Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Kb-ribaki.org and zodiac-game.info problem


  • This topic is locked This topic is locked
9 replies to this topic

#1 TuvTuv

TuvTuv

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:50 PM

Posted 13 December 2016 - 04:45 AM

Hi everyone,

 

I have this problem that whenever I start my computer the zodiac-game.info website pops up in Google Chrome full of advertisements. I have tried running AdwCleaner and manually deleted the kb-ribaki.org from the registry but after a while it comes back. I hope you can help me fix this problem, thanks in advance.

Attached Files


Edited by TuvTuv, 13 December 2016 - 04:46 AM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:50 PM

Posted 13 December 2016 - 11:00 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

This application can be problematic.
Popcorn Time (HKLM-x32\...\Popcorn Time_is1) (Version: 5.5.1.2 - Popcorn Time) <==== ATTENTION
https://mic.com/articles/162004/popcorn-time-virus-how-a-new-ransomware-came-about-and-what-to-do-if-it-happens-to-you#.ts8hYkVnT

If any problems remove it via the Control Panel > Programs > Programs and features. Your call.
----

Copy the text IN THE QUOTE BOX below to notepad. Save it as fixme.reg to your desktop.
Be sure the "Save as" type is set to "all files" Once you have saved Right click the .reg file and allow it to merge with the registry.

Windows Registry Editor Version 5.00

[HKEY_USERS\HKU\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"HenriV"=-


DO NOT RESTART THE COMPUTER JUST NOW.


You can delete the fixme.reg file when done.
===

Run this fix.

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.


Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

Winlogon\Notify\ScCertProp: wlnotify.dll [X]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Chrome Media Router) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-12]
CHR Extension: (Chrome Media Router) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-13]
CHR HKLM-x32\...\Chrome\Extension: [ckjefchnfjhjfedoccjbhjpbncimppeg] - hxxps://clients2.google.com/service/update2/crx
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
Task: {72B98616-D81C-4334-865B-A8E9C580A8BC} - System32\Tasks\HenriV => /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v HenriV /t REG_SZ /d "explorer.exe hxxp://kb-ribaki.org" <==== ATTENTION
Task: {C67DCBE7-DC5C-42F6-BAA2-7AB8129D66C3} - System32\Tasks\DX => hxxp://kb-ribaki.org
Task: {0A77E657-B39D-4EEA-8A5D-13E7E534A167} - System32\Tasks\GetNetworkInfo => C:\Users\HenriV\AppData\Local\Temp\setdebug.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [346]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [346]
AlternateDataStreams: C:\Users\HenriV:Heroes & Generals [38]
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [346]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [346]
AlternateDataStreams: C:\Users\HenriV\Application Data:NT [40]
AlternateDataStreams: C:\Users\HenriV\Application Data:NT2 [346]
AlternateDataStreams: C:\Users\HenriV\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\HenriV\AppData\Roaming:NT2 [346]
C:\Users\HenriV\AppData\Local\Temp\setdebug.exe

Reboot:

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.

Please post the fixlog.txt and llet me know what problem persists with this computer.


p.s.
For your security remove this old version of Java via the Control Panel > Programs > Programs and Features.
Java SE Development Kit 8 Update 73 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180730}) (Version: 8.0.730.2 - Oracle Corporation)

===

#3 TuvTuv

TuvTuv
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:50 PM

Posted 13 December 2016 - 12:17 PM

Thank you for your reply

 

I am not able to merge the fixme.reg file with the registry as I receive the following error : "Cannot import C:\Users\HenriV\Desktop\fixme.reg: Error accesing the registry" .



#4 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:50 PM

Posted 13 December 2016 - 01:27 PM

Add the line Windows Registry Editor Version 5.00 to your .reg file.

Copy all the text in the Code box.

#5 TuvTuv

TuvTuv
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:50 PM

Posted 13 December 2016 - 01:42 PM

That is what I did, the line is there but it still gives me the same error for some reason.



#6 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:50 PM

Posted 13 December 2016 - 02:24 PM

Run the Farbar fix and post the Fixlog for my review.

Before you post your logs execute this.

Lets see what we can find in the Registry.

Please run the Farbar Recovery Scan Tool. Enter HenriV in the Search Box.
Click the Search Registry button, post the content of the Search.txt file in your next reply.

#7 TuvTuv

TuvTuv
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:50 PM

Posted 13 December 2016 - 02:57 PM

Alright, here is the fixlog.txt file

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 07-12-2016

Ran by HenriV (13-12-2016 20:45:37) Run:1
Running from C:\Users\HenriV\Downloads
Loaded Profiles: HenriV (Available Profiles: HenriV)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Chrome Media Router) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-12]
CHR Extension: (Chrome Media Router) - C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-13]
CHR HKLM-x32\...\Chrome\Extension: [ckjefchnfjhjfedoccjbhjpbncimppeg] - hxxps://clients2.google.com/service/update2/crx
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
Task: {72B98616-D81C-4334-865B-A8E9C580A8BC} - System32\Tasks\HenriV => /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v HenriV /t REG_SZ /d "explorer.exe hxxp://kb-ribaki.org" <==== ATTENTION
Task: {C67DCBE7-DC5C-42F6-BAA2-7AB8129D66C3} - System32\Tasks\DX => hxxp://kb-ribaki.org
Task: {0A77E657-B39D-4EEA-8A5D-13E7E534A167} - System32\Tasks\GetNetworkInfo => C:\Users\HenriV\AppData\Local\Temp\setdebug.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [346]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [346]
AlternateDataStreams: C:\Users\HenriV:Heroes & Generals [38]
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [346]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [346]
AlternateDataStreams: C:\Users\HenriV\Application Data:NT [40]
AlternateDataStreams: C:\Users\HenriV\Application Data:NT2 [346]
AlternateDataStreams: C:\Users\HenriV\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\HenriV\AppData\Roaming:NT2 [346]
C:\Users\HenriV\AppData\Local\Temp\setdebug.exe
 
Reboot:
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp" => key removed successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\HenriV\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ckjefchnfjhjfedoccjbhjpbncimppeg" => key removed successfully
dbx => service removed successfully
FairplayKD => service removed successfully
WinRing0_1_2_0 => service removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{72B98616-D81C-4334-865B-A8E9C580A8BC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B98616-D81C-4334-865B-A8E9C580A8BC}" => key removed successfully
C:\Windows\System32\Tasks\HenriV => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HenriV" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C67DCBE7-DC5C-42F6-BAA2-7AB8129D66C3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C67DCBE7-DC5C-42F6-BAA2-7AB8129D66C3}" => key removed successfully
C:\Windows\System32\Tasks\DX => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DX" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0A77E657-B39D-4EEA-8A5D-13E7E534A167}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0A77E657-B39D-4EEA-8A5D-13E7E534A167}" => key removed successfully
C:\Windows\System32\Tasks\GetNetworkInfo => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GetNetworkInfo" => key removed successfully
C:\ProgramData => ":NT" ADS removed successfully.
C:\ProgramData => ":NT2" ADS removed successfully.
"C:\Users\All Users" => ":NT" ADS not found.
"C:\Users\All Users" => ":NT2" ADS not found.
C:\Users\HenriV => ":Heroes & Generals" ADS removed successfully.
"C:\ProgramData\Application Data" => ":NT" ADS not found.
"C:\ProgramData\Application Data" => ":NT2" ADS not found.
C:\ProgramData\MTA San Andreas All => ":NT" ADS removed successfully.
C:\ProgramData\MTA San Andreas All => ":NT2" ADS removed successfully.
C:\Users\HenriV\Application Data => ":NT" ADS removed successfully.
C:\Users\HenriV\Application Data => ":NT2" ADS removed successfully.
"C:\Users\HenriV\AppData\Roaming" => ":NT" ADS not found.
"C:\Users\HenriV\AppData\Roaming" => ":NT2" ADS not found.
"C:\Users\HenriV\AppData\Local\Temp\setdebug.exe" => not found.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 29954139 B
Java, Flash, Steam htmlcache => 119469728 B
Windows/system/drivers => 4833022 B
Edge => 0 B
Chrome => 457538495 B
Firefox => 5018403 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58558540 B
systemprofile32 => 139320 B
LocalService => 66228 B
NetworkService => 1115082 B
HenriV => 60711214 B
UpdatusUser => 0 B
 
RecycleBin => 703 B
EmptyTemp: => 711.3 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 20:46:23 ====

 

and here is the Search.txt file 

 

 

Farbar Recovery Scan Tool (x64) Version: 07-12-2016

Ran by HenriV (13-12-2016 20:54:21)
Running from C:\Users\HenriV\Downloads
Boot Mode: Normal
 
================== Search Registry: "HenriV" ===========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21EE4A31AE32173319EEFE3BD6FDFFE3\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2013\12.0.21005.1\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21EE4A31AE32173319EEFE3BD6FDFFE3\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2013\12.0.21005.1\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\22BEFC8F7E2A1793E9ADB411DEFE1C58\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2013\12.0.21005.1\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\22BEFC8F7E2A1793E9ADB411DEFE1C58\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2013\12.0.21005.1\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2468110110F\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jre1.8.0_111_x64\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2468110110F\SourceList\Net]
"1"="C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jre1.8.0_111_x64\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4F4A3A46297B6D117AA8000B0D817003\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jdk1.8.0_73_x64\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4F4A3A46297B6D117AA8000B0D817003\SourceList\Net]
"1"="C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jdk1.8.0_73_x64\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5951D032AD753394C8E4737579BE7B1E\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\{6C926261-9316-495D-B829-32FDAF6B76FB}\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5951D032AD753394C8E4737579BE7B1E\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\{6C926261-9316-495D-B829-32FDAF6B76FB}\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2013\12.0.21005.1\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2013\12.0.21005.1\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2013\12.0.21005.1\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2013\12.0.21005.1\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2012\11.0.61030.0\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2012\11.0.61030.0\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A6D790106CE8D6743A63B252693C1957\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\Temp1_CardReader_Alcor_Win7_Win8_Z3614262248.zip\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A6D790106CE8D6743A63B252693C1957\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\Temp1_CardReader_Alcor_Win7_Win8_Z3614262248.zip\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\IXP001.TMP\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\IXP001.TMP\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C025571B2A687A53689168CD7369889B\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2012\11.0.61030.0\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C025571B2A687A53689168CD7369889B\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2012\11.0.61030.0\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\c1c4f01781cc94c4c8fb1542c0981a2a\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\IXP000.TMP\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\c1c4f01781cc94c4c8fb1542c0981a2a\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\IXP000.TMP\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2012\11.0.61030.0\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2012\11.0.61030.0\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\DC8A59DBF9D1DA5389A1E3975220E6BB\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2012\11.0.61030.0\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\DC8A59DBF9D1DA5389A1E3975220E6BB\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2012\11.0.61030.0\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jre1.8.0_111\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\SourceList\Net]
"1"="C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jre1.8.0_111\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{493DB4BD-8FE5-4DC6-845F-814A10B3C924}\1.0\0\win32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{493DB4BD-8FE5-4DC6-845F-814A10B3C924}\1.0\HELPDIR]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0D3DB963-A4ED-4E83-987B-93B447EB671C}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5F4B69EF-1A7C-4FDD-8F61-31ACD03A95B3}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7F411237-8CB3-4812-B934-D1CF7F60403B}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9FEA9E8E-50CD-4551-BE0E-1AFFAB772D99}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B403A89C-2CA8-43AD-911E-BC8429BCB418}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C5C6830E-806F-4F28-863B-C01B1B41AB98}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Temp\{8C662C9B-EAEC-413F-B76F-CD0F3CE6ABE1}\{7D916FA5-DAE9-4A25-B089-655C70EAF607}\InstallHelper.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Disc Soft\DAEMON Tools Lite\DevicesState]
"dev0"="C:\Users\HenriV\Desktop\Mängud\Trials.Fusion-CODEX\codex-trials.fusion.iso"
[HKEY_LOCAL_MACHINE\SOFTWARE\Disc Soft\DAEMON Tools Lite\DevicesState]
"dev1"="C:\Users\HenriV\Desktop\Mängud\Midtown2.iso"
[HKEY_LOCAL_MACHINE\SOFTWARE\Disc Soft\DAEMON Tools Lite\DevicesState]
"dev2"="C:\Users\HenriV\Desktop\Mängud\Hidden And dangerous 2  + Sabre Squadron (Expansion Pack)\Hidden And dangerous 2\DISK2\DISK2.iso"
[HKEY_LOCAL_MACHINE\SOFTWARE\Disc Soft\DAEMON Tools Lite\DevicesState]
"dev3"="C:\Users\HenriV\Desktop\Mängud\Hidden And dangerous 2  + Sabre Squadron (Expansion Pack)\Hidden And dangerous 2\DISK3\DISK3.iso"
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Wireless\Folders\HenriV-PC]
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Wireless\Folders\HenriV-PC\HenriV]
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Wireless\Folders\HenriV-PC\HenriV]
"Path"="C:\Users\HenriV\AppData\Roaming\Intel\Wireless\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Wireless\Folders\HenriV-PC\HENRIV-PC]
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Wireless\Folders\WORKGROUP\HENRIV-PC]
[HKEY_LOCAL_MACHINE\SOFTWARE\Intel\Wireless\Folders\WORKGROUP\HENRIV-PC$]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI]
"LastLoggedOnSAMUser"="HenriV-PC\HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI]
"LastLoggedOnUser"=".\HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData\1]
"LoggedOnSAMUser"="HenriV-PC\HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\SessionData\1]
"LoggedOnUsername"=".\HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2685811~31bf3856ad364e35~amd64~~6.1.1.11]
"InstallLocation"="\\?\C:\Users\HenriV\AppData\Local\Temp\70E43764-D2B6-43D0-983E-A625F4E8091D\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_3_for_KB2685811~31bf3856ad364e35~amd64~~6.1.1.11]
"InstallLocation"="\\?\C:\Users\HenriV\AppData\Local\Temp\70E43764-D2B6-43D0-983E-A625F4E8091D\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2685811_SP1~31bf3856ad364e35~amd64~~6.1.1.11]
"InstallLocation"="\\?\C:\Users\HenriV\AppData\Local\Temp\70E43764-D2B6-43D0-983E-A625F4E8091D\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2685811~31bf3856ad364e35~amd64~~6.1.1.11]
"InstallLocation"="\\?\C:\Users\HenriV\AppData\Local\Temp\70E43764-D2B6-43D0-983E-A625F4E8091D\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-1604467813-914689706-2192655327-1000\{F1BD4E91-E7E6-4AA2-83CA-A8632E40CD52}]
"ConfigApplicationPath"="C:\Users\HenriV\Desktop\Mängud\Mafia"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\S-1-5-21-1604467813-914689706-2192655327-1000\{F1BD4E91-E7E6-4AA2-83CA-A8632E40CD52}]
"AppExePath"="C:\Users\HenriV\Desktop\Mängud\Mafia\Game.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\HomeGroup\HME\Members]
"94-DB-C9-B1-56-04"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\HomeGroup\HME\Members]
"94-DB-C9-B2-48-34"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\HomeGroup\HME\Members]
"00-00-00-00-00-00"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Users\HenriV\AppData\Roaming\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Users\HenriV\AppData\Roaming\Microsoft\Installer\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1604467813-914689706-2192655327-1000\Products\40B16698646C21446B3DE5910FF2F173\InstallProperties]
"RegOwner"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1604467813-914689706-2192655327-1000\Products\40B16698646C21446B3DE5910FF2F173\InstallProperties]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\_is6BC\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability]
"LastComputerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID HWMonitor_is1]
"Inno Setup: User"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Git_is1]
"Inno Setup: User"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sublime Text 2_is1]
"Inno Setup: User"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{230D1595-57DA-4933-8C4E-375797EBB7E1}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\{6C926261-9316-495D-B829-32FDAF6B76FB}\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F64180111F0}]
"InstallSource"="C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jre1.8.0_111_x64\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37B8F9C7-03FB-3253-8781-2517C99D7C00}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2012\11.0.61030.0\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{64A3A4F4-B792-11D6-A78A-00B0D0180730}]
"InstallSource"="C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jdk1.8.0_73_x64\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{929FBD26-9020-399B-9A7A-751D61F0B942}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2013\12.0.21005.1\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2013\12.0.21005.1\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x64\VCRedist_x64\MVC+2012\11.0.61030.0\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Devices\00-00-00-00-00-00]
"FriendlyName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Devices\94-DB-C9-B1-56-04]
"FriendlyName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Devices\94-DB-C9-B2-48-34]
"FriendlyName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Servers\3A5D4EE8-18F6-462F-B768-8E6DFC173038]
"FriendlyName"="HENRIV-PC: HenriV:"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\UDNRenderers\526B9E9A-8A81-4AFD-AC40-C902D853B69C]
"FriendlyName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion]
"RegisteredOwner"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer\DsSpooler]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2016\DsSpooler]
"uNCName"="\\HenriV-PC\Send To OneNote 2016"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2016\DsSpooler]
"serverName"="HenriV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2016\DsSpooler]
"shortServerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1604467813-914689706-2192655327-1000]
"ProfileImagePath"="C:\Users\HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6]
"URL"="file:///C:\Users\HenriV\AppData\*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7]
"URL"="file:///C:\Users\HenriV\Favorites\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6]
"URL"="file:///C:\Users\HenriV\AppData\*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7]
"URL"="file:///C:\Users\HenriV\Favorites\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\6]
"Path"="file:///C:\Users\HenriV\AppData\*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GOG.com\GOGEMPIREEARTH2]
"SAVEGAMEFOLDER"="C:\Users\HenriV\Documents\Empire Earth II"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GOG.com\GOGEMPIREEARTH2ADDON]
"SAVEGAMEFOLDER"="C:\Users\HenriV\Documents\Empire Earth II The Art of Supremacy"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-1604467813-914689706-2192655327-1000]
"SharedLibraryPath"="C:\Users\HenriV\AppData\Local\Microsoft\Media Player"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-1604467813-914689706-2192655327-1000]
"DisplayName"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219\KB2151757]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219\KB2467173]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219\KB982573]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219\SP1\KB2565063]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219\KB2151757]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219\KB2467173]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219\KB982573]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Updates\Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219\SP1\KB2565063]
"InstalledBy"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AmUStor]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\Temp1_CardReader_Alcor_Win7_Win8_Z3614262248.zip\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AmUStor]
"RegOwner"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Empire Earth II Gold Edition_is1]
"Inno Setup: User"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PokerStars.eu]
"InstallSource"="C:\Users\HenriV\Downloads\PokerStarsInstallEU.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PokerStars.eu]
"QLLink"="C:\Users\HenriV\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PokerStars.eu.lnk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Razer Cortex_is1]
"Inno Setup: User"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{01097D6A-8EC6-476D-A336-2B2596C39175}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\Temp1_CardReader_Alcor_Win7_Win8_Z3614262248.zip\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2013\12.0.21005.1\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3108C217-BE83-42E4-AE9E-A56A2A92E549}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\Temp1_LAN_Atheros_Win8_64_Z2107.zip\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}]
"InstallSource"="C:\Users\HenriV\AppData\LocalLow\Oracle\Java\jre1.8.0_111\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\IXP000.TMP\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7299052b-02a4-4627-81f2-1818da5d550d}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\IXP001.TMP\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7D916FA5-DAE9-4A25-B089-655C70EAF607}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\Temp1_WLAN_Atheros_Win7_64_Z920504.zip\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{89661B04-C646-4412-B6D3-5E19F02F1F37}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\_is6BC\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2012\11.0.61030.0\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2012\11.0.61030.0\Minimum\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}]
"RegOwner"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\Temp1_Audio_Realtek_Win8_64_Z6016710.zip\Realtek\ALC269_ALC663_ALC680_ALC277_ALC282\Vista32_Vista64_Win7_32_Win7_64_Win8_32_Win8_64_6.0.1.6710\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}]
"InstallSource"="C:\Users\HenriV\AppData\Local\Temp\VCRedist\x86\VCRedist_x86\MVC+2013\12.0.21005.1\Additional\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion]
"RegisteredOwner"="HenriV"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer\DsSpooler]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2016\DsSpooler]
"uNCName"="\\HenriV-PC\Send To OneNote 2016"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2016\DsSpooler]
"serverName"="HenriV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2016\DsSpooler]
"shortServerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1604467813-914689706-2192655327-1000]
"ProfileImagePath"="C:\Users\HenriV"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName]
"ComputerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName]
"ComputerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Microsoft XPS Document Writer\DsSpooler]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Send To OneNote 2016\DsSpooler]
"uNCName"="\\HenriV-PC\Send To OneNote 2016"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Send To OneNote 2016\DsSpooler]
"serverName"="HenriV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Send To OneNote 2016\DsSpooler]
"shortServerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist]
"\Registry\User\S-1-5-21-1604467813-914689706-2192655327-1000"="\Device\HarddiskVolume6\Users\HenriV\NTUSER.DAT"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist]
"\Registry\User\S-1-5-21-1604467813-914689706-2192655327-1000_Classes"="\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Microsoft\Windows\UsrClass.dat"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BtFilter\LE]
"name"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\HomeGroupProvider\ServiceData]
"LocalJoiningUser"="HenriV"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\HomeGroupProvider\ServiceData]
"Owner"="HenriV"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\HomeGroupProvider\ServiceData]
"OwnerMachineName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\HomeGroupProvider\ServiceData\Members\a3371e1969f15e37514747a49098d3ad8a20ca34.HomeGroupClassifier]
"ComputerName"="HENRIV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5F994DC3-9562-4242-B19B-0B64DA13EF88}"="v2.10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{9CF7F1A6-55F5-4259-89C8-FF3938365FB2}"="v2.10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters]
"NV Hostname"="HenriV-PC"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters]
"Hostname"="HenriV-PC"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows Media\WMSDK\General]
"ComputerName"="HENRIV-PC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Control Panel\Desktop]
"Wallpaper"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\Annots\cAnnots\cAnnot]
"tauthor"="HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/GT--Lecture--11--Wolfvision.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c10]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/FirstOrderLogic.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c11]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/Uncertainty.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c12]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/Artificial Intelligence A Modern Approach (3rd Edition).pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c13]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/Planning.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c14]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/InferenceFirstOrderLogic.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c15]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/GamePlaying.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c16]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/InformedSearchAlgorithms.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c17]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/ProblemSolvingAndSearch.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c18]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/RT 2016 Exercises series1.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c19]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/Prentice.Hall.Artificial.Intelligence.A.Modern.Approach.3rd.Edition.Dec.2009.ISBN.0136042597.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c2]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/GT--Lecture--08--Wolfvision.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c20]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter16.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c21]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter14b.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c22]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter14a.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c23]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter13.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c24]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter11.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c25]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter09.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c26]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter08.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c27]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter07.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c28]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter06.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c29]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter05.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c3]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/GT--Lecture--04--Wolfvision (1).pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c30]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter03.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c31]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/chapter04.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c32]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Machine Learning/01 ML - Linear Regression, Logistic Regression, Artificial Neural Networks.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c33]
"tDIText"="/C/Users/HenriV/Desktop/Korter/Rental agreement for Mr. Henri Viigimae - Statensingel 201 Object 4 Maastricht - 10291.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c4]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/GT--Lecture--02+03--Wolfvision (1).pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c5]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/GT--Lecture--01--Wolfvision (1).pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c6]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/sheet_01.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c7]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Graph theory/GrTh5_Ch1.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c8]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/ConstraintSatisfactionProblems.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c9]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/LogicalAgents.pdf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c1]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Reasoning techinques/"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c2]
"tDIText"="/C/Users/HenriV/Desktop/Henri TA/YEAR 2/Machine Learning/"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c3]
"tDIText"="/C/Users/HenriV/Desktop/Korter/"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Atheros\VistaAddOn\BIP\Server]
"ShellFolder"="C:\Users\HenriV\Documents\Bluetooth Folder"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Atheros\VistaAddOn\FTP\Server]
"ShellFolder"="C:\Users\HenriV\Documents\Bluetooth Folder"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Bitcoin\Bitcoin-Qt]
"strDataDir"="C:\Users\HenriV\AppData\Roaming\Bitcoin"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Estonian ID Card\qdigidocclient]
"lastPath"="C:/Users/HenriV/Desktop"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"Username"="HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\GDIPlus]
"FontCachePath"="C:\Users\HenriV\AppData\Local"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Installer\Products\40B16698646C21446B3DE5910FF2F173\SourceList]
"LastUsedSource"="n;1;C:\Users\HenriV\AppData\Local\Temp\_is6BC\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Installer\Products\40B16698646C21446B3DE5910FF2F173\SourceList\Net]
"1"="C:\Users\HenriV\AppData\Local\Temp\_is6BC\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\Desktop\General]
"WallpaperSource"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"Path"="C:\Users\HenriV\Favorites\Links\Suggested Sites.url"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"Path"="C:\Users\HenriV\Favorites\Links\Web Slice Gallery.url"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1159240f_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Mängud\Mafia\Game.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1973bfef_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Midtown Madness 2\midtown2.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e01789c_0]
""="{0.0.0.00000000}.{22b94113-cc61-46e9-ad63-20f315e39364}
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29f15d48_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Tor Browser\Browser\firefox.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\3da0008_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-O15BS.tmp\setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\430e4d77_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\EBU5E43.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\51da6e89_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-J29JL.tmp\Setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\70a96d8c_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-JPS10.tmp\setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\717c47e_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Trials2\trials2.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\7a1973ba_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-QL9S3.tmp\Setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\92feb661_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Trials2\trials2_low2.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\9573de58_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Mängud\Harry Potter and the Philosopher's Stone\System\HP.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\95dbb8ae_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-R2C90.tmp\setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\9f9fe75d_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\EBUA688.EXE%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\aa1e0601_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-L7FD6.tmp\setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\c89729c4_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\AppData\Local\Temp\is-0HMP1.tmp\Setup.tmp%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\d91c76f_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Mängud\hl.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\eb3e6ff2_0]
""="{0.0.0.00000000}.{7e8c8da0-1995-4446-9e3f-f81c1e079817}
\Device\HarddiskVolume6\Users\HenriV\Desktop\Zzagor\cracktro.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\$RECYCLE.BIN"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\Favorites"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\LocalLow"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Cookies"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Microsoft\Windows\History"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Microsoft\Windows\INetCache\Low"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Microsoft\Feeds"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Temp\Low"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\LowRegistry\IEShims\NormalizedPaths]
"C:\Users\HenriV\AppData\Local\Microsoft\PlayReady"=""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch]
"User Favorites Path"="file:///C:\Users\HenriV\Favorites\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"FaviconPath"="C:\Users\HenriV\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"NTLogoPath"="C:\Users\HenriV\AppData\LocalLow\Microsoft\Internet Explorer\Services\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\Suggested Sites]
"SlicePath"="C:\Users\HenriV\Favorites\Links\Suggested Sites.url"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Internet Explorer\Suggested Sites]
"LogFileFolder"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences]
"ObfuscatedSyncPlaylistsPath"="C:\Users\HenriV\AppData\Local\Microsoft\Media Player\Sync Playlists\et-EE\0000B26D"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences]
"TrackFoldersDirectories0"="C:\Users\HenriV\Music"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences]
"TrackFoldersDirectories1"="C:\Users\HenriV\Pictures"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences]
"TrackFoldersDirectories2"="C:\Users\HenriV\Videos"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences\HME\LastSharedFolders]
"Folders0"="C:\Users\HenriV\Music"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences\HME\LastSharedFolders]
"Folders1"="C:\Users\HenriV\Pictures"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\MediaPlayer\Preferences\HME\LastSharedFolders]
"Folders2"="C:\Users\HenriV\Videos"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\odc-xml-resource=OneDriveSyncClientUpsell&lcid=1061&syslcid=1061&uilcid=1061&ver=15\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\cdn.odc.officeapps.live.com\odc-xml-resource=OneDriveSyncClientUpsell&lcid=1061&syslcid=1061&uilcid=1061&ver=150"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt01794867.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt01794867.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02790978.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02790978.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02803622.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02803622.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02805140.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02805140.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835051.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835051.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835056.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835056.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835057.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835057.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835058.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835058.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835063.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835063.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835064.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835064.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835065.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02835065.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02843595.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02843595.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02895215.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02895215.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02901164.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02901164.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02904833.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02904833.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02911900.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02911900.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02919302.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02919302.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02919339.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02919339.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02923949.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt02923949.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03456617.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03456617.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03457705.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03457705.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03457711.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03457711.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03457715.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03457715.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03703996.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03703996.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03704116.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03704116.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03704176.png\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\clienttemplates.content.office.net\support-templates-et-ee-mt03704176.png0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4797&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4797&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4805&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4805&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4815&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4815&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4823&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4823&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4833&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4833&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4841&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4841&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4859&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4859&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\Internet\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4867&crev=3\0]
"FilePath"="C:\Users\HenriV\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1061&syslcid=1061&uilcid=1061&build=15.0.4867&crev=30"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Common\OfficeStart\Web\Templates\3b20fa74a56f2c04_LiveId\1061;1061;1061\Word\DownloadedTemplates]
"http://clienttemplates.content.office.net/support/templates/et-ee/tp02923949.cab"="C:\Users\HenriV\AppData\Roaming\Microsoft\Templates\Tere tulemast kasutama Wordi!.dotx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Registration\HENRIV-PC]
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 0]
"File Path"="C:\Users\HenriV\Desktop\Henri TA\Oppelaen_esildis.doc"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 1]
"File Path"="C:\Users\HenriV\AppData\Local\Temp\Oppelaen_esildis.doc"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 2]
"File Path"="C:\Users\HenriV\Downloads\CV_Henri Viigimäe.docx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 3]
"File Path"="C:\Users\HenriV\Desktop\Henri TA\YEAR 2\Databases\Database Summary.docx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 4]
"File Path"="C:\Users\HenriV\Downloads\avaldus_6ppelaenu_maksegraafik.doc"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 6]
"File Path"="C:\Users\HenriV\Desktop\Midtown Madness 2\trouble.rtf"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 7]
"File Path"="C:\Users\HenriV\Desktop\RTA\Iseloomustused.docx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\15.0\Word\Reading Locations\Document 8]
"File Path"="C:\Users\HenriV\Desktop\RTA\10_11_12A_parimad palad.docx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Common\OfficeStart\Web\Templates\Anonymous\1061;1061;1061\Excel\DownloadedTemplates]
"http://clienttemplates.content.office.net/support/templates/et-ee/tp10000137.cab"="C:\Users\HenriV\AppData\Roaming\Microsoft\Templates\Tere tulemast kasutama Excelit!.xltx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Common\OfficeStart\Web\Templates\Anonymous\1061;1061;1061\Excel\DownloadedTemplates]
"http://clienttemplates.content.office.net/support/templates/et-ee/tp10000140.cab"="C:\Users\HenriV\AppData\Roaming\Microsoft\Templates\Kalendri ülevaated.xltm"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Common\OfficeStart\Web\Templates\Anonymous\1061;1061;1061\Excel\DownloadedTemplates]
"http://clienttemplates.content.office.net/support/templates/et-ee/tp10000138.cab"="C:\Users\HenriV\AppData\Roaming\Microsoft\Templates\Rahavoo analüüs.xltm"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Common\OfficeStart\Web\Templates\Anonymous\1061;1061;1061\Excel\DownloadedTemplates]
"http://clienttemplates.content.office.net/support/templates/et-ee/tp10000139.cab"="C:\Users\HenriV\AppData\Roaming\Microsoft\Templates\Aktsiasümbolite võrdlus.xltm"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Excel\File MRU]
"Item 1"="[F00000000][T01D24C64F613D0A0][O00000000]*C:\Users\HenriV\Downloads\HjMVmalenoor06.xls"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Excel\File MRU]
"Item 2"="[F00000000][T01D23AB231AC97B0][O00000000]*C:\Users\HenriV\Downloads\groepsindeling 2-1 block 2.2 16-17.xls"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Excel\Place MRU]
"Item 1"="[F00000000][T01D24C64F613A990][O00000000]*C:\Users\HenriV\Downloads\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\OneNote\General]
"LastMyDocumentsPathUsed"="C:\Users\HenriV\Documents\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\OneNote\Place MRU]
"Item 1"="[F00000000][T01D25257791753D0][O00000000]*C:\Users\HenriV\Documents\OneNote'i märkmikud\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\OneNote\RecentNotebooks]
"Item 1"="[F00000000][T01D25257791D2030][O00000000]*C:\Users\HenriV\Documents\OneNote'i märkmikud\Minu märkmik"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\PowerPoint\File MRU]
"Item 1"="[F00000000][T01D24D63A4E09B51][O00000000]*C:\Users\HenriV\Desktop\Henri TA\YEAR 2\Machine Learning\IntroductionToMachineLearning-2013.ppt"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\PowerPoint\Place MRU]
"Item 1"="[F00000000][T01D24D63A4E07440][O00000000]*C:\Users\HenriV\Desktop\Henri TA\YEAR 2\Machine Learning\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Registration\HENRIV-PC]
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Word\File MRU]
"Item 1"="[F00000000][T01D24C6968FFD740][O00000000]*C:\Users\HenriV\Desktop\RTA\Treeningkava.docx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Word\File MRU]
"Item 2"="[F00000000][T01D24B3C2743EE50][O00000000]*C:\Users\HenriV\Desktop\Henri TA\Oppelaen_esildis.doc"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Word\Place MRU]
"Item 1"="[F00000000][T01D24C6968FF6210][O00000000]*C:\Users\HenriV\Desktop\RTA\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Word\Place MRU]
"Item 2"="[F00000000][T01D24B3C274526D0][O00000000]*C:\Users\HenriV\Desktop\Henri TA\"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\16.0\Word\Reading Locations\Document 0]
"File Path"="C:\Users\HenriV\Desktop\RTA\Treeningkava.docx"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\Common]
"FontBmpCache"="C:\Users\HenriV\AppData\Roaming\Microsoft\Office\fbc4689.tmp"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Office\Common\UserInfo]
"UserName"="HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\OneDrive]
"CurrentVersionPath"="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\OneDrive]
"OneDriveTrigger"="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\OneDrive.exe"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\OneDrive\17.3.5951.0827]
"InstallPath"="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\OneDrive\17.3.5951.0827]
"InstallPaths"="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827;"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Shared Tools\Proofing Tools\1.0\Custom Dictionaries]
"1_3b20fa74a56f2c04_LiveId"="C:\Users\HenriV\AppData\Roaming\Microsoft\Office\15.0\8ba6688c\Proofing\RoamingCustom.dic"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\WAB\Me]
""="/GUID:"bfffab70-c155-4a23-b13d-2588317683b8" /PATH:"C:\Users\HenriV\Contacts\HenriV.contact""
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File1"="C:\Users\HenriV\Desktop\RTA\71a4f9962067f94571724682981632b4.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File2"="C:\Users\HenriV\Desktop\RTA\1476683_615772648485266_1441655730_n.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File3"="C:\Users\HenriV\Desktop\RTA\idontevenknowFATLADYWANTSACOOKIEEE.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File4"="C:\Users\HenriV\Desktop\RTA\10446657_807218179289430_4581226981696827507_n.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List]
"File5"="C:\Users\HenriV\Downloads\ss.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{29881cd9-6dab-11e6-a070-94dbc9b24834}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn3"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{29881cdd-6dab-11e6-a070-94dbc9b24834}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn4"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{580bbab7-d7d0-11e5-9059-94dbc9b24834}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn2"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{97cd9b1c-0194-11e6-96a2-94dbc9b24834}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn2"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{a7c71a6d-3bde-11e6-a110-94dbc9b24834}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{ad3d015a-cf5e-11e5-a559-806e6f6e6963}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{e917ff2e-cf41-11e5-8d75-806e6f6e6963}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo\Volume{f3ada1b6-dd51-11e5-987b-94dbc9b24834}]
"StagingPath"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData"="C:\Users\HenriV\AppData\Roaming"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData"="C:\Users\HenriV\AppData\Local"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Video"="C:\Users\HenriV\Videos"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Libraries"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures"="C:\Users\HenriV\Pictures"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop"="C:\Users\HenriV\Desktop"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\History"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"NetHood"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Network Shortcuts"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{56784854-C6CB-462B-8169-88E350ACB882}"="C:\Users\HenriV\Contacts"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Cookies"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites"="C:\Users\HenriV\Favorites"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"SendTo"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\SendTo"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Start Menu"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Music"="C:\Users\HenriV\Music"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Start Menu\Programs"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Recent"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Recent"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CD Burning"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Burn\Burn"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"PrintHood"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Printer Shortcuts"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}"="C:\Users\HenriV\Searches"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{374DE290-123F-4565-9164-39C4925E467B}"="C:\Users\HenriV\Downloads"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{A520A1A4-1780-4FF6-BD18-167343C5AF16}"="C:\Users\HenriV\AppData\LocalLow"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Administrative Tools"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal"="C:\Users\HenriV\Documents"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}"="C:\Users\HenriV\Links"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache"="C:\Users\HenriV\AppData\Local\Microsoft\Windows\Temporary Internet Files"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Templates"="C:\Users\HenriV\AppData\Roaming\Microsoft\Windows\Templates"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}"="C:\Users\HenriV\Saved Games"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\HomeGroup\UIStatusCache]
"Modifier"="HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\HomeGroup\UIStatusCache]
"ModifierSystem"="HENRIV-PC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Photo Acquisition\Camera and Portable Device]
"FilenameTemplate"="C:\Users\HenriV\Desktop\Telo pildid\$(AcquisitionDate)$([ ]GroupTag)\$(GroupTag[ ])$(AcquisitionSequence).$(OriginalExtension)"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Photo Acquisition\Camera and Portable Device]
"VideoFilenameTemplate"="C:\Users\HenriV\Desktop\Telo pildid\$(AcquisitionDate)$([ ]GroupTag)\$(GroupTag[ ])$(AcquisitionSequence).$(OriginalExtension)"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Photo Acquisition\Camera and Portable Device]
"RootDirectory"="C:\Users\HenriV\Desktop\Telo pildid"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Photo Acquisition\Camera and Portable Device]
"VideoRootDirectory"="C:\Users\HenriV\Desktop\Telo pildid"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Photo Acquisition\DestinationMru]
"MruEntry0"="C:\Users\HenriV\Desktop\Telo pildid"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Photo Acquisition\VideoDestinationMru]
"MruEntry0"="C:\Users\HenriV\Desktop\Telo pildid"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent]
"DisplayIcon"=""C:\Users\HenriV\AppData\Roaming\BitTorrent\BitTorrent.exe",0"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent]
"UninstallString"=""C:\Users\HenriV\AppData\Roaming\BitTorrent\BitTorrent.exe" /UNINSTALL"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent]
"InstallLocation"="C:\Users\HenriV\AppData\Roaming\BitTorrent"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe]
"DisplayIcon"="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\OneDriveSetup.exe"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe]
"UninstallString"="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\OneDriveSetup.exe  /uninstall "
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows Media\WMSDK\General]
"ComputerName"="HENRIV-PC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows Media\WMSDK\Namespace]
"LocalBase"="C:\Users\HenriV\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows Media\WMSDK\Namespace]
"DTDFile"="C:\Users\HenriV\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows Media\WMSDK\Namespace]
"LocalDelta"="C:\Users\HenriV\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSD.XML"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows Media\WMSDK\Namespace]
"RemoteDelta"="C:\Users\HenriV\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSR.XML"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\Desktop\Mängud\Call of duty 2 repack Mr DJ\Setup.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\Downloads\mtasa-1.5.3.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\AppData\Local\Temp\3432148e-67f9-4826-867b-3eeb4cd12240\setup.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\Downloads\PopcornTime-latest.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\Desktop\Mängud\Harry Potter and The Philosopher's Stone (Sorcerer's Stone) 2001 + Key + No CD Crack [UJ.rip]\Harry Potter and The Philosopher's Stone\setup\Setup.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\HenriV\AppData\Local\Temp\jre-8u111-windows-au.exe"="1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Microsoft\Windows Search\ProcessedSearchRoots\0004\Default]
"SavePath"="C:\Users\HenriV\Searches\Microsoft OneNote.searchconnector-ms"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\QtProject\OrganizationDefaults\FileDialog]
"lastVisited"="file:///C:/Users/HenriV/Desktop/Henri TA"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\ArcHistory]
"0"="C:\Users\HenriV\Downloads\the.killing.room.(2009).eng.1cd.(4047204) (1).zip"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\ArcHistory]
"1"="C:\Users\HenriV\Downloads\Westworld.S01E05.HDTV.KILLERS.en_1.zip"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\ArcHistory]
"2"="C:\Users\HenriV\Downloads\Westworld.S01E04.720p.HDTV.AVS.en_1.zip"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\ArcHistory]
"3"="C:\Users\HenriV\Downloads\westworld-season-1-episode-4-english-26019.zip"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"0"="C:\Users\HenriV\Desktop\Filmid\The.Killing.Room.2009.DVDRip.XviD-VoMiT"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"1"="C:\Users\HenriV\Desktop\Filmid"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"2"="C:\Users\HenriV\Desktop\Filmid\Disturbia.2007.1080p.Bluray.x264.anoXmous"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"3"="C:\Users\HenriV\Desktop\Filmid\The Magnificent Seven (2016) [1080p] [YTS.AG]"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"4"="C:\Users\HenriV\Desktop\Filmid\Masterminds.2016.1080p.READNFO.WEB-DL.H264.AC3-EVO"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"5"="C:\Users\HenriV\Desktop\Filmid\Mr. Church (2016) [1080p] [YTS.AG]"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"6"="C:\Users\HenriV\Desktop\Filmid\Bridget.Jones.Baby.2016.1080p.WEB-DL.AAC2.0.H264-FGT[EtHD]"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"7"="C:\Users\HenriV\Desktop\Filmid\Inferno 2016 HC 1080p WEBRip 1.8 GB - iExTV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"8"="C:\Users\HenriV\Desktop\Filmid\The Gift (2015) [1080p]"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"9"="C:\Users\HenriV\Desktop\Filmid\Gosford.Park.2001.1080p.BluRay.x264.anoXmous"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"10"="C:\Users\HenriV\Desktop\Filmid\Deja.Vu.2006.1080p.BluRay.H264.AAC-RARBG"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"11"="C:\Users\HenriV\Desktop\Filmid\Non Stop (2014) [1080p]"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"12"="C:\Users\HenriV\Desktop\Filmid\Michael Clayton (2007)"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"13"="C:\Users\HenriV\Desktop\Filmid\The Hitchhiker's Guide to the Galaxy (2005) [1080p]"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"14"="C:\Users\HenriV\Desktop\Trials2"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\DialogEditHistory\ExtrPath]
"15"="C:\Users\HenriV\Desktop"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\WinRAR\General]
"LastFolder"="C:\Users\HenriV\Downloads"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"Username"="HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Applications\BitTorrent.exe\shell\open\command]
""=""C:\Users\HenriV\AppData\Roaming\BitTorrent\BitTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\BitTorrent\DefaultIcon]
""="C:\Users\HenriV\AppData\Roaming\BitTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\BitTorrent\shell\open\command]
""=""C:\Users\HenriV\AppData\Roaming\BitTorrent\BitTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncApi64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\71\Shell]
"Logo"="C:\Users\HenriV\Desktop\RTA\1290085_550543128347649_154753510_n.jpg"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\HenriV\Desktop\HOODLUM\hlm-intro.exe"="hlm-intro"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\HenriV\Desktop\Midtown Madness 2\midtown2.exe"="Midtown Madness 2 Executable"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\HenriV\AppData\Roaming\BitTorrent\BitTorrent.exe"="BitTorrent"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\HenriV\Desktop\Crack\Base\Binaries\Win64Steam\CivilizationVI.exe"="Sid Meier's Civilization VI"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\HenriV\Desktop\Tor Browser\Browser\firefox.exe"="Tor Browser"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\HenriV\Downloads\AutoClicker.exe"="OP Auto Clicker"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Magnet\DefaultIcon]
""="C:\Users\HenriV\AppData\Roaming\BitTorrent\maindoc.ico"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Magnet\shell\open\command]
""=""C:\Users\HenriV\AppData\Roaming\BitTorrent\BitTorrent.exe" "%1" /SHELLASSOC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{909A6CCD-6810-46C4-89DF-05BE7EB61E6C}\1.0\0\win32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\OneDrive.exe\1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{909A6CCD-6810-46C4-89DF-05BE7EB61E6C}\1.0\HELPDIR]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{A195846E-1536-4ACD-A720-9DB32D3AD239}\1.0\0\win32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncApi.dll\1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{A195846E-1536-4ACD-A720-9DB32D3AD239}\1.0\0\win64]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncApi64.dll\1"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{A195846E-1536-4ACD-A720-9DB32D3AD239}\1.0\HELPDIR]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{BAE13F6C-0E2A-4DEB-AA46-B8F55319347C}\1.0\0\win32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\SyncEngine.dll\2"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{BAE13F6C-0E2A-4DEB-AA46-B8F55319347C}\1.0\HELPDIR]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\0\win32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\0\win64]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64\FileSyncShell64.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\HELPDIR]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}\LocalServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\OneDrive.exe /autoplay"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\LocalServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\OneDrive.exe /cci /client=Personal"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}\LocalServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\OneDrive.exe /cci /client=Personal"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\LocalServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\OneDrive.exe /cci /client=Personal"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncShell.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Software\Classes\Wow6432Node\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32]
""="C:\Users\HenriV\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\FileSyncApi.dll"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"LOGONSERVER"="\\HENRIV-PC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"USERDOMAIN"="HenriV-PC"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"USERNAME"="HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"USERPROFILE"="C:\Users\HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"HOMEPATH"="\Users\HenriV"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"APPDATA"="C:\Users\HenriV\AppData\Roaming"
[HKEY_USERS\S-1-5-21-1604467813-914689706-2192655327-1000\Volatile Environment]
"LOCALAPPDATA"="C:\Users\HenriV\AppData\Local"
 
====== End of Search ======


#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:50 PM

Posted 14 December 2016 - 08:52 AM

I do not see any references to kb-ribaki on your registry.

Has the problem been solved?

#9 TuvTuv

TuvTuv
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:50 PM

Posted 14 December 2016 - 09:40 AM

Yes, it seems to have been solved!

 

Thank you for your time and assistance!



#10 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:50 PM

Posted 14 December 2016 - 09:52 AM

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users