dwmapi.dll",
                "C:\\Windows\\system32\\DXGIDebug.dll",
                "

Signatures

[
    {
        "markcount": 10,
        "families": [],
        "description": "Queries for the computername",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.15525,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 2263
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.26425,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 3465
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.29625,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 3592
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.37425,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 3711
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.38925,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 3830
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.38925,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 3997
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.40525,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 4124
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.40525,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 4243
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087192.40525,
                    "tid": 2260,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 4362
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1599087194.468375,
                    "tid": 1828,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 3773
            }
        ],
        "references": [],
        "name": "antivm_queries_computername"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "D:\\Projects\\WinRAR\\sfx\\setup\\build\\sfxrar32\\Release\\sfxrar.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Tries to locate where the browsers are installed",
        "severity": 1,
        "marks": [
            {
                "category": "file",
                "ioc": "c:\\program files (x86)\\mozilla firefox\\firefox.exe",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "locates_browser"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GlobalMemoryStatusEx",
                    "return_value": 1,
                    "arguments": {},
                    "time": 1599087189.28025,
                    "tid": 344,
                    "flags": {}
                },
                "pid": 2096,
                "type": "call",
                "cid": 769
            }
        ],
        "references": [],
        "name": "antivm_memory_available"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".gfids",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "One or more processes crashed",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "__notification__",
                    "status": 1,
                    "stacktrace": [],
                    "raw": [
                        "stacktrace"
                    ],
                    "api": "__exception__",
                    "return_value": 0,
                    "arguments": {
                        "stacktrace": "0\nx\n2\nc\n1\n1\n9\n0\n4\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0\n\n\n0\nx\n3\n0",
                        "registers": {
                            "r14": 237106680,
                            "r9": 0,
                            "rcx": 48,
                            "rsi": 237106680,
                            "r10": 0,
                            "rbx": 98185776,
                            "rdi": 98255408,
                            "r11": 192936176,
                            "r8": 2007859596,
                            "rdx": 8796092404304,
                            "rbp": 192933520,
                            "r15": 262145,
                            "r12": 262144,
                            "rsp": 192933400,
                            "rax": 46209280,
                            "r13": 192934913
                        },
                        "exception": {
                            "instruction_r": "83 3d 8d d1 02 00 00 68 53 12 69 fb c7 44 24 04",
                            "instruction": "cmp dword ptr [rip + 0x2d18d], 0",
                            "exception_code": "0xc0000005",
                            "symbol": "",
                            "address": "0x2c11904"
                        }
                    },
                    "time": 1599087272.452375,
                    "tid": 1296,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 250423
            }
        ],
        "references": [],
        "name": "raises_exception"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Explorer",
                        "free_bytes_available": 23508860928,
                        "total_number_of_free_bytes": 0,
                        "total_number_of_bytes": 0
                    },
                    "time": 1599087237.483375,
                    "tid": 2808,
                    "flags": {}
                },
                "pid": 1788,
                "type": "call",
                "cid": 138920
            }
        ],
        "references": [],
        "name": "antivm_disk_size"
    },
    {
        "markcount": 16,
        "families": [],
        "description": "Creates a shortcut to an executable file",
        "severity": 2,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Command Prompt.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\Public\\Desktop\\WinRAR.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\Internet Explorer.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\WinRAR.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\Desktop\\WinRAR.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\Windows Explorer.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\Firefox.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\What is new in the latest version.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\Console RAR manual.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\Windows Media Player.lnk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\WinRAR\\WinRAR help.lnk",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "creates_shortcut"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Installs itself for autorun at Windows startup",
        "severity": 3,
        "marks": [
            {
                "type": "generic",
                "reg_key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B41DB860-64E4-11D2-9906-E49FADC173CA}\\InProcServer32\\(Default)",
                "reg_value": "C:\\Program Files (x86)\\WinRAR\\rarext64.dll"
            }
        ],
        "references": [],
        "name": "persistence_autorun"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Writes a potential ransom message to disk",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "file",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtWriteFile",
