md5,sha256 C:\Windows\system32\DllHost.exe /Processid C:\Windows\system32\SearchIndexer.exe /Embedding C:\Windows\system32\CompatTelRunner.exe C:\Windows\system32\audiodg.exe C:\Windows\system32\conhost.exe C:\Windows\system32\musNotification.exe C:\Windows\system32\musNotificationUx.exe C:\Windows\system32\powercfg.exe C:\Windows\system32\sndVol.exe C:\Windows\system32\sppsvc.exe C:\Windows\system32\wbem\WmiApSrv.exe C:\Windows\System32\plasrv.exe C:\Windows\System32\wifitask.exe C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe C:\Windows\System32\smartscreen.exe C:\Windows\System32\msfeedssync.exe C:\Windows\System32\RuntimeBroker.exe C:\Windows\System32\TokenBrokerCookies.exe C:\windows\system32\wermgr.exe -queuereporting C:\windows\system32\wermgr.exe -queuereporting "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" C:\WINDOWS\system32\wermgr.exe -upload \SystemRoot\System32\smss.exe \??\C:\WINDOWS\system32\autochk.exe * AppContainer %%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\mobsync.exe C:\Windows\system32\wbem\wmiprvse.exe -Embedding C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding C:\Windows\system32\SppExtComObj.Exe C:\Windows\system32\PrintIsolationHost.exe C:\Program Files\Windows Defender C:\Windows\system32\MpSigStub.exe C:\Windows\SoftwareDistribution\Download\Install\AM_ C:\Windows\system32\svchost.exe -k appmodel -s StateRepository C:\Windows\system32\svchost.exe -k appmodel C:\WINDOWS\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc C:\Windows\system32\svchost.exe -k camera -s FrameServer C:\Windows\system32\svchost.exe -k dcomlaunch -s LSM C:\Windows\system32\svchost.exe -k dcomlaunch -s PlugPlay C:\Windows\system32\svchost.exe -k defragsvc C:\Windows\system32\svchost.exe -k devicesflow -s DevicesFlowUserSvc C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k localService -s EventSystem C:\Windows\system32\svchost.exe -k localService -s bthserv C:\Windows\system32\svchost.exe -k localService -s nsi C:\Windows\system32\svchost.exe -k localService -s w32Time C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s Dhcp C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s EventLog C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s TimeBrokerSvc C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s WFDSConMgrSvc C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SensrSvc C:\Windows\system32\svchost.exe -k localServiceNoNetwork C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s WPDBusEnum C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s fhsvc C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s DeviceAssociationService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s NcbService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s SensorService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpService C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnum C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WdiSystemHost C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc C:\Windows\system32\svchost.exe -k netsvcs -p -s ncaSvc C:\Windows\system32\svchost.exe -k netsvcs -s BDESVC C:\Windows\system32\svchost.exe -k netsvcs -s BITS C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvc C:\Windows\system32\svchost.exe -k netsvcs -s Gpsvc C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvc C:\Windows\system32\svchost.exe -k netsvcs -s SENS C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnv C:\Windows\system32\svchost.exe -k netsvcs -s Themes C:\Windows\system32\svchost.exe -k netsvcs -s Winmgmt C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k networkService -p -s DoSvc C:\Windows\system32\svchost.exe -k networkService -s Dnscache C:\Windows\system32\svchost.exe -k networkService -s LanmanWorkstation C:\Windows\system32\svchost.exe -k networkService -s NlaSvc C:\Windows\system32\svchost.exe -k networkService -s TermService C:\Windows\system32\svchost.exe -k networkService C:\Windows\system32\svchost.exe -k networkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k rPCSS C:\Windows\system32\svchost.exe -k secsvcs C:\Windows\system32\svchost.exe -k swprv C:\Windows\system32\svchost.exe -k unistackSvcGroup C:\Windows\system32\svchost.exe -k utcsvc C:\Windows\system32\svchost.exe -k wbioSvcGroup C:\Windows\system32\svchost.exe -k werSvcGroup C:\WINDOWS\System32\svchost.exe -k wsappx -p -s ClipSVC C:\WINDOWS\system32\svchost.exe -k wsappx -p -s AppXSvc C:\Windows\system32\svchost.exe -k wsappx -s ClipSVC C:\Windows\system32\svchost.exe -k wsappx C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe C:\Program Files\Microsoft Office\Office16\MSOSYNC.EXE C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Microsoft Office\Office16\msoia.exe C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe C:\Program Files\Windows Media Player\wmpnscfg.