Code: Select all
1=HKEY_CURRENT_USER\SessionInformation
2=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop
3=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar
4=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Protected Storage System Provider
5=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
6=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable
7=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
8=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
9=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
10=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
11=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
12=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache
13=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
14=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\BagMRU
15=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags
16=HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ShellNoRoam
17=HKEY_CURRENT_USER\Volatile Environment
18=HKEY_LOCAL_MACHINE\HARDWARE
19=HKEY_LOCAL_MACHINE\SAM
20=HKEY_LOCAL_MACHINE\SECURITY
21=HKEY_LOCAL_MACHINE\SYSTEM\Clone
22=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
23=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002
24=HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003
25=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class
26=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit
27=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power
28=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dhcp
29=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache
30=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxDAV
31=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip
32=HKEY_LOCAL_MACHINE\SYSTEM\Setup
33=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll
34=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ocx
35=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sys
36=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\certificate_wab_auto_file
37=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\certificatefile
38=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CertificateStoreFile
39=HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Charset
40=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG
41=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DrWatson
42=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EventSystem
43=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\BROWSE\USEBHO
44=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Remote Desktop\Pending Help Session
45=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc
46=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates
47=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TShoot\TroubleshooterList
48=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates
49=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM
50=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
51=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\NSCookieUpgrade
52=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents
53=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ActiveX Cache
54=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedBehaviors
55=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedDragImageExts
56=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedDragProtocols
57=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache
58=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
59=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters
60=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Last Update
61=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
62=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\NoFileLifetimeExtension
63=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
64=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Passport
65=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\PluggableProtocols
66=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SafeSites
67=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Secure Mime Handlers
68=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SO
69=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SOIEAK
70=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Subscription Folder
71=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies
72=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Unattend
73=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
74=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp
75=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
76=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
77=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability
78=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
79=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate
80=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
81=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE
82=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache
83=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Compatibility\Applications\_MSSETUP
84=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Compatibility\Applications\_MSTEST
85=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Compatibility\Applications\WSVERIFY
86=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
87=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search
88=HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSec
89=HKEY_USERS\*\Software\Microsoft\Protected Storage System Provider
90=HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam
91=HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam