Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspicious Behavior before and after reinstalling Windows 10


  • This topic is locked This topic is locked
4 replies to this topic

#1 winconlin

winconlin

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:16 AM

Posted 12 December 2016 - 02:23 PM

I just ran GMER after reinstalling Windows 10. Before Windows behaved..."strange" mainly suddenly slower.

 

Now I have the following log:

GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2016-12-12 20:19:05
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\00000028 Samsung_SSD_840_Series rev.DXT07B0Q 232,89GB
Running: tku3106o.exe; Driver: C:\Users\matth\AppData\Local\Temp\awrdrpow.sys


---- User code sections - GMER 2.2 ----

.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDeviceCapabilities                                                                                  00007ffe0f951a80 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDeviceCapabilities + 668                                                                            00007ffe0f951d1c 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    ...                                                                                                                                                                                            * 2
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDocumentEvent                                                                                       00007ffe0f95a390 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDocumentPropertySheets                                                                              00007ffe0f95b3c0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDocumentPropertySheets + 684                                                                        00007ffe0f95b66c 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDocumentProperties                                                                                  00007ffe0f95b730 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvAdvancedDocumentProperties                                                                          00007ffe0f95b820 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvConvertDevMode                                                                                      00007ffe0f95b8f0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvConvertDevMode + 440                                                                                00007ffe0f95baa8 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    ...                                                                                                                                                                                            * 3
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DevQueryPrintEx                                                                                        00007ffe0f95d1f0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDriverEvent                                                                                         00007ffe0f95d220 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDriverEvent + 256                                                                                   00007ffe0f95d320 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    ...                                                                                                                                                                                            * 4
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvPrinterEvent                                                                                        00007ffe0f95d710 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvPrinterEvent + 716                                                                                  00007ffe0f95d9dc 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!DrvDevicePropertySheets                                                                                00007ffe0f95e560 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!PrinterProperties                                                                                      00007ffe0f95ec10 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL!PrinterProperties + 196                                                                                00007ffe0f95ecd4 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSWZRD.dll!FaxFreeSendWizardData                                                                                00007ffe0f928be0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSWZRD.dll!FaxFreeSendWizardData + 196                                                                          00007ffe0f928ca4 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSWZRD.dll!FaxSendWizard                                                                                        00007ffe0f929180 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL!DllMain                                                                                               00007ffe10141190 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL!DrvQueryDriverInfo                                                                                    00007ffe101412a0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL!DrvEnableDriver                                                                                       00007ffe10141330 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL!DrvEnableDriver + 224                                                                                 00007ffe10141410 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL!DrvDisableDriver                                                                                      00007ffe10141eb0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\WINDOWS\System32\spoolsv.exe[3064] C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL!DrvDisableDriver + 76                                                                                 00007ffe10141efc 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\Windows\System32\WUDFHost.exe[7252] C:\Windows\System32\drivers\UMDF\WpdFs.dll!DllCanUnloadNow                                                                                              00007ffe069317c0 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\Windows\System32\WUDFHost.exe[7252] C:\Windows\System32\drivers\UMDF\WpdFs.dll!DllGetClassObject                                                                                            00007ffe06931800 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\Windows\System32\WUDFHost.exe[7252] C:\Windows\System32\drivers\UMDF\WpdFs.dll!DllRegisterServer                                                                                            00007ffe06931940 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\Windows\System32\WUDFHost.exe[7252] C:\Windows\System32\drivers\UMDF\WpdFs.dll!DllUnregisterServer                                                                                          00007ffe06931a70 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]
.text    C:\Windows\System32\WUDFHost.exe[7252] C:\Windows\System32\drivers\UMDF\WpdFs.dll!DllUnregisterServer + 160                                                                                    00007ffe06931b10 9 bytes [48, 8B, 04, 24, 64, 48, 89, ...]

---- Threads - GMER 2.2 ----

Thread   C:\WINDOWS\system32\csrss.exe [5064:3632]                                                                                                                                                      ffffbe31063d4330
Thread   C:\WINDOWS\system32\csrss.exe [5064:2536]                                                                                                                                                      ffffbe31063d4330
Thread   C:\WINDOWS\system32\csrss.exe [5064:5032]                                                                                                                                                      ffffbe31063d4330

---- Services - GMER 2.2 ----

Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [AUTO] CDPUserSvc_91996                                                                                        <-- ROOTKIT !!!
Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [MANUAL] DevicesFlowUserSvc_91996                                                                              <-- ROOTKIT !!!
Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [MANUAL] MessagingService_91996                                                                                <-- ROOTKIT !!!
Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [AUTO] OneSyncSvc_91996                                                                                        <-- ROOTKIT !!!
Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [MANUAL] PimIndexMaintenanceSvc_91996                                                                          <-- ROOTKIT !!!
Service  C:\WINDOWS\System32\svchost.exe (*** hidden *** )                                                                                                                                              [MANUAL] UnistoreSvc_91996                                                                                     <-- ROOTKIT !!!
Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [MANUAL] UserDataSvc_91996                                                                                     <-- ROOTKIT !!!
Service  C:\WINDOWS\system32\svchost.exe (*** hidden *** )                                                                                                                                              [MANUAL] WpnUserService_91996                                                                                  <-- ROOTKIT !!!

