You are on page 1of 27

Key Operation Value Data Type Old Data

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Components\32D8053C2633EC74290223B1BDA1A1CC\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Components\32D8053C2633EC74290223B1BDA1A1CC\ Set
EC97BDF2391593A428BB0E1085CC5133 C:\Program Files\WireGuard\wireguard.exe
REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Components\644FC0453CCF25449BBFBEC420872015\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Components\644FC0453CCF25449BBFBEC420872015\ Set
EC97BDF2391593A428BB0E1085CC5133 C:\Program Files\WireGuard\wg.exe REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
LocalPackage C:\WINDOWS\Installer\27187e0.msi REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
AuthorizedCDFPrefix REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
Comments REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
Contact REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
DisplayVersion 0.5.3 REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
HelpLink REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
HelpTelephone REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
InstallDate 20230731 REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
InstallLocation REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
InstallSource C:\WINDOWS\Temp\ REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
ModifyPath MsiExec.exe /X{2FDB79CE-5193-4A39-82BB-E00158CC1533} REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
NoModify 1 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
Publisher WireGuard LLC REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
Readme REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set Size
REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
EstimatedSize 8132 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
UninstallString MsiExec.exe /X{2FDB79CE-5193-4A39-82BB-E00158CC1533}
REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
URLInfoAbout https://www.wireguard.com/ REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
URLUpdateInfo REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
VersionMajor 0 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
VersionMinor 5 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
WindowsInstaller 1 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
Version 327683 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
Language 1033 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\InstallProperties\ Set
DisplayName WireGuard REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\Usage\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\Features\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\Features\ Set
WireGuardFeature BDkjg$w_)?!Wzg+ZKpZjoJ2$C%{Uz9lZKf@K}*&B REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\Patches\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-
1-5-18\Products\EC97BDF2391593A428BB0E1085CC5133\Patches\ Set AllPatches
REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\
Set C:\Program Files\WireGuard\ REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\
Set C:\WINDOWS\Installer\{2FDB79CE-5193-4A39-82BB-E00158CC1533}\ REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\
UpgradeCodes\5AD1A5E563ABD40429CE1450D0C197C9\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\
UpgradeCodes\5AD1A5E563ABD40429CE1450D0C197C9\ Set
EC97BDF2391593A428BB0E1085CC5133 REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set AuthorizedCDFPrefix REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Comments REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Contact REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set DisplayVersion 0.5.3 REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set HelpLink REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set HelpTelephone REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set InstallDate 20230731 REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set InstallLocation REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set InstallSource C:\WINDOWS\Temp\ REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set ModifyPath MsiExec.exe /X{2FDB79CE-5193-
4A39-82BB-E00158CC1533} REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set NoModify 1 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Publisher WireGuard LLC REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Readme REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Size REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set EstimatedSize 8132 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set UninstallString MsiExec.exe /X{2FDB79CE-
5193-4A39-82BB-E00158CC1533} REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set URLInfoAbout https://www.wireguard.com/
REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set URLUpdateInfo REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set VersionMajor 0 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set VersionMinor 5 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set WindowsInstaller 1 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Version 327683 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set Language 1033 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2FDB79CE-
5193-4A39-82BB-E00158CC1533}\ Set DisplayName WireGuard REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\UFH\ARP\ Set 157
Software\Microsoft\Windows\CurrentVersion\Uninstall {2FDB79CE-5193-4A39-82BB-
E00158CC1533} MsiExec.exe /X{2FDB79CE-5193-4A39-82BB-E00158CC1533} REG_MULTI_SZ
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall {a9334a30-de6e-
40f7-a861-18b29a7d5d19} "C:\ProgramData\Package Cache\{a9334a30-de6e-40f7-a861-
18b29a7d5d19}\nitro_pro13.exe" /uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\Data\
Set 418A073AA3BC1C75
f4c0000000404010ed0200029966045f9a24dadc14e7dd16675926fda61894da18e882295e2f29bb852
a6b6c1be8c51c31312d28c71df18d2df8452e9f672f168c11048a92104c8e21727ab2179338117c06f1
1a2d4221b779811be0a621bf6b01ec33022018f20213ac312278ce022a773123a85223116e1237af812
46b46124acc7024c18b1254f6e1264ba81267f9d22945112969e4129a89e22bd8e512c9f7a22fa8ff13
1484f0329f7a2361ee1136e9d20388a323e5bed13fdcd141bc3a242757b242822e242c54d245668a245
6db604677301483bdb148484c248c24f049cba3149da1b24adee114b2a9114b6ee314bf47424d3ed914
e1faa24ed77824fa53325020e01508f0251413e251b23425355e4154dfe2154e0a4255ffc01564a6057
7af81578a1b25792e257ad1215a28925af78325b12325c359815c732025ef05f261d98c161e99b26229
511639677063ec7426454e265a69e065ed1d265f4a6267ba6b269592a269b99226a61e816a736516a95
e216bf42b26d239026f8e5b272701b272a242172cd9917321fb0785dd3179f99c27a479427b90eb17c8
2c917d904a17df1e817e104417e5030281b069282fb2a283f160084e11e285311b285e341287d514287
f025187fc38288d13328aa7fb18beef208bfd6e18c1d8828c8f9428e48b018e78a209123d3092591609
28271092f6ef1931352947091295857b29b4a7229c429b29c4d2229ce0a809d9d9209f83142a2560a7c
2331a7e23e2a8723f2a8ea4e2a918e51aa2e831aab1fc1ab9fc91ac9322ad2db81af9c22b09e972b2ba
fc1b373202b4d7c51b566122b7e23e2b8ea892b9b92a2b9fa772ba8c6f1baaea72beaf8a2c079a0c2d9
52c36d810c399f30c4b4a82c75dd70c9ffc31ca23b70cb4ea02cc32922cc49560cdba832ce99e01d017
560d0f6e41d1e19f2d382610d6ef582d7d2c51d7e86c2d8e79c1d940e91dab731daff841dbb95d2dbe2
3e2deef372e118252e193b01e21b560e2b4631e3b0642e469c90e5e0392e61d282e6bd392e7e23e2eb3
b942ec63c51ee9322eeaf9b2efa9992f0e0b60f0ed3e2f1ad3d1f1d8422f2e932f38db0f31e5c2f37d6
a2f3a1e50f7125e0f7ed6a0f7ff9a2f9dfa11fbca22fe784f2fee2631ff10dd150600014669e24bfc6d
