C:\Users\xihale\AppData\Local\Temp\QzoneMusic.exe
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\css\bootstrap.css
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\css\popup.css
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\fonts\glyphicons-halflings-regular.eot
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\fonts\glyphicons-halflings-regular.svg
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\fonts\glyphicons-halflings-regular.ttf
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\fonts\glyphicons-halflings-regular.woff
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\fonts\glyphicons-halflings-regular.woff2
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\img\check.png
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\img\close.png
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\img\dev.png
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\img\disoption.png
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\img\option.png
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\img\remove.png
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\js\background.js
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\js\bootstrap.js
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\js\jquery.js
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\js\popup.js
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\js\system.js
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\popup.html
C:\Users\xihale\AppData\Local\Temp\scoped_dir9756_1989772700\CRX_INSTALL\_metadata\verified_contents.json
C:\Users\xihale\AppData\Local\Temp\Temp1_Office_Tool_v8.2.zip\Office Tool\Office Tool Plus.exe
C:\Users\xihale\AppData\Local\Temp\wct64CF.tmp
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1028\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1028\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1029\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1029\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1031\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1031\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1036\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1036\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1040\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1040\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1041\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1041\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1042\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1042\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1045\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1045\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1046\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1046\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1049\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1049\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1055\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\1055\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\2052\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\2052\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\3082\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\3082\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\BootstrapperApplicationData.xml
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\license.rtf
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\logo.png
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\thm.wxl
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\thm.xml
C:\Users\xihale\AppData\Local\Temp\{5AB636EB-61CA-4E27-A088-5753C28675F7}\.ba\wixstdba.dll
C:\Windows\temp\wct549C.tmp
C:\Windows\temp\wct6C8.tmp
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\2[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\aria-web-telemetry-2.8.2.min[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\b016bj9yb[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\common[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\completenojavas[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\complete_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\daagave-boot[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\daagave-vertical[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\favicon-16x16-aedbfeac[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\favicon-32x32-04b7d908[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\icon_down[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\Java3BillDevices_EN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\l10n[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\l10n[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\layout[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\LocStrings[1].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\LocStrings[2].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\masthead_fill[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\masthead_fill[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\masthead_left[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\masthead_left[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\outlook-createpoll-new-16[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\outlook-createpoll-new-80[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\Outlook_32pxby32px__24png__0296aa[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\outlook_strings[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\PreSignInSettingsConfig[1].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\progress[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\progress_bg_right[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\progress_fg_left[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\progress_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\toptraffic[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\tree[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\welcome[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\1D1075XB\welcome_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\21.109.0530[2].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\common[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\common[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\complete_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\daagave-core[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\gl[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\host[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\iAVdonx0egb[2].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\iOnrSnw547g[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\Java3BillDevices_EN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\jquery-1.10.2.min[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\l10n[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\layout[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\masthead_left[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\masthead_left[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\MicrosoftAjax[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\office_strings[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\onenotev2-logo16x16[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\outlook-createpoll-new-32[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\Outlook_16x16_16px__64c8d8[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\Outlook_80x80_80px__64c8d8[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\progress_bg_fill[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\progress_bg_left[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\progress_bg_right[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\progress_fg_right[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\RRI1KD88.htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\runtime[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\style[1].css
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\Teams_Logo_80x80[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\Vertical-Advanced[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\weixin[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\welcome[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\welcome[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\welcome_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\2AM51C1R\welcome_zh_CN[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\21.109.0530[1].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\analytics[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\app_icon[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\check[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\check[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\common[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\common[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\completenojavas_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\complete[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\copy[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\gl[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\HD8JG0KZ.htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\HighResolutionIcon64px__64c8d8[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\host[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\host[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\l10n[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\onenotev2-logo32x32[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\onenotev2-logo48x48[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\onenotev2-logo80x80[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\oteljs_agave[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\outlook-win32-16.02[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\progress_bg_fill[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\progress_bg_left[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\progress_fg_fill[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\progress_fg_right[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\qq[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\RelatedSearch[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\rtutils[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\rtutils[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\runtime[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\settings-tipset[1].xml
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\update50[1].xml
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\Vertical[1].css
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\weixin_250x250[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\36DV2KSR\windows-app-web-link[1].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\19.043.0304[1].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\21.109.0530[1].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\21.109.0530[2].json
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\2[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\360zipupd[1].cab
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\app_icon_large[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\check[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\complete[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\fn[1].htm
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\host[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\icon_eyuyan[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\icon_file[1].gif
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\layout[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\layout[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\masthead_fill[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\masthead_fill[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\office[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\onenote-icon64x64[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\onenote-icon80x80[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\onenotev2-logo25x25[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\outlook-createpoll-new-80[1].png
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\progress[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\progress_fg_fill[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\progress_fg_left[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\progress_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\rtutils[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\rtutils[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\runtime[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\runtime[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\runtime[2]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\vendor[1].js
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\voldev[1].jpg
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\welcome[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\welcome_zh_CN[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\H33K85XY\x[1]
C:\Users\xihale\AppData\Local\Microsoft\Windows\INetCache\IE\container.dat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRULegacy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\backup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
C:\Windows\DtcInstall.log
C:\Windows\lsasetup.log
C:\Windows\PFRO.log
C:\Windows\setupact.log
C:\Windows\setuperr.log
C:\Windows\Debug\PASSWD.LOG
C:\Windows\Debug\sammui.log