---- Registry - GMER 2.2 ----

Reg      HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\GSM58E816843009_01_07DC_21+EXP09011_00_07D4_AB+AAA00000_06_07DC_8B^019B19E31958F72AB2842EE3C6A9EBC1@Timestamp              0xB5 0xA8 0x41 0x99 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed                                                                                                              7433983
Reg      HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@GlassSessionId                                                                                                                           1
Reg      HKLM\SYSTEM\CurrentControlSet\Services\BITS@Start                                                                                                                                              2
Reg      HKLM\SYSTEM\CurrentControlSet\Services\BITS\Performance@PerfMMFileName                                                                                                                         Global\MMF_BITSd1948588-7628-4dc9-91f0-c1ee500059de
Reg      HKLM\SYSTEM\CurrentControlSet\Services\BITS                                                                                                                                                    
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996                                                                                                                                        
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@Type                                                                                                                                   224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@Start                                                                                                                                  2
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@ErrorControl                                                                                                                           1
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@ImagePath                                                                                                                              C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@DisplayName                                                                                                                            CDPUserSvc_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@FailureActions                                                                                                                         0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996@Description                                                                                                                            @%SystemRoot%\system32\cdpusersvc.dll,-101
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996\Security                                                                                                                               
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996\Security@Security                                                                                                                      0x01 0x00 0x14 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_91996                                                                                                                                        
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996                                                                                                                                
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@Type                                                                                                                           224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@Start                                                                                                                          3
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@ErrorControl                                                                                                                   1
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@ImagePath                                                                                                                      C:\WINDOWS\system32\svchost.exe -k DevicesFlow
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@DisplayName                                                                                                                    DevicesFlow_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@FailureActions                                                                                                                 0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996@Description                                                                                                                    @%SystemRoot%\system32\DevicesFlowBroker.dll,-104
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996\Security                                                                                                                       
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996\Security@Security                                                                                                              0x01 0x00 0x04 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\DevicesFlowUserSvc_91996                                                                                                                                
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996                                                                                                                                  
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@Type                                                                                                                             224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@Start                                                                                                                            3
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@ErrorControl                                                                                                                     0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@ImagePath                                                                                                                        C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@DisplayName                                                                                                                      MessagingService_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@FailureActions                                                                                                                   0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996@Description                                                                                                                      @%SystemRoot%\system32\MessagingService.dll,-101
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\Security                                                                                                                         
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\Security@Security                                                                                                                0x01 0x00 0x14 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo                                                                                                                      
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo\0                                                                                                                    
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo\0@Type                                                                                                               7
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo\0@Action                                                                                                             1
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo\0@Guid                                                                                                               0x16 0x28 0x7A 0x2D ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo\0@Data0                                                                                                              0x75 0x18 0xBC 0xA3 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996\TriggerInfo\0@DataType0                                                                                                          1
Reg      HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_91996                                                                                                                                  
Reg      HKLM\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies@                                                                                                               
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996                                                                                                                                        
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@Type                                                                                                                                   224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@Start                                                                                                                                  2
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@ErrorControl                                                                                                                           0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@ImagePath                                                                                                                              C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@DisplayName                                                                                                                            Synchronisierungshost_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@FailureActions                                                                                                                         0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996@Description                                                                                                                            @%SystemRoot%\system32\APHostRes.dll,-10001
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996\Security                                                                                                                               
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996\Security@Security                                                                                                                      0x01 0x00 0x04 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_91996                                                                                                                                        
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996                                                                                                                            
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@Type                                                                                                                       224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@Start                                                                                                                      3
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@ErrorControl                                                                                                               0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@ImagePath                                                                                                                  C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@DisplayName                                                                                                                Kontaktdaten_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@FailureActions                                                                                                             0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996@Description                                                                                                                @%SystemRoot%\system32\UserDataAccessRes.dll,-15000
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996\Security                                                                                                                   
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996\Security@Security                                                                                                          0x01 0x00 0x04 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_91996                                                                                                                            
Reg      HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch                                                                                                                               6
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996                                                                                                                                       
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@Type                                                                                                                                  224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@Start                                                                                                                                 3
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@ErrorControl                                                                                                                          0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@ImagePath                                                                                                                             C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@DisplayName                                                                                                                           Benutzerdatenspeicher _91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@FailureActions                                                                                                                        0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996@Description                                                                                                                           @%SystemRoot%\system32\UserDataAccessRes.dll,-10002
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996\Security                                                                                                                              
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996\Security@Security                                                                                                                     0x01 0x00 0x04 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_91996                                                                                                                                       
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996                                                                                                                                       
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@Type                                                                                                                                  224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@Start                                                                                                                                 3
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@ErrorControl                                                                                                                          0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@ImagePath                                                                                                                             C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@DisplayName                                                                                                                           Benutzerdatenzugriff_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@FailureActions                                                                                                                        0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996@Description                                                                                                                           @%SystemRoot%\system32\UserDataAccessRes.dll,-14000
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996\Security                                                                                                                              
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996\Security@Security                                                                                                                     0x01 0x00 0x04 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_91996                                                                                                                                       
Reg      HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated                                                                                                            0xE1 0xBD 0x1B 0xB6 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh                                                                                                                 0xE1 0x25 0xE0 0x17 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow                                                                                                                  0xE1 0x55 0x57 0x54 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996                                                                                                                                    
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@Type                                                                                                                               224
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@Start                                                                                                                              3
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@ErrorControl                                                                                                                       0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@ImagePath                                                                                                                          C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@DisplayName                                                                                                                        Windows-Pushbenachrichtigungs-Benutzerdienst_91996
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@FailureActions                                                                                                                     0x80 0x51 0x01 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996@Description                                                                                                                        @%SystemRoot%\system32\WpnUserService.dll,-2
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996\Security                                                                                                                           
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996\Security@Security                                                                                                                  0x01 0x00 0x04 0x80 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_91996                                                                                                                                    
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent@StartColorMenu                                                                                                                  -6725888
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent@AccentColorMenu                                                                                                                 -2777792
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.zunemusic_8wekyb3d8bbwe                                                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.net.native.runtime.1.3_8wekyb3d8bbwe                                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-windows.immersivecontrolpanel_cw5n1h2txyewy-0                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-startpage-internet-explorer                                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windows.shellexperiencehost_cw5n1h2txyewy                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-servicepoweredqsa-internet-explorer                                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windowsstore_8wekyb3d8bbwe                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.aad.brokerplugin_cw5n1h2txyewy-0                                                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windowscommunicationsapps_8wekyb3d8bbwe                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-searchsuggestion-internet-explorer                                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.xboxidentityprovider_8wekyb3d8bbwe-0                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-trackingprotection-internet-explorer                                                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.microsoftedge_8wekyb3d8bbwe                                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-imejpn                                                                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-spellingdictionary                                                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.net.native.framework.1.3_8wekyb3d8bbwe                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-formsuggestaskuser-internet-explorer                                                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-windowcolorization                                                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windows.shellexperiencehost_cw5n1h2txyewy                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windows.cloudexperiencehost_cw5n1h2txyewy                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-trackingprotectionlists-internet-explorer                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.windows.shellexperiencehost_cw5n1h2txyewy-0                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-personalization                                                                                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windows.contentdeliverymanager_cw5n1h2txyewy                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.xboxidentityprovider_8wekyb3d8bbwe                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-popupblockerallowlist-internet-explorer                                                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.desktopappinstaller_8wekyb3d8bbwe                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-privacyadvanced-internet-explorer                                                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-osk                                                                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-favoriteurls-internet-explorer                                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-tabroaming-internet-explorer                                                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-explorer                                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windows.contentdeliverymanager_cw5n1h2txyewy                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.windowscamera_8wekyb3d8bbwe-0                                                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.microsoftedge_8wekyb3d8bbwe                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-taskbarpersonalization                                                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-picturepasswordpicture                                                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windows.cortana_cw5n1h2txyewy                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windows.photos_8wekyb3d8bbwe                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-openwith                                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-wininet-internet-explorer                                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-thirdpartycookies-internet-explorer                                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.windows.cloudexperiencehost_cw5n1h2txyewy-0                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windows.cortana_cw5n1h2txyewy                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-trackingprotectionexceptions-internet-explorer                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-slideshow                                                                                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.windowscamera_8wekyb3d8bbwe                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.desktopappinstaller_8wekyb3d8bbwe                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.vclibs.140.00_8wekyb3d8bbwe                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-moimechs                                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-imekor                                                                                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.net.native.framework.1.3_8wekyb3d8bbwe                                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.xboxidentityprovider_8wekyb3d8bbwe                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windowscamera_8wekyb3d8bbwe                                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-emojimfu                                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windowsstore_8wekyb3d8bbwe                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.vclibs.140.00_8wekyb3d8bbwe                                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-tabbedbrowsing-internet-explorer                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.aad.brokerplugin_cw5n1h2txyewy                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.windows.contentdeliverymanager_cw5n1h2txyewy-15                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-windows.immersivecontrolpanel_cw5n1h2txyewy                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.zunemusic_8wekyb3d8bbwe                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-fullscreenallowsites-internet-explorer                                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.windows.cortana_cw5n1h2txyewy-0                                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.bingweather_8wekyb3d8bbwe                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windows.photos_8wekyb3d8bbwe                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-windows.immersivecontrolpanel_cw5n1h2txyewy                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.net.native.runtime.1.3_8wekyb3d8bbwe                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.windows.photos_8wekyb3d8bbwe-0                                                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.desktopappinstaller_8wekyb3d8bbwe-0                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-formsuggest-internet-explorer                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.aad.brokerplugin_cw5n1h2txyewy                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windows.cloudexperiencehost_cw5n1h2txyewy                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-flipahead-internet-explorer                                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-microsoft.windowscommunicationsapps_8wekyb3d8bbwe                                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windows-backstack                                                                                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@packagestate-microsoft.microsoftedge_8wekyb3d8bbwe-0                                                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@windowspackagesettings-notifications-microsoft.bingweather_8wekyb3d8bbwe                                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\DirtyRemoteCollections@browsersettings-typedurls-internet-explorer                                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsBandwidthBucketCounter                                                                                           0
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsRequestBucketCounter                                                                                             0
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsRequestBucketDrainTime                                                                                       0x0C 0xD9 0x43 0xCE ...
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsLargeRequestBucketDrainTime                                                                                  0x0C 0xD9 0x43 0xCE ...
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherBandwidthBucketCounter                                                                                             203
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherRequestBucketCounter                                                                                               89
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastOtherRequestBucketDrainTime                                                                                         0x0C 0xD9 0x43 0xCE ...
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalBandwidthBucketCounter                                                                                            203
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalRequestBucketCounter                                                                                              89
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastGlobalRequestBucketDrainTime                                                                                        0x0C 0xD9 0x43 0xCE ...
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@RoamingSyncToken                                                                                                        LM%3d63617165917893%3bID%3d3E06458E009A7EC2!107%3bLR%3d63617165687580%3bEP%3d13%3bSI%3d57%3bSO%3d0%3bPI%3d49
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastUploadTime                                                                                                          0x5C 0xB9 0xAB 0xBE ...
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@RenewCollectionsInterestDirty                                                                                        110
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@LastRenewCollectionsInterest                                                                                         0xFE 0xB1 0x3C 0xCE ...
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData@PendingOperations                                                                                                          278
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\domainsuggestion-internet-explorer@AttemptedOperations                                           5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\favoriteurls-internet-explorer@IsLocalReplicaDirty                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\favoriteurls-internet-explorer@PendingOperations                                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\favoriteurls-internet-explorer@AttemptedOperations                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\flipahead-internet-explorer@IsLocalReplicaDirty                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\flipahead-internet-explorer@PendingOperations                                                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\flipahead-internet-explorer@AttemptedOperations                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\formsuggest-internet-explorer@IsLocalReplicaDirty                                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\formsuggest-internet-explorer@PendingOperations                                                  8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\formsuggest-internet-explorer@AttemptedOperations                                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\formsuggestaskuser-internet-explorer@IsLocalReplicaDirty                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\formsuggestaskuser-internet-explorer@PendingOperations                                           8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\formsuggestaskuser-internet-explorer@AttemptedOperations                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\fullscreenallowsites-internet-explorer@IsLocalReplicaDirty                                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\fullscreenallowsites-internet-explorer@PendingOperations                                         8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\fullscreenallowsites-internet-explorer@AttemptedOperations                                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\popupblockerallowlist-internet-explorer@IsLocalReplicaDirty                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\popupblockerallowlist-internet-explorer@PendingOperations                                        8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\popupblockerallowlist-internet-explorer@AttemptedOperations                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\privacyadvanced-internet-explorer@IsLocalReplicaDirty                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\privacyadvanced-internet-explorer@PendingOperations                                              8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\privacyadvanced-internet-explorer@AttemptedOperations                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\searchsuggestion-internet-explorer@IsLocalReplicaDirty                                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\searchsuggestion-internet-explorer@PendingOperations                                             8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\searchsuggestion-internet-explorer@AttemptedOperations                                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\servicepoweredqsa-internet-explorer@IsLocalReplicaDirty                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\servicepoweredqsa-internet-explorer@PendingOperations                                            8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\servicepoweredqsa-internet-explorer@AttemptedOperations                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\startpage-internet-explorer@IsLocalReplicaDirty                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\startpage-internet-explorer@PendingOperations                                                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\startpage-internet-explorer@AttemptedOperations                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\tabbedbrowsing-internet-explorer@IsLocalReplicaDirty                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\tabbedbrowsing-internet-explorer@PendingOperations                                               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\tabbedbrowsing-internet-explorer@AttemptedOperations                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\tabroaming-internet-explorer@IsLocalReplicaDirty                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\tabroaming-internet-explorer@PendingOperations                                                   8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\tabroaming-internet-explorer@AttemptedOperations                                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\thirdpartycookies-internet-explorer@IsLocalReplicaDirty                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\thirdpartycookies-internet-explorer@PendingOperations                                            8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\thirdpartycookies-internet-explorer@AttemptedOperations                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotection-internet-explorer@IsLocalReplicaDirty                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotection-internet-explorer@PendingOperations                                           8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotection-internet-explorer@AttemptedOperations                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotectionexceptions-internet-explorer@IsLocalReplicaDirty                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotectionexceptions-internet-explorer@PendingOperations                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotectionexceptions-internet-explorer@AttemptedOperations                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotectionlists-internet-explorer@IsLocalReplicaDirty                                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotectionlists-internet-explorer@PendingOperations                                      8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\trackingprotectionlists-internet-explorer@AttemptedOperations                                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\typedurls-internet-explorer@IsLocalReplicaDirty                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\typedurls-internet-explorer@PendingOperations                                                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\typedurls-internet-explorer@AttemptedOperations                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\wininet-internet-explorer@PendingOperations                                                      8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\browsersettings\wininet-internet-explorer@AttemptedOperations                                                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.aad.brokerplugin_cw5n1h2txyewy-0@IsLocalReplicaDirty                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.aad.brokerplugin_cw5n1h2txyewy-0@PendingOperations                                        8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.aad.brokerplugin_cw5n1h2txyewy-0@AttemptedOperations                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.desktopappinstaller_8wekyb3d8bbwe-0@IsLocalReplicaDirty                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.desktopappinstaller_8wekyb3d8bbwe-0@PendingOperations                                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.desktopappinstaller_8wekyb3d8bbwe-0@AttemptedOperations                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.microsoftedge_8wekyb3d8bbwe-0@IsLocalReplicaDirty                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.microsoftedge_8wekyb3d8bbwe-0@PendingOperations                                           8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.microsoftedge_8wekyb3d8bbwe-0@AttemptedOperations                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy-0@IsLocalReplicaDirty                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy-0@PendingOperations                             8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy-0@AttemptedOperations                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy-15@IsLocalReplicaDirty                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy-15@PendingOperations                         8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy-15@AttemptedOperations                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.cortana_cw5n1h2txyewy-0@IsLocalReplicaDirty                                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.cortana_cw5n1h2txyewy-0@PendingOperations                                         8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.cortana_cw5n1h2txyewy-0@AttemptedOperations                                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.photos_8wekyb3d8bbwe-0@IsLocalReplicaDirty                                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.photos_8wekyb3d8bbwe-0@PendingOperations                                          8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.photos_8wekyb3d8bbwe-0@AttemptedOperations                                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.shellexperiencehost_cw5n1h2txyewy-0@IsLocalReplicaDirty                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.shellexperiencehost_cw5n1h2txyewy-0@PendingOperations                             8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windows.shellexperiencehost_cw5n1h2txyewy-0@AttemptedOperations                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windowscamera_8wekyb3d8bbwe-0@IsLocalReplicaDirty                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windowscamera_8wekyb3d8bbwe-0@PendingOperations                                           8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windowscamera_8wekyb3d8bbwe-0@AttemptedOperations                                         1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windowscommunicationsapps_8wekyb3d8bbwe-0@AttemptedOperations                             5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.windowsstore_8wekyb3d8bbwe-0@AttemptedOperations                                          5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.xboxidentityprovider_8wekyb3d8bbwe-0@IsLocalReplicaDirty                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.xboxidentityprovider_8wekyb3d8bbwe-0@PendingOperations                                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.xboxidentityprovider_8wekyb3d8bbwe-0@AttemptedOperations                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\microsoft.zunemusic_8wekyb3d8bbwe-0@AttemptedOperations                                             5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\windows.immersivecontrolpanel_cw5n1h2txyewy-0@IsLocalReplicaDirty                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\windows.immersivecontrolpanel_cw5n1h2txyewy-0@PendingOperations                                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\windows.immersivecontrolpanel_cw5n1h2txyewy-0@AttemptedOperations                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\accessibility@AttemptedOperations                                                                        5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\backstack@IsLocalReplicaDirty                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\backstack@PendingOperations                                                                              8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\backstack@AttemptedOperations                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\commandpromptwin10@PendingOperations                                                                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\commandpromptwin10@AttemptedOperations                                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\credentials@IsLocalReplicaDirty                                                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\credentials@PendingOperations                                                                            8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\credentials@AttemptedOperations                                                                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\emojimfu@IsLocalReplicaDirty                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\emojimfu@PendingOperations                                                                               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\emojimfu@AttemptedOperations                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\explorer@IsLocalReplicaDirty                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\explorer@PendingOperations                                                                               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\explorer@AttemptedOperations                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\homegroup@IsLocalReplicaDirty                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\homegroup@PendingOperations                                                                              8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\homegroup@AttemptedOperations                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\imejpn@IsLocalReplicaDirty                                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\imejpn@PendingOperations                                                                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\imejpn@AttemptedOperations                                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\imekor@IsLocalReplicaDirty                                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\imekor@PendingOperations                                                                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\imekor@AttemptedOperations                                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\inputpersonalization@AttemptedOperations                                                                 5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\inputsettings@AttemptedOperations                                                                        5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\language@AttemptedOperations                                                                             5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\moimechs@IsLocalReplicaDirty                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\moimechs@PendingOperations                                                                               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\moimechs@AttemptedOperations                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\mouse@AttemptedOperations                                                                                5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\narrator@AttemptedOperations                                                                             5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\openwith@IsLocalReplicaDirty                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\openwith@PendingOperations                                                                               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\openwith@AttemptedOperations                                                                             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\osk@IsLocalReplicaDirty                                                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\osk@PendingOperations                                                                                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\osk@AttemptedOperations                                                                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\personalization@IsLocalReplicaDirty                                                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\personalization@PendingOperations                                                                        8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\personalization@AttemptedOperations                                                                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\picturepasswordpicture@IsLocalReplicaDirty                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\picturepasswordpicture@PendingOperations                                                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\picturepasswordpicture@AttemptedOperations                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\screenmagnifier@AttemptedOperations                                                                      5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\slideshow@IsLocalReplicaDirty                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\slideshow@PendingOperations                                                                              8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\slideshow@AttemptedOperations                                                                            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\spellingdictionary@IsLocalReplicaDirty                                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\spellingdictionary@PendingOperations                                                                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\spellingdictionary@AttemptedOperations                                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\startpersonalization@AttemptedOperations                                                                 5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\taskbar@AttemptedOperations                                                                              5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\taskbarpersonalization@IsLocalReplicaDirty                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\taskbarpersonalization@PendingOperations                                                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\taskbarpersonalization@AttemptedOperations                                                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\theme@AttemptedOperations                                                                                5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\usertile@AttemptedOperations                                                                             5
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\windowcolorization@IsLocalReplicaDirty                                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\windowcolorization@PendingOperations                                                                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\windowcolorization@AttemptedOperations                                                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.aad.brokerplugin_cw5n1h2txyewy@IsLocalReplicaDirty                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.aad.brokerplugin_cw5n1h2txyewy@PendingOperations                                8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.aad.brokerplugin_cw5n1h2txyewy@AttemptedOperations                              1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.bingweather_8wekyb3d8bbwe@IsLocalReplicaDirty                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.bingweather_8wekyb3d8bbwe@PendingOperations                                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.bingweather_8wekyb3d8bbwe@AttemptedOperations                                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.desktopappinstaller_8wekyb3d8bbwe@IsLocalReplicaDirty                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.desktopappinstaller_8wekyb3d8bbwe@PendingOperations                             8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.desktopappinstaller_8wekyb3d8bbwe@AttemptedOperations                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.microsoftedge_8wekyb3d8bbwe@IsLocalReplicaDirty                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.microsoftedge_8wekyb3d8bbwe@PendingOperations                                   8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.microsoftedge_8wekyb3d8bbwe@AttemptedOperations                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.net.native.framework.1.3_8wekyb3d8bbwe@IsLocalReplicaDirty                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.net.native.framework.1.3_8wekyb3d8bbwe@PendingOperations                        8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.net.native.framework.1.3_8wekyb3d8bbwe@AttemptedOperations                      1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.net.native.runtime.1.3_8wekyb3d8bbwe@IsLocalReplicaDirty                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.net.native.runtime.1.3_8wekyb3d8bbwe@PendingOperations                          8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.net.native.runtime.1.3_8wekyb3d8bbwe@AttemptedOperations                        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.vclibs.140.00_8wekyb3d8bbwe@IsLocalReplicaDirty                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.vclibs.140.00_8wekyb3d8bbwe@PendingOperations                                   8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.vclibs.140.00_8wekyb3d8bbwe@AttemptedOperations                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy@IsLocalReplicaDirty                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy@PendingOperations                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.cloudexperiencehost_cw5n1h2txyewy@AttemptedOperations                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy@IsLocalReplicaDirty                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy@PendingOperations                  8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy@AttemptedOperations                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.cortana_cw5n1h2txyewy@IsLocalReplicaDirty                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.cortana_cw5n1h2txyewy@PendingOperations                                 8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.cortana_cw5n1h2txyewy@AttemptedOperations                               1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.photos_8wekyb3d8bbwe@IsLocalReplicaDirty                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.photos_8wekyb3d8bbwe@PendingOperations                                  8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.photos_8wekyb3d8bbwe@AttemptedOperations                                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.shellexperiencehost_cw5n1h2txyewy@IsLocalReplicaDirty                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.shellexperiencehost_cw5n1h2txyewy@PendingOperations                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windows.shellexperiencehost_cw5n1h2txyewy@AttemptedOperations                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowscamera_8wekyb3d8bbwe@IsLocalReplicaDirty                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowscamera_8wekyb3d8bbwe@PendingOperations                                   8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowscamera_8wekyb3d8bbwe@AttemptedOperations                                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowscommunicationsapps_8wekyb3d8bbwe@IsLocalReplicaDirty                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowscommunicationsapps_8wekyb3d8bbwe@PendingOperations                       8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowscommunicationsapps_8wekyb3d8bbwe@AttemptedOperations                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowsstore_8wekyb3d8bbwe@IsLocalReplicaDirty                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowsstore_8wekyb3d8bbwe@PendingOperations                                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.windowsstore_8wekyb3d8bbwe@AttemptedOperations                                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.xboxidentityprovider_8wekyb3d8bbwe@IsLocalReplicaDirty                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.xboxidentityprovider_8wekyb3d8bbwe@PendingOperations                            8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.xboxidentityprovider_8wekyb3d8bbwe@AttemptedOperations                          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.zunemusic_8wekyb3d8bbwe@IsLocalReplicaDirty                                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.zunemusic_8wekyb3d8bbwe@PendingOperations                                       8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\microsoft.zunemusic_8wekyb3d8bbwe@AttemptedOperations                                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.aad.brokerplugin_cw5n1h2txyewy@IsLocalReplicaDirty                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.aad.brokerplugin_cw5n1h2txyewy@PendingOperations                  8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.aad.brokerplugin_cw5n1h2txyewy@AttemptedOperations                1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.bingweather_8wekyb3d8bbwe@IsLocalReplicaDirty                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.bingweather_8wekyb3d8bbwe@PendingOperations                       8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.bingweather_8wekyb3d8bbwe@AttemptedOperations                     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.desktopappinstaller_8wekyb3d8bbwe@IsLocalReplicaDirty             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.desktopappinstaller_8wekyb3d8bbwe@PendingOperations               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.desktopappinstaller_8wekyb3d8bbwe@AttemptedOperations             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.microsoftedge_8wekyb3d8bbwe@IsLocalReplicaDirty                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.microsoftedge_8wekyb3d8bbwe@PendingOperations                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.microsoftedge_8wekyb3d8bbwe@AttemptedOperations                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.net.native.framework.1.3_8wekyb3d8bbwe@IsLocalReplicaDirty        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.net.native.framework.1.3_8wekyb3d8bbwe@PendingOperations          8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.net.native.framework.1.3_8wekyb3d8bbwe@AttemptedOperations        1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.net.native.runtime.1.3_8wekyb3d8bbwe@IsLocalReplicaDirty          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.net.native.runtime.1.3_8wekyb3d8bbwe@PendingOperations            8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.net.native.runtime.1.3_8wekyb3d8bbwe@AttemptedOperations          1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.vclibs.140.00_8wekyb3d8bbwe@IsLocalReplicaDirty                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.vclibs.140.00_8wekyb3d8bbwe@PendingOperations                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.vclibs.140.00_8wekyb3d8bbwe@AttemptedOperations                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.cloudexperiencehost_cw5n1h2txyewy@IsLocalReplicaDirty     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.cloudexperiencehost_cw5n1h2txyewy@PendingOperations       8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.cloudexperiencehost_cw5n1h2txyewy@AttemptedOperations     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.contentdeliverymanager_cw5n1h2txyewy@IsLocalReplicaDirty  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.contentdeliverymanager_cw5n1h2txyewy@PendingOperations    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.contentdeliverymanager_cw5n1h2txyewy@AttemptedOperations  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.cortana_cw5n1h2txyewy@IsLocalReplicaDirty                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.cortana_cw5n1h2txyewy@PendingOperations                   8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.cortana_cw5n1h2txyewy@AttemptedOperations                 1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.photos_8wekyb3d8bbwe@IsLocalReplicaDirty                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.photos_8wekyb3d8bbwe@PendingOperations                    8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.photos_8wekyb3d8bbwe@AttemptedOperations                  1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.shellexperiencehost_cw5n1h2txyewy@IsLocalReplicaDirty     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.shellexperiencehost_cw5n1h2txyewy@PendingOperations       8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windows.shellexperiencehost_cw5n1h2txyewy@AttemptedOperations     1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowscamera_8wekyb3d8bbwe@IsLocalReplicaDirty                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowscamera_8wekyb3d8bbwe@PendingOperations                     8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowscamera_8wekyb3d8bbwe@AttemptedOperations                   1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowscommunicationsapps_8wekyb3d8bbwe@IsLocalReplicaDirty       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowscommunicationsapps_8wekyb3d8bbwe@PendingOperations         8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowscommunicationsapps_8wekyb3d8bbwe@AttemptedOperations       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowsstore_8wekyb3d8bbwe@IsLocalReplicaDirty                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowsstore_8wekyb3d8bbwe@PendingOperations                      8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.windowsstore_8wekyb3d8bbwe@AttemptedOperations                    1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.xboxidentityprovider_8wekyb3d8bbwe@IsLocalReplicaDirty            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.xboxidentityprovider_8wekyb3d8bbwe@PendingOperations              8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.xboxidentityprovider_8wekyb3d8bbwe@AttemptedOperations            1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.zunemusic_8wekyb3d8bbwe@IsLocalReplicaDirty                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.zunemusic_8wekyb3d8bbwe@PendingOperations                         8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-microsoft.zunemusic_8wekyb3d8bbwe@AttemptedOperations                       1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-windows.immersivecontrolpanel_cw5n1h2txyewy@IsLocalReplicaDirty             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-windows.immersivecontrolpanel_cw5n1h2txyewy@PendingOperations               8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\notifications-windows.immersivecontrolpanel_cw5n1h2txyewy@AttemptedOperations             1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\windows.immersivecontrolpanel_cw5n1h2txyewy@IsLocalReplicaDirty                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\windows.immersivecontrolpanel_cw5n1h2txyewy@PendingOperations                             8
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windowspackagesettings\windows.immersivecontrolpanel_cw5n1h2txyewy@AttemptedOperations                           1
Reg      HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\History\Colors@ColorHistory0                                                                                                             13405993
Reg      HKCU\Software\Microsoft\Windows\DWM@ColorizationColor                                                                                                                                          4234709
Reg      HKCU\Software\Microsoft\Windows\DWM@ColorizationColorBalance                                                                                                                                   -13
Reg      HKCU\Software\Microsoft\Windows\DWM@ColorizationAfterglow                                                                                                                                      4234709
Reg      HKCU\Software\Microsoft\Windows\DWM@ColorizationBlurBalance                                                                                                                                    103
Reg      HKCU\Software\Microsoft\Windows\DWM@EnableWindowColorization                                                                                                                                   1
Reg      HKCU\Software\Microsoft\Windows\DWM@AccentColor                                                                                                                                                -2777792
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3g2                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3g2\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3g2\UserChoice@Hash                                                                                                                 +Njbashi6ZE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3g2\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp\UserChoice@Hash                                                                                                                 JZ5L0FQPTpg=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp2                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp2\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp2\UserChoice@Hash                                                                                                                laXnjo90Wy0=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gp2\UserChoice@ProgId                                                                                                              WMP11.AssocFile.3G2
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gpp                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gpp\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gpp\UserChoice@Hash                                                                                                                kiLAWtvFBKY=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.3gpp\UserChoice@ProgId                                                                                                              AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.aac                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.aac\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.aac\UserChoice@Hash                                                                                                                 hOC49bjZi/8=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.aac\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adt                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adt\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adt\UserChoice@Hash                                                                                                                 i1fFvJ6KTgY=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adt\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adts                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adts\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adts\UserChoice@Hash                                                                                                                jUHXUSD8Glc=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.adts\UserChoice@ProgId                                                                                                              AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.amr                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.amr\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.amr\UserChoice@Hash                                                                                                                 Ftzcc6apLOg=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.amr\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.arw                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.arw\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.arw\UserChoice@Hash                                                                                                                 4AkaeS2Wwk4=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.arw\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.avi                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.avi\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.avi\UserChoice@Hash                                                                                                                 lyQoWTs8TBI=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.avi\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.bmp                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.bmp\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.bmp\UserChoice@Hash                                                                                                                 i7FlMsHxJYk=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.bmp\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.cr2                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.cr2\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.cr2\UserChoice@Hash                                                                                                                 b4pJvjvqyBE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.cr2\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.crw                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.crw\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.crw\UserChoice@Hash                                                                                                                 Mu7WX+0MEb4=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.crw\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.dib                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.dib\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.dib\UserChoice@Hash                                                                                                                 jUWn8KtGdUQ=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.dib\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.erf                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.erf\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.erf\UserChoice@Hash                                                                                                                 5qFAJOcnzmw=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.erf\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.flac                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.flac\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.flac\UserChoice@Hash                                                                                                                aLSOpeS3Tds=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.flac\UserChoice@ProgId                                                                                                              AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.gif                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.gif\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.gif\UserChoice@Hash                                                                                                                 z6z6B1u478g=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.gif\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.htm\UserChoice@Hash                                                                                                                 +8ygvSSLBKY=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.htm\UserChoice@ProgId                                                                                                               AppX4hxtad77fbk3jkkeerkrm0ze94wjf3s9
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.html\UserChoice@Hash                                                                                                                78jhpapvLKM=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.html\UserChoice@ProgId                                                                                                              AppX4hxtad77fbk3jkkeerkrm0ze94wjf3s9
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jfif                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jfif\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jfif\UserChoice@Hash                                                                                                                uxxXn7TiNYY=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jfif\UserChoice@ProgId                                                                                                              AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpe                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpe\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpe\UserChoice@Hash                                                                                                                 bvwr94kzgoY=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpe\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpeg                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpeg\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpeg\UserChoice@Hash                                                                                                                YJOOZYP6wnw=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpeg\UserChoice@ProgId                                                                                                              AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpg                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpg\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpg\UserChoice@Hash                                                                                                                 7i29xmIcF04=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jpg\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jxr                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jxr\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jxr\UserChoice@Hash                                                                                                                 nGxhL+fqES4=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.jxr\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.kdc                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.kdc\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.kdc\UserChoice@Hash                                                                                                                 R6W8rzauhqU=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.kdc\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2t                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2t\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2t\UserChoice@Hash                                                                                                                 uaqdbYK6i10=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2t\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2ts                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2ts\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2ts\UserChoice@Hash                                                                                                                huZvNJPcNSM=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m2ts\UserChoice@ProgId                                                                                                              AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m3u                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m3u\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m3u\UserChoice@Hash                                                                                                                 zksCr3/5BKk=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m3u\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4a                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4a\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4a\UserChoice@Hash                                                                                                                 UqiCBHYw5cc=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4a\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4r                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4r\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4r\UserChoice@Hash                                                                                                                 VByvB1ecwVc=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4r\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4v                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4v\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4v\UserChoice@Hash                                                                                                                 KEkum40Iaws=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.m4v\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mkv                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mkv\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mkv\UserChoice@Hash                                                                                                                 ZN4s7Ho8I54=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mkv\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mod                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mod\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mod\UserChoice@Hash                                                                                                                 HBWq2NdTtfQ=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mod\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mov                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mov\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mov\UserChoice@Hash                                                                                                                 N1SRz+NOSxE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mov\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MP2                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MP2\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MP2\UserChoice@Hash                                                                                                                 yY+pf/iD4eo=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MP2\UserChoice@ProgId                                                                                                               WMP11.AssocFile.MP3
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp3                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp3\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp3\UserChoice@Hash                                                                                                                 vav24WOscMo=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp3\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4\UserChoice@Hash                                                                                                                 nnfvWJ3VLgw=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4v                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4v\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4v\UserChoice@Hash                                                                                                                8gpSrfb3Z94=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mp4v\UserChoice@ProgId                                                                                                              AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpa                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpa\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpa\UserChoice@Hash                                                                                                                 GrxNped3BXQ=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpa\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MPE                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MPE\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MPE\UserChoice@Hash                                                                                                                 kjvJDRPANRg=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.MPE\UserChoice@ProgId                                                                                                               WMP11.AssocFile.MPE
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpeg                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpeg\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpeg\UserChoice@Hash                                                                                                                1+vPTYV4PwU=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpeg\UserChoice@ProgId                                                                                                              WMP11.AssocFile.mpeg
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpg                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpg\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpg\UserChoice@Hash                                                                                                                 ZeYkcWKADDY=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpg\UserChoice@ProgId                                                                                                               WMP11.AssocFile.mpg