25e61b028b28942dcef8e240401006041ae0682c900a5adcf0ce99e01 REG_BINARY
f3c0000000404010ed0200029966045f9a24dadc14e7dd16675926fda61894da18e882295e2f29bb852
a6b6c1be8c51c31312d28c71df18d2df8452e9f672f168c11048a92104c8e21727ab2179338117c06f1
1a2d4221b779811be0a621bf6b01ec33022018f20213ac312278ce022a773123a85223116e1237af812
46b46124acc7024c18b1254f6e1264ba81267f9d22945112969e4129a89e22bd8e512c9f7a22fa8ff13
1484f0329f7a2361ee1136e9d20388a323e5bed13fdcd141bc3a242757b242822e242c54d245668a245
6db604677301483bdb148484c248c24f049cba3149da1b24adee114b2a9114b6ee314bf47424d3ed914
e1faa24ed77824fa53325020e01508f0251413e251b23425355e4154dfe2154e0a4255ffc01564a6057
7af81578a1b25792e257ad1215a28925af78325b12325c359815c732025ef05f261d98c161e99b26229
511639677063ec7426454e265a69e065ed1d265f4a6267ba6b269592a269b99226a61e816a736516a95
e216bf42b26d239026f8e5b272701b272a242172cd9917321fb0785dd3179f99c27a479427b90eb17c8
2c917d904a17df1e817e104417e5030281b069282fb2a283f160084e11e285311b285e341287d514287
f025187fc38288d13328aa7fb18beef208bfd6e18c1d8828c8f9428e48b018e78a209123d3092591609
28271092f6ef1931352947091295857b29b4a7229c429b29c4d2229ce0a809d9d9209f83142a2560a7c
2331a7e23e2a8723f2a8ea4e2a918e51aa2e831aab1fc1ab9fc91ac9322ad2db81af9c22b09e972b2ba
fc1b373202b4d7c51b566122b7e23e2b8ea892b9b92a2b9fa772ba8c6f1baaea72beaf8a2c079a0c2d9
52c36d810c399f30c4b4a82c75dd70c9ffc31ca23b70cb4ea02cc32922cc49560cdba832ce99e01d017
560d0f6e41d1e19f2d382610d6ef582d7d2c51d7e86c2d8e79c1d940e91dab731daff841dbb95d2dbe2
3e2deef372e118252e193b01e21b560e2b4631e3b0642e469c90e5e0392e61d282e6bd392e7e23e2eb3
b942ec63c51ee9322eeaf9b2efa9992f0e0b60f0ed3e2f1ad3d1f1d8422f2e932f38db0f31e5c2f37d6
a2f3a1e50f7125e0f7ed6a0f7ff9a2f9dfa11fbca22fe784f2fee2631ff10dd140600014669e24bfc6d
28b28942dcef8e240401006041ae0682c900a5adcf0ce99e01
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\Data\
Set 418A073AA3BC3475
8ecf000000404012100000700079534427010002800007d7507000276b69140003dd73419a00056737d
0840006b507e0f2000cbf66084000e6c53101064000f000cd67c515065000550001c955c09300065a69
e076000a2560d62900e6c5310bf400f0e0b602066000c600065a69e054000a2560106700022000a2560
10680006e000a2560106900027b0065a69e01070000800065a69e01071000300065a69e010720005ad0
0a25601073000c600065a69e01077000900065a69e010780007200065a69e0107d0008200065a69e010
7f000b600065a69e01081000410065a69e0 REG_BINARY
8dcf000000404012100000700079534427010002800007d7507000276b69140003dd73419900056737d
0840006b507e0f2000cbf66084000e6c53101064000f000cd67c515065000550001c955c09300065a69
e076000a2560d62900e6c5310bf400f0e0b602066000c600065a69e054000a2560106700022000a2560
10680006e000a2560106900027b0065a69e01070000800065a69e01071000300065a69e010720005ad0
0a25601073000c600065a69e01077000900065a69e010780007200065a69e0107d0008200065a69e010
7f000b600065a69e01081000410065a69e0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
EC97BDF2391593A428BB0E1085CC5133\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\
EC97BDF2391593A428BB0E1085CC5133\ Set WireGuardFeature REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set ProductName WireGuard REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set PackageCode
95F92915D6255534F9EA3FE06731F9BB REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set Language 1033 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set Version 327683 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set Assignment 1 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set AdvertiseFlags 388 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set ProductIcon C:\WINDOWS\Installer\
{2FDB79CE-5193-4A39-82BB-E00158CC1533}\wireguard.ico REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set InstanceType 0 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set AuthorizedLUAApp 0 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set DeploymentFlags 3 REG_DWORD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\ Set Clients : REG_MULTI_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\ Set PackageName
7ee7436d24f863fe208dbf422d76ff8d40cc818a377610b9ea51e70f66658a7d REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\ Set LastUsedSource n;1;C:\
WINDOWS\Temp\ REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\Net\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\Net\ Set 1 C:\WINDOWS\Temp\
REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\Media\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\
EC97BDF2391593A428BB0E1085CC5133\SourceList\Media\ Set 1 ; REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
5AD1A5E563ABD40429CE1450D0C197C9\ Created
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\
5AD1A5E563ABD40429CE1450D0C197C9\ Set EC97BDF2391593A428BB0E1085CC5133
REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\
Set GlobalAssocChangedCounter 3 REG_DWORD 2
HKEY_LOCAL_MACHINE\SOFTWARE\ESET\ESET Security\CurrentVersion\Config\internal\
Set NextAutoInc 3933 REG_BINARY 393300
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-
4052716965-1104184976-741843801-1001\ Set \Device\HarddiskVolume3\Windows\
System32\dllhost.exe 7aa22ce8a0c3d910000000000002000 REG_BINARY
57884cd18dc3d910000000000002000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-
4052716965-1104184976-741843801-1001\ Set \Device\HarddiskVolume3\
RevoUninstallerPro\x64\RevoAppBar.exe f5f312d2a0c3d910000000000002000
REG_BINARY 871350d0a0c3d910000000000002000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-
4052716965-1104184976-741843801-1001\ Set SequenceNumber 130 REG_DWORD
127
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-
4052716965-1104184976-741843801-1001\ Set \Device\HarddiskVolume3\Users\
regman\Downloads\wireguard-installer.exe 84822be6a0c3d910000000000002000
REG_BINARY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-
4052716965-1104184976-741843801-1001\ Set \Device\HarddiskVolume3\Windows\
System32\msiexec.exe 696f21e6a0c3d910000000000002000 REG_BINARY
9f2234adedc1d910000000000002000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-21-
4052716965-1104184976-741843801-1001\ Set \Device\HarddiskVolume3\Program
Files\WireGuard\wireguard.exe 64b6e4e7a0c3d910000000000002000 REG_BINARY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\bam\State\UserSettings\S-1-5-18\
Set \Device\HarddiskVolume3\Windows\System32\msiexec.exe
696f21e6a0c3d910000000000002000 REG_BINARY e6b260eec1d910000000000002000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Created
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Set Type
16 REG_DWORD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Set Start
2 REG_DWORD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Set
ErrorControl 1 REG_DWORD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Set
ImagePath "C:\Program Files\WireGuard\wireguard.exe" /managerservice
REG_EXPAND_SZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Set
DisplayName WireGuard Manager REG_SZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WireGuardManager\ Set
ObjectName LocalSystem REG_SZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment\ Set
PATH C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\
Amazon Corretto\jdk19.0.2_7\bin;C:\Program Files\Amazon Corretto\jre8\bin;
%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\
System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\
Process Lasso\;C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\script\
c\bin;C:\script\perl\bin;C:\script\perl\site\bin;C:\Program Files\Docker\Docker\
resources\bin;C:\ProgramData\DockerDesktop\version-bin;C:\Program Files (x86)\