C:\Windows\security\logs\scesetup.log
C:\Windows\SoftwareDistribution\ReportingEvents.log
C:\Windows\Logs\CBS\CBS.log
C:\Windows\Logs\DISM\dism.log
C:\Windows\Logs\DPX\setupact.log
C:\Windows\Logs\DPX\setuperr.log
C:\Windows\Logs\MeasuredBoot\0000000001-0000000000.log
C:\Windows\Logs\MeasuredBoot\0000000002-0000000000.log
C:\Windows\Logs\MeasuredBoot\0000000003-0000000000.log
C:\Windows\Logs\MeasuredBoot\0000000004-0000000000.log
C:\Windows\Logs\MeasuredBoot\0000000004-0000000001.log
C:\Windows\Logs\MeasuredBoot\0000000004-0000000002.log
C:\Windows\Logs\MeasuredBoot\0000000004-0000000003.log
C:\Windows\Logs\MoSetup\ActionList.xml
C:\Windows\Logs\MoSetup\DeviceInventory.xml
C:\Windows\Logs\MoSetup\UpdateAgent.log
C:\Windows\Logs\NetSetup\service.0.etl
C:\Windows\Logs\SIH\SIH.20210703.215336.381.1.etl
C:\Windows\Logs\SIH\SIH.20210707.154529.223.1.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_134959_494.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_135319_744.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_140006_490.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_140257_730.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_141120_392.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_141912_258.etl
C:\Windows\Logs\waasmedic\waasmedic.20210703_143346_789.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_004357_777.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_023440_928.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_024747_951.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_032129_144.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_044106_500.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_052020_208.etl
C:\Windows\Logs\waasmedic\waasmedic.20210704_053236_896.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_074801_305.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_074949_150.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_075120_516.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_075222_364.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_075421_628.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_075556_159.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_080301_531.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_080504_229.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_080613_914.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_080738_427.etl
C:\Windows\Logs\waasmedic\waasmedic.20210707_081231_241.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.140.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.141.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.142.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.143.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.144.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.145.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.146.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.147.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.148.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.149.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.150.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.151.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.152.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.153.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.154.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.155.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.156.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.157.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.158.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.159.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.160.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.161.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.162.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.163.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.164.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.165.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.166.etl
C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20210704.133237.531.167.etl
C:\Windows\Logs\WinREAgent\diagerr.xml
C:\Windows\Logs\WinREAgent\diagwrn.xml
C:\Windows\Logs\WinREAgent\setupact.log
C:\Windows\Logs\WinREAgent\setuperr.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\WebCache\V01.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\WebCache\V0100012.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\WebCache\V0100013.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb00001.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb00002.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb00003.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\metastore\edbtmp.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb00001.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb00002.log
C:\Users\xihale\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edbtmp.log
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
C:\Windows\inf\setupapi.dev.log
C:\Windows\Panther\UnattendGC\diagerr.xml
C:\Windows\Panther\UnattendGC\diagwrn.xml
C:\Windows\Panther\UnattendGC\setupact.log
C:\Windows\Panther\UnattendGC\setuperr.log
C:\Windows\Panther\appcompat.xml
C:\Windows\Panther\appcompat_detailed.htm
C:\Windows\Panther\cbs.log
C:\Windows\Panther\Contents0.dir
C:\Windows\Panther\Contents1.dir
C:\Windows\Panther\DDACLSys.log
C:\Windows\Panther\diagerr.xml
C:\Windows\Panther\diagwrn.xml
C:\Windows\Panther\MainQueueOnline0.que
C:\Windows\Panther\MainQueueOnline1.que
C:\Windows\Panther\setup.etl
C:\Windows\Panther\setupact.log
C:\Windows\Panther\setuperr.log
C:\Windows\Panther\setupinfo
C:\Windows\Panther\_s_5F95.tmp
C:\Windows\Panther\_s_6515.tmp
C:\Windows\Panther\_s_6777.tmp
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\GfxDownloadWrapper.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\IGCCTray.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\LocalBridge.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\v2rayN.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Notepad++_.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\powershell.exe.log
C:\Users\xihale\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Updater.exe.log
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\NGenTask.exe.log
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\rundll32.exe.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb0003A.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb0003B.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb0003C.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb0003D.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb0003E.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb0003F.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00040.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00041.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00042.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00043.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00044.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00045.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00046.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00047.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00048.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edb00049.log
C:\Windows\SoftwareDistribution\DataStore\Logs\edbtmp.log
C:\Windows\System32\LogFiles\CloudFiles\CldFlt0.etl
C:\Windows\System32\LogFiles\CloudFiles\CldFlt1.etl
C:\Windows\System32\LogFiles\CloudFiles\CldFlt2.etl
C:\Windows\System32\LogFiles\Scm\SCM.EVM
C:\Windows\System32\LogFiles\Scm\SCM.EVM.1
C:\Windows\System32\LogFiles\Scm\SCM.EVM.2
C:\Windows\System32\LogFiles\Scm\SCM.EVM.3
C:\Windows\System32\LogFiles\Scm\SCM.EVM.4
C:\Windows\System32\LogFiles\WMI\CloudExperienceHostOobe.etl.001
C:\Windows\System32\LogFiles\WMI\CloudExperienceHostOobe.etl.002
C:\Windows\System32\LogFiles\WMI\CloudExperienceHostOobe.etl.003
C:\Windows\System32\LogFiles\WMI\CloudExperienceHostOobe.etl.004
C:\Windows\System32\LogFiles\WMI\LwtNetLog.etl
C:\Windows\System32\LogFiles\WMI\Microsoft-Windows-Rdp-Graphics-RdpIdd-Trace.etl
C:\Windows\System32\LogFiles\WMI\NetCore.etl
C:\Windows\System32\LogFiles\WMI\NtfsLog.etl
C:\Windows\System32\LogFiles\WMI\RadioMgr.etl
C:\Windows\System32\LogFiles\WMI\SpoolerLogger.etl.001
C:\Windows\System32\LogFiles\WMI\SpoolerLogger.etl.002
C:\Windows\System32\LogFiles\WMI\SpoolerLogger.etl.003
C:\Windows\System32\LogFiles\WMI\SpoolerLogger.etl.004
C:\Windows\System32\LogFiles\WMI\Wifi.etl
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\NGenTask.exe.log
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\OneApp.IGCC.WinService.exe.log
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.log
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\RemoteFXvGPUDisablement.exe.log
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\taskhostw.exe.log
C:\Windows\System32\catroot2\dberr.txt
C:\Windows\System32\catroot2\edb.log
C:\Windows\System32\catroot2\edb00001.log
C:\Windows\System32\catroot2\edbtmp.log
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_coodesker-x64.ex_88d836464855631e6e416b413ccae4757646adb8_470510f0_63185862-1cb8-4529-bd80-c87fd35eab6a\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_e.exe_474c2b8f756de2692c59ea1cab31d2ce26492469_4530a6b3_5f7f29ff-4965-48c3-ad16-b3aa4ae8272a\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_msedge.exe_9c8b54ad79469e6eea6d6db22a851443393f5d_00000000_0b3ba237-57fd-4df0-8605-6d95f64787c6\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;ScanForUp_5e5fdadbb356fdb476b81414ebbb64299612f41_00000000_58b114a2-ca35-4ac5-a24e-ebacdbab57fa\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;ScanForUp_88a42c9350fb3041d3a63f14b8fb50575054ff63_00000000_c45b3ca6-2197-4ae9-9d7e-22dad9f6c372\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;ScanForUp_8bb1bc289f6a9027cb2d313e9e4e20efa6d3b0fc_00000000_d5280d7a-42c5-4abb-bfeb-d0eda27c7847\Report.wer
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Update;ScanForUp_962136ed3a442759f1e9a24ba2a67733659c542_00000000_b7e87821-09bc-43ad-bcca-2d14de07ad84\Report.wer
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_1280.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_1920.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_2560.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_768.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_96.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_custom_stream.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_exif.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_sr.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide_alternate.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1280.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_16.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1920.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_2560.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_768.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_custom_stream.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_exif.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_wide.db
C:\Users\xihale\AppData\Local\Microsoft\Windows\Explorer\thumbcache_wide_alternate.db
C:\Users\xihale\AppData\Local\IconCache.db
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs|url1
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\1.1-17.10.30-release.tar.gz.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\20210613_222902.mp4.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\bilibili插图.png.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\bilibili插图.psd.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\Compressed.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\DnsPod.txt.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\https--xihale-my.sharepoint.com-personal-xihale_xihale_top-.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\https--xihale-my.sharepoint.com-personal-xihale_xihale_top-_layouts-15-onedrive.aspxview=5.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\inet_download_manager_6.35.8.zip.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\Internet.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\IXCM工作室成员档案2021第暑期集中办公期间(1).docx.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\Lanzou.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\lanzous.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\link.ini.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\main.py.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay---.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\ms-gamingoverlay--startuptips-TitleId=1791712750&ProcessId=13228&WindowId=788494.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\ms-settingsconnecteddevices.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\ms-settingsdefaultapps.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\ms-settingsnetwork.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\ms-settingswindowsupdate.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\Office_Tool_v8.2.zip.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\OneDrive - xihale.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\pngs.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\Ps-test.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\simpler_dark.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\timg.jpg.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\timg1.jpg.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\tools.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\windowsdefender--threat-.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\三丰云.png.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\下载.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\修改版.e.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\右键安装.inf.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\新建文件夹.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\蓝凑云.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\蓝奏多包下载.e.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\酷呆桌面1.backup.lnk
C:\Users\xihale\AppData\Roaming\Microsoft\Windows\Recent\酷呆桌面3.backup.lnk
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.aspx?view=5
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.backup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.docx
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.e
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.gz
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.inf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.ini
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.jpg
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.mp4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.png
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.psd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.py
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.txt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.zip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\Folder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU|a
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU|MRUList
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{1BCF58F3-B2B1-4DB2-9D33-A84BC99AFE7C}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{20924622-8016-4D73-9CFA-D83DC1640AD6}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{227C2CCB-8A9A-4CD0-987A-78A93EE2A83F}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{2B24BA47-26C2-41C4-B21E-7D271C077D07}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3EBFB56F-516F-4A39-B21D-DB4CBBE53F03}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3FB9E875-C2F1-4D10-9900-FF73F6013800}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3FDCE4DA-F9B8-483F-B5DE-09D2F9C033BE}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{49EEE960-590D-4721-8213-99223F582474}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{4B2FEC2D-78BF-4E85-8E28-DFF36D9A58D3}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{4CCD0D32-AB29-4F26-8B2D-F37A012C0A08}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{517D7D2E-C70D-442E-B9CC-3FF75287326F}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{546B54E3-31D0-459D-9891-9BCF3AF3550C}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{5761B008-E73A-4005-A280-3EEB35F275B3}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{618BFC3E-0527-43B6-BA50-7F81EC3F79C1}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{7806D5EA-1B27-479D-AAC9-DD352175EC3B}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{7CE00937-6A42-4B69-837B-9BA5FF848BE9}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{84BA5FAE-1F1A-44C3-B808-CACAEC8FBCFB}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{877F640B-CB74-489F-B8B6-225E8EBDDAD7}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{8AAD151E-F239-40BA-A10C-C4407139B9BF}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{8E9243B1-74A0-41F8-AB28-895E12F0C65E}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{95891EAE-A54B-48CC-B8FA-A7A5F0E1FF6E}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A10471C8-2665-41AF-95E3-E1788CEEBE21}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A1BCA2F7-D0D4-47DE-8F6A-52BE45063CBF}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A28E7043-6FF0-4727-B9E5-E440B39CD253}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A3D9A146-72A3-48CE-A68B-A0E4669C963C}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{B9B3000B-1DA6-4EDF-977E-79E039E774FB}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{BC59CB56-5DD3-425A-A686-FCEE1E10F54E}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{C0BCE1B3-7EFE-43AE-9C99-CAD1893EECBA}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{CB722497-DFD3-40AC-9C46-14F79A631293}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{D4BF22BF-DB77-431C-BCDD-B7D22A95A576}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{D56BB29B-CA9D-4D2E-B4A6-BD43688769F3}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{D7A8AD15-73A0-4D8C-9B64-083B6358691E}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{DDFE671E-B87E-45D2-9FCA-6E12C0779CE1}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{E1BECC77-08CE-4CE3-8ACF-48F6D4F28D90}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{E580B782-B52E-4651-B0DA-4FFE089D1683}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{E887E357-0E6D-4202-97FD-EFF3439D3C19}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F1C31CF4-F844-4B5E-9740-5B20F63ED6FA}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F4C9B81C-AF42-4C42-B6BF-FF706EE66192}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F6013013-6CA3-4AFC-BE09-A95EAFDA86EE}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{FB1795D8-E750-4D8D-BF79-B2B337F90062}
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{FB8B27B7-627D-46AE-8E28-D3855DCA2752}
C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20210703-215000.log
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-20201119-074910.log
C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-360A4C039C93CFC7562D3229715C562F15564063.bin
C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin
C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20210703-215000-00000003-ffffffff.bin
C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20210703-215207-00000003-ffffffff.bin
C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20210703-220919-00000003-ffffffff.bin
C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20210703-221709-00000003-ffffffff.bin
C:\Users\xihale\AppData\Local\Microsoft\OneDrive\logs\Personal\SyncDiagnostics.log
C:\Users\xihale\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceArchive.0211.0002-1.etl
C:\Users\xihale\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceArchive.0304.0013-0.etl
C:\Users\xihale\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceCurrent.0211.0002.etl
C:\Users\xihale\AppData\Roaming\Microsoft\Office\Recent\index.dat
C:\Users\xihale\AppData\Roaming\Microsoft\Office\Recent\IXCM工作室成员档案2021第暑期集中办公期间(1).docx.LNK
C:\Users\xihale\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK
C:\Users\xihale\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\10A9C4F0-49A2-4EE5-8364-FF27499EBB7C
C:\Users\xihale\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1AA6E0D8-CEAD-4608-AE03-A4DCD4FF3C50
C:\Users\xihale\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD2CB25A-A3CB-45DB-9CF9-29F77D0903D4
C:\Users\xihale\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\ogma.osi.office.net\7F67FC9C-B90F-450C-A9DF-C7D3CFDA5CED
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\OneNote\RecentNotebooks
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU\ADAL_48909F08B6BAF178E6C7F38E7E223D41A9FCD39DBA51D55036E27D2885583713
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU\LiveId_CAF5B81530E5714DA4F79AD6A07668EFC0FB46F70A0FBF9B0508523EA46BFB84
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU\ADAL_48909F08B6BAF178E6C7F38E7E223D41A9FCD39DBA51D55036E27D2885583713\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU\ADAL_48909F08B6BAF178E6C7F38E7E223D41A9FCD39DBA51D55036E27D2885583713\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU\LiveId_CAF5B81530E5714DA4F79AD6A07668EFC0FB46F70A0FBF9B0508523EA46BFB84\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\User MRU\LiveId_CAF5B81530E5714DA4F79AD6A07668EFC0FB46F70A0FBF9B0508523EA46BFB84\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU\ADAL_48909F08B6BAF178E6C7F38E7E223D41A9FCD39DBA51D55036E27D2885583713
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU\LiveId_CAF5B81530E5714DA4F79AD6A07668EFC0FB46F70A0FBF9B0508523EA46BFB84
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU\ADAL_48909F08B6BAF178E6C7F38E7E223D41A9FCD39DBA51D55036E27D2885583713\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU\ADAL_48909F08B6BAF178E6C7F38E7E223D41A9FCD39DBA51D55036E27D2885583713\Place MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU\LiveId_CAF5B81530E5714DA4F79AD6A07668EFC0FB46F70A0FBF9B0508523EA46BFB84\File MRU
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\PowerPoint\User MRU\LiveId_CAF5B81530E5714DA4F79AD6A07668EFC0FB46F70A0FBF9B0508523EA46BFB84\Place MRU
C:\Users\xihale\AppData\Roaming\IDM\UrlHistory.txt
C:\Users\xihale\AppData\Roaming\IDM\foldresHistory.txt
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\12D25EEC119B36D4F609776800B40F1F_42170A45C376B5FFBC938F0DE68031E8
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_1DC6D7385EA816C957BA2B715AC5C442
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_C5130A0BDC8C859A2757D77746C10868
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\8A07532D6AAE6A04052D31515DB38D1D_BA5ED34D7D9CF479DAF468F7DF908D45
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\8A07532D6AAE6A04052D31515DB38D1D_BFF87F5FDFE4DE3ED1ECADB4890C4FE3
C:\Users\xihale\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\AC\Microsoft\CryptnetUrlCache\Content\FB0D848F74F70BB2EAA93746D24D9749
MTU Discovery
MTU Black Hole Detect
Selective
Time to live (TTL)
Duplicate
Tcp 1323 Options
Max Connection Per Server
Max Connection Per 1_0 Server
LAN Request Buffer
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Html Help
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Html Help
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRULegacy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRULegacy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\backup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\backup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\backup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\png
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3ds
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.a11
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.anm
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b&w
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b1n
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b8
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bga
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bld
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bm
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.b_w
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cmp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cps
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cvs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dkb
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dw2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dwg
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fh3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fh4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gcd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gl
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gsd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hrf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hs2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hsi
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iax
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ica
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icb
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itc2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itdb
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jas
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jff
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jps
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jtf
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.neo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pda
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pse
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qdv
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rif
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rl4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rl8
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sg1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.van
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vda
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vssettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Optimize CertPropSvc service to improve performance
Optimize PeerDistSvc service to improve performance
Optimize TrkWks service to improve performance
Optimize MSiSCSI service to improve performance
Optimize SNMPTRAP service to improve performance
Streamline Windows Services [SysMain]
Disable 8.3 names for NTFS and speed up disk access [NtfsDisable8dot3NameCreation]
Boost priority of foreground applications [ForegroundLockTimeout]
End hung applications faster [HungAppTimeout]
End hung applications faster [WaitToKillAppTimeout]
Speed up menu display [MenuShowDelay]
Increase the icon cache size to make the icons load faster [Max Cached Icons]
Show translucent selection rectangle [ListviewAlphaSelect]
Animations in the taskbar and Start Menu [TaskbarAnimations]