RegRipper & keys parsed by plugins

This table is an attempt to list all registry keys parsed by all RegRipper plugins available at RegRipper v2.8 released on Oct 22th, 2014, last update Sep 2018 (retrieved on Nov 4th, 2018)
The list has been generated by a perl script which I called - for the fun of it - RegRipper Ripper a.k.a. 3R.
The name is similar to 3RPG and it's not a coincident either;
in fact, I was curious which keys are actually being already covered by the RegRipper plugins bundle.
With 300+ existing plugin it's easy to get lost, and perhaps even end up re-inventing the wheel by writing a plugin for a key that already has its plugin.

Most of the data below has been extracted automatically by 3R, and a few manual correction were added for items that 3R was unable to retrieve directly from the source code.
I can only wish that the author(s) of the plug-ins will be more consistent in the future while writing them; the syntax, variable names and the way these variables are initialized and used varies really a lot across all the plug-ins and makes it really tricky to parse it all w/o errors.
In any case, if you find any mistakes or omissions, please let me know and I will fix that.
Thanks.

There are two tables - one sorted by hive/key pair and second by plugin file names:

    By Hive / Key

    By Plugin file name



By Hive / Key

HiveKeyScans
Wow6432Node
Plugin file
all(Entire Hive)N/Aregtime_tln.pl
allAll keys (all hives)N/Asizes.pl
allBeginN/Amalware.pl
allBINARYN/Amalware.pl
allCheck key/value names in a hive for leading null charN/Anull.pl
allClasses\BJ\StaticN/Amalware.pl
allClasses\FASTN/Amalware.pl
allClasses\Network\SharingHandlerN/Amalware.pl
allClasses\XXXXN/Amalware.pl
allClients\NetrauN/Amalware.pl
allClients\sdataN/Amalware.pl
allLook for Slack spaceN/Aslack.pl
allMicrosoft\HTMLHelpN/Amalware.pl
allMicrosoft\Rpc\InternetN/Amalware.pl
allMicrosoft\ShipTrN/Amalware.pl
allMicrosoft\ShipUpN/Amalware.pl
allMicrosoft\WBEM\ESS\//./root/CIMV2\Win32ClockProviderN/Amalware.pl
allParse hive, check key/value names for RLO characterN/Arlo.pl
allParse hive, print deleted keys/valuesN/Adel_tln.pl
allPolicies\Microsoft\Windows DefenderN/Amalware.pl
allPolicies\Microsoft\Windows Defender\Real-Time ProtectionN/Amalware.pl
allPolicy\SecretsN/Amalware.pl
allrootN/Afindexes.pl
allScans a hive file, checking sizes of binary value dataN/Abaseline.pl
allSoftware\Adobe\Adobe ARM\1.0\ARMN/Amalware.pl
allSoftware\Adobe\Adobe Reader\<VERSION>\IPMN/Amalware.pl
allSoftware\BINARYN/Amalware.pl
allSoftware\Google\Update\network\secureN/Amalware.pl
allSoftware\LockyN/Amalware.pl
allSoftware\Microsoft\ClockN/Amalware.pl
allSoftware\Microsoft\CurrentHalInfN/Amalware.pl
allSoftware\Microsoft\CurrentPnpSetupN/Amalware.pl
allSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATIONN/Amalware.pl
allSoftware\Microsoft\Office test\Special\PerfN/Amalware.pl
allSoftware\Microsoft\Wbem\WMICN/Amalware.pl
allSoftware\TransPanN/Amalware.pl
allWow6432Node\WRData\Threats\HistoryN/Amalware.pl
allWRData\Threats\HistoryN/Amalware.pl
amcacheRoot\FileN/Aamcache_tln.pl
amcacheRoot\InventoryApplicationN/Aamcache_tln.pl
amcacheRoot\InventoryApplicationFileN/Aamcache_tln.pl
amcacheRoot\ProgramsN/Aamcache.pl
ntuser.dat, softwareMicrosoft\Windows NT\CurrentVersion\AppCompatFlags\CustomYesappcompatflags.pl
ntuser.dat, softwareMicrosoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDBYesappcompatflags.pl
ntuser.dat, softwareMicrosoft\Windows NT\CurrentVersion\AppCompatFlags\LayersYesappcompatflags.pl
ntuser.dat, softwareMicrosoft\Windows\CurrentVersion\Explorer\AppKeyNoappkeys_tln.pl
ntuser.dat, softwareSoftware\Microsoft\OfficeYeskankan.pl
ntuser.dat, softwareSoftware\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersYesappcompatflags.pl
ntuser.dat, softwareSoftware\Microsoft\Windows\CurrentVersion\Explorer\AppKeyNoappkeys_tln.pl
ntuser.dat, softwareWow6432Node\Microsoft\OfficeYeskankan.pl
ntuser.dat, softwareWow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersYesappcompatflags.pl
ntuser.dat, softwareWow6432Node\Software\Microsoft\OfficeYeskankan.pl
ntuser.dat, softwareWow6432Node\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersYesappcompatflags.pl
ntuser.dat, systemControlSetXXX\Control\Session Manager\EnvironmentN/Aprofiler.pl
ntuser.dat, systemEnvironmentN/Aprofiler.pl
ntuser.dat,usrclass.datLocal Settings\Software\Microsoft\Windows\Shell\MUICacheN/Amuicache_tln.pl
ntuser.dat,usrclass.datSoftware\Microsoft\Windows\ShellNoRoam\MUICacheN/Amuicache_tln.pl
ntuser.dat;softwareMicrosoft\Windows\CurrentVersion\Internet SettingsNoie_zones.pl
ntuser.dat;softwareSoftware\Microsoft\Windows\CurrentVersion\Internet SettingsNoie_zones.pl
ntuser.datappdataN/Aurun_tln.pl
ntuser.datapplication dataN/Aurun_tln.pl
ntuser.dataudio\.genN/Aares.pl
ntuser.datControl Panel\DesktopN/Aautoendtasks.pl
ntuser.datControl Panel\don\'t loadN/Acpldontload.pl
ntuser.datControl Panel\International\GeoN/Anation.pl
ntuser.datCover DesignerN/Anero.pl
ntuser.datEnvironmentN/Aenvironment.pl
ntuser.datEulaAcceptedN/Arootkit_revealer.pl
ntuser.datFlmgPlgN/Anero.pl
ntuser.datgen\.genN/Aares.pl
ntuser.datglobalrootN/Aurun_tln.pl
ntuser.datIdentitiesN/Aidentities.pl
ntuser.datimage\.genN/Aares.pl
ntuser.datInstallPathN/Aaports.pl
ntuser.datNero PhotoSnapN/Anero.pl
ntuser.datNetworkN/Antusernetwork.pl
ntuser.datNSPluginMgrN/Anero.pl
ntuser.datpasswordN/Ahaven_and_hearth.pl
ntuser.datPhotoEffectsN/Anero.pl
ntuser.datPrintersN/Aprinters.pl
ntuser.datPrinters\Settings\Wizard\ConnectMRUN/Aprintermru.pl
ntuser.datProxyPortN/Aodysseus.pl
ntuser.datProxyUpstreamHostN/Aodysseus.pl
ntuser.datProxyUpstreamPortN/Aodysseus.pl
ntuser.datrecycleN/Aurun_tln.pl
ntuser.datsavedtokenN/Ahaven_and_hearth.pl
ntuser.datServerCertN/Aodysseus.pl
ntuser.datServerCertPassN/Aodysseus.pl
ntuser.datSoftwareN/Alistsoft.pl
ntuser.datSoftware\7-ZipN/Asevenzip.pl
ntuser.datSoftware\Adobe\Acrobat Reader\<VERSION>\AVGeneral\cRecentFilesN/Aadoberdr.pl
ntuser.datSoftware\AheadN/Anero.pl
ntuser.datSoftware\America Online\AOL Instant Messenger (TM)\CurrentVersion\UsersN/Aaim.pl
ntuser.datSoftware\AresN/Aares.pl
ntuser.datSoftware\bindshell.net\OdysseusN/Aodysseus.pl
ntuser.datSoftware\Blizzard Entertainment\Warcraft III\StringN/Awarcraft3.pl
ntuser.datSoftware\Cain\SettingsN/Acain.pl
ntuser.datSoftware\ClientsN/Astartmenuinternetapps_cu.pl
ntuser.datSoftware\DECAFmeN/Adecaf.pl
ntuser.datSoftware\Eraser\Eraser 6N/Aeraser.pl
ntuser.datSoftware\Foxit Software\Foxit Reader <VERSION>N/Afoxitrdr.pl
ntuser.datSoftware\Google\Google Toolbar\4.0\whitelistN/Agtwhitelist.pl
ntuser.datSoftware\Google\NavClient\1.1\HistoryN/Agthist.pl
ntuser.datSoftware\Google\Update\network\secureN/Alatentbot.pl
ntuser.datSoftware\ImgBurnN/Aimgburn1.pl
ntuser.datSoftware\JavaSoft\Java Update\Policy\JavaFXN/Ajavafx.pl
ntuser.datSoftware\JavaSoft\Prefs\havenN/Ahaven_and_hearth.pl
ntuser.datSoftware\Martin Prikryl\WinSCP 2N/Awinscp.pl
ntuser.datSoftware\MicrosoftN/Aosversion_tln.pl
ntuser.datSoftware\Microsoft\Command ProcessorN/Acmdproc_tln.pl
ntuser.datSoftware\Microsoft\CTF\LangBarAddInN/Ammo.pl
ntuser.datSoftware\Microsoft\Dependency Walker\Recent File ListN/Adependency_walker.pl
ntuser.datSoftware\Microsoft\Installer\Products\D4676621F4CF7AF46BB388D4351B86F0N/Anetassist.pl
ntuser.datSoftware\Microsoft\Installer\Products\D4676621F4CF7AF46BB388D4351B86F0\SourceListN/Anetassist.pl
ntuser.datSoftware\Microsoft\IntelliPoint\AppSpecificN/Aappspecific.pl
ntuser.datSoftware\Microsoft\Internet Account Manager\AccountsN/Aclampi.pl
ntuser.datSoftware\Microsoft\Internet ExplorerN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStoreN/Amixer_tln.pl
ntuser.datSoftware\Microsoft\Internet Explorer\MainN/Avawtrak.pl
ntuser.datSoftware\Microsoft\Internet Explorer\Main\WindowsSearchN/Aie_settings.pl
ntuser.datSoftware\Microsoft\Internet Explorer\SearchScopesN/Asearchscopes.pl
ntuser.datSoftware\Microsoft\Internet Explorer\SettingsN/Aclampitm.pl
ntuser.datSoftware\Microsoft\Internet Explorer\ToolbarN/Areveton.pl
ntuser.datSoftware\Microsoft\Internet Explorer\TypedURLsN/Atypedurls_tln.pl
ntuser.datSoftware\Microsoft\Internet Explorer\TypedURLsTimeN/Atypedurlstime_tln.pl
ntuser.datSoftware\Microsoft\MediaPlayer\Player\RecentFileListN/Ampmru.pl
ntuser.datSoftware\Microsoft\MediaPlayer\PreferencesN/Abrisv.pl
ntuser.datSoftware\Microsoft\Microsoft Management Console\Recent File ListN/Ammc_tln.pl
ntuser.datSoftware\Microsoft\Multimedia\OtherN/Ammo.pl
ntuser.datSoftware\Microsoft\Office\<VERSION>\<OFFICE_APP>
where VERSION depends on Office version
and OFFICE_APP is: Word, PowerPoint, Excel, Access
N/Atrustrecords_tln.pl
ntuser.datSoftware\Microsoft\Office\<VERSION>\Common\Internet\Server CacheN/Aoisc.pl
ntuser.datSoftware\Microsoft\Office\<VERSION>\Common\Open FindN/Aofficedocs.pl
ntuser.datSoftware\Microsoft\Office\14.0N/Aofficedocs2010_tln.pl
ntuser.datSoftware\Microsoft\Office\15.0\Word\Reading LocationsN/Areading_locations.pl
ntuser.datSoftware\Microsoft\Office\CommonN/Auserinfo.pl
ntuser.datSoftware\Microsoft\PIMSRVN/Abrisv.pl
ntuser.datSoftware\Microsoft\Search Assistant\ACMruN/Aacmru.pl
ntuser.datSoftware\Microsoft\Snapshot Viewer\Recent File ListN/Asnapshot_viewer.pl
ntuser.datSoftware\Microsoft\Terminal Server Client\DefaultN/Atsclient_tln.pl
ntuser.datSoftware\Microsoft\Terminal Server Client\ServersN/Atsclient_tln.pl
ntuser.datSoftware\Microsoft\User Location Service\ClientN/Auserlocsvc.pl
ntuser.datSoftware\Microsoft\Windows Live Contacts\DatabaseN/AliveContactsGUID.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\DeviceDisplayObjectsN/Addo.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\PrinterPortsN/Aprinters.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\ProfilesN/Aoutlook.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookN/Aoutlook2.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046N/Aolsearch.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\WindowsN/Auser_win.pl
ntuser.datSoftware\Microsoft\Windows NT\CurrentVersion\WinlogonN/Awinlogon_u.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersionN/Apolicies_u.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\App Management\ARPCacheN/Aarpcache.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\AppletsN/Aapplets_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$$windows.data.taskflow.shellactivities\CurrentN/Ashellactivities.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\ExplorerN/Alogonusername.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\AdvancedN/Adisablemru.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\Advanced\N/Areveton.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\AutoCompleteN/Aclampi.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\KnownDevicesN/Aknowndev.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\BitBucketN/Avista_bitbucket.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfoN/Acdstaginginfo.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32N/Acomdlg32.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptionsN/Acompdesc.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\ControlPanelN/Acontrolpanel.pl
ntuser.datSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExtsN/Acortana.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExtsN/Afileexts.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\LogonStatsN/Alogonstats.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRUN/Amndmru_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\MenuOrderN/Amenuorder.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2N/Amp3.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\PublishingWizard\AddNetworkPlace\AddNetPlace\LocationMRUN/Apublishingwizard.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsN/Arecentdocs_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\RunMRUN/Arunmru_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersN/Astartup.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\StartPageN/Astartpage.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\TypedPathsN/Atypedpaths_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersN/Astartup.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\UserAssistN/Auserassist_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRUN/Awallpaper.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQueryN/Awordwheelquery.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{8AD9C840-044E-11D1-B3E9-00805F499D93}N/Aiejava.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\FileHistoryN/Afilehistory.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet SettingsN/Aproxysettings.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\<SUBKEY>\HistoryN/Ainternet_settings_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\AutoCompleteN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\DOMStorageN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\IETldN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\MainN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\PrivacyN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\RecoveryN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery\ActiveN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery\AdminActiveN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery\PendingDeleteN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Suggested SitesN/Ainternet_explorer_cu.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapN/Adomains.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3N/Avawtrak.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Policies\AssociationsN/Aattachmgr_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Policies\AttachmentsN/Aattachmgr_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Policies\Comdlg32N/Adisablemru.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Policies\ExplorerN/Adisablemru.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Policies\System\N/Areveton.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\RunN/Avawtrak.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Search\JumpListDataN/Ajumplistdata.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Search\RecentAppsN/Arecentapps_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Shell Extensions\CachedN/Acached_tln.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\UFH\SHCN/Ashc.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Uninstall\NetAssistantN/Anetassist.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentN/Autorrent.pl
ntuser.datSoftware\Microsoft\Windows\CurrentVersion\UnreadMailN/Aunreadmail.pl
ntuser.datSoftware\Microsoft\Windows\Shell\Bags\1\DesktopN/Aitempos.pl
ntuser.datSoftware\Microsoft\Windows\ShellNoRoam\BagMRUN/Ashellbags_xp.pl
ntuser.datSoftware\Microsoft\Windows\ShellNoRoam\BagsN/Aitempos.pl
ntuser.datSoftware\Mozilla\Firefox\ExtensionsN/Anetassist.pl
ntuser.datSoftware\Nico Mak Computing\WinZipN/Awinzip.pl
ntuser.datSoftware\ORL\VNCHooks\Application_PrefsN/Avnchooksapplicationprefs.pl
ntuser.datSoftware\ORL\VNCviewer\MRUN/Avncviewer.pl
ntuser.datSoftware\ORL\WinVNC3N/Awinvnc.pl
ntuser.datSoftware\ORL\WinVNC3\DefaultN/Awinvnc.pl
ntuser.datSoftware\ORL\WinVNC\DefaultN/Awinvnc.pl
ntuser.datSoftware\Piriform\CCleanerN/Accleaner.pl
ntuser.datSoftware\PrivoxyN/Aprivoxy.pl
ntuser.datSoftware\RealNetworks\RealPlayer\6.0\PreferencesN/Arealplayer6.pl
ntuser.datSoftware\RealVNC\DefaultN/Awinvnc.pl
ntuser.datSoftware\RealVNC\VNCViewer4\MRUN/Avncviewer.pl
ntuser.datSoftware\RealVNC\WinVNC4N/Awinvnc.pl
ntuser.datSoftware\SimonTatham\PuTTY\SessionsN/Aputty_sessions.pl
ntuser.datSoftware\SimonTatham\PuTTY\SshHostKeysN/Aputty.pl
ntuser.datSoftware\SkypeN/Askype.pl
ntuser.datSoftware\SmartLine Vision\aportsN/Aaports.pl
ntuser.datSoftware\SysInternalsN/Asysinternals_tln.pl
ntuser.datSoftware\Sysinternals\RootkitRevealerN/Arootkit_revealer.pl
ntuser.datSoftware\VMware, Inc.\VMware Player\VMplayer\Window positionN/Avmplayer.pl
ntuser.datSoftware\VMware\Virtual Infrastructure Client\Preferences\UI\ClientsXmlN/Avmware_vsphere_client.pl
ntuser.datSoftware\VMware\VMware Infrastructure Client\PreferencesN/Avmware_vsphere_client.pl
ntuser.datSoftware\WinRAR\ArcHistoryN/Awinrar_tln.pl
ntuser.datSoftware\WinRAR\DialogEditHistory\ArcNameN/Awinrar2.pl
ntuser.datSoftware\WinRAR\DialogEditHistory\ExtrPathN/Awinrar2.pl
ntuser.datSoftware\Wow6432Node\7-ZipN/Asevenzip.pl
ntuser.datSoftware\Wow6432Node\Microsoft\Windows NT\CurrentVersion\WinlogonN/Awinlogon_u.pl
ntuser.datSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\RunN/Avawtrak.pl
ntuser.datSoftware\Yahoo\pagerN/Ayahoo_cu.pl
ntuser.datsystem volume informationN/Aurun_tln.pl
ntuser.dattempN/Aurun_tln.pl
ntuser.datuserbnetN/Awarcraft3.pl
ntuser.datuserlocalN/Awarcraft3.pl
ntuser.datusernameN/Ahaven_and_hearth.pl
ntuser.datvideo\.autN/Aares.pl
ntuser.datvideo\.datN/Aares.pl
ntuser.datvideo\.genN/Aares.pl
ntuser.datvideo\.titN/Aares.pl
ntuser.datXlmgPlgN/Anero.pl
samSAM\Domains\Account\UsersN/Asamparse_tln.pl
samSAM\Domains\Builtin\AliasesN/Asamparse.pl
securityPolicy\PolAcDmSN/Apolacdms.pl
securityPolicy\PolAdtEvN/Aauditpol_xp.pl
securityPolicy\PolPrDmSN/Apolacdms.pl
securityPolicy\SecretsN/Asecrets_tln.pl
software, ntuser.datMicrosoft\Windows\CurrentVersion\UninstallYesuninstall_tln.pl