                    "return_value": 0,
                    "arguments": {
                        "file_handle": "0x000002f8",
                        "filepath": "C:\\Program Files (x86)\\WinRAR\\WhatsNew.txt",
                        "buffer": "                WinRAR - What's new in the latest version\r\n\r\n\r\n   Version 5.50 beta 1\r\n\r\n   1. WinRAR and command line RAR use RAR 5.0 archive format by default.\r\n      You can change it to RAR 4.x compatible format with \"RAR4\" option\r\n      in archiving dialog or -ma4 command line switch.\r\n      \r\n      If you prefer RAR 4.x format by default, use \"Create default...\"\r\n      button on \"Compression\" page of WinRAR settings and set \"RAR4\"\r\n      in the displayed dialog.\r\n\r\n      This change affects only new clean installs. If you already saved\r\n      RAR format in the default compression profile in previous versions,\r\n      WinRAR respects stored settings.\r\n   \r\n   2. Use \"Set master password\" button in \"Organize passwords\" dialog\r\n      to encrypt saved password records and protect them from unauthorized\r\n      access. \r\n      \r\n      If saved passwords are protected with master password, you need to\r\n      enter the master password and press \"OK\" in password prompt to access\r\n      them. If entered password does not match the master password,\r\n      it is treated as a usual password for archive operations.\r\n\r\n      Once entered, the master password is valid until WinRAR is closed.\r\n      Close WinRAR and open it again after specifying the master password\r\n      if you wish to see how protection works. Enter a valid and then\r\n      empty master password to remove encryption from previously protected\r\n      password records.\r\n\r\n      This WinRAR version uses a new data format for password organizer,\r\n      so passwords stored in \"Organize passwords\" dialog are not readable\r\n      by older versions. It does not affect archive encryption formats\r\n      and encrypted archives are compatible with previous WinRAR version.\r\n      Organizer data is converted to a new format only when you save it\r\n      and not immediately after installing WinRAR.\r\n\r\n   3. Prompt proposing to set the master password is displayed\r\n      when storing a password in compression profile. You can enter\r\n      the master password to encrypt password data stored in Registry\r\n      and protect it from unauthorized access. You will need to enter\r\n      the master password in password prompt dialog to access\r\n      such compression profile after that.\r\n\r\n      Once entered, the master password is valid until WinRAR is closed.\r\n      Close WinRAR and open it again after specifying the master password\r\n      if you wish to see how protection works.\r\n\r\n   4. By default, WinRAR uses AES-256 in CTR mode to encrypt ZIP archives.\r\n      While AES-256 is significantly more secure than ZIP 2.0 legacy\r\n      encryption algorithm, it can be incompatible with some older\r\n      unzip software. If compatibility with such tools is required,\r\n      you can enable \"ZIP legacy encryption\" option in the password\r\n      dialog or use -mezl switch in the command line mode. \r\n   \r\n   5. Added extraction support for .LZ archives created by Lzip compressor.\r\n   \r\n   6. Modern TAR tools can store high precision file times, lengthy\r\n      file names and large file sizes in special PAX extended headers\r\n      inside of TAR archive. Now WinRAR supports such PAX headers\r\n      and uses them when extracting TAR archives.\r\n\r\n   7. New \"Store modification time\" option on \"Time\" page of archiving\r\n      dialog can be used to prohibit storing the file modification time\r\n      in RAR 5.x archives. Former \"High precision modification time\"\r\n      option is replaced by \"High precision time format\".\r\n\r\n   8. New \"Full paths in title bar\" option in \"Settings\/General\" dialog.\r\n      If enabled, the full path of currently opened folder or archive\r\n      is displayed in WinRAR title bar.\r\n\r\n   9. New \"Settings\/Archives\" page provides \"File types to open as\r\n      archives first\" group of options. Here you can define how Enter\r\n      or double click on a file with non-archive extension and archive\r\n      contents should be processed in WinRAR file list. Examples\r\n      of such files are .docx or self-extracting .exe archives.\r\n      You can instruct WinRAR to open such files as archives,\r\n      to ru",
                        "offset": 0
                    },
                    "time": 1599087188.812625,
                    "tid": 2888,
                    "flags": {}
                },
                "pid": 2460,
                "type": "call",
                "cid": 2964
            }
        ],
        "references": [],
        "name": "ransomware_message"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 662,
            "time": 6.229002952575684,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5342,
            "time": 12.245139837265015,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7186,
            "time": 6.161933898925781,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7514,
            "time": 4.164245843887329,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7842,
            "time": 6.169143915176392,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8170,
            "time": 4.6691670417785645,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8498,
            "time": 3.0628700256347656,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 8826,
            "time": 4.268188953399658,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28236,
            "time": 4.230681896209717,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36620,
            "time": 6.2443578243255615,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "f441f184a86a54d69d582fbd8f1f67d4425f2a6db642835f987a452794b9da03",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "56a5019d8056df757a36d481ac24a394fd82b321a0b1b9b7e085f3935f9f5d75",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

Hashes [?]

PropertyValue
MD5c86f5ce7023cba07fb0126353882b62a
SHA25683d80d034d31b88652506e88a1cd1f16472dc68e66eeaab48e7a355c09338077

Error Messages

These are some of the error messages that can appear related to winrar-5-50-beta-1-x86.exe:

winrar-5-50-beta-1-x86.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

winrar-5-50-beta-1-x86.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

winrar-5-50-beta-1-x86.exe has stopped working.

End Program - winrar-5-50-beta-1-x86.exe. This program is not responding.

winrar-5-50-beta-1-x86.exe is not a valid Win32 application.

winrar-5-50-beta-1-x86.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply