| Key | Value | Data |
|---|---|---|
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\0000000001251d6b\StartupHasBeenRun | ||
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\0000000001251d6b\StartupHasBeenRun | ||
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | LastUpdate | dword:f5ce2faa |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\E\_GVI | Version | dword:00000003 |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Control | ||
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\E\_GVI | ||
| HKEY_LOCAL_MACHINE\HARDWARE\RESOURCEMAP\PnP Manager\PnpManager | \Device\004538.Translated | hex(8):01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,04,00,00,00,02,01,01,00,15,00,00,00,36,00,00,00,01,00,00,00,01,01,11,00,f0,03,00,00,00,00,00,00,06,00,00,00,04,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,01,01,05,00,f7,03,00,00,00,00,00,00,01,00,00,00, |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\_Notif | ||
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | ||
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager | PendingFileRenameOperations | hex(7):5c,3f,3f,5c,69,3a,5c,50,72,6f,67,72,61,6d,46,69,6c,65,73,5c,4d,61,70,6c,65,56,52,65,6c,65,61,73,65,35,2e,31,2d,53,65,72,76,65,72,5c,41,46,4d,5c,74,6d,72,2e,61,66,6d,00,00,5c,3f,3f,5c,69,3a,5c,50,72,6f,67,72,61,6d,46,69,6c,65,73,5c,4d,61,70,6c,65,56,52,65,6c,65,61,73,65,35,2e,31,2d,53,65,72,76,65,72,5c,41,46,4d,5c,74,6d,62,2e,61,66,6d,00,00,5c,3f,3f,5c,69,3a,5c,50,72,6f,67,72,61,6d,46,69,6c,65,73,5c,4d,61,70,6c,65,56,52,65,6c,65,61,73,65,35,2e,31,2d,53,65,72,76,65,72,5c,41,46,4d,5c,74,6d,69,2e,61,66,6d,00,00,5c,3f,3f,5c,69,3a,5c,50,72,6f,67,72,61,6d,46,69,6c,65,73,5c,4d,61,70,6c,65,56,52,65,6c,65,61,73,65,35,2e,31,2d,53,65,72,76,65,72,5c,41,46,4d,5c,73,79,6d,2e,61,66,6d,00,00,5c,3f,3f,5c,69,3a,5c,50,72,6f,67,72,61,6d,46,69,6c,65,73,5c,4d,61,70,6c,65,56,52,65,6c,65,61,73,65,35,2e,31,2d,53,65,72,76,65,72,5c,41,46,4d,5c,68,65,62,2e,61,66,6d,00,00,5c,3f,3f,5c,69,3a,5c,50,72,6f,67,72,61,6d,46,69,6c,65,73,5c,4d,61,70,6c,65,56,52,65,6c,65,61,73,65,35,2e,31,2d,53,65,72,76,65,72,5c,41,46,4d,5c,63,6f,62,2e, |
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\E\_GVI | ||
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\_Notif | ||
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | LastUpdate | dword:f5ce2faa |
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\_Notif | I | dword:00000001 |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSISERVER\0000\Control | ||
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum | 0 | "SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}" |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_REMOTEACCESS\0000\Control | ||
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | Version | dword:0000000d |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | Cache | hex:00,04,00,00, |
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\0000000001251d6b | ||
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | Version | dword:0000000d |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\0000000001251d6b | ||
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000\Control | ActiveService | "AppMgmt" |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\_Notif | I | dword:00000001 |
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | Cache | hex:00,04,00,00, |
| HKEY_USERS\S-1-5-21-57989841-1957994488-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\E\_GVI | Version | dword:00000003 |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_REMOTEACCESS\0000\Control | *NewlyCreated* | dword:00000000 |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints\I\_DriveFlags | ||
| HKEY_LOCAL_MACHINE\HARDWARE\RESOURCEMAP\PnP Manager\PnpManager | \Device\004538.Raw | hex(8):01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,04,00,00,00,02,01,01,00,06,00,00,00,06,00,00,00,ff,ff,ff,ff,01,01,11,00,f0,03,00,00,00,00,00,00,06,00,00,00,04,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,01,01,05,00,f7,03,00,00,00,00,00,00,01,00,00,00, |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSISERVER\0000\Control | ActiveService | "MSIServer" |
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\Control | DeviceReference | dword:811d1530 |