software, ntuser.datSoftware\Microsoft\Windows\CurrentVersion\UninstallYesuninstall_tln.pl
software, ntuser.datWow6432Node\Microsoft\Windows\CurrentVersion\UninstallYesuninstall_tln.pl
software,ntuser.datMicrosoft\Windows\CurrentVersion\App Paths\thunderbird.exeYesthunderbirdinstalled.pl
software,ntuser.datMicrosoft\Windows\CurrentVersion\RunYesahaha.pl
software,ntuser.datSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\RunYesahaha.pl
software,ntuser.datWOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\thunderbird.exeYesthunderbirdinstalled.pl
software,ntuser.datWow6432Node\Microsoft\Windows\CurrentVersion\RunYesahaha.pl
software,usrclassClassesYesassoc.pl
software,usrclassClasses\Wow6432NodeYesassoc.pl
software,usrclassWow6432NodeYesassoc.pl
softwareADatumCorporation\OpenCandyYesopencandy.pl
softwareClasses\<EXTENSION>file\shell\open\command
where EXTENSION is exe, cmd, bat, cs, hta, pif
Nocmd_shell_tln.pl
softwareClasses\CLSIDYesinprocserver.pl
softwareClasses\HTTP\shell\open\commandNodefbrowser.pl
softwareClasses\Installer\ProductsNomsis.pl
softwareClasses\Network\SharingHandlerNohandler.pl
softwareClasses\Wow6432Node\CLSIDYesinprocserver.pl
softwareClientsNostartmenuinternetapps_lm.pl
softwareClients\StartMenuInternetNodefbrowser.pl
softwareCLSIDYesinprocserver.pl
softwareControlSetXXX\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}Nomacaddr.pl
softwareJavaSoft\Java Plug-inYesjavasoft.pl
softwareLANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLogYeslandesk_tln.pl
softwareLicensesNolicenses.pl
softwareLogMeIn\V5\PerBrowserYeslogmein_tln.pl
softwareMicrosoftYesdirect_tln.pl
softwareMicrosoft\Active Setup\Installed ComponentsYesinstalledcomp.pl
softwareMicrosoft\Dfrg\BootOptimizeFunctionNodfrg.pl
softwareMicrosoft\DRM\amtyNorenocide.pl
softwareMicrosoft\DrWatsonNodrwatson.pl
softwareMicrosoft\EAPOL\Parameters\InterfacesNossid.pl
softwareMicrosoft\ESENT\ProcessNoesent.pl
softwareMicrosoft\Internet ExplorerNosnapshot.pl
softwareMicrosoft\MSSQLServer\Client\SuperSocketNetLib\LastConnectNosql_lastconnect.pl
softwareMicrosoft\NetShNonetsh.pl
softwareMicrosoft\PowerShell\1\ShellIds\Microsoft.PowershellNoexecpolicy.pl
softwareMicrosoft\RemovalTools\MRTNomrt.pl
softwareMicrosoft\RFC1156Agent\CurrentVersion\ParametersNotrappoll.pl
softwareMicrosoft\Rpc\InternetNodcom.pl
softwareMicrosoft\SchedulingAgentNoschedagent.pl
softwareMicrosoft\Security CenterNosecctr.pl
softwareMicrosoft\TracingYestracing_tln.pl
softwareMicrosoft\Updates\Windows XP\SP4\KB950582Nokb950582.pl
softwareMicrosoft\WBEM\WDMNowbem.pl
softwareMicrosoft\Windows Genuine AdvantageNomacaddr.pl
softwareMicrosoft\Windows NT\CurrentVersionNowinver.pl
softwareMicrosoft\Windows NT\CurrentVersion\AeDebugNodrwatson.pl
softwareMicrosoft\Windows NT\CurrentVersion\Drivers32Yesdrivers32.pl
softwareMicrosoft\Windows NT\CurrentVersion\EMDMgmtNoemdmgmt.pl
softwareMicrosoft\Windows NT\CurrentVersion\Image File Execution OptionsYesimagefile.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkNonetworkuid.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkCardsNossid.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkListNonetworklist_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\IntranetNonetworklist_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkList\ProfilesNonetworklist_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkList\Signatures\ManagedNonetworklist_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\NetworkList\Signatures\UnmanagedNonetworklist_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\ProfileListNoprofilelist.pl
softwareMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\TasksNoregback.pl
softwareMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\TreeNoat_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Registry\RegIdleBackupNoregback.pl
softwareMicrosoft\Windows NT\CurrentVersion\SilentProcessExitNosilentprocessexit_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\SPP\ClientsNospp_clients.pl
softwareMicrosoft\Windows NT\CurrentVersion\SvcHostNosvchost.pl
softwareMicrosoft\Windows NT\CurrentVersion\SystemRestoreNodisablesr.pl
softwareMicrosoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunYessrun_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnceYessrun_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\WindowsNoinit_dlls.pl
softwareMicrosoft\Windows NT\CurrentVersion\WinlogonYeswinlogon_tln.pl
softwareMicrosoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListYeswinlogon_tln.pl
softwareMicrosoft\Windows Portable Devices\DevicesNoremovdev.pl
softwareMicrosoft\Windows Script Host\SettingsNowsh_settings.pl
softwareMicrosoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\PathsNosystemindex.pl
softwareMicrosoft\Windows Search\VolumeInfoCacheNovolinfocache.pl
softwareMicrosoft\Windows\CurrentVersionNowin_cv.pl
softwareMicrosoft\Windows\CurrentVersion\App PathsYesapppaths_tln.pl
softwareMicrosoft\Windows\CurrentVersion\Authentication\LogonUINolastloggedon.pl
softwareMicrosoft\Windows\CurrentVersion\Component Based Servicing\PackagesNoupdates.pl
softwareMicrosoft\Windows\CurrentVersion\Control PanelNoctrlpnl.pl
softwareMicrosoft\Windows\CurrentVersion\ExplorerNovirut.pl
softwareMicrosoft\Windows\CurrentVersion\Explorer\BitBucketNobitbucket.pl
softwareMicrosoft\Windows\CurrentVersion\Explorer\Browser Helper ObjectsYesbho.pl
softwareMicrosoft\Windows\CurrentVersion\Explorer\ShellExecuteHooksYesshellexec.pl
softwareMicrosoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiersNoshelloverlay.pl
softwareMicrosoft\Windows\CurrentVersion\Group Policy\HistoryNogpohist_tln.pl
softwareMicrosoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0Nopsscript.pl
softwareMicrosoft\Windows\CurrentVersion\Group Policy\State\Machine\Scripts\Startup\0\0Nopsscript.pl
softwareMicrosoft\Windows\CurrentVersion\Installer\UserDataNoproduct.pl
softwareMicrosoft\Windows\CurrentVersion\Internet Settings\urlzoneNourlzone.pl
softwareMicrosoft\Windows\CurrentVersion\MMDevices\AudioNoaudiodev.pl
softwareMicrosoft\Windows\CurrentVersion\Policies\ExplorerNokb950582.pl
softwareMicrosoft\Windows\CurrentVersion\Policies\Explorer\RunYessrun_tln.pl
softwareMicrosoft\Windows\CurrentVersion\policies\systemNouac.pl
softwareMicrosoft\Windows\CurrentVersion\ReliabilityYesgauss.pl
softwareMicrosoft\Windows\CurrentVersion\RunYessrun_tln.pl
softwareMicrosoft\Windows\CurrentVersion\RunOnceYessrun_tln.pl
softwareMicrosoft\Windows\CurrentVersion\RunServicesYessrun_tln.pl
softwareMicrosoft\Windows\CurrentVersion\Shell Extensions\ApprovedNoshellext.pl
softwareMicrosoft\Windows\CurrentVersion\SideBySideYessbs.pl
softwareMicrosoft\Windows\CurrentVersion\Uninstall\KB950582Nokb950582.pl
softwareMicrosoft\Windows\CurrentVersion\WindowsBackup\ScheduleParams\TargetDeviceNowinbackup.pl
softwareMicrosoft\Windows\CurrentVersion\WindowsBackup\StatusNowinbackup.pl
softwareMicrosoft\Windows\CurrentVersion\WindowsUpdateNosusclient.pl
softwareMicrosoft\Windows\CurrentVersion\WINEVT\ChannelsNowinevt.pl
softwareMicrosoft\Windows\CurrentVersion\Wordpad\ComChecks\SafelistYeslazyshell.pl
softwareMicrosoft\WZCSVC\Parameters\InterfacesNossid.pl
softwareODBC.ININoetos.pl
softwareODBC\ODBC.ININoetos.pl
softwarePolicies\Microsoft\Windows NT\Windows File ProtectionNosfc.pl
softwarePolicies\Microsoft\Windows\Safer\CodeIdentifiersNocodeid.pl
softwareSelectNomacaddr.pl
softwareSoftware\Microsoft\Windows\CurrentVersion\Group Policy\HistoryNogpohist_tln.pl
softwareTeamViewerYesteamviewer.pl
softwareWidComm\BTConfig\DevicesNobtconfig.pl
softwareWow6432Node\ADatumCorporation\OpenCandyYesopencandy.pl
softwareWow6432Node\CLSIDYesinprocserver.pl
softwareWow6432Node\JavaSoft\Java Plug-inYesjavasoft.pl
softwareWow6432Node\LANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLogYeslandesk_tln.pl
softwareWow6432Node\LogMeIn\V5\PerBrowserYeslogmein_tln.pl
softwareWow6432Node\MicrosoftYesdirect_tln.pl
softwareWow6432Node\Microsoft\Active Setup\Installed ComponentsYesinstalledcomp.pl
softwareWow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32Yesdrivers32.pl
softwareWow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsYesimagefile.pl
softwareWow6432Node\Microsoft\Windows NT\CurrentVersion\WindowsYesappinitdlls.pl
softwareWow6432Node\Microsoft\Windows NT\CurrentVersion\WinlogonYeswinlogon_tln.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\App PathsYesapppaths.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper ObjectsYesbho.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooksYesshellexec.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunYessrun_tln.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\ReliabilityYesgauss.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\RunYessrun_tln.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\RunOnceYessrun_tln.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\SideBySideYessbs.pl
softwareWow6432Node\Microsoft\Windows\CurrentVersion\Wordpad\ComChecks\SafelistYeslazyshell.pl
softwareWow6432Node\TeamViewerYesteamviewer.pl
softwareYahooNoyahoo_lm.pl
system\Control\Session ManagerN/Ashimcache_tln.pl
systemControlSetXXX\Control\BackupRestore\FilesNotToBackupN/Abackuprestore.pl
systemControlSetXXX\Control\BackupRestore\FilesNotToSnapshotN/Abackuprestore.pl
systemControlSetXXX\Control\BackupRestore\KeysNotToRestoreN/Abackuprestore.pl
systemControlSetXXX\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}N/Astillimage.pl
systemControlSetXXX\Control\ComputerName\ComputerNameN/Ausbstor2.pl
systemControlSetXXX\Control\CrashControlN/Acrashcontrol.pl
systemControlSetXXX\Control\DDMN/Addm.pl
systemControlSetXXX\Control\DeviceClasses\{10497b1b-ba51-44e5-8318-a65c837b6661}N/Awpdbusenum.pl
systemControlSetXXX\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}N/Aide.pl
systemControlSetXXX\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}N/Adevclass.pl
systemControlSetXXX\Control\FileSystemN/Adisablelastaccess.pl
systemControlSetXXX\Control\LSAN/Alsa_packages.pl
systemControlSetXXX\Control\LsaN/Anolmhash.pl
systemControlSetXXX\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}N/Anic_mst2.pl
systemControlSetXXX\Control\ProductOptionsN/Aproducttype.pl
systemControlSetXXX\Control\SafeBootN/Asafeboot.pl
systemControlSetXXX\Control\SecurityProvidersN/Asecurityproviders.pl
systemControlSetXXX\Control\Session ManagerN/Apending.pl
systemControlSetXXX\Control\Session Manager\AppCertDllsN/Aappcertdlls.pl
systemControlSetXXX\Control\Session Manager\EnvironmentN/Aprocessor_architecture.pl
systemControlSetXXX\Control\Session Manager\Memory ManagementN/Apagefile.pl
systemControlSetXXX\Control\Session Manager\Memory Management\PrefetchParametersN/Aprefetch.pl
systemControlSetXXX\Control\Session Manager\PowerN/Ahibernate.pl
systemControlSetXXX\Control\StillImage\LoggingN/Astillimage.pl
systemControlSetXXX\Control\Terminal ServerN/Atermserv.pl
systemControlSetXXX\Control\Terminal Server\WinStations\RDP-TcpN/Ardpport.pl
systemControlSetXXX\Control\TimeZoneInformationN/Atimezone.pl
systemControlSetXXX\Control\Watchdog\DisplayN/Ashutdowncount.pl
systemControlSetXXX\Control\WindowsN/Ashutdown.pl
systemControlSetXXX\Control\Windows\SystemLookupN/Aangelfire.pl
systemControlSetXXX\Enum\IDEN/Aide.pl
systemControlSetXXX\Enum\RootN/Anetsvcs.pl
systemControlSetXXX\Enum\SWD\DAFUPnPProviderN/Adafupnp.pl
systemControlSetXXX\Enum\USBN/Ausbdevices.pl
systemControlSetXXX\Enum\USBStorN/Ausbstor3.pl
systemControlSetXXX\Enum\WpdBusEnumRootN/Awpdbusenum.pl
systemControlSetXXX\ServicesN/Asvcdll.pl
systemControlSetXXX\Services\bam\UserSettingsN/Abam_tln.pl
systemControlSetXXX\services\BTHPORT\Parameters\DevicesN/Abthport_tln.pl
systemControlSetXXX\services\BTHPORT\Parameters\Radio SupportN/Abthport.pl
systemControlSetXXX\Services\EventlogN/Aeventlogs.pl
systemControlSetXXX\Services\LanmanServer\SharesN/Ashares.pl
systemControlSetXXX\Services\msupdateN/Aphdet.pl
systemControlSetXXX\services\RemoteAccess\Parameters\AccountLockoutN/Aremoteaccess.pl
systemControlSetXXX\services\SysMainN/Aprefetch.pl
systemControlSetXXX\Services\Tcpip\ParametersN/Acompname.pl
systemControlSetXXX\Services\Tcpip\Parameters\InterfacesN/Anic_mst2.pl
systemControlSetXXX\Services\Tcpip\Parameters\PersistentRoutesN/Aroutes.pl
systemControlSetXXX\Services\TermService\ParametersN/Atermcert.pl
systemControlSetXXX\Services\VSS\Diag\SystemRestoreN/Adiag_sr.pl
systemMountedDevicesN/Ausbstor2.pl
systemSelectN/Awpdbusenum.pl
systemSetupN/Asource_os.pl
systemWPA\MediaCenterN/Axpedition.pl
systemWPA\TabletPCN/Axpedition.pl
unknownSoftware\Martin Prikryl\WinSCP 2\SessionsN/Awinscp_sessions.pl
unknownSoftware\Martin Prikryl\WinSCP 2\SshHostKeysN/Assh_host_keys.pl
unknownSoftware\SimonTatham\Putty\SshHostKeysN/Assh_host_keys.pl
usrclass.dat\shell\open\commandN/Acmd_shell_u.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsN/Amsedge_win10.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsTimeN/Amsedge_win10.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsVisitCountN/Amsedge_win10.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByAppN/Aphotos_win10.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\SchemasN/Aphotos_win10.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft\.windowsphotos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByAppN/Aphotos.pl
usrclass.datLocal Settings\Software\Microsoft\Windows\Shell\BagMRUN/Ashellbags_tln.pl
usrclass.datSoftware\Microsoft\Windows\ShellNoRoam\Bags\<NODESLOT>\ShellN/Ashellbags_test.pl

By Plugin file name

Plugin FileHiveScans
Wow6432Node
Keys
acmru.plntuser.datN/ASoftware\Microsoft\Search Assistant\ACMru
adoberdr.plntuser.datN/ASoftware\Adobe\Acrobat Reader\<VERSION>\AVGeneral\cRecentFiles
ahaha.plsoftware,ntuser.datYesMicrosoft\Windows\CurrentVersion\Run
ahaha.plsoftware,ntuser.datYesSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
ahaha.plsoftware,ntuser.datYesWow6432Node\Microsoft\Windows\CurrentVersion\Run
aim.plntuser.datN/ASoftware\America Online\AOL Instant Messenger (TM)\CurrentVersion\Users
amcache.plamcacheN/ARoot\File
amcache.plamcacheN/ARoot\InventoryApplication
amcache.plamcacheN/ARoot\InventoryApplicationFile
amcache.plamcacheN/ARoot\Programs
amcache_tln.plamcacheN/ARoot\File
amcache_tln.plamcacheN/ARoot\InventoryApplication
amcache_tln.plamcacheN/ARoot\InventoryApplicationFile
angelfire.plsystemN/AControlSetXXX\Control\Windows\SystemLookup
angelfire.plsystemN/ASelect
aports.plntuser.datN/AInstallPath
aports.plntuser.datN/ASoftware\SmartLine Vision\aports
appcertdlls.plsystemN/AControlSetXXX\Control\Session Manager\AppCertDlls
appcertdlls.plsystemN/ASelect
appcompatcache.plsystemN/AControlSetXXX\Control\Session Manager
appcompatcache.plsystemN/ASelect
appcompatcache_tln.plsystemN/AControlSetXXX\Control\Session Manager
appcompatcache_tln.plsystemN/ASelect
appcompatflags.plntuser.dat, softwareYesMicrosoft\Windows NT\CurrentVersion\AppCompatFlags\Custom
appcompatflags.plntuser.dat, softwareYesMicrosoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB
appcompatflags.plntuser.dat, softwareYesMicrosoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
appcompatflags.plntuser.dat, softwareYesSoftware\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
appcompatflags.plntuser.dat, softwareYesWow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
appcompatflags.plntuser.dat, softwareYesWow6432Node\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
appinitdlls.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Windows
appinitdlls.plsoftwareYesWow6432Node\Microsoft\Windows NT\CurrentVersion\Windows
appkeys.plntuser.dat, softwareNoMicrosoft\Windows\CurrentVersion\Explorer\AppKey
appkeys.plntuser.dat, softwareNoSoftware\Microsoft\Windows\CurrentVersion\Explorer\AppKey
appkeys_tln.plntuser.dat, softwareNoMicrosoft\Windows\CurrentVersion\Explorer\AppKey
appkeys_tln.plntuser.dat, softwareNoSoftware\Microsoft\Windows\CurrentVersion\Explorer\AppKey
applets.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Applets
applets_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Applets
apppaths.plsoftwareYesMicrosoft\Windows\CurrentVersion\App Paths
apppaths.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\App Paths
apppaths_tln.plsoftwareYesMicrosoft\Windows\CurrentVersion\App Paths
appspecific.plntuser.datN/ASoftware\Microsoft\IntelliPoint\AppSpecific
ares.plntuser.datN/Aaudio\.gen
ares.plntuser.datN/Agen\.gen
ares.plntuser.datN/Aimage\.gen
ares.plntuser.datN/ASoftware\Ares
ares.plntuser.datN/Avideo\.aut
ares.plntuser.datN/Avideo\.dat
ares.plntuser.datN/Avideo\.gen
ares.plntuser.datN/Avideo\.tit
arpcache.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\App Management\ARPCache
assoc.plsoftware,usrclassYesClasses
assoc.plsoftware,usrclassYesClasses\Wow6432Node
assoc.plsoftware,usrclassYesWow6432Node
at.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree
at_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree
attachmgr.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Associations
attachmgr.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Attachments
attachmgr_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Associations
attachmgr_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Attachments
audiodev.plsoftwareNoMicrosoft\Windows\CurrentVersion\MMDevices\Audio