Microsoft SQL Server\150\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\
Tools\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\
Binn\;C:\Program Files\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files (x86)\
Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\Azure Data Studio\bin;C:\
Program Files\PowerShell\7\;C:\Program Files\WireGuard\ REG_EXPAND_SZ C:\
Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\Amazon
Corretto\jdk19.0.2_7\bin;C:\Program Files\Amazon Corretto\jre8\bin;%SystemRoot%\
system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\
WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Process
Lasso\;C:\Program Files (x86)\Microsoft SQL Server\150\DTS\Binn\;C:\script\c\
bin;C:\script\perl\bin;C:\script\perl\site\bin;C:\Program Files\Docker\Docker\
resources\bin;C:\ProgramData\DockerDesktop\version-bin;C:\Program Files (x86)\
Microsoft SQL Server\150\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\
Tools\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\
Binn\;C:\Program Files\Microsoft SQL Server\150\DTS\Binn\;C:\Program Files (x86)\
Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\Azure Data Studio\bin;C:\
Program Files\PowerShell\7\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\ Set
StringCacheGeneration 473 REG_DWORD 471
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e972-e325-11ce-bfc1-
08002be10318}\ Set LastDeleteDate e66ff7e7a0c3d91 REG_BINARY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ Deleted
HKEY_LOCAL_MACHINE\SYSTEM\Software\Microsoft\TIP\AggregateResults\ Set data
cfaea5110080f5c467000020000000d9a7a811030ec3f46f000090300a00049a8a8112305c4614a6000
02a00024000d1a8a81123064b6561100006d1300e000d1a8a811240fb3b54eb0000ba30019000c25cab
13050cfa1db1e0000100077610023acad12240546dd0b40000100025000affbb911008055161afb0000
100026f60084ec31100806938f310000100000004428c3110080469996a20000c500beee004428c3130
040efd5a1db000010007d1004428c314010541f4af400007000000043ec8110a0fc89bffc00002000c2
00043ec8110b0654c22200002000ad10043ec81401094b12f2d00002000c00006597c9112080eb47f5d
000002000c61002c6d8110408a1488b400008000e512002c6d812010073f1d26d00004000b9e00823fd
91100806cc91420000200074000823fd91401022f8a52200002000710004245d9112507177b2f300004
0007d1e004245d911070436cb73f000030003819004245d9110806413a63500005000923300f3ced911
0080e138f4b000010009f0009f49dd11008045734be10000e00000006a44df11008054528c5d0000100
04e2f00a17edf130b0a676cac90000100022009178e1110080df19d73200002b000ad00081f7e1117f0
80cffd5c73000010009030081f7e114010c177129c0000c32009e1400c123e21100808fcdf2c0000100
058100addbe311008033784279000010008c000b7d2e411000dd78932000035000d5200ec9be5110080
6e4c67b60000100020007fe9e9110080a5b9b0290000d0001c2000c527eb1100804b8d54fb00003000d
50008c5ff21103025b04d21000010005000babf311000248cdfd40000a000321c006efcf31101079586
e9900003d0001432006efcf311020e2d270bf0000c70004152006efcf3110304b4d73e500001659002d
77306efcf3110501d427831000013000e43006efcf3110080105e37360000d430008719003fef411008
0e58c865c0000c9400ed2900ee8ff81100809096e6c20000c000dd9006289fd110080cc449ae0000100
0e90007489fd120205993a370000100080003d4a6210080c39240f00000e00084200564a6217f080784
a674b0000100064500bfde821008065b49d6b000023000fe005f3711210080856d77ff0000200035300
d2ef142100803c97c1700003000ab1006d3816210080738b74c7000010008d30037dd1b23017407838a
4be0000100042d00a41027217f08026fb9f90000a700069600bcf430210080be9498180000100042120
023f73021208091e6e45f000010003000e6ce332100808ef8219000010001000aa23421108014b450ca
000020002d000c752342100806d70b1f6000010006000b65b3421008058479dc8000020007d0006c973
4210080ee1839b9000050000000a8e38212080f269bf1a000010009000144382100804fe56b76000010
004c4003130392101016d2233a0000801004440031303921020ad57211400003000fe80031303923014
0ac788b5600001000596b0031303923014401b0ab44000010003795e409a4839210106d537548000010
00100092b13d2110807c27f6310000100085100dd9140210080e3e8517000001000280008ac04024020
41e1ce6000047000320007d3d4121020b1b246d6000090006a4007d3d4121030483844b000009000861
0005f304221008085a02cfe000010000000333942210080a1b1db3f00003000d3600a1f44210080ef87
caef00001000000029564521000f7519cdd0000a000ac3a00b9be452100808712a98300001000481007
73846217f50101e3ea300001000b000d6f47210080f82c30d1000010000000b4e747210206448b5c000
020004000487c4d210080127a123700003f0007f0008411552102034a7a6b1000010004000be5655210
080e0946b48000010003300050345922040ab9d207c00001b00057390050345923020d6c8482100001a
000a81a0093fe592121098fbb9d600001c0000000477f61210080ed3b2446000050009000b6ae612304
0b82f9da00003000851009e2664211080c0a21113000010000000579264210080fd299895000010002e
13009aaf6821050c99682fa00001000b000d9586f2104083c4de7f00004b000f5220048c17321008012
a5b518000030008000f3f073210080e1bd40cd00008300022000ff4089210080252a784000009eb00f5
1500ff408923004026ccd655000060003000461494210080682b516c00001000b17200
REG_BINARY
cfaea5110080f5c467000020000000d9a7a811030ec3f46f00008f300a00049a8a8112305c4614a6000
02a00024000d1a8a81123064b6561100006d1300e000d1a8a811240fb3b54eb0000b930019000c25cab
13050cfa1db1e0000100077610023acad12240546dd0b40000100025000affbb911008055161afb0000
100026f60084ec31100806938f310000100000004428c3110080469996a20000c500beee004428c3130
040efd5a1db000010007d1004428c314010541f4af400007000000043ec8110a0fc89bffc00002000c2
00043ec8110b0654c22200002000ad10043ec81401094b12f2d00002000c00006597c9112080eb47f5d
000002000c61002c6d8110408a1488b400008000e512002c6d812010073f1d26d00004000b9e00823fd
91100806cc91420000200074000823fd91401022f8a52200002000710004245d9112507177b2f300004
0007d1e004245d911070436cb73f000030003819004245d9110806413a63500005000923300f3ced911
0080e138f4b000010009f0009f49dd11008045734be10000e00000006a44df11008054528c5d0000100
04e2f00a17edf130b0a676cac90000100022009178e1110080df19d73200002b000ad00081f7e1117f0
80cffd5c73000010009030081f7e114010c177129c0000c32009e1400c123e21100808fcdf2c0000100
058100addbe311008033784279000010008c000b7d2e411000dd78932000035000d5200ec9be5110080
6e4c67b60000100020007fe9e9110080a5b9b0290000d0001c2000c527eb1100804b8d54fb00003000d
50008c5ff21103025b04d21000010005000babf311000248cdfd40000a000321c006efcf31101079586
e9900003d0001432006efcf311020e2d270bf0000c70004152006efcf3110304b4d73e500001659002d
77306efcf3110501d427831000013000e43006efcf3110080105e37360000d430008719003fef411008
0e58c865c0000c9400ed2900ee8ff81100809096e6c20000c000dd9006289fd110080cc449ae0000100
0e90007489fd120205993a370000100080003d4a6210080c39240f00000e00084200564a6217f080784
a674b0000100064500bfde821008065b49d6b000023000fe005f3711210080856d77ff0000200035300
d2ef142100803c97c1700003000ab1006d3816210080738b74c7000010008d30037dd1b23017407838a
4be0000100042d00a41027217f08026fb9f90000a700069600bcf430210080be9498180000100042120
023f73021208091e6e45f000010003000e6ce332100808ef8219000010001000aa23421108014b450ca
000020002d000c752342100806d70b1f6000010006000b65b3421008058479dc8000020007d0006c973
4210080ee1839b9000050000000a8e38212080f269bf1a000010009000144382100804fe56b76000010
004c4003130392101016d2233a0000801004440031303921020ad57211400003000fe80031303923014
0ac788b5600001000596b0031303923014401b0ab44000010003795e409a4839210106d537548000010
00100092b13d2110807c27f6310000100085100dd9140210080e3e8517000001000280008ac04024020
41e1ce6000047000320007d3d4121020b1b246d6000090006a4007d3d4121030483844b000009000861
0005f304221008085a02cfe000010000000333942210080a1b1db3f00003000d3600a1f44210080ef87
caef00001000000029564521000f7519cdd0000a000ac3a00b9be452100808712a98300001000481007
73846217f50101e3ea300001000b000d6f47210080f82c30d1000010000000b4e747210206448b5c000
020004000487c4d210080127a123700003f0007f0008411552102034a7a6b1000010004000be5655210
080e0946b48000010003300050345922040ab9d207c00001b00057390050345923020d6c8482100001a
000a81a0093fe592121098fbb9d600001c0000000477f61210080ed3b2446000050009000b6ae612304
0b82f9da00003000851009e2664211080c0a21113000010000000579264210080fd299895000010002e
13009aaf6821050c99682fa00001000b000d9586f2104083c4de7f00004b000f5220048c17321008012
a5b518000030008000f3f073210080e1bd40cd00008300022000ff4089210080252a784000009eb00f5
1500ff408923004026ccd655000060003000461494210080682b516c00001000b17200
HKEY_USERS\S-1-5-21-4052716965-1104184976-741843801-1001\Software\ESET\ESET
Security\CurrentVersion\Plugins\01000200\ Set ProxyLastPrecache 0
REG_QWORD 0
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\ Deleted
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\ci.dll,-100 REG_NONE Isolated User Mode
(IUM)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\ci.dll,-101 REG_NONE Enclave
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\dnsapi.dll,-103 REG_NONE Domain Name
System (DNS) Server Trust
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\fveui.dll,-843 REG_NONE BitLocker Drive
Encryption
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\fveui.dll,-844 REG_NONE BitLocker Data
Recovery Agent
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wuaueng.dll,-400 REG_NONE Windows
Update
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
REG_NONE Document Encryption
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\NgcRecovery.dll,-100 REG_NONE Windows
Hello Recovery Key Encryption
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @C:\WINDOWS\System32\msimsg.dll,-34 REG_NONE Windows Installer
Package
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @C:\WINDOWS\system32\windows.storage.dll,-10152 REG_NONE File
folder
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @C:\WINDOWS\system32\Taskmgr.exe,-32420 REG_NONE Task Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @C:\WINDOWS\system32\mstsc.exe,-4000 REG_NONE Remote Desktop
Connection
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\FirewallControlPanel.dll,-12122 REG_NONE
Windows Defender Firewall
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @Winlangdb.dll,-1121 REG_NONE English (United States)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\powrprof.dll,-15 REG_NONE Balanced
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\powrprof.dll,-1405 REG_NONE Better
Battery-life Overlay
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\powrprof.dll,-1401 REG_NONE High
Performance Overlay
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\powrprof.dll,-1403 REG_NONE Max
Performance Overlay
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wpnservice.dll,-1 REG_NONE Windows Push
Notifications System Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\usermgr.dll,-100 REG_NONE User Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\audiosrv.dll,-200 REG_NONE Windows
Audio
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\windows.staterepository.dll,-1 REG_NONE
State Repository Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\netprofmsvc.dll,-202 REG_NONE Network
List Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\CapabilityAccessManager.dll,-1 REG_NONE
Capability Access Manager Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\WpnUserService.dll,-1 REG_NONE Windows
Push Notifications User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wlidsvc.dll,-100 REG_NONE Microsoft
Account Sign-in Assistant
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\cryptsvc.dll,-1001 REG_NONE
Cryptographic Services
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\shsvcs.dll,-12288 REG_NONE Shell
Hardware Detection
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\webthreatdefsvc.dll,-100 REG_NONE Web
Threat Defense Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\cdpsvc.dll,-100 REG_NONE Connected
Devices Platform Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\wbem\wmisvc.dll,-205 REG_NONE Windows
Management Instrumentation
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\dps.dll,-500 REG_NONE Diagnostic Policy
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\appinfo.dll,-100 REG_NONE Application
Information
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\tokenbroker.dll,-100 REG_NONE Web
Account Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-2 REG_NONE Microsoft Script
Detection
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-5 REG_NONE Microsoft
Transliteration Engine
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-4 REG_NONE Microsoft
Simplified Chinese to Traditional Chinese Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-6 REG_NONE Microsoft
Cyrillic to Latin Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-10 REG_NONE Microsoft Hangul
Decomposition Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-3 REG_NONE Microsoft
Traditional Chinese to Simplified Chinese Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-7 REG_NONE Microsoft
Devanagari to Latin Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-8 REG_NONE Microsoft
Malayalam to Latin Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-9 REG_NONE Microsoft Bengali
to Latin Transliteration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted C:\WINDOWS\system32,@elscore.dll,-1 REG_NONE Microsoft
Language Detection
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\sysmain.dll,-1000 REG_NONE SysMain
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\bdesvc.dll,-100 REG_NONE BitLocker
Drive Encryption Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\windowsudkservices.shellcommon.dll,-100
REG_NONE Udk User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\Windows.Internal.Management.dll,-100
REG_NONE Device Management Enrollment Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\sppsvc.exe,-101 REG_NONE Software
Protection
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\dhcpcore.dll,-100 REG_NONE DHCP Client
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wscsvc.dll,-200 REG_NONE Security
Center
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\cbdhsvc.dll,-100 REG_NONE Clipboard
User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wuaueng.dll,-105 REG_NONE Windows
Update
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @comres.dll,-2450 REG_NONE COM+ Event System
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\appxdeploymentserver.dll,-1 REG_NONE
AppX Deployment Service (AppXSVC)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204 REG_NONE
Windows Audio Endpoint Builder
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\bfe.dll,-1001 REG_NONE Base Filtering
Engine
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\system32\bisrv.dll,-100 REG_NONE Background Tasks
Infrastructure Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\coremessaging.dll,-1 REG_NONE
CoreMessaging
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @combase.dll,-5012 REG_NONE DCOM Server Process Launcher
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\das.dll,-100 REG_NONE Device
Association Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\dispbroker.desktop.dll,-101 REG_NONE
Display Policy Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\
Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000 REG_NONE
Display Enhancement Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\dnsapi.dll,-101 REG_NONE DNS Client
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\dusmsvc.dll,-1 REG_NONE Data Usage
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wevtsvc.dll,-200 REG_NONE Windows Event
Log
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\FntCache.dll,-100 REG_NONE Windows Font
Cache Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\PresentationHost.exe,-3309 REG_NONE
Windows Presentation Foundation Font Cache 3.0.0.0
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @gpapi.dll,-112 REG_NONE Group Policy Client
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\hidserv.dll,-101 REG_NONE Human
Interface Device Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\HostNetSvc.dll,-100 REG_NONE Host
Network Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\hvhostsvc.dll,-100 REG_NONE HV Host
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\ikeext.dll,-501 REG_NONE IKE and AuthIP
IPsec Keying Modules
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\iphlpsvc.dll,-500 REG_NONE IP Helper
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @keyiso.dll,-100 REG_NONE CNG Key Isolation
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\srvsvc.dll,-100 REG_NONE Server
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wkssvc.dll,-100 REG_NONE Workstation
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\lmhsvc.dll,-101 REG_NONE TCP/IP NetBIOS
Helper
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\system32\lsm.dll,-1001 REG_NONE Local Session
Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\FirewallAPI.dll,-23090 REG_NONE Windows
Defender Firewall
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\ncbservice.dll,-500 REG_NONE Network
Connection Broker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\dosvc.dll,-100 REG_NONE Delivery
Optimization
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\NetSetupSvc.dll,-3 REG_NONE Network
Setup Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\nsisvc.dll,-200 REG_NONE Network Store
Interface Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\NvAgent.dll,-100 REG_NONE Network
Virtualization Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\umpnpmgr.dll,-200 REG_NONE Plug and
Play
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\lpksetup.exe,-2 REG_NONE Language Pack
Installer
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\polstore.dll,-5010 REG_NONE IPsec
Policy Agent
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\umpo.dll,-100 REG_NONE Power
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\profsvc.dll,-300 REG_NONE User Profile
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\rasmans.dll,-200 REG_NONE Remote Access
Connection Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\RMapi.dll,-1001 REG_NONE Radio
Management Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\system32\RpcEpMap.dll,-1001 REG_NONE RPC Endpoint
Mapper
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @combase.dll,-5010 REG_NONE Remote Procedure Call (RPC)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\samsrv.dll,-1 REG_NONE Security
Accounts Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\schedsvc.dll,-100 REG_NONE Task
Scheduler
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\Sens.dll,-200 REG_NONE System Event
Notification Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\sensorservice.dll,-1000 REG_NONE Sensor
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\ipnathlp.dll,-106 REG_NONE Internet
Connection Sharing (ICS)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\spoolsv.exe,-1 REG_NONE Print Spooler
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\sstpsvc.dll,-200 REG_NONE Secure Socket
Tunneling Protocol Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wiaservc.dll,-9 REG_NONE Windows Image
Acquisition (WIA)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\system32\SystemEventsBrokerServer.dll,-1001 REG_NONE
System Events Broker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\TabSvc.dll,-100 REG_NONE Text Input
Management Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\themeservice.dll,-8192 REG_NONE Themes
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\system32\TimeBrokerServer.dll,-1001 REG_NONE Time
Broker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\trkwks.dll,-1 REG_NONE Distributed Link
Tracking Client
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wcmsvc.dll,-4097 REG_NONE Windows
Connection Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\winhttp.dll,-100 REG_NONE WinHTTP Web
Proxy Auto-Discovery Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wlansvc.dll,-257 REG_NONE WLAN
AutoConfig
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wpdbusenum.dll,-100 REG_NONE Portable
Device Enumerator Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\servicing\TrustedInstaller.exe,-100 REG_NONE
Windows Modules Installer
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\StorSvc.dll,-100 REG_NONE Storage
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\ClipSVC.dll,-103 REG_NONE Client
License Service (ClipSVC)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\SecurityHealthAgent.dll,-1002 REG_NONE
Windows Security Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\vaultsvc.dll,-1003 REG_NONE Credential
Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\moshost.dll,-100 REG_NONE Downloaded
Maps Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\pcasvc.dll,-1 REG_NONE Program
Compatibility Assistant Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\Sgrm\SgrmBroker.exe,-100 REG_NONE
System Guard Runtime Monitor Broker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\usosvc.dll,-101 REG_NONE Update
Orchestrator Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\pushtoinstall.dll,-200 REG_NONE Windows
PushToInstall Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wbiosrvc.dll,-100 REG_NONE Windows
Biometric Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\ngcsvc.dll,-100 REG_NONE Microsoft
Passport
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\NgcCtnrSvc.dll,-1 REG_NONE Microsoft
Passport Container
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wuaueng.dll,-106 REG_NONE Enables the
detection, download, and installation of updates for Windows and other programs. If
this service is disabled, users of this computer will not be able to use Windows
Update or its automatic updating feature, and programs will not be able to use the
Windows Update Agent (WUA) API.
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\servicing\TrustedInstaller.exe,-101 REG_NONE
Enables installation, modification, and removal of Windows updates and optional
components. If this service is disabled, install or uninstall of Windows updates
might fail for this computer.
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\dosvc.dll,-101 REG_NONE Performs
content delivery optimization tasks
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\qmgr.dll,-1000 REG_NONE Background
Intelligent Transfer Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\qmgr.dll,-1001 REG_NONE Transfers files
in the background using idle network bandwidth. If the service is disabled, then
any applications that depend on BITS, such as Windows Update or MSN Explorer, will
be unable to automatically download programs and other information.
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\usosvc.dll,-102 REG_NONE Manages
Windows Updates. If stopped, your devices will not be able to download and install
the latest updates.
