md5,sha256
C:\Windows\system32\DllHost.exe /Processid
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\CompatTelRunner.exe
C:\Windows\system32\audiodg.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\musNotification.exe
C:\Windows\system32\musNotificationUx.exe
C:\Windows\system32\powercfg.exe
C:\Windows\system32\sndVol.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\System32\plasrv.exe
C:\Windows\System32\wifitask.exe
C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
C:\Windows\System32\smartscreen.exe
C:\Windows\System32\msfeedssync.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\TokenBrokerCookies.exe
C:\windows\system32\wermgr.exe -queuereporting
C:\windows\system32\wermgr.exe -queuereporting
"C:\Windows\system32\wermgr.exe" "-queuereporting_svc"
C:\WINDOWS\system32\wermgr.exe -upload
\SystemRoot\System32\smss.exe
\??\C:\WINDOWS\system32\autochk.exe *
AppContainer
%%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\mobsync.exe
C:\Windows\system32\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\system32\SppExtComObj.Exe
C:\Windows\system32\PrintIsolationHost.exe
C:\Program Files\Windows Defender
C:\Windows\system32\MpSigStub.exe
C:\Windows\SoftwareDistribution\Download\Install\AM_
C:\Windows\system32\svchost.exe -k appmodel -s StateRepository
C:\Windows\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc
C:\Windows\system32\svchost.exe -k camera -s FrameServer
C:\Windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\Windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\Windows\system32\svchost.exe -k defragsvc
C:\Windows\system32\svchost.exe -k devicesflow -s DevicesFlowUserSvc
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k localService -s EventSystem
C:\Windows\system32\svchost.exe -k localService -s bthserv
C:\Windows\system32\svchost.exe -k localService -s nsi
C:\Windows\system32\svchost.exe -k localService -s w32Time
C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s Dhcp
C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s EventLog
C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s TimeBrokerSvc
C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted -s WFDSConMgrSvc
C:\Windows\system32\svchost.exe -k localServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k localServiceAndNoImpersonation -s SensrSvc
C:\Windows\system32\svchost.exe -k localServiceNoNetwork
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s WPDBusEnum
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -p -s fhsvc
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s DeviceAssociationService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s NcbService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s SensorService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s TabletInputService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s UmRdpService
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WPDBusEnum
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted -s WdiSystemHost
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc
C:\Windows\system32\svchost.exe -k netsvcs -p -s ncaSvc
C:\Windows\system32\svchost.exe -k netsvcs -s BDESVC
C:\Windows\system32\svchost.exe -k netsvcs -s BITS
C:\Windows\system32\svchost.exe -k netsvcs -s CertPropSvc
C:\Windows\system32\svchost.exe -k netsvcs -s DsmSvc
C:\Windows\system32\svchost.exe -k netsvcs -s Gpsvc
C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc
C:\Windows\system32\svchost.exe -k netsvcs -s ProfSvc
C:\Windows\system32\svchost.exe -k netsvcs -s SENS
C:\Windows\system32\svchost.exe -k netsvcs -s SessionEnv
C:\Windows\system32\svchost.exe -k netsvcs -s Themes
C:\Windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k networkService -p -s DoSvc
C:\Windows\system32\svchost.exe -k networkService -s Dnscache
C:\Windows\system32\svchost.exe -k networkService -s LanmanWorkstation
C:\Windows\system32\svchost.exe -k networkService -s NlaSvc
C:\Windows\system32\svchost.exe -k networkService -s TermService
C:\Windows\system32\svchost.exe -k networkService
C:\Windows\system32\svchost.exe -k networkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k rPCSS
C:\Windows\system32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k swprv
C:\Windows\system32\svchost.exe -k unistackSvcGroup
C:\Windows\system32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k wbioSvcGroup
C:\Windows\system32\svchost.exe -k werSvcGroup
C:\WINDOWS\System32\svchost.exe -k wsappx -p -s ClipSVC
C:\WINDOWS\system32\svchost.exe -k wsappx -p -s AppXSvc
C:\Windows\system32\svchost.exe -k wsappx -s ClipSVC
C:\Windows\system32\svchost.exe -k wsappx
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k localSystemNetworkRestricted
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe
C:\Program Files\Microsoft Office\Office16\MSOSYNC.EXE
C:\Program Files (x86)\Microsoft Office\Office16\MSOSYNC.EXE
C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\Microsoft Office\Office16\msoia.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=
C:\Program Files (x86)\Google\Update\
C:\Program Files (x86)\Google\Update\
"C:\Program Files\Mozilla Firefox\plugin-container.exe" --channel
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel
AcroRd32.exe" /CR
AcroRd32.exe" --channel=
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\LogTransport2.exe
C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\AcroCEF\AcroCEF.exe
C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\LogTransport2.exe
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\LogTransport2.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AdobeGCClient.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P6\adobe_licutil.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P7\adobe_licutil.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
"C:\Program Files\DellTPad\ApMsgFwd.exe" -s{
C:\Windows\system32\igfxsrvc.exe -Embedding
C:\Program Files\DellTPad\HidMonitorSvc.exe
C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
C:\Program Files (x86)\Dell\CommandUpdate\InvColPC.exe
C:\Program Files\Dell\SupportAssist\pcdrcui.exe
C:\Program Files\Dell\SupportAssist\koala.exe
"-outc=C:\ProgramData\Dell\CommandUpdate\inventory.xml" "-logc=C:\ProgramData\Dell\CommandUpdate\scanerrs.xml" "-lang=en" "-enc=UTF-16"
C:\Users
OneDrive.exe
C:\Windows\system32\backgroundTaskHost.exe
setup
install
Update\
redist.exe
msiexec.exe
TrustedInstaller.exe
C:\Users
C:\ProgramData
C:\Windows\Temp
at.exe
certutil.exe
cmd.exe
cmstp.exe
cscript.exe
driverquery.exe
dsquery.exe
hh.exe
infDefaultInstall.exe
java.exe
javaw.exe
javaws.exe
mmc.exe
msbuild.exe
mshta.exe
msiexec.exe
nbtstat.exe
net.exe
net1.exe
notepad.exe
nslookup.exe
powershell.exe
qprocess.exe
qwinsta.exe
qwinsta.exe
reg.exe
regsvcs.exe
regsvr32.exe
rundll32.exe
rwinsta.exe
sc.exe
schtasks.exe
taskkill.exe
tasklist.exe
wmic.exe
wscript.exe
nc.exe
ncat.exe
psexec.exe
psexesvc.exe
tor.exe
vnc.exe
vncservice.exe
vncviewer.exe
winexesvc.exe
nmap.exe
psinfo.exe
22
23
25
142
3389
5800
5900
1080
3128
8080
1723
4500
9001
9030
Spotify.exe
AppData\Roaming\Dropbox\bin\Dropbox.exe
g2ax_comm_expert.exe
g2mcomm.exe
OneDrive.exe
OneDriveStandaloneUpdater.exe
AppData\Local\Microsoft\Teams\current\Teams.exe
microsoft.com
microsoft.com.akadns.net
microsoft.com.nsatc.net
127.0.0.1
fe80:0:0:0
C:\Users
microsoft
windows
Intel
C:\Windows\system32\wbem\WmiPrvSE.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\audiodg.exe
C:\Windows\system32\kernel32.dll
Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Windows\system32\lsass.exe
\Start Menu
\Startup\
\Content.Outlook\
\Downloads\
.application
.appref-ms
.bat
.chm
.cmd
.cmdline
.dmp
.docm
.exe
.jar
.jnlp
.jse
.hta
.pptm
.ps1
.sys
.scr
.vbe
.vbs
.xlsm
proj
.sln
C:\Users\Default
C:\Windows\system32\Drivers
C:\Windows\SysWOW64\Drivers
C:\Windows\system32\GroupPolicy\Machine\Scripts
C:\Windows\system32\GroupPolicy\User\Scripts
C:\Windows\system32\Wbem
C:\Windows\SysWOW64\Wbem
C:\Windows\system32\WindowsPowerShell
C:\Windows\SysWOW64\WindowsPowerShell
C:\Windows\Tasks\
C:\Windows\system32\Tasks
C:\Windows\AppPatch\Custom
VirtualStore
.xls
.ppt
.rft
C:\Program Files (x86)\EMET 5.5\EMET_Service.exe
C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
C:\Windows\system32\smss.exe
C:\Windows\system32\CompatTelRunner.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\mobsync.exe
C:\Windows\system32\DriverStore\Temp\
C:\Windows\system32\wbem\Performance\
WRITABLE.TST
C:\Windows\Installer\
C:\$WINDOWS.~BT\Sources\
C:\Windows\winsxs\amd64_microsoft-windows
C:\Program Files (x86)\Dell\CommandUpdate\InvColPC.exe
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\Tasks\Adobe Acrobat Update Task
C:\Windows\System32\Tasks\Adobe Flash Player Updater
CurrentVersion\Run
Policies\Explorer\Run
Group Policy\Scripts
Windows\System\Scripts
CurrentVersion\Windows\Load
CurrentVersion\Windows\Run
CurrentVersion\Winlogon\Shell
CurrentVersion\Winlogon\System
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug
UserInitMprLogonScript
\ServiceDll
\ServiceManifest
\ImagePath
\Start
shell\open\command\
shell\open\ddeexec\
shell\install\command\
Explorer\FileExts\
{86C86720-42A0-1069-A2E8-08002B30309D}