auditfail.plsystemN/AControlSetXXX\Control\Lsa
auditfail.plsystemN/ASelect
auditpol.plsecurityN/APolicy\PolAdtEv
auditpol_xp.plsecurityN/APolicy\PolAdtEv
autoendtasks.plntuser.datN/AControl Panel\Desktop
autorun.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer
backuprestore.plsystemN/AControlSetXXX\Control\BackupRestore\FilesNotToBackup
backuprestore.plsystemN/AControlSetXXX\Control\BackupRestore\FilesNotToSnapshot
backuprestore.plsystemN/AControlSetXXX\Control\BackupRestore\KeysNotToRestore
backuprestore.plsystemN/ASelect
bam.plsystemN/AControlSetXXX\Services\bam\UserSettings
bam.plsystemN/ASelect
bam_tln.plsystemN/AControlSetXXX\Services\bam\UserSettings
bam_tln.plsystemN/ASelect
banner.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Winlogon
banner.plsoftwareNoMicrosoft\Windows\CurrentVersion\policies\system
baseline.plallN/AScans a hive file, checking sizes of binary value data
bho.plsoftwareYesMicrosoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
bho.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
bitbucket.plsoftwareNoMicrosoft\Windows\CurrentVersion\Explorer\BitBucket
bitbucket_user.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\BitBucket
brisv.plntuser.datN/ASoftware\Microsoft\MediaPlayer\Preferences
brisv.plntuser.datN/ASoftware\Microsoft\PIMSRV
btconfig.plsoftwareNoWidComm\BTConfig\Devices
bthport.plsystemN/AControlSetXXX\services\BTHPORT\Parameters\Devices
bthport.plsystemN/AControlSetXXX\services\BTHPORT\Parameters\Radio Support
bthport.plsystemN/ASelect
bthport_tln.plsystemN/AControlSetXXX\services\BTHPORT\Parameters\Devices
bthport_tln.plsystemN/ASelect
cached.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
cached_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
cain.plntuser.datN/ASoftware\Cain\Settings
ccleaner.plntuser.datN/ASoftware\Piriform\CCleaner
cdstaginginfo.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\StagingInfo
clampi.plntuser.datN/ASoftware\Microsoft\Internet Account Manager\Accounts
clampi.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Main
clampi.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
clampitm.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Settings
clsid.plsoftwareYesClasses\CLSID
clsid.plsoftwareYesClasses\Wow6432Node\CLSID
clsid_tln.plsoftwareYesClasses\CLSID
clsid_tln.plsoftwareYesClasses\Wow6432Node\CLSID
cmd_shell.plsoftwareNoClasses\<EXTENSION>file\shell\open\command
where EXTENSION is exe, cmd, bat, cs, hta, pif
cmd_shell_tln.plsoftwareNoClasses\<EXTENSION>file\shell\open\command
where EXTENSION is exe, cmd, bat, cs, hta, pif
cmd_shell_u.plusrclass.datN/A\shell\open\command
cmdproc.plntuser.datN/ASoftware\Microsoft\Command Processor
cmdproc_tln.plntuser.datN/ASoftware\Microsoft\Command Processor
codeid.plsoftwareNoPolicies\Microsoft\Windows\Safer\CodeIdentifiers
comdlg32.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
comfoo.plsystemN/ASelect
compdesc.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions
compname.plsystemN/AControlSetXXX\Control\ComputerName\ComputerName
compname.plsystemN/AControlSetXXX\Services\Tcpip\Parameters
compname.plsystemN/ASelect
controlpanel.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel
cortana.plntuser.datN/ASOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts
cpldontload.plntuser.datN/AControl Panel\don\'t load
crashcontrol.plsystemN/AControlSetXXX\Control\CrashControl
crashcontrol.plsystemN/ASelect
ctrlpnl.plsoftwareNoMicrosoft\Windows\CurrentVersion\Control Panel
dafupnp.plsystemN/AControlSetXXX\Enum\SWD\DAFUPnPProvider
dafupnp.plsystemN/ASelect
dcom.plsoftwareNoMicrosoft\Rpc\Internet
ddm.plsystemN/AControlSetXXX\Control\DDM
ddm.plsystemN/ASelect
ddo.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\DeviceDisplayObjects
decaf.plntuser.datN/ASoftware\DECAFme
defbrowser.plsoftwareNoClasses\HTTP\shell\open\command
defbrowser.plsoftwareNoClients\StartMenuInternet
del.plallN/AParse hive, print deleted keys/values
del_tln.plallN/AParse hive, print deleted keys/values
dependency_walker.plntuser.datN/ASoftware\Microsoft\Dependency Walker\Recent File List
devclass.plsystemN/AControlSetXXX\Control\DeviceClasses\{10497b1b-ba51-44e5-8318-a65c837b6661}
devclass.plsystemN/AControlSetXXX\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
devclass.plsystemN/AControlSetXXX\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
devclass.plsystemN/ASelect
dfrg.plsoftwareNoMicrosoft\Dfrg\BootOptimizeFunction
diag_sr.plsystemN/AControlSetXXX\Services\VSS\Diag\SystemRestore
diag_sr.plsystemN/ASelect
direct.plsoftwareYesMicrosoft
direct.plsoftwareYesWow6432Node\Microsoft
direct_tln.plsoftwareYesMicrosoft
direct_tln.plsoftwareYesWow6432Node\Microsoft
disablelastaccess.plsystemN/AControlSetXXX\Control\FileSystem
disablelastaccess.plsystemN/ASelect
disablemru.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Advanced
disablemru.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
disablemru.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer
disablesr.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\SystemRestore
dllsearch.plsystemN/AControlSetXXX\Control\Session Manager
dllsearch.plsystemN/ASelect
dnschanger.plsystemN/AControlSetXXX\Services\Tcpip\Parameters\Interfaces
domains.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
drivers32.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Drivers32
drivers32.plsoftwareYesWow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
drwatson.plsoftwareNoMicrosoft\DrWatson
drwatson.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\AeDebug
emdmgmt.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\EMDMgmt
environment.plntuser.datN/AEnvironment
eraser.plntuser.datN/ASoftware\Eraser\Eraser 6
esent.plsoftwareNoMicrosoft\ESENT\Process
etos.plsoftwareNoODBC.INI
etos.plsoftwareNoODBC\ODBC.INI
eventlog.plsystemN/AControlSetXXX\Services\Eventlog
eventlog.plsystemN/ASelect
eventlogs.plsystemN/AControlSetXXX\Services\Eventlog
eventlogs.plsystemN/ASelect
execpolicy.plsoftwareNoMicrosoft\PowerShell\1\ShellIds\Microsoft.Powershell
fileexts.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts
filehistory.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\FileHistory
fileless.plallN/AAll keys (all hives)
findexes.plallN/Aroot
foxitrdr.plntuser.datN/ASoftware\Foxit Software\Foxit Reader <VERSION>
fw_config.plsystemN/ASelect
gauss.plsoftwareYesMicrosoft\Windows\CurrentVersion\Reliability
gauss.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\Reliability
gpohist.plsoftwareNoMicrosoft\Windows\CurrentVersion\Group Policy\History
gpohist.plsoftwareNoSoftware\Microsoft\Windows\CurrentVersion\Group Policy\History
gpohist_tln.plsoftwareNoMicrosoft\Windows\CurrentVersion\Group Policy\History
gpohist_tln.plsoftwareNoSoftware\Microsoft\Windows\CurrentVersion\Group Policy\History
gthist.plntuser.datN/ASoftware\Google\NavClient\1.1\History
gtwhitelist.plntuser.datN/ASoftware\Google\Google Toolbar\4.0\whitelist
handler.plsoftwareNoClasses\Network\SharingHandler
haven_and_hearth.plntuser.datN/Apassword
haven_and_hearth.plntuser.datN/Asavedtoken
haven_and_hearth.plntuser.datN/ASoftware\JavaSoft\Prefs\haven
haven_and_hearth.plntuser.datN/Ausername
hibernate.plsystemN/AControlSetXXX\Control\Session Manager\Power
hibernate.plsystemN/ASelect
ide.plsystemN/AControlSetXXX\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
ide.plsystemN/AControlSetXXX\Enum\IDE
ide.plsystemN/ASelect
identities.plntuser.datN/AIdentities
ie_main.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Main
ie_settings.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Main\WindowsSearch
ie_settings.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings
ie_version.plsoftwareNoMicrosoft\Internet Explorer
ie_zones.plntuser.dat;softwareNoMicrosoft\Windows\CurrentVersion\Internet Settings
ie_zones.plntuser.dat;softwareNoSoftware\Microsoft\Windows\CurrentVersion\Internet Settings
iejava.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{8AD9C840-044E-11D1-B3E9-00805F499D93}
imagedev.plsystemN/AControlSetXXX\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
imagedev.plsystemN/ASelect
imagefile.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Image File Execution Options
imagefile.plsoftwareYesWow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
imgburn1.plntuser.datN/ASoftware\ImgBurn
init_dlls.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Windows
inprocserver.plsoftwareYesClasses\CLSID
inprocserver.plsoftwareYesClasses\Wow6432Node\CLSID
inprocserver.plsoftwareYesCLSID
inprocserver.plsoftwareYesWow6432Node\CLSID