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\licensemanagersvc.dll,-200 REG_NONE
Windows License Manager Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\browser.dll,-100 REG_NONE Computer
Browser
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\FrameServerMonitor.dll,-100 REG_NONE
Windows Camera Frame Server Monitor
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\FrameServer.dll,-100 REG_NONE Windows
Camera Frame Server
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\urlmon.dll,-4200 REG_NONE Open File -
Security Warning
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\AarSvc.dll,-100 REG_NONE Agent
Activation Runtime
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\afd.sys,-1000 REG_NONE
Ancillary Function Driver for Winsock
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\ahcache.sys,-102 REG_NONE
Application Compatibility Cache
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\AJRouter.dll,-2 REG_NONE AllJoyn Router
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\Alg.exe,-112 REG_NONE Application Layer
Gateway Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\srpapi.dll,-100 REG_NONE AppID Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\appidsvc.dll,-100 REG_NONE Application
Identity
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\srpapi.dll,-102 REG_NONE Smartlocker
Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\AppReadiness.dll,-1000 REG_NONE App
Readiness
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32000 REG_NONE RAS
Asynchronous Media Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\autotimesvc.dll,-6 REG_NONE Cellular
Time
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\AxInstSV.dll,-103 REG_NONE ActiveX
Installer (AxInstSV)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\bam.sys,-100 REG_NONE
Background Activity Moderator Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\BcastDVRUserService.dll,-100 REG_NONE
GameDVR and Broadcast User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\bfs.sys,-100 REG_NONE Brokering
File System
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\bindflt.sys,-100 REG_NONE
Windows Bind Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101
REG_NONE Bluetooth User Support Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wkssvc.dll,-2001 REG_NONE Browser
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\BTAGService.dll,-101 REG_NONE Bluetooth
Audio Gateway Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\BthAvctpSvc.dll,-101 REG_NONE AVCTP
service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\bthserv.dll,-101 REG_NONE Bluetooth
Support Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\CaptureService.dll,-100 REG_NONE
CaptureService
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\cdpusersvc.dll,-100 REG_NONE Connected
Devices Platform User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\certprop.dll,-11 REG_NONE Certificate
Propagation
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\clfs.sys,-100 REG_NONE Common
Log (CLFS)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\cnghwassist.sys,-100 REG_NONE
CNG Hardware Assist algorithm provider
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @comres.dll,-947 REG_NONE COM+ System Application
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\ConsentUxClient.dll,-100 REG_NONE
ConsentUX User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100
REG_NONE CredentialEnrollmentManagerUserSvc
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\dam.sys,-100 REG_NONE Desktop
Activity Moderator Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\defragsvc.dll,-101 REG_NONE Optimize
drives
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\deviceaccess.dll,-107 REG_NONE
DeviceAssociationBroker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\umpnpmgr.dll,-100 REG_NONE Device
Install Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006 REG_NONE
DevicePicker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\DevicesFlowBroker.dll,-103 REG_NONE
DevicesFlow
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\DevQueryBroker.dll,-100 REG_NONE
DevQuery Background Discovery Broker
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wkssvc.dll,-1008 REG_NONE DFS Namespace
Client Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\DiagSvcs\
DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 REG_NONE Microsoft
(R) Diagnostics Hub Standard Collector Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\DiagSvc.dll,-100 REG_NONE Diagnostic
Execution Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\diagtrack.dll,-3001 REG_NONE Connected
User Experiences and Telemetry
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\dmwappushsvc.dll,-200 REG_NONE Device
Management Wireless Application Protocol (WAP) Push message Routing Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\dot3svc.dll,-1102 REG_NONE Wired
AutoConfig
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\DeviceSetupManager.dll,-1000 REG_NONE
Device Setup Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\dssvc.dll,-10003 REG_NONE Data Sharing
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\eapsvc.dll,-1 REG_NONE Extensible
Authentication Protocol
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\efssvc.dll,-100 REG_NONE Encrypting
File System (EFS)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\EhStorClass.sys,-100 REG_NONE
Enhanced Storage Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\embeddedmodesvc.dll,-201 REG_NONE
Embedded Mode
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @EnterpriseAppMgmtSvc.dll,-1 REG_NONE Enterprise App
Management Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\Drivers\ExecutionContext.sys,-101 REG_NONE
CPU Scheduler for High Performance I/O
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\fxsresm.dll,-118 REG_NONE Fax
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\fdPHost.dll,-100 REG_NONE Function
Discovery Provider Host
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\fdrespub.dll,-100 REG_NONE Function
Discovery Resource Publication
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\fhsvc.dll,-101 REG_NONE File History
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\filecrypt.sys,-100 REG_NONE
FileCrypt
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\fileinfo.sys,-100 REG_NONE File
Information FS MiniFilter
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\filetrace.sys,-10001 REG_NONE
FileTrace
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\fltmgr.sys,-10001 REG_NONE
FltMgr
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\fsdepends.sys,-10001 REG_NONE
File System Dependency Minifilter
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\fvevol.sys,-100 REG_NONE
BitLocker Drive Encryption Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\GraphicsPerfSvc.dll,-100 REG_NONE
GraphicsPerfSvc
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\hnswfpdriver.sys,-5000 REG_NONE
HNS WFP Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\http.sys,-1 REG_NONE HTTP
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\hwpolicy.sys,-101 REG_NONE
Hardware Policy Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\tetheringservice.dll,-4097 REG_NONE
Windows Mobile Hotspot Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\IndirectKmd.sys,-100 REG_NONE
Indirect Displays Kernel-Mode Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\inventorysvc.dll,-501 REG_NONE
Inventory and Compatibility Appraisal service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\iorate.sys,-101 REG_NONE Disk
I/O Rate Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32013 REG_NONE IP Traffic
Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\ipxlatcfg.dll,-500 REG_NONE IP
Translation Configuration Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @comres.dll,-2946 REG_NONE KtmRm for Distributed Transaction
Coordinator
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\l2bridge.sys,-5000 REG_NONE
Bridge Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\lfsvc.dll,-1 REG_NONE Geolocation
Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\lltdres.dll,-6 REG_NONE Link-Layer
Topology Discovery Mapper I/O Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\lltdres.dll,-1 REG_NONE Link-Layer
Topology Discovery Mapper
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\luafv.sys,-100 REG_NONE UAC
File Virtualization
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\LanguageOverlayServer.dll,-100 REG_NONE
Language Experience Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\lxss.sys,-100 REG_NONE LXSS
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\lxss\LxssManager.dll,-100 REG_NONE
LXSSMANAGER
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\MessagingService.dll,-100 REG_NONE
MessagingService
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\MixedRealityRuntime.dll,-101 REG_NONE
Windows Mixed Reality OpenXR Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\mmcss.sys,-100 REG_NONE
Multimedia Class Scheduler
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\mountmgr.sys,-100 REG_NONE
Mount Point Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\mpsdrv.sys,-23092 REG_NONE
Windows Defender Firewall Authorization Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\webclnt.dll,-104 REG_NONE WebDav Client
Redirector Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wkssvc.dll,-1002 REG_NONE SMB
MiniRedirector Wrapper and Engine
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wkssvc.dll,-1006 REG_NONE SMB 2.0
MiniRedirector
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\bridgeres.dll,-1 REG_NONE Microsoft MAC
Bridge
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @comres.dll,-2797 REG_NONE Distributed Transaction Coordinator
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\mshidumdf.sys,-100 REG_NONE
Pass-through HID to UMDF Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\iscsidsc.dll,-5000 REG_NONE Microsoft
iSCSI Initiator Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\msimsg.dll,-27 REG_NONE Windows
Installer
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\mslldp.sys,-200 REG_NONE
Microsoft Link-Layer Discovery Protocol
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\msquic.sys,-200 REG_NONE MSQUIC
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\mup.sys,-101 REG_NONE MUP
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\nwifi.sys,-101 REG_NONE
NativeWiFi Filter
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\NaturalAuth.dll,-100 REG_NONE Natural
Authentication
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\ncasvc.dll,-3009 REG_NONE Network
Connectivity Assistant
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\NcdAutoSetup.dll,-100 REG_NONE Network
Connected Devices Auto-Setup
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\ndis.sys,-200 REG_NONE NDIS
System Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\ndiscap.sys,-5000 REG_NONE
Microsoft NDIS Capture
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\ndisimplatform.sys,-501 REG_NONE
Microsoft Network Adapter Multiplexor Protocol
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32001 REG_NONE Remote
Access NDIS TAPI Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200 REG_NONE
Microsoft Virtual Network Adapter Enumerator
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32002 REG_NONE Remote
Access NDIS WAN Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32014 REG_NONE Remote
Access LEGACY NDIS WAN Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\ndproxy.sys,-6000 REG_NONE NDIS
Proxy Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\Ndu.sys,-10001 REG_NONE Windows
Network Data Usage Monitoring Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\system32\drivers\netbios.sys,-503 REG_NONE NetBIOS
Interface
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\netbt.sys,-2 REG_NONE NETBT
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\netlogon.dll,-102 REG_NONE Netlogon
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\netman.dll,-109 REG_NONE Network
Connections
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\Microsoft.NET\Framework64\v4.0.30319\
ServiceModelInstallRC.dll,-8201 REG_NONE Net.Tcp Port Sharing Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\netprofmsvc.dll,-208 REG_NONE Network
Location Awareness
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\nsiproxy.sys,-2 REG_NONE NSI
Proxy Service Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\APHostRes.dll,-10002 REG_NONE Sync Host
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\pnrpsvc.dll,-8004 REG_NONE Peer
Networking Identity Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\p2psvc.dll,-8006 REG_NONE Peer
Networking Grouping
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\p9rdr.sys,-100 REG_NONE Plan 9
Redirector Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\p9rdrservice.dll,-102 REG_NONE
P9RdrService
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\partmgr.sys,-100 REG_NONE
Partition driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\passthruparser.sys,-10010 REG_NONE
PassthroughParser
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\pdc.sys,-100 REG_NONE PDC
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\PenService.dll,-100 REG_NONE PenService
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\PerceptionSimulation\
PerceptionSimulationService.exe,-101 REG_NONE Windows Perception
Simulation Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\sysWow64\perfhost.exe,-2 REG_NONE Performance
Counter DLL Host
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\PhoneserviceRes.dll,-10000 REG_NONE
Phone Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\UserDataAccessRes.dll,-15001 REG_NONE
Contact Data
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\pla.dll,-500 REG_NONE Performance Logs
& Alerts
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\pnrpauto.dll,-8002 REG_NONE PNRP
Machine Name Publication Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\pnrpsvc.dll,-8000 REG_NONE Peer Name
Resolution Protocol
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32006 REG_NONE WAN Miniport
(PPTP)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll,-1
REG_NONE Printer Extensions and Notifications
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\PrintWorkflowService.dll,-100 REG_NONE
PrintWorkflow
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%windir%\System32\drivers\pacer.sys,-101 REG_NONE QoS Packet
Scheduler
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\qwave.dll,-1 REG_NONE Quality Windows
Audio Video Experience
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\qwavedrv.sys,-1 REG_NONE QWAVE
driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\rasauto.dll,-200 REG_NONE Remote Access
Auto Connection Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32005 REG_NONE WAN Miniport
(L2TP)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32007 REG_NONE Remote
Access PPPOE Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\sstpsvc.dll,-202 REG_NONE WAN Miniport
(SSTP)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wkssvc.dll,-1000 REG_NONE Redirected
Buffering Sub System
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100 REG_NONE Remote
Desktop Device Redirector Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\mprdim.dll,-200 REG_NONE Routing and
Remote Access
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @regsvc.dll,-1 REG_NONE Remote Registry
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\RDXService.dll,-256 REG_NONE Retail
Demo Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\Locator.exe,-2 REG_NONE Remote
Procedure Call (RPC) Locator
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\lltdres.dll,-5 REG_NONE Link-Layer
Topology Discovery Responder
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\SCardSvr.dll,-1 REG_NONE Smart Card
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\ScDeviceEnum.dll,-100 REG_NONE Smart
Card Device Enumeration Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\scfilter.sys,-11 REG_NONE Smart
card PnP Class Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\certprop.dll,-13 REG_NONE Smart Card
Removal Policy
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\sdrsvc.dll,-107 REG_NONE Windows Backup
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\seclogon.dll,-7001 REG_NONE Secondary
Logon
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\SEMgrSvc.dll,-1001 REG_NONE Payments
and NFC/SE Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\SensorDataService.exe,-101 REG_NONE
Sensor Data Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\sensrsvc.dll,-1000 REG_NONE Sensor
Monitoring Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\SessEnv.dll,-1026 REG_NONE Remote
Desktop Configuration
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\Drivers\SgrmAgent.sys,-1001 REG_NONE
System Guard Runtime Monitor Agent
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\SharedRealitySvc.dll,-100 REG_NONE
Spatial Data Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100
REG_NONE Shared PC Account Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\smphost.dll,-102 REG_NONE Microsoft
Storage Spaces SMP
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\SmsRouterSvc.dll,-10001 REG_NONE
Microsoft Windows SMS Router Service.