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpv2                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpv2\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpv2\UserChoice@Hash                                                                                                                XSwLzGdWFao=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mpv2\UserChoice@ProgId                                                                                                              AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mrw                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mrw\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mrw\UserChoice@Hash                                                                                                                 +Yti34dagI0=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mrw\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mts                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mts\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mts\UserChoice@Hash                                                                                                                 rqfFiraGr+U=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.mts\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nef                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nef\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nef\UserChoice@Hash                                                                                                                 ZZ6GAHzf5kE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nef\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nrw                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nrw\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nrw\UserChoice@Hash                                                                                                                 Zhve1oHnhOM=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.nrw\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.orf                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.orf\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.orf\UserChoice@Hash                                                                                                                 VU2BxPdWzdM=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.orf\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.oxps                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.oxps\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.oxps\UserChoice@Hash                                                                                                                t7oBppb3t8I=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.oxps\UserChoice@ProgId                                                                                                              Windows.XPSReachViewer
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pdf                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pdf\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pdf\UserChoice@Hash                                                                                                                 4UTa6ujLZu0=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pdf\UserChoice@ProgId                                                                                                               AppXd4nrz8ff68srnhf9t5a8sbjyar1cr723
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pef                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pef\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pef\UserChoice@Hash                                                                                                                 0va0o77s66A=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.pef\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.png                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.png\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.png\UserChoice@Hash                                                                                                                 0tItc/CQAhc=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.png\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raf                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raf\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raf\UserChoice@Hash                                                                                                                 KMSxWErN59k=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raf\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raw                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raw\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raw\UserChoice@Hash                                                                                                                 Rv+l2dgQYEg=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.raw\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rw2                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rw2\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rw2\UserChoice@Hash                                                                                                                 CXxbzMBtsIE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rw2\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rwl                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rwl\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rwl\UserChoice@Hash                                                                                                                 v1ag1G3I1dk=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.rwl\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.sr2                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.sr2\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.sr2\UserChoice@Hash                                                                                                                 oh2cJHO3mIc=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.sr2\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.srw                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.srw\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.srw\UserChoice@Hash                                                                                                                 3nNUrcRmLS4=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.srw\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tif                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tif\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tif\UserChoice@Hash                                                                                                                 bawApQo5qvU=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tif\UserChoice@ProgId                                                                                                               PhotoViewer.FileAssoc.Tiff
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tiff                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tiff\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tiff\UserChoice@Hash                                                                                                                9IUpX6DAycs=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.tiff\UserChoice@ProgId                                                                                                              PhotoViewer.FileAssoc.Tiff
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TS                                                                                                                                  
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TS\UserChoice                                                                                                                       
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TS\UserChoice@Hash                                                                                                                  rxRx+AUNZCQ=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TS\UserChoice@ProgId                                                                                                                AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TTS                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TTS\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TTS\UserChoice@Hash                                                                                                                 24L7u30mykw=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.TTS\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.txt                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.txt\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.txt\UserChoice@Hash                                                                                                                 lCjYgHC/qXE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.txt\UserChoice@ProgId                                                                                                               txtfile
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.url                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.url\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.url\UserChoice@Hash                                                                                                                 0ZC58IHHc70=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.url\UserChoice@ProgId                                                                                                               IE.AssocFile.URL
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wav                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wav\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wav\UserChoice@Hash                                                                                                                 TXKBwBABYsM=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wav\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wdp                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wdp\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wdp\UserChoice@Hash                                                                                                                 i7hpaUEQnj4=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wdp\UserChoice@ProgId                                                                                                               AppX43hnxtbyyps62jhe9sqpdzxn1790zetc
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.website                                                                                                                             
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.website\UserChoice                                                                                                                  
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.website\UserChoice@Hash                                                                                                             Sgg9EKFSI2g=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.website\UserChoice@ProgId                                                                                                           IE.AssocFile.WEBSITE
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wm                                                                                                                                  
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wm\UserChoice                                                                                                                       
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wm\UserChoice@Hash                                                                                                                  ETIZkSsVO0A=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wm\UserChoice@ProgId                                                                                                                AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wma                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wma\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wma\UserChoice@Hash                                                                                                                 Lgwn1Bz4VQw=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wma\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wmv                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wmv\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wmv\UserChoice@Hash                                                                                                                 +6dxewXnyBE=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.wmv\UserChoice@ProgId                                                                                                               AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.WPL                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.WPL\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.WPL\UserChoice@Hash                                                                                                                 Rm++XJT8uwc=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.WPL\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xps                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xps\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xps\UserChoice@Hash                                                                                                                 +f9k7iSyuSk=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xps\UserChoice@ProgId                                                                                                               Windows.XPSReachViewer
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xvid                                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xvid\UserChoice                                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xvid\UserChoice@Hash                                                                                                                IxglaRM13b4=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xvid\UserChoice@ProgId                                                                                                              AppX6eg8h5sxqq90pv53845wmnbewywdqq5h
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.zpl                                                                                                                                 
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.zpl\UserChoice                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.zpl\UserChoice@Hash                                                                                                                 /IN3AtmHEpk=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.zpl\UserChoice@ProgId                                                                                                               AppXqj98qxeaynz6dv4459ayz6bnqxbyaqcs
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\bingmaps                                                                                                                      
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\bingmaps\UserChoice                                                                                                           
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\bingmaps\UserChoice@Hash                                                                                                      z72odScV/js=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\bingmaps\UserChoice@ProgId                                                                                                    AppXp9gkwccvk6fa6yyfq3tmsk8ws2nprk1p
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\http\UserChoice@Hash                                                                                                          TvDao6Cz5+Q=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\http\UserChoice@ProgId                                                                                                        AppXq0fevzme2pys62n3e0fbqa7peapykr8v
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\https\UserChoice@Hash                                                                                                         BzIbg2uMDD8=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\https\UserChoice@ProgId                                                                                                       AppX90nv6nhay5n6a98fnetv7tpk64pp35es
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsmusic                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsmusic\UserChoice                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsmusic\UserChoice@Hash                                                                                                iFOi7u15Pz0=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsmusic\UserChoice@ProgId                                                                                              AppXtggqqtcfspt6ks3fjzyfppwc05yxwtwy
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsvideo                                                                                                                
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsvideo\UserChoice                                                                                                     
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsvideo\UserChoice@Hash                                                                                                6gATKtTTruM=
Reg      HKCU\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\mswindowsvideo\UserChoice@ProgId                                                                                              AppX6w6n4f8xch1s3vzwf3af6bfe88qhxbza

---- EOF - GMER 2.2 ----

I am somewhat concerned.



BC AdBot (Login to Remove)

 


#2 RayS

RayS

  • Malware Study Hall Senior
  • 2,131 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:04:16 AM

Posted 17 December 2016 - 08:43 AM

Hello winconlin,

My name is Ray and I'll be assisting you with your issue. Please give me a day or two to review your logs and prepare a reply. Since I'm still a trainee, all my posts have to be reviewed by my instructor prior to being posted to make sure that you receive the best assistance possible.

Thank you for your understanding, I'll be with you shortly!

RayS


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#3 RayS

RayS

  • Malware Study Hall Senior
  • 2,131 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:04:16 AM

Posted 19 December 2016 - 05:26 PM

Hello winconlin, and welcome to Bleeping Computer.

Please call me "Ray".

I will be helping you with your computer problem. If you would permit me to call you by your first name, please tell it to me.

Before we get started

  • Please do not attach any log files to your replies unless specifically requested. Instead, please copy and paste the entire text of the logs into the body of your reply. Use separate consecutive posts if that's easier for you.
  • Please do not try to fix anything without being advised to do so.
  • Always read my entire message before you begin to follow my instructions.
  • It may be helpful for you to print my instructions for easy reference.
  • Perform my instructions in the order as given.
  • Any fixes I provide are for this specific problem on this machine only.
  • Removing malware is hazardous. I will not knowingly advise actions that will damage your computer, but it is impossible to guarantee the safety of your system. It may even become necessary to re-format and re-install your operating system.

 

 

 

Scan using Farbar Recovery Scan Tool (FRST)

  • Please download the 64-bit version of FRST to your desktop from https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/.
  • Launch the tool by double-clicking on FRST64.exe.
  • Don't change any of the preset options. Just click Scan.
  • When FRST is done generating its reports, it will create them as FRST.txt and Addition.txt.
  • Copy and paste the entire contents of both reports into the body of your reply.

For an illustrated guide, see step :step6: of Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help.


In your next reply...

  • Copy and paste the contents of FRST.txt and Addition.txt into the body of your message.
  • Expand on the sequence of events that led you to seek our help. What symptoms do you see? Include verbatim copies of any error messages.
  • What is the current state of your PC?

Thank you,

Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#4 RayS

RayS

  • Malware Study Hall Senior
  • 2,131 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:04:16 AM

Posted 23 December 2016 - 07:16 AM

Hi winconlin,

3 Day Bump

It has been 3 days since my last post.

  • Do you still need help with this? If not, please let me know as soon as possible. Other people are requesting my help.
  • If you will be away for an extended period, please let me know in advance.
  • If you have not replied within 48 hours I will assume you have abandoned the Topic and it will be closed.

Thank you,

Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:16 AM

Posted 26 December 2016 - 10:07 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users