installedcomp.plsoftwareYesMicrosoft\Active Setup\Installed Components
installedcomp.plsoftwareYesWow6432Node\Microsoft\Active Setup\Installed Components
installer.plsoftwareNoMicrosoft\Windows\CurrentVersion\Installer\UserData
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Internet Explorer
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\AutoComplete
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\DOMStorage
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\IETld
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Main
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Privacy
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery\Active
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery\AdminActive
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Recovery\PendingDelete
internet_explorer_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Suggested Sites
internet_settings_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings
internet_settings_cu.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\<SUBKEY>\History
itempos.plntuser.datN/ASoftware\Microsoft\Windows\Shell\Bags\1\Desktop
itempos.plntuser.datN/ASoftware\Microsoft\Windows\ShellNoRoam\Bags
javafx.plntuser.datN/ASoftware\JavaSoft\Java Update\Policy\JavaFX
javasoft.plsoftwareYesJavaSoft\Java Plug-in
javasoft.plsoftwareYesWow6432Node\JavaSoft\Java Plug-in
jumplistdata.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Search\JumpListData
kankan.plntuser.dat, softwareYesSoftware\Microsoft\Office
kankan.plntuser.dat, softwareYesWow6432Node\Microsoft\Office
kankan.plntuser.dat, softwareYesWow6432Node\Software\Microsoft\Office
kb950582.plsoftwareNoMicrosoft\Updates\Windows XP\SP4\KB950582
kb950582.plsoftwareNoMicrosoft\Windows\CurrentVersion\Policies\Explorer
kb950582.plsoftwareNoMicrosoft\Windows\CurrentVersion\Uninstall\KB950582
kbdcrash.plsystemN/ASelect
knowndev.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\KnownDevices
landesk.plsoftwareYesLANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLog
landesk.plsoftwareYesWow6432Node\LANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLog
landesk_tln.plsoftwareYesLANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLog
landesk_tln.plsoftwareYesWow6432Node\LANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLog
lastloggedon.plsoftwareNoMicrosoft\Windows\CurrentVersion\Authentication\LogonUI
latentbot.plntuser.datN/ASoftware\Google\Update\network\secure
latentbot.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows
lazyshell.plsoftwareYesMicrosoft\Windows\CurrentVersion\Wordpad\ComChecks\Safelist
lazyshell.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\Wordpad\ComChecks\Safelist
legacy.plsystemN/AControlSetXXX\Enum\Root
legacy.plsystemN/ASelect
legacy_tln.plsystemN/AControlSetXXX\Enum\Root
legacy_tln.plsystemN/ASelect
licenses.plsoftwareNoLicenses
listsoft.plntuser.datN/ASoftware
liveContactsGUID.plntuser.datN/ASoftware\Microsoft\Windows Live Contacts\Database
load.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows
logmein.plsoftwareYesLogMeIn\V5\PerBrowser
logmein.plsoftwareYesWow6432Node\LogMeIn\V5\PerBrowser
logmein_tln.plsoftwareYesLogMeIn\V5\PerBrowser
logmein_tln.plsoftwareYesWow6432Node\LogMeIn\V5\PerBrowser
logonstats.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\LogonStats
logonusername.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer
lsa_packages.plsystemN/AControlSetXXX\Control\LSA
lsa_packages.plsystemN/ASelect
lsasecrets.plsecurityN/APolicy\Secrets
macaddr.plsoftwareNoControlSetXXX\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}
macaddr.plsoftwareNoMicrosoft\Windows Genuine Advantage
macaddr.plsoftwareNoSelect
malware.plallN/ABegin
malware.plallN/ABINARY
malware.plallN/AClasses\BJ\Static
malware.plallN/AClasses\FAST
malware.plallN/AClasses\Network\SharingHandler
malware.plallN/AClasses\XXXX
malware.plallN/AClients\Netrau
malware.plallN/AClients\sdata
malware.plallN/AMicrosoft\HTMLHelp
malware.plallN/AMicrosoft\Rpc\Internet
malware.plallN/AMicrosoft\ShipTr
malware.plallN/AMicrosoft\ShipUp
malware.plallN/AMicrosoft\WBEM\ESS\//./root/CIMV2\Win32ClockProvider
malware.plallN/APolicies\Microsoft\Windows Defender
malware.plallN/APolicies\Microsoft\Windows Defender\Real-Time Protection
malware.plallN/APolicy\Secrets
malware.plallN/ASoftware\Adobe\Adobe ARM\1.0\ARM
malware.plallN/ASoftware\Adobe\Adobe Reader\<VERSION>\IPM
malware.plallN/ASoftware\BINARY
malware.plallN/ASoftware\Google\Update\network\secure
malware.plallN/ASoftware\Locky
malware.plallN/ASoftware\Microsoft\Clock
malware.plallN/ASoftware\Microsoft\CurrentHalInf
malware.plallN/ASoftware\Microsoft\CurrentPnpSetup
malware.plallN/ASoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
malware.plallN/ASoftware\Microsoft\Office test\Special\Perf
malware.plallN/ASoftware\Microsoft\Wbem\WMIC
malware.plallN/ASoftware\TransPan
malware.plallN/AWow6432Node\WRData\Threats\History
malware.plallN/AWRData\Threats\History
menuorder.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder
mixer.plntuser.datN/ASoftware\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
mixer_tln.plntuser.datN/ASoftware\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
mmc.plntuser.datN/ASoftware\Microsoft\Microsoft Management Console\Recent File List
mmc_tln.plntuser.datN/ASoftware\Microsoft\Microsoft Management Console\Recent File List
mmo.plntuser.datN/ASoftware\Microsoft\CTF\LangBarAddIn
mmo.plntuser.datN/ASoftware\Microsoft\Multimedia\Other
mndmru.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
mndmru_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU
mountdev.plsystemN/AMountedDevices
mountdev2.plsystemN/AMountedDevices
mp2.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
mp3.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
mpmru.plntuser.datN/ASoftware\Microsoft\MediaPlayer\Player\RecentFileList
mrt.plsoftwareNoMicrosoft\RemovalTools\MRT
msedge_win10.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLs
msedge_win10.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsTime
msedge_win10.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsVisitCount
msis.plsoftwareNoClasses\Installer\Products
mspaper.plntuser.datN/ASoftware\Microsoft
muicache.plntuser.dat,usrclass.datN/ALocal Settings\Software\Microsoft\Windows\Shell\MUICache
muicache.plntuser.dat,usrclass.datN/ASoftware\Microsoft\Windows\ShellNoRoam\MUICache
muicache_tln.plntuser.dat,usrclass.datN/ALocal Settings\Software\Microsoft\Windows\Shell\MUICache
muicache_tln.plntuser.dat,usrclass.datN/ASoftware\Microsoft\Windows\ShellNoRoam\MUICache
mzthunderbird.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\UnreadMail
nation.plntuser.datN/AControl Panel\International\Geo
nero.plntuser.datN/ACover Designer
nero.plntuser.datN/AFlmgPlg
nero.plntuser.datN/ANero PhotoSnap
nero.plntuser.datN/ANSPluginMgr
nero.plntuser.datN/APhotoEffects
nero.plntuser.datN/ASoftware\Ahead
nero.plntuser.datN/AXlmgPlg
netassist.plntuser.datN/ASoftware\Microsoft\Installer\Products\D4676621F4CF7AF46BB388D4351B86F0
netassist.plntuser.datN/ASoftware\Microsoft\Installer\Products\D4676621F4CF7AF46BB388D4351B86F0\SourceList
netassist.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Uninstall\NetAssistant
netassist.plntuser.datN/ASoftware\Mozilla\Firefox\Extensions
netsh.plsoftwareNoMicrosoft\NetSh
netsvcs.plsystemN/AControlSetXXX\Enum\Root
netsvcs.plsystemN/AControlSetXXX\Services
netsvcs.plsystemN/ASelect
network.plsystemN/AControlSetXXX\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
network.plsystemN/ASelect
networkcards.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkCards
networklist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList
networklist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet
networklist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Profiles
networklist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed
networklist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged
networklist_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList
networklist_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet
networklist_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Profiles
networklist_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed
networklist_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged
networkuid.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Network
nic.plsystemN/AControlSetXXX\Services
nic2.plsystemN/AControlSetXXX\Services\Tcpip\Parameters\Interfaces
nic_mst2.plsystemN/AControlSetXXX\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
nic_mst2.plsystemN/AControlSetXXX\Services\Tcpip\Parameters\Interfaces
