Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\diasymreader.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\iehost.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\microsoft.jscript.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.JScript.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\microsoft.vsa.vb.codedomprocessor.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscordbi.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscoree.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscorlib.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscorrc.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscorsec.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\system.configuration.install.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\system.data.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\System.Drawing.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\system.enterpriseservices.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\System.EnterpriseServices.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\System.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\System.Windows.Forms.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\vsavb7rt.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\wminet_utils.dll"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\Microsoft.JScript.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\mscoree.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\mscorlib.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\System.Drawing.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\System.EnterpriseServices.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\System.tlb"=dword:00001fff [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Windows\\Microsoft.NET\\Framework\\v1.1.4322\\System.Windows.Forms.tlb"=dword:00001fff [HKEY_CLASSES_ROOT\ZbTaskEOSUtility.TEU_EOSUtilityTask] [HKEY_CLASSES_ROOT\ZbTaskEOSUtility.TEU_EOSUtilityTask.1] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b5t] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b5t\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b6t] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b6t\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwt] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwt\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ccd] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ccd\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdi] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdi\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hc] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hc\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.idx] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.idx\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipa] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipa\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iscsi] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iscsi\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.isz] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.isz\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itc2] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itc2\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itdb] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itdb\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jps] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jps\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.json] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.json\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.map] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.map\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mdf] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mdf\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mdx] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mdx\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tc] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tc\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdi] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdi\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vmdk] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vmdk\UserChoice] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vssettings] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vssettings\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps\UserChoice] "Hash"="YBeukYNsNp0=" "ProgId"="Windows.XPSReachViewer" [HKEY_CLASSES_ROOT\acestream\shell\open] [HKEY_CLASSES_ROOT\acestream\shell\open\command] @="\"C:\\Users\\Acer\\AppData\\Roaming\\ACEStream\\player\\ace_player.exe\" --started-from-file \"%1\"" [HKEY_CLASSES_ROOT\AppXaf0097ws4bwb0wre67gmp7pc9fjr8en6\DefaultIcon] @="C:\\Program Files\\WindowsApps\\Microsoft.Office.OneNote_16001.10827.20152.0_x64__8wekyb3d8bbwe\\images\\OneNoteLogo_150x150.png" [HKEY_CLASSES_ROOT\AppXj4qrs60k02d8kcd8ycgdx89mga9t57z3\DefaultIcon] @="C:\\Program Files\\WindowsApps\\Microsoft.WindowsFeedbackHub_1.1805.2331.0_x64__8wekyb3d8bbwe\\images\\icon.png" [HKEY_CLASSES_ROOT\AppXztymbw55c24qp3qfb1jac0r6a8w3rtfq\DefaultIcon] @="C:\\Program Files\\WindowsApps\\Microsoft.Microsoft3DViewer_5.1807.6012.1000_x64__8wekyb3d8bbwe\\Assets\\Images\\Tiles\\StoreLogo.png" [HKEY_CLASSES_ROOT\MailFileAtt] [HKEY_CLASSES_ROOT\MailFileAtt\CLSID] @="{00020D05-0000-0000-C000-000000000046}" [HKEY_CLASSES_ROOT\mapifvbx.object] @="MAPIForm object" [HKEY_CLASSES_ROOT\mapifvbx.object\Clsid] @="{41116C00-8B90-101B-96CD-00AA003B14FC}" [HKEY_CLASSES_ROOT\mapifvbx.object.1] @="MAPIForm object (V 1.0)" [HKEY_CLASSES_ROOT\mapifvbx.object.1\Clsid] @="{41116C00-8B90-101B-96CD-00AA003B14FC}" [HKEY_CLASSES_ROOT\CLSID\{206FA6D0-A493-41FA-943D-3F655088F7B9}] @="Perception Simulation Calibration Runtime" [HKEY_CLASSES_ROOT\CLSID\{206FA6D0-A493-41FA-943D-3F655088F7B9}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{363BE3C0-DDD4-4B21-BC6D-7E9DF8CE19CB}] @="Perception Simulation Hand Tracker Monitor" [HKEY_CLASSES_ROOT\CLSID\{363BE3C0-DDD4-4B21-BC6D-7E9DF8CE19CB}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{3F052B8E-512B-419D-9E06-9B9ADDC7118C}] [HKEY_CLASSES_ROOT\CLSID\{3F052B8E-512B-419D-9E06-9B9ADDC7118C}\InProcServer32] @="C:\\Windows\\SysWOW64\\MapsCSP.dll" "ThreadingModel"="Free" [HKEY_CLASSES_ROOT\CLSID\{5EB699B3-9296-41BA-9258-DE70F03B7D6C}] @="Perception Simulation Spatial Graph Monitor" [HKEY_CLASSES_ROOT\CLSID\{5EB699B3-9296-41BA-9258-DE70F03B7D6C}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{8685C4A9-D0E4-444C-87A0-D9FB858235A7}] @="Perception Simulation Surface Reconstruction Monitor" [HKEY_CLASSES_ROOT\CLSID\{8685C4A9-D0E4-444C-87A0-D9FB858235A7}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{95BD18C1-D7FB-4BD3-839A-1C37C90131B1}] @="Perception Simulation Spatial Graph Runtime" [HKEY_CLASSES_ROOT\CLSID\{95BD18C1-D7FB-4BD3-839A-1C37C90131B1}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C}] [HKEY_CLASSES_ROOT\CLSID\{98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C}\LocalServer32] @="\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\AcroRd32Info.exe\" /PDFShell" [HKEY_CLASSES_ROOT\CLSID\{994B3B2F-2880-4318-A583-15C38A01F571}] @="Perception Simulation Hand Tracker Runtime" [HKEY_CLASSES_ROOT\CLSID\{994B3B2F-2880-4318-A583-15C38A01F571}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{A020FAD9-D661-4857-AA43-E6A86FF1163E}] @="Perception Simulation Calibration Monitor" [HKEY_CLASSES_ROOT\CLSID\{A020FAD9-D661-4857-AA43-E6A86FF1163E}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{A82536D7-C8E6-4CEF-AA66-11E97EDDFC6D}] @="Perception Simulation Surface Reconstruction Runtime" [HKEY_CLASSES_ROOT\CLSID\{A82536D7-C8E6-4CEF-AA66-11E97EDDFC6D}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{CDAEB70C-E686-4299-93EB-7D63D77B7F63}] @="Perception Simulation Head Tracker Runtime" [HKEY_CLASSES_ROOT\CLSID\{CDAEB70C-E686-4299-93EB-7D63D77B7F63}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{D38406DA-E8AA-484b-B80D-3D3DBDCC2FB2}] [HKEY_CLASSES_ROOT\CLSID\{D38406DA-E8AA-484b-B80D-3D3DBDCC2FB2}\LocalServer32] @="\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\AcroRd32Info.exe\" /PDFShell" [HKEY_CLASSES_ROOT\CLSID\{D8E090A5-4149-467D-8103-BFB8F51E8BCB}] @="Perception Simulation Head Tracker Monitor" [HKEY_CLASSES_ROOT\CLSID\{D8E090A5-4149-467D-8103-BFB8F51E8BCB}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{FA274B26-38A2-73DA-C53D-22B0F40255C4}] [HKEY_CLASSES_ROOT\CLSID\{FA274B26-38A2-73DA-C53D-22B0F40255C4}\InprocServer32] @="%SystemRoot%\\system32\\ajjiesxe.dll" [HKEY_CLASSES_ROOT\CLSID\{FA6C507D-A9AF-4385-86C0-80115F0AE20B}] @="Perception Simulation Secondary Head Tracker Runtime" [HKEY_CLASSES_ROOT\CLSID\{FA6C507D-A9AF-4385-86C0-80115F0AE20B}\InProcServer32] @="C:\\Windows\\SysWOW64\\PerceptionSimulationExtensions.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}] @="ISearch" [HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\ProxyStubClsid] @="{00020424-0000-0000-C000-000000000046}" [HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\TypeLib] @="{47A7A4B0-2723-41BA-865E-EBBB7081A602}" "Version"="1.0" [HKEY_CLASSES_ROOT\Applications\provtool.exe\shell\open] [HKEY_CLASSES_ROOT\Applications\provtool.exe\shell\open\command] @=hex(2):22,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,70,00,\ 72,00,6f,00,76,00,74,00,6f,00,6f,00,6c,00,2e,00,65,00,78,00,65,00,22,00,20,\ 00,22,00,25,00,31,00,22,00,20,00,2f,00,73,00,6f,00,75,00,72,00,63,00,65,00,\ 20,00,53,00,68,00,65,00,6c,00,6c,00,4f,00,70,00,65,00,6e,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers] "D:\\Program Files (x86)\\BDESERT\\bin64\\blackdesert64.exe"="HIGHDPIAWARE" [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Microsoft\\OneDrive\\17.3.6816.0313\\FileSyncConfig.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,78,7c,03,00,37,65,\ 04,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,01,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Microsoft\\OneDrive\\18.111.0603.0006\\FileSyncConfig.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,a0,f6,03,00,d1,40,\ 04,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,01,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "D:\\Archivos de progama (x86)\\Pro Evolution Soccer 2018\\PES2018.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,00,44,34,0d,79,9a,\ 34,0d,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,7d,41,00,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Packages\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\TempState\\Downloads\\SteamSetup (1).exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,c0,02,18,00,84,1d,\ 18,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,fa,2d,09,00,00,00,00,00,06,\ 00,00,00,06,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "D:\\Archivos de progama (x86)\\Steam\\steamapps\\common\\Counter-Strike Global Offensive\\csgo.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,20,e3,11,00,f7,bb,\ 12,00,01,00,00,00,00,00,00,00,00,00,02,06,00,01,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,90,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,3d,58,01,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Packages\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\TempState\\Downloads\\ChromeSetup (1).exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,58,41,11,00,43,dd,\ 11,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,78,da,02,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Windows.old\\Program Files (x86)\\Steam\\uninstall.exe"=hex:53,41,43,50,\ 01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,40,26,02,00,9f,b4,02,00,01,\ 00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,\ 00,00,00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,01,41,00,00,00,00,00,00,02,00,00,00,02,\ 00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Windows.old\\Program Files (x86)\\Steam\\Steam.exe"=hex:53,41,43,50,01,\ 00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,20,e9,30,00,9d,24,31,00,01,00,\ 00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,\ 00,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Battle.net\\Battle.net Launcher.exe"=hex:53,41,43,\ 50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,e8,59,03,00,ba,bf,03,00,\ 01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,\ 00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,80,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,dc,ec,01,00,00,00,00,00,01,00,00,\ 00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Battle.net\\Battle.net.exe"=hex:53,41,43,50,01,00,\ 00,00,00,00,00,00,07,00,00,00,28,00,00,00,e8,15,10,00,76,c9,10,00,01,00,00,\ 00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,00,\ 00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,93,f3,2f,00,00,00,00,00,02,00,00,00,02,00,\ 00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\Downloads\\ccsetup545.exe"=hex:53,41,43,50,01,00,00,00,00,\ 00,00,00,07,00,00,00,28,00,00,00,38,af,fd,00,5d,73,fe,00,01,00,00,00,00,00,\ 00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,00,00,00,00,\ 00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,f4,91,1a,01,00,00,00,00,01,00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files\\Malwarebytes\\Anti-Malware\\unins000.exe"=hex:53,41,43,\ 50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,d0,2c,12,00,e0,61,12,00,\ 03,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,\ 00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,9d,34,00,00,00,00,00,00,01,00,00,\ 00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Microsoft\\OneDrive\\18.131.0701.0007\\FileSyncConfig.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,a8,02,04,00,3e,a4,\ 04,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,01,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Temp\\Temp1_Odin_3.12.3.zip\\Odin_3.12.3\\Odin3_v3.12.3.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,00,20,29,00,71,e5,\ 29,00,01,00,00,00,00,00,00,00,00,00,00,0a,71,22,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,d4,09,00,00,00,00,00,00,02,\ 00,00,00,02,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Temp\\Temp1_Odin3_v3.13.1.zip\\Odin3_v3.13.1\\Odin3 v3.13.1.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,00,6a,30,00,00,00,\ 00,00,01,00,00,00,00,00,00,00,00,00,00,0a,71,22,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,d8,03,00,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\POWERPNT.EXE"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,a0,ce,1c,00,99,d7,\ 1c,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,91,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files\\Common Files\\microsoft shared\\ClickToRun\\OfficeClickToRun.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,e0,19,87,00,d2,8b,\ 87,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,21,7f,07,00,00,00,00,00,05,\ 00,00,00,05,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WINWORD.EXE"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,50,be,1d,00,55,5c,\ 1e,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,91,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files\\DAEMON Tools Lite\\DTAgent.exe"=hex:53,41,43,50,01,00,00,\ 00,00,00,00,00,07,00,00,00,28,00,00,00,68,28,0b,00,6b,64,0b,00,01,00,00,00,\ 00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,00,00,\ 00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,8e,12,00,00,00,00,00,00,02,00,00,00,02,00,00,\ 00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "D:\\Renzo\\kms\\OFF2016X64\\Office Professional Plus 2016 W64\\Activadores\\KMSAuto.Net.v1.3.9.Portable\\KMSAuto Net 2015 v1.3.9 Portable\\KMSAuto Net.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,f8,1a,80,00,87,5d,\ 80,00,01,00,00,00,00,00,00,00,00,00,00,0a,75,22,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,16,d7,00,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "D:\\Program Files (x86)\\BDESERT\\BlackDesertLauncher.exe"=hex:53,41,43,50,\ 01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,98,cd,0f,00,0c,0e,10,00,01,\ 00,00,00,00,00,00,00,00,00,00,0a,71,22,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,\ 00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,80,00,00,40,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,a4,d8,26,00,00,00,00,00,05,00,00,00,\ 05,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "D:\\Program Files (x86)\\BDESERT\\RemoveBDO.exe"=hex:53,41,43,50,01,00,00,\ 00,00,00,00,00,07,00,00,00,28,00,00,00,e0,33,00,00,ee,47,00,00,01,00,00,00,\ 00,00,00,00,00,00,00,0a,75,22,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,00,00,\ 00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,fa,0d,00,00,00,00,00,00,01,00,00,00,01,00,00,\ 00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Lavasoft\\Web Companion\\Application\\WebCompanionInstaller.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,20,fd,04,00,78,64,\ 05,00,03,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,c9,87,01,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Microsoft\\OneDrive\\18.151.0729.0006\\FileSyncConfig.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,20,f8,03,00,ee,6c,\ 04,00,01,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,01,00,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\Downloads\\readerdc_es_xa_crd_install.exe"=hex:53,41,43,50,\ 01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,f8,6d,12,00,5d,37,13,00,01,\ 00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,\ 00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,27,e8,12,00,00,00,00,00,01,00,00,00,\ 01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Roaming\\ACEStream\\engine\\ace_engine.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,38,6d,00,00,a4,ba,\ 00,00,01,00,00,00,00,00,00,00,00,00,03,06,71,02,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0e,03,00,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Roaming\\ACEStream\\player\\ace_player.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,28,cb,01,00,4c,a3,\ 02,00,01,00,00,00,00,00,00,00,00,00,03,06,71,00,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,b8,e5,2f,00,00,00,00,00,05,\ 00,00,00,05,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files\\WindowsApps\\XBMCFoundation.Kodi_17.9.601.0_x86__4n2hpmxwrvr6p\\kodi.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,00,d4,e0,00,00,00,\ 00,00,01,00,00,00,00,00,00,00,00,00,00,0a,71,22,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,84,2a,08,00,00,00,00,00,02,\ 00,00,00,02,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Roaming\\uTorrent\\uTorrent.exe"=hex:53,41,43,50,\ 01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,b8,54,1e,00,87,c4,1e,00,03,\ 00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,\ 00,00,00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,c8,32,00,00,00,00,00,00,01,00,00,00,01,\ 00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files\\DAEMON Tools Lite\\uninst.exe"=hex:53,41,43,50,01,00,00,\ 00,00,00,00,00,07,00,00,00,28,00,00,00,68,18,58,00,e7,f3,58,00,03,00,00,00,\ 00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,00,00,\ 00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,a8,ca,16,00,00,00,00,00,01,00,00,00,01,00,00,\ 00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Roaming\\ACEStream\\Uninstall.exe"=hex:53,41,43,\ 50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,a0,5d,02,00,bd,df,26,05,\ 03,00,00,00,00,00,00,00,00,00,00,0a,00,21,00,00,bf,a2,13,9d,ed,d1,d3,01,00,\ 00,00,00,00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,a5,93,00,00,00,00,00,00,01,00,00,00,\ 01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Users\\Acer\\AppData\\Local\\Temp\\AcerDiagnosticSuiteToolkit\\ADSToolkit.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,30,39,08,00,5c,0d,\ 09,00,01,00,00,00,00,00,00,00,00,00,00,0a,75,22,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,28,4d,1a,00,00,00,00,00,01,\ 00,00,00,01,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Canon\\EOS Utility\\EOS Utility.exe"=hex:53,41,43,\ 50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,78,d3,18,00,4a,91,19,00,\ 01,00,00,00,00,00,00,00,00,00,00,0a,71,20,00,00,bf,a2,13,9d,ed,d1,d3,01,00,\ 00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,a4,4f,9b,00,00,00,00,00,02,00,00,\ 00,02,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Program Files (x86)\\Canon\\EOS Utility\\EU2\\EOS Utility 2.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,00,d0,19,02,b0,b7,\ 1a,02,01,00,00,00,00,00,00,00,00,00,00,0a,71,22,00,00,bf,a2,13,9d,ed,d1,d3,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,9f,87,00,00,00,00,00,00,03,\ 00,00,00,03,00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "D:\\Renzo\\MrNiceGuysDownloader.exe"=hex:53,41,43,50,01,00,00,00,00,00,00,\ 00,07,00,00,00,28,00,00,00,00,0e,0c,00,00,00,00,00,01,00,00,00,00,00,00,00,\ 00,00,00,0a,75,22,00,00,bf,a2,13,9d,ed,d1,d3,01,00,00,00,00,00,00,00,00,02,\ 00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,bb,fc,01,00,00,00,00,00,01,00,00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files (x86)\\Qualcomm\\fakeboarddata\\"="" [HKEY_CURRENT_USER\Software\Malwarebytes] [HKEY_CURRENT_USER\Software\Norton] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Piriform] [HKEY_LOCAL_MACHINE\Software\Symantec] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "Collab-P2PHost-In-TCP"="v2.28|Action=Allow|Active=FALSE|Dir=In|Protocol=6|App=%SystemRoot%\\system32\\p2phost.exe|Name=@FirewallAPI.dll,-32003|Desc=@FirewallAPI.dll,-32006|EmbedCtxt=@FirewallAPI.dll,-32002|Edge=TRUE|Defer=App|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "Collab-P2PHost-Out-TCP"="v2.28|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|App=%SystemRoot%\\system32\\p2phost.exe|Name=@FirewallAPI.dll,-32007|Desc=@FirewallAPI.dll,-32010|EmbedCtxt=@FirewallAPI.dll,-32002|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "Collab-P2PHost-WSD-In-UDP"="v2.28|Action=Allow|Active=FALSE|Dir=In|Protocol=17|LPort=3702|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\\system32\\p2phost.exe|Name=@FirewallAPI.dll,-32011|Desc=@FirewallAPI.dll,-32014|EmbedCtxt=@FirewallAPI.dll,-32002|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "Collab-P2PHost-WSD-Out-UDP"="v2.28|Action=Allow|Active=FALSE|Dir=Out|Protocol=17|RPort=3702|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\\system32\\p2phost.exe|Name=@FirewallAPI.dll,-32015|Desc=@FirewallAPI.dll,-32018|EmbedCtxt=@FirewallAPI.dll,-32002|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "MCX-In-TCP"="v2.28|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=554|LPort=8554|LPort=8555|LPort=8556|LPort=8557|LPort=8558|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\\ehome\\ehshell.exe|Name=@FirewallAPI.dll,-30761|Desc=@FirewallAPI.dll,-30764|EmbedCtxt=@FirewallAPI.dll,-30752|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "MCX-Out-TCP"="v2.28|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\\ehome\\ehshell.exe|Name=@FirewallAPI.dll,-30765|Desc=@FirewallAPI.dll,-30768|EmbedCtxt=@FirewallAPI.dll,-30752|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "MCX-In-UDP"="v2.28|Action=Allow|Active=FALSE|Dir=In|Protocol=17|LPort=7777|LPort=7778|LPort=7779|LPort=7780|LPort=7781|LPort=5004|LPort=5005|LPort=50004|LPort=50005|LPort=50006|LPort=50007|LPort=50008|LPort=50009|LPort=50010|LPort=50011|LPort=50012|LPort=50013|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\\ehome\\ehshell.exe|Name=@FirewallAPI.dll,-30801|Desc=@FirewallAPI.dll,-30804|EmbedCtxt=@FirewallAPI.dll,-30752|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "MCX-Out-UDP"="v2.28|Action=Allow|Active=FALSE|Dir=Out|Protocol=17|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\\ehome\\ehshell.exe|Name=@FirewallAPI.dll,-30805|Desc=@FirewallAPI.dll,-30808|EmbedCtxt=@FirewallAPI.dll,-30752|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "MCX-Prov-Out-TCP"="v2.28|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|App=%SystemRoot%\\ehome\\mcx2prov.exe|Name=@FirewallAPI.dll,-30812|Desc=@FirewallAPI.dll,-30813|EmbedCtxt=@FirewallAPI.dll,-30752|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "MCX-McrMgr-Out-TCP"="v2.28|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|App=%SystemRoot%\\ehome\\mcrmgr.exe|Name=@FirewallAPI.dll,-30818|Desc=@FirewallAPI.dll,-30819|EmbedCtxt=@FirewallAPI.dll,-30752|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{ADFCE789-8AFA-469A-9387-586ACD254B0E}"="v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Domain|Profile=Private|Profile=Public|App=D:\\Program Files (x86)\\Steam\\bin\\cef\\cef.win7\\steamwebhelper.exe|Name=Steam Web Helper|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{D1DA1F4D-CC9F-490F-897C-CE98A09BC1C1}"="v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Domain|Profile=Private|Profile=Public|App=D:\\Program Files (x86)\\Steam\\bin\\cef\\cef.win7\\steamwebhelper.exe|Name=Steam Web Helper|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "TCP Query User{E9CEB966-CE1E-4662-BBD8-9B9786C0524B}C:\\program files\\windowsapps\\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\\kodi.exe"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\\program files\\windowsapps\\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\\kodi.exe|Name=Kodi|Desc=Kodi|Defer=User|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "UDP Query User{530833BD-627E-44AF-8A86-0F58ACBD3C0C}C:\\program files\\windowsapps\\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\\kodi.exe"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\\program files\\windowsapps\\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\\kodi.exe|Name=Kodi|Desc=Kodi|Defer=User|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "TCP Query User{7E4786B5-1320-4B0E-807A-B705D52EB9F7}C:\\users\\acer\\appdata\\roaming\\acestream\\engine\\ace_engine.exe"="v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\\users\\acer\\appdata\\roaming\\acestream\\engine\\ace_engine.exe|Name=ace_engine.exe|Desc=ace_engine.exe|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "UDP Query User{186C556D-F192-4B59-9805-DEFFD3402EBA}C:\\users\\acer\\appdata\\roaming\\acestream\\engine\\ace_engine.exe"="v2.10|Action=Block|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\\users\\acer\\appdata\\roaming\\acestream\\engine\\ace_engine.exe|Name=ace_engine.exe|Desc=ace_engine.exe|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1609A420-0FEC-4C20-A9E6-6240322470F9}"="v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\\Program Files (x86)\\Canon\\EOS Utility\\EOSUPNPSV.exe|Name=Canon EOS UPNP Detector|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{4C897E86-BAEE-42C2-AD3A-CE12EBA44B03}"="v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|RA4=LocalSubnet|RA6=LocalSubnet|App=C:\\Program Files (x86)\\Canon\\EOS Utility\\EOSUPNPSV.exe|Name=Canon EOS UPNP Detector|" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Web Companion"="C:\\Program Files (x86)\\Lavasoft\\Web Companion\\Application\\WebCompanion.exe --minimize "