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @firewallapi.dll,-50323 REG_NONE SNMP Trap
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\spectrum.exe,-101 REG_NONE Windows
Perception Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\srvsvc.dll,-104 REG_NONE Server SMB
2.xxx Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\ssdpsrv.dll,-100 REG_NONE SSDP
Discovery
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\storqosflt.sys,-101 REG_NONE
Storage QoS Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\svsvc.dll,-101 REG_NONE Spot Verifier
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\swprv.dll,-103 REG_NONE Microsoft
Software Shadow Copy Provider
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\tapisrv.dll,-10100 REG_NONE Telephony
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\tcpip.sys,-10001 REG_NONE
TCP/IP Protocol Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\tcpipcfg.dll,-50004 REG_NONE NetIO
Legacy TDI Support Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\termsrv.dll,-268 REG_NONE Remote
Desktop Services
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\TieringEngineService.exe,-702 REG_NONE
Storage Tiers Management
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\MitigationClient.dll,-103 REG_NONE
Recommended Troubleshooting Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\tsusbflt.sys,-1000 REG_NONE
Remote Desktop USB Hub Class Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\tunnel.sys,-500 REG_NONE
Microsoft Tunnel Miniport Adapter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\tzautoupdate.dll,-200 REG_NONE Auto
Time Zone Updater
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\umrdp.dll,-1000 REG_NONE Remote Desktop
Services UserMode Port Redirector
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\UserDataAccessRes.dll,-10003 REG_NONE
User Data Storage
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\upnphost.dll,-213 REG_NONE UPnP Device
Host
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\UserDataAccessRes.dll,-14001 REG_NONE
User Data Access
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\vac.dll,-200 REG_NONE Volumetric Audio
Compositor Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\vds.exe,-100 REG_NONE Virtual Disk
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\VerifierExt.sys,-1000 REG_NONE
Driver Verifier Extension
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\vmbusr.sys,-1001 REG_NONE
Virtual Machine Bus Provider
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\vmcompute.exe,-100 REG_NONE Hyper-V
Host Compute Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvc.dll,-801 REG_NONE Hyper-V Guest
Service Interface
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvc.dll,-101 REG_NONE Hyper-V
Heartbeat Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvc.dll,-201 REG_NONE Hyper-V Data
Exchange Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvcext.dll,-601 REG_NONE Hyper-V
Remote Desktop Virtualization Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvc.dll,-301 REG_NONE Hyper-V Guest
Shutdown Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvc.dll,-401 REG_NONE Hyper-V Time
Synchronization Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvc.dll,-901 REG_NONE Hyper-V
PowerShell Direct Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\icsvcvss.dll,-101 REG_NONE Hyper-V
Volume Shadow Copy Requestor
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\volmgrx.sys,-100 REG_NONE
Dynamic Volume Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\volsnap.sys,-100 REG_NONE
Volume Shadow Copy driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\vssvc.exe,-102 REG_NONE Volume Shadow
Copy
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\vwifibus.sys,-257 REG_NONE
Virtual Wireless Bus Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\vwififlt.sys,-259 REG_NONE
Virtual WiFi Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\vwifimp.sys,-261 REG_NONE
Virtual WiFi Miniport Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\w32time.dll,-200 REG_NONE Windows Time
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\WalletService.dll,-1000 REG_NONE
WalletService
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32011 REG_NONE Remote
Access IP ARP Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\mprmsg.dll,-32012 REG_NONE Remote
Access IPv6 ARP Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\Windows.WARP.JITService.dll,-100 REG_NONE
Warp JIT Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wbengine.exe,-104 REG_NONE Block Level
Backup Engine Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\drivers\wcifs.sys,-100 REG_NONE Windows
Container Isolation
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wcncsvc.dll,-3 REG_NONE Windows Connect
Now - Config Registrar
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390 REG_NONE
Microsoft Defender Antivirus Boot Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\Wdf01000.sys,-1000 REG_NONE
Kernel Mode Driver Frameworks service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330 REG_NONE
Microsoft Defender Antivirus Mini-Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wdi.dll,-502 REG_NONE Diagnostic
Service Host
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wdi.dll,-500 REG_NONE Diagnostic System
Host
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-370 REG_NONE
Microsoft Defender Antivirus Network Inspection System Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 REG_NONE
Microsoft Defender Antivirus Network Inspection Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\webclnt.dll,-100 REG_NONE WebClient
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\webthreatdefusersvc.dll,-100 REG_NONE
Web Threat Defense User Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wecsvc.dll,-200 REG_NONE Windows Event
Collector
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\wephostsvc.dll,-100 REG_NONE Windows
Encryption Provider Host Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wercplsupport.dll,-101 REG_NONE Problem
Reports Control Panel Support
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wersvc.dll,-100 REG_NONE Windows Error
Reporting Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000 REG_NONE Wi-Fi
Direct Services Connection Manager Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\drivers\wfplwfs.sys,-6000 REG_NONE
Microsoft Windows Filtering Platform
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\wiarpc.dll,-2 REG_NONE Still Image
Acquisition Events
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\wimmount.sys,-101 REG_NONE
WIMMount
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 REG_NONE
Microsoft Defender Antivirus Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\winnat.sys,-10001 REG_NONE
Windows NAT Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\wsmsvc.dll,-101 REG_NONE Windows Remote
Management (WS-Management)
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\flightsettings.dll,-103 REG_NONE
Windows Insider Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\lpasvc.dll,-1000 REG_NONE Local Profile
Assistant Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\Windows.Management.Service.dll,-100
REG_NONE Windows Management Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 REG_NONE WMI
Performance Adapter
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 REG_NONE
Windows Media Player Network Sharing Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\workfolderssvc.dll,-102 REG_NONE Work
Folders
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\WpcRefreshTask.dll,-100 REG_NONE
Parental Controls
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\System32\drivers\WpdUpFltr.sys,-100 REG_NONE WPD
Upper Class Filter Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\System32\drivers\ws2ifsl.sys,-1000 REG_NONE
Winsock IFS Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\wtd.sys,-1000 REG_NONE WTD
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\Wudfpf.sys,-1000 REG_NONE User
Mode Driver Frameworks Platform Driver
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\system32\drivers\WudfRd.sys,-1000 REG_NONE
Windows Driver Foundation - User-mode Driver Framework Reflector
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%SystemRoot%\System32\wwansvc.dll,-257 REG_NONE WWAN
AutoConfig
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\XblAuthManager.dll,-100 REG_NONE Xbox
Live Auth Manager
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\XblGameSave.dll,-100 REG_NONE Xbox Live
Game Save
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\xboxgipsvc.dll,-100 REG_NONE Xbox
Accessory Management Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d7\52C64B7E\
Deleted @%systemroot%\system32\XboxNetApiSvc.dll,-100 REG_NONE Xbox
Live Networking Service
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\ Created
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\
Created
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\System32\ci.dll,-100 Isolated User Mode (IUM) REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\System32\ci.dll,-101 Enclave REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\system32\dnsapi.dll,-103 Domain Name System (DNS) Server Trust
REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\System32\fveui.dll,-843 BitLocker Drive Encryption REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\System32\fveui.dll,-844 BitLocker Data Recovery Agent REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\System32\wuaueng.dll,-400 Windows Update REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124 Document
Encryption REG_SZ
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\1d9\52C64B7E\ Set
@%SystemRoot%\system32\NgcRecovery.dll,-100 Windows Hello Recovery Key
Encryption REG_SZ
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
ZoneMap\ Set ProxyBypass 1 REG_DWORD 1
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
ZoneMap\ Set IntranetName 1 REG_DWORD 1
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
ZoneMap\ Set UNCAsIntranet 1 REG_DWORD 1
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
ZoneMap\ Set AutoDetect 0 REG_DWORD 0
HKEY_USERS\.DEFAULT\Software\ESET\ESET Security\CurrentVersion\Plugins\01000200\
Set ProxyLastPrecache 0 REG_QWORD 0

You might also like