nic_mst2.plsystemN/ASelect
nolmhash.plsystemN/AControlSetXXX\Control\Lsa
nolmhash.plsystemN/ASelect
ntusernetwork.plntuser.datN/ANetwork
null.plallN/ACheck key/value names in a hive for leading null char
odysseus.plntuser.datN/AProxyPort
odysseus.plntuser.datN/AProxyUpstreamHost
odysseus.plntuser.datN/AProxyUpstreamPort
odysseus.plntuser.datN/AServerCert
odysseus.plntuser.datN/AServerCertPass
odysseus.plntuser.datN/ASoftware\bindshell.net\Odysseus
officedocs.plntuser.datN/ASoftware\Microsoft\Office\<VERSION>\Common\Open Find
officedocs2010.plntuser.datN/ASoftware\Microsoft\Office\14.0
officedocs2010_tln.plntuser.datN/ASoftware\Microsoft\Office\14.0
oisc.plntuser.datN/ASoftware\Microsoft\Office\<VERSION>\Common\Internet\Server Cache
olsearch.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
opencandy.plsoftwareYesADatumCorporation\OpenCandy
opencandy.plsoftwareYesWow6432Node\ADatumCorporation\OpenCandy
osversion.plntuser.datN/ASoftware\Microsoft
osversion_tln.plntuser.datN/ASoftware\Microsoft
outlook.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
outlook2.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
pagefile.plsystemN/AControlSetXXX\Control\Session Manager\Memory Management
pagefile.plsystemN/ASelect
pending.plsystemN/AControlSetXXX\Control\Session Manager
pending.plsystemN/ASelect
phdet.plsystemN/AControlSetXXX\Services\msupdate
phdet.plsystemN/ASelect
photos.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\microsoft\.windowsphotos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
photos_win10.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp
photos_win10.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\Schemas
polacdms.plsecurityN/APolicy\PolAcDmS
polacdms.plsecurityN/APolicy\PolPrDmS
policies_u.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion
port_dev.plsoftwareNoMicrosoft\Windows Portable Devices\Devices
prefetch.plsystemN/AControlSetXXX\Control\Session Manager\Memory Management\PrefetchParameters
prefetch.plsystemN/AControlSetXXX\services\SysMain
prefetch.plsystemN/ASelect
printermru.plntuser.datN/APrinters\Settings\Wizard\ConnectMRU
printers.plntuser.datN/APrinters
printers.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\PrinterPorts
printers.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows
privoxy.plntuser.datN/ASoftware\Privoxy
processor_architecture.plsystemN/AControlSetXXX\Control\Session Manager\Environment
processor_architecture.plsystemN/ASelect
product.plsoftwareNoMicrosoft\Windows\CurrentVersion\Installer\UserData
productpolicy.plsystemN/AControlSetXXX\Control\ProductOptions
producttype.plsystemN/AControlSetXXX\Control\ProductOptions
producttype.plsystemN/ASelect
profilelist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\ProfileList
profilelist.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Winlogon
profiler.plntuser.dat, systemN/AControlSetXXX\Control\Session Manager\Environment
profiler.plntuser.dat, systemN/AEnvironment
proxysettings.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings
psscript.plsoftwareNoMicrosoft\Windows\CurrentVersion\Group Policy\Scripts\Startup\0\0
psscript.plsoftwareNoMicrosoft\Windows\CurrentVersion\Group Policy\State\Machine\Scripts\Startup\0\0
publishingwizard.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\PublishingWizard\AddNetworkPlace\AddNetPlace\LocationMRU
putty.plntuser.datN/ASoftware\SimonTatham\PuTTY\SshHostKeys
putty_sessions.plntuser.datN/ASoftware\SimonTatham\PuTTY\Sessions
rdphint.plntuser.datN/ASoftware\Microsoft\Terminal Server Client\Servers
rdpnla.plsystemN/AControlSetXXX\Control\Terminal Server\WinStations\RDP-Tcp
rdpport.plsystemN/AControlSetXXX\Control\Terminal Server\WinStations\RDP-Tcp
reading_locations.plntuser.datN/ASoftware\Microsoft\Office\15.0\Word\Reading Locations
realplayer6.plntuser.datN/ASoftware\RealNetworks\RealPlayer\6.0\Preferences
realvnc.plntuser.datN/ASoftware\RealVNC\VNCViewer4\MRU
recentapps.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Search\RecentApps
recentapps_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Search\RecentApps
recentdocs.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
recentdocs_timeline.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
recentdocs_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
regback.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks
regback.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Registry\RegIdleBackup
regin.plsystemN/ASelect
regtime.plallN/A(Entire Hive)
regtime_tln.plallN/A(Entire Hive)
remoteaccess.plsystemN/AControlSetXXX\services\RemoteAccess\Parameters\AccountLockout
remoteaccess.plsystemN/ASelect
removdev.plsoftwareNoMicrosoft\Windows Portable Devices\Devices
renocide.plsoftwareNoMicrosoft\DRM\amty
reveton.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Main
reveton.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Toolbar
reveton.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
reveton.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Policies\System\
reveton.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Run
reveton.plntuser.datN/ASoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
rlo.plallN/AParse hive, check key/value names for RLO character
rootkit_revealer.plntuser.datN/AEulaAccepted
rootkit_revealer.plntuser.datN/ASoftware\Sysinternals\RootkitRevealer
routes.plsystemN/AControlSetXXX\Services\Tcpip\Parameters\PersistentRoutes
routes.plsystemN/ASelect
runmru.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
runmru_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
safeboot.plsystemN/AControlSetXXX\Control\SafeBoot
safeboot.plsystemN/ASelect
samparse.plsamN/ASAM\Domains\Account\Users
samparse.plsamN/ASAM\Domains\Builtin\Aliases
samparse_tln.plsamN/ASAM\Domains\Account\Users
sbs.plsoftwareYesMicrosoft\Windows\CurrentVersion\SideBySide
sbs.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\SideBySide
schedagent.plsoftwareNoMicrosoft\SchedulingAgent
searchscopes.plntuser.datN/ASoftware\Microsoft\Internet Explorer\SearchScopes
secctr.plsoftwareNoMicrosoft\Security Center
secrets.plsecurityN/APolicy\Secrets
secrets_tln.plsecurityN/APolicy\Secrets
securityproviders.plsystemN/AControlSetXXX\Control\SecurityProviders
securityproviders.plsystemN/ASelect
services.plsystemN/AControlSetXXX\Services
services.plsystemN/ASelect
sevenzip.plntuser.datN/ASoftware\7-Zip
sevenzip.plntuser.datN/ASoftware\Wow6432Node\7-Zip
sfc.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\Winlogon
sfc.plsoftwareNoPolicies\Microsoft\Windows NT\Windows File Protection
shares.plsystemN/AControlSetXXX\Services\LanmanServer\Shares
shc.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\UFH\SHC
shellactivities.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\CloudStore\Store\Cache\DefaultAccount\$$windows.data.taskflow.shellactivities\Current
shellbags.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\Shell\BagMRU
shellbags_test.plusrclass.datN/ASoftware\Microsoft\Windows\ShellNoRoam\Bags\<NODESLOT>\Shell
shellbags_tln.plusrclass.datN/ALocal Settings\Software\Microsoft\Windows\Shell\BagMRU
shellbags_xp.plntuser.datN/ASoftware\Microsoft\Windows\ShellNoRoam\BagMRU
shellexec.plsoftwareYesMicrosoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
shellexec.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
shellext.plsoftwareNoMicrosoft\Windows\CurrentVersion\Shell Extensions\Approved
shellfolders.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
shelloverlay.plsoftwareNoMicrosoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
shimcache.plsystemN/A\Control\Session Manager
shimcache_tln.plsystemN/A\Control\Session Manager
shutdown.plsystemN/AControlSetXXX\Control\Windows
shutdown.plsystemN/ASelect
shutdowncount.plsystemN/AControlSetXXX\Control\Watchdog\Display
shutdowncount.plsystemN/ASelect
silentprocessexit.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\SilentProcessExit
silentprocessexit_tln.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\SilentProcessExit
sizes.plallN/AAll keys (all hives)
skype.plntuser.datN/ASoftware\Skype
slack.plallN/ALook for Slack space
snapshot.plsoftwareNoMicrosoft\Internet Explorer
snapshot_viewer.plntuser.datN/ASoftware\Microsoft\Snapshot Viewer\Recent File List
soft_run.plsoftwareYesMicrosoft\Windows\CurrentVersion\Run
source_os.plsystemN/ASetup
spp_clients.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\SPP\Clients
sql_lastconnect.plsoftwareNoMicrosoft\MSSQLServer\Client\SuperSocketNetLib\LastConnect
srun_tln.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
srun_tln.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce
srun_tln.plsoftwareYesMicrosoft\Windows\CurrentVersion\Policies\Explorer\Run
srun_tln.plsoftwareYesMicrosoft\Windows\CurrentVersion\Run
srun_tln.plsoftwareYesMicrosoft\Windows\CurrentVersion\RunOnce
srun_tln.plsoftwareYesMicrosoft\Windows\CurrentVersion\RunServices
srun_tln.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
srun_tln.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\Run
srun_tln.plsoftwareYesWow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
ssh_host_keys.plunknownN/ASoftware\Martin Prikryl\WinSCP 2\SshHostKeys
ssid.plsoftwareNoMicrosoft\EAPOL\Parameters\Interfaces
ssid.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\NetworkCards
ssid.plsoftwareNoMicrosoft\WZCSVC\Parameters\Interfaces
startmenuinternetapps_cu.plntuser.datN/ASoftware\Clients
startmenuinternetapps_lm.plsoftwareNoClients
startpage.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\StartPage
startup.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
startup.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
stillimage.plsystemN/AControlSetXXX\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
stillimage.plsystemN/AControlSetXXX\Control\StillImage\Logging
stillimage.plsystemN/ASelect
susclient.plsoftwareNoMicrosoft\Windows\CurrentVersion\WindowsUpdate
svc.plsystemN/AControlSetXXX\Services
svc.plsystemN/ASelect
svc_plus.plsystemN/AControlSetXXX\Services
svc_plus.plsystemN/ASelect
svc_tln.plsystemN/AControlSetXXX\Services
svc_tln.plsystemN/ASelect
svcdll.plsystemN/AControlSetXXX\Services
svcdll.plsystemN/ASelect
svchost.plsoftwareNoMicrosoft\Windows NT\CurrentVersion\SvcHost
sysinternals.plntuser.datN/ASoftware\SysInternals
sysinternals_tln.plntuser.datN/ASoftware\SysInternals
systemindex.plsoftwareNoMicrosoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths
teamviewer.plsoftwareYesTeamViewer
teamviewer.plsoftwareYesWow6432Node\TeamViewer
termcert.plsystemN/AControlSetXXX\Services\TermService\Parameters
termcert.plsystemN/ASelect
termserv.plsystemN/AControlSetXXX\Control\Terminal Server
termserv.plsystemN/ASelect
thunderbirdinstalled.plsoftware,ntuser.datYesMicrosoft\Windows\CurrentVersion\App Paths\thunderbird.exe
thunderbirdinstalled.plsoftware,ntuser.datYesWOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\thunderbird.exe
timezone.plsystemN/AControlSetXXX\Control\TimeZoneInformation
timezone.plsystemN/ASelect
tracing.plsoftwareYesMicrosoft\Tracing
tracing_tln.plsoftwareYesMicrosoft\Tracing
trappoll.plsoftwareNoMicrosoft\RFC1156Agent\CurrentVersion\Parameters
trustrecords.plntuser.datN/ASoftware\Microsoft\Office\<VERSION>\<OFFICE_APP>
where VERSION depends on Office version
and OFFICE_APP is: Word, PowerPoint, Excel, Access
trustrecords_tln.plntuser.datN/ASoftware\Microsoft\Office\<VERSION>\<OFFICE_APP>
where VERSION depends on Office version
and OFFICE_APP is: Word, PowerPoint, Excel, Access
tsclient.plntuser.datN/ASoftware\Microsoft\Terminal Server Client\Default
tsclient.plntuser.datN/ASoftware\Microsoft\Terminal Server Client\Servers
tsclient_tln.plntuser.datN/ASoftware\Microsoft\Terminal Server Client\Default
tsclient_tln.plntuser.datN/ASoftware\Microsoft\Terminal Server Client\Servers
typedpaths.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
typedpaths_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
typedurls.plntuser.datN/ASoftware\Microsoft\Internet Explorer\TypedURLs
typedurls_tln.plntuser.datN/ASoftware\Microsoft\Internet Explorer\TypedURLs
typedurlstime.plntuser.datN/ASoftware\Microsoft\Internet Explorer\TypedURLsTime
typedurlstime_tln.plntuser.datN/ASoftware\Microsoft\Internet Explorer\TypedURLsTime
uac.plsoftwareNoMicrosoft\Windows\CurrentVersion\policies\system
uninstall.plsoftware, ntuser.datYesMicrosoft\Windows\CurrentVersion\Uninstall
uninstall.plsoftware, ntuser.datYesSoftware\Microsoft\Windows\CurrentVersion\Uninstall
uninstall.plsoftware, ntuser.datYesWow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
uninstall_tln.plsoftware, ntuser.datYesMicrosoft\Windows\CurrentVersion\Uninstall
uninstall_tln.plsoftware, ntuser.datYesSoftware\Microsoft\Windows\CurrentVersion\Uninstall
uninstall_tln.plsoftware, ntuser.datYesWow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
unreadmail.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\UnreadMail
updates.plsoftwareNoMicrosoft\Windows\CurrentVersion\Component Based Servicing\Packages
urlzone.plsoftwareNoMicrosoft\Windows\CurrentVersion\Internet Settings\urlzone
urun_tln.plntuser.datN/Aappdata
urun_tln.plntuser.datN/Aapplication data
urun_tln.plntuser.datN/Aglobalroot
urun_tln.plntuser.datN/Arecycle
urun_tln.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows
urun_tln.plntuser.datN/Asystem volume information
urun_tln.plntuser.datN/Atemp
usb.plsystemN/AControlSetXXX\Enum\USB
usb.plsystemN/ASelect
usbdevices.plsystemN/AControlSetXXX\Enum\USB
usbdevices.plsystemN/ASelect
usbstor.plsystemN/AControlSetXXX\Enum\USBStor
usbstor.plsystemN/ASelect
usbstor2.plsystemN/AControlSetXXX\Control\ComputerName\ComputerName
usbstor2.plsystemN/AControlSetXXX\Enum\USBStor
usbstor2.plsystemN/AMountedDevices
usbstor2.plsystemN/ASelect
usbstor3.plsystemN/AControlSetXXX\Enum\USBStor
usbstor3.plsystemN/ASelect
user_run.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows
user_win.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Windows
userassist.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
userassist_tln.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
userinfo.plntuser.datN/ASoftware\Microsoft\Office\Common
userlocsvc.plntuser.datN/ASoftware\Microsoft\User Location Service\Client
utorrent.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
vawtrak.plntuser.datN/ASoftware\Microsoft\Internet Explorer\Main
vawtrak.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
vawtrak.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Run
vawtrak.plntuser.datN/ASoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
virut.plsoftwareNoMicrosoft\Windows\CurrentVersion\Explorer
vista_bitbucket.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\BitBucket
vmplayer.plntuser.datN/ASoftware\VMware, Inc.\VMware Player\VMplayer\Window position
vmware_vsphere_client.plntuser.datN/ASoftware\VMware\VMware Infrastructure Client\Preferences
vnchooksapplicationprefs.plntuser.datN/ASoftware\ORL\VNCHooks\Application_Prefs
vncviewer.plntuser.datN/ASoftware\ORL\VNCviewer\MRU
vncviewer.plntuser.datN/ASoftware\RealVNC\VNCViewer4\MRU
volinfocache.plsoftwareNoMicrosoft\Windows Search\VolumeInfoCache
wallpaper.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
warcraft3.plntuser.datN/ASoftware\Blizzard Entertainment\Warcraft III\String
warcraft3.plntuser.datN/Auserbnet
warcraft3.plntuser.datN/Auserlocal
wbem.plsoftwareNoMicrosoft\WBEM\WDM
win_cv.plsoftwareNoMicrosoft\Windows\CurrentVersion
winbackup.plsoftwareNoMicrosoft\Windows\CurrentVersion\WindowsBackup\ScheduleParams\TargetDevice
winbackup.plsoftwareNoMicrosoft\Windows\CurrentVersion\WindowsBackup\Status
winevt.plsoftwareNoMicrosoft\Windows\CurrentVersion\WINEVT\Channels
winlogon.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Winlogon
winlogon.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
winlogon.plsoftwareYesWow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon
winlogon_tln.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Winlogon
winlogon_tln.plsoftwareYesMicrosoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
winlogon_tln.plsoftwareYesWow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon
winlogon_u.plntuser.datN/ASoftware\Microsoft\Windows NT\CurrentVersion\Winlogon
winlogon_u.plntuser.datN/ASoftware\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon
winnt_cv.plsoftwareNoMicrosoft\Windows NT\CurrentVersion
winrar.plntuser.datN/ASoftware\WinRAR\ArcHistory
winrar2.plntuser.datN/ASoftware\WinRAR\DialogEditHistory\ExtrPath
winrar_tln.plntuser.datN/ASoftware\WinRAR\ArcHistory
winscp.plntuser.datN/ASoftware\Martin Prikryl\WinSCP 2
winscp_sessions.plunknownN/ASoftware\Martin Prikryl\WinSCP 2\Sessions
winver.plsoftwareNoMicrosoft\Windows NT\CurrentVersion
winvnc.plntuser.datN/ASoftware\RealVNC\Default
winzip.plntuser.datN/ASoftware\Nico Mak Computing\WinZip
wordwheelquery.plntuser.datN/ASoftware\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
wpdbusenum.plsystemN/AControlSetXXX\Control\DeviceClasses\{10497b1b-ba51-44e5-8318-a65c837b6661}
wpdbusenum.plsystemN/AControlSetXXX\Enum\WpdBusEnumRoot
wpdbusenum.plsystemN/ASelect
wsh_settings.plsoftwareNoMicrosoft\Windows Script Host\Settings
xpedition.plsystemN/AWPA\TabletPC
yahoo_cu.plntuser.datN/ASoftware\Yahoo\pager
yahoo_lm.plsoftwareNoYahoo