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type= "C:\Program Files\Google\Chrome\Application\chrome.exe" --type= C:\Program Files (x86)\Google\Update\ C:\Program Files (x86)\Google\Update\ "C:\Program Files\Mozilla Firefox\plugin-container.exe" --channel "C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel AcroRd32.exe" /CR AcroRd32.exe" --channel= C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\LogTransport2.exe C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\AcroCEF\AcroCEF.exe C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\LogTransport2.exe C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\LogTransport2.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AdobeGCClient.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P6\adobe_licutil.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe "C:\Program Files\DellTPad\ApMsgFwd.exe" -s{ C:\Windows\system32\igfxsrvc.exe -Embedding C:\Program Files\DellTPad\HidMonitorSvc.exe C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe C:\Program Files (x86)\Dell\CommandUpdate\InvColPC.exe C:\Program Files\Dell\SupportAssist\pcdrcui.exe C:\Program Files\Dell\SupportAssist\koala.exe "-outc=C:\ProgramData\Dell\CommandUpdate\inventory.xml" "-logc=C:\ProgramData\Dell\CommandUpdate\scanerrs.xml" "-lang=en" "-enc=UTF-16" C:\Users OneDrive.exe C:\Windows\system32\backgroundTaskHost.exe setup install Update\ redist.exe msiexec.exe TrustedInstaller.exe C:\Users C:\ProgramData C:\Windows\Temp at.exe certutil.exe cmd.exe cmstp.exe cscript.exe driverquery.exe dsquery.exe hh.exe infDefaultInstall.exe java.exe javaw.exe javaws.exe mmc.exe msbuild.exe mshta.exe msiexec.exe nbtstat.exe net.exe net1.exe notepad.exe nslookup.exe powershell.exe qprocess.exe qwinsta.exe qwinsta.exe reg.exe regsvcs.exe regsvr32.exe rundll32.exe rwinsta.exe sc.exe schtasks.exe taskkill.exe tasklist.exe wmic.exe wscript.exe nc.exe ncat.exe psexec.exe psexesvc.exe tor.exe vnc.exe vncservice.exe vncviewer.exe winexesvc.exe nmap.exe psinfo.exe 22 23 25 142 3389 5800 5900 1080 3128 8080 1723 4500 9001 9030 Spotify.exe AppData\Roaming\Dropbox\bin\Dropbox.exe g2ax_comm_expert.exe g2mcomm.exe OneDrive.exe OneDriveStandaloneUpdater.exe AppData\Local\Microsoft\Teams\current\Teams.exe microsoft.com microsoft.com.akadns.net microsoft.com.nsatc.net 127.0.0.1 fe80:0:0:0 C:\Users microsoft windows Intel C:\Windows\system32\wbem\WmiPrvSE.exe C:\Windows\system32\svchost.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\audiodg.exe C:\Windows\system32\kernel32.dll Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Webroot\WRSA.exe C:\Windows\system32\lsass.exe \Start Menu \Startup\ \Content.Outlook\ \Downloads\ .application .appref-ms .bat .chm .cmd .cmdline .dmp .docm .exe .jar .jnlp .jse .hta .pptm .ps1 .sys .scr .vbe .vbs .xlsm proj .sln C:\Users\Default C:\Windows\system32\Drivers C:\Windows\SysWOW64\Drivers C:\Windows\system32\GroupPolicy\Machine\Scripts C:\Windows\system32\GroupPolicy\User\Scripts C:\Windows\system32\Wbem C:\Windows\SysWOW64\Wbem C:\Windows\system32\WindowsPowerShell C:\Windows\SysWOW64\WindowsPowerShell C:\Windows\Tasks\ C:\Windows\system32\Tasks C:\Windows\AppPatch\Custom VirtualStore .xls .ppt .rft C:\Program Files (x86)\EMET 5.5\EMET_Service.exe C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe C:\Windows\system32\smss.exe C:\Windows\system32\CompatTelRunner.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Windows\system32\mobsync.exe C:\Windows\system32\DriverStore\Temp\ C:\Windows\system32\wbem\Performance\ WRITABLE.TST C:\Windows\Installer\ C:\$WINDOWS.~BT\Sources\ C:\Windows\winsxs\amd64_microsoft-windows C:\Program Files (x86)\Dell\CommandUpdate\InvColPC.exe C:\Windows\system32\igfxCUIService.exe C:\Windows\System32\Tasks\Adobe Acrobat Update Task C:\Windows\System32\Tasks\Adobe Flash Player Updater CurrentVersion\Run Policies\Explorer\Run Group Policy\Scripts Windows\System\Scripts CurrentVersion\Windows\Load CurrentVersion\Windows\Run CurrentVersion\Winlogon\Shell CurrentVersion\Winlogon\System HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32 HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug UserInitMprLogonScript \ServiceDll \ServiceManifest \ImagePath \Start shell\open\command\ shell\open\ddeexec\ shell\install\command\ Explorer\FileExts\ {86C86720-42A0-1069-A2E8-08002B30309D} exefile \InprocServer32\(Default) \Hidden \ShowSuperHidden \HideFileExt Classes\*\ Classes\AllFilesystemObjects\ Classes\Directory\ Classes\Drive\ Classes\Folder\ ContextMenuHandlers\ CurrentVersion\Shell HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjectDelayLoad HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\ HKLM\SYSTEM\CurrentControlSet\Services\WinSock\ \ProxyServer HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider HKLM\SYSTEM\CurrentControlSet\Control\Lsa\ HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\ HKLM\SOFTWARE\Microsoft\Netsh HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles \EnableFirewall \DoNotAllowExceptions HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\ HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\ Microsoft\Office\Outlook\Addins\ Office Test\ Security\Trusted Documents\TrustRecords Internet Explorer\Toolbar\ Internet Explorer\Extensions\ Browser Helper Objects\ \DisableSecuritySettingsCheck \3\1206 \3\2500 \3\1809 {AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\ \UrlUpdateInfo \InstallSource HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy HKLM\SOFTWARE\Microsoft\Security Center\AllAlertsDisabled HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverride HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify HKLM\SOFTWARE\Microsoft\Security Center\DisableMonitoring HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverride HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideSCAHealth HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB VirtualStore HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\ HKLM\SYSTEM\CurrentControlSet\Control\Safeboot\ HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\ \FriendlyName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default) HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32 Office\root\integration\integrator.exe C:\Windows\system32\backgroundTaskHost.exe C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe C:\Program Files (x86)\EMET 5.5\EMET_Service.exe Toolbar\WebBrowser Toolbar\WebBrowser\ITBar7Height Toolbar\WebBrowser\ITBar7Layout Toolbar\ShellBrowser\ITBar7Layout Internet Explorer\Toolbar\Locked Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93} ShellBrowser \CurrentVersion\Run \CurrentVersion\RunOnce \CurrentVersion\App Paths \CurrentVersion\Image File Execution Options \CurrentVersion\Shell Extensions\Cached \CurrentVersion\Shell Extensions\Approved }\PreviousPolicyAreas \Control\WMI\Autologger\ HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\Start \Lsa\OfflineJoin\CurrentValue \Components\TrustedInstaller\Events \Components\TrustedInstaller \Components\Wlansvc \Components\Wlansvc\Events HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\ \Directory\shellex \Directory\shellex\DragDropHandlers \Drive\shellex \Drive\shellex\DragDropHandlers _Classes\AppX HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\ C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit\AuditPolicy HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System HKLM\SYSTEM\CurrentControlSet\Control\Lsa\LsaPid HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit \services\bits\Start \services\clr_optimization_v2.0.50727_32\Start \services\clr_optimization_v2.0.50727_64\Start \services\clr_optimization_v4.0.30319_32\Start \services\clr_optimization_v4.0.30319_64\Start \services\deviceAssociationService\Start \services\fhsvc\Start \services\nal\Start \services\trustedInstaller\Start \services\tunnel\Start \services\usoSvc\Start \OpenWithProgids \OpenWithList \UserChoice \UserChoice\ProgId \UserChoice\Hash \OpenWithList\MRUList } 0xFFFF HKLM\System\CurrentControlSet\Control\Lsa\Audit\SpecialGroups SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0 SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\PSScriptOrder SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\SOM-ID SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\GPO-ID SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\IsPowershell SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\ExecTime SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0 SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\PSScriptOrder SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\SOM-ID SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\GPO-ID SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\IsPowershell SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\ExecTime \safer\codeidentifiers\0\HASHES\{ C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe HKCR\VLC. HKCR\iTunes. Downloads Temp\7z Startup .bat .cmd .hta .lnk .ps1 .ps2 .reg .jse .vb .vbe .vbs