exefile
\InprocServer32\(Default)
\Hidden
\ShowSuperHidden
\HideFileExt
Classes\*\
Classes\AllFilesystemObjects\
Classes\Directory\
Classes\Drive\
Classes\Folder\
ContextMenuHandlers\
CurrentVersion\Shell
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjectDelayLoad
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\InitialProgram
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\
HKLM\SYSTEM\CurrentControlSet\Services\WinSock\
\ProxyServer
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\
HKLM\SOFTWARE\Microsoft\Netsh
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order\
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles
\EnableFirewall
\DoNotAllowExceptions
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls\
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\
Microsoft\Office\Outlook\Addins\
Office Test\
Security\Trusted Documents\TrustRecords
Internet Explorer\Toolbar\
Internet Explorer\Extensions\
Browser Helper Objects\
\DisableSecuritySettingsCheck
\3\1206
\3\2500
\3\1809
{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\
\UrlUpdateInfo
\InstallSource
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy
HKLM\SOFTWARE\Microsoft\Security Center\AllAlertsDisabled
HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverride
HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify
HKLM\SOFTWARE\Microsoft\Security Center\DisableMonitoring
HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify
HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverride
HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify
HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideSCAHealth
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB
VirtualStore
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\
HKLM\SYSTEM\CurrentControlSet\Control\Safeboot\
HKLM\SYSTEM\CurrentControlSet\Control\Winlogon\
\FriendlyName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default)
HKLM\SOFTWARE\Microsoft\Tracing\RASAPI32
Office\root\integration\integrator.exe
C:\Windows\system32\backgroundTaskHost.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files (x86)\EMET 5.5\EMET_Service.exe
Toolbar\WebBrowser
Toolbar\WebBrowser\ITBar7Height
Toolbar\WebBrowser\ITBar7Layout
Toolbar\ShellBrowser\ITBar7Layout
Internet Explorer\Toolbar\Locked
Toolbar\WebBrowser\{47833539-D0C5-4125-9FA8-0819E2EAAC93}
ShellBrowser
\CurrentVersion\Run
\CurrentVersion\RunOnce
\CurrentVersion\App Paths
\CurrentVersion\Image File Execution Options
\CurrentVersion\Shell Extensions\Cached
\CurrentVersion\Shell Extensions\Approved
}\PreviousPolicyAreas
\Control\WMI\Autologger\
HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\Start
\Lsa\OfflineJoin\CurrentValue
\Components\TrustedInstaller\Events
\Components\TrustedInstaller
\Components\Wlansvc
\Components\Wlansvc\Events
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\
\Directory\shellex
\Directory\shellex\DragDropHandlers
\Drive\shellex
\Drive\shellex\DragDropHandlers
_Classes\AppX
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit\AuditPolicy
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\LsaPid
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit
\services\bits\Start
\services\clr_optimization_v2.0.50727_32\Start
\services\clr_optimization_v2.0.50727_64\Start
\services\clr_optimization_v4.0.30319_32\Start
\services\clr_optimization_v4.0.30319_64\Start
\services\deviceAssociationService\Start
\services\fhsvc\Start
\services\nal\Start
\services\trustedInstaller\Start
\services\tunnel\Start
\services\usoSvc\Start
\OpenWithProgids
\OpenWithList
\UserChoice
\UserChoice\ProgId
\UserChoice\Hash
\OpenWithList\MRUList
} 0xFFFF
HKLM\System\CurrentControlSet\Control\Lsa\Audit\SpecialGroups
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\PSScriptOrder
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\SOM-ID
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\GPO-ID
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\IsPowershell
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0\ExecTime
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\PSScriptOrder
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\SOM-ID
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\GPO-ID
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\IsPowershell
SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\Shutdown\0\0\ExecTime
\safer\codeidentifiers\0\HASHES\{
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
HKCR\VLC.
HKCR\iTunes.
Downloads
Temp\7z
Startup
.bat
.cmd
.hta
.lnk
.ps1
.ps2
.reg
.jse
.vb
.vbe
.vbs