DescriptionXPVistaWin 7Win 8Win 10key
$MFT Zone DefinitionXP7810SYSTEM\ControlSet###\Control\ FileSystem / NtfsMftZoneReservation
64 BitShim Cache7HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache\AppCompatCache
AccessData FTK Time Zone CacheNTUSER.DAT\Software\AccessData\ Products\Forensic Toolkit\\ Settings\ TimeZoneCache
AccessData Registry Viewer Recent File ListNTUSER.DAT\Software\Accessdata\ Registry Viewer\Recent File List
Acro Software CutePDFNTUSER.DAT\Software\Acro Software Inc\CPW
AdobeNTUSER.DAT\Software\Adobe\
Adobe AcrobatNTUSER.DAT\Software\Adobe\Acrobat Reader\AVGeneral\cRecentFiles\c#
Adobe Photoshop Last FolderNTUSER.DAT\Software\Adobe\ Photoshop\\VisitedDirs
Adobe Photoshop MRUsNTUSER.DAT\Software\Adobe\ MediaBrowser\MRU\Photoshop\ FileList\
AIMNTUSER.DAT\Software\America Online\AOL InstantMessenger\ CurrentVersion\Users\ username
AIMNTUSER.DAT\Software\America Online\AOL Instant Messenger\ CurrentVersion\Users
AIM Away MessagesNTUSER.DAT\Software\America Online\AOL Instant Messenger(TM)\ CurrentVersion\Users\screen name\ IAmGoneList
AIM File Transfers & SharingNTUSER.DAT\Software\America Online\AOL Instant Messenger\ CurrentVersion\Users\screen name\ Xfer
AIM Last UserNTUSER.DAT\Software\America Online\AOL Instant Messenger (TM)\ CurrentVersion\Login - Screen Name
AIM Profile InfoNTUSER.DAT\Software\America Online\AOL Instant Messenger\ CurrentVersion\Users\screen name\DirEntry
AIM Recent ContactsNTUSER.DAT\Software\America Online\AOL Instant Messenger\ CurrentVersion\users\ username\ recent IM ScreenNames
AIM Saved Buddy ListNTUSER.DAT\Software\America Online\AOL Instant Messenger\ CurrentVersion\Users\username\Config Transport
All UsrClass data in HKCR hive7810HKCR\Local Settings
AOL 8 Messenger Away Messages7NTUSER.DAT\Software\America Online\AOL Instant Messenger(TM)\CurrentVersion\Users\[screen name]\IAmGoneList
AOL 8 Messenger Buddy List7NTUSER.DAT\Software\America Online\AOL Instant Messenger\CurrentVersion\Users\username\Config Transport
AOL 8 Messenger File Transfers7NTUSER.DAT\Software\America Online\AOL Instant Messenger (TM)\Current Version\Users\[screen name]\Xfer
AOL 8 Messenger Information7NTUSER.DAT\Software\America Online\AOL Instant Messenger\CurrentVersion\Users\username
AOL 8 Messenger Last User7NTUSER.DAT\Software\America Online\AOL Instant Messenger (TM)\CurrentVersion\[Login - Screen Name]
AOL 8 Messenger Profile Info7NTUSER.DAT\Software\America Online\AOL Instant Messenger (TM)\CurrentVersion\Users\[screen name]\DirEntry
AOL 8 Messenger Recent Contact7NTUSER.DAT\Software\America Online\AOL Instant Messenger\CurrentVersion\users\username\[recent IM ScreenNames]
AOL 8 Messenger Registered User7NTUSER.DAT\Software\America Online\AOL Instant Messenger\CurrentVersion\Users
App Information10UsrClass.dat\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.Microsoftedge\Microsoft.MicrosoftEdge_20.10240.16384.0_neutral 8wekyb3d8b bwe\MicrosoftEdge\Capabilities\FileAssociations
App Install Date/Time10UsrClass.dat\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Families\Microsoft.Microsoftedge_8wekyb3d8bbwe\Microsoft.MicrosoftEdge_20.10240.16384.0_neut ral 8wekyb3d8bbwe / InstallTime
App Install Date/Time810UsrClass.dat\Local Settings\Software\ Microsoft\Windows\CurrentVersion\ AppModel\Repository\Families\\/ InstallTime
Application InformationXP7810NTUSER.DAT\Software\%Application Name%
Application Last Accessed7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\
Application MRU Last Visited7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\
Application MRU Open Saved7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Application MRU Recent Document7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
AppX App Values810UsrClass.dat\
Auto Run Programs List7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run
Autorun USBs, CDs, DVDsXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ AutoplayHandlers / DisableAutoplay
Background Activity ModeratorSYSTEM\CurrentControlSet\Services\bam\UserSettings\{SID}
Background Activity ModeratorSYSTEM\CurrentControlSet\Services\dam\UserSettings\{SID
BitComet Agent 17HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}
BitComet Agent 1.07HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Typelib\{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}
BitComet Agent 27HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{B99B5DF3-3AD2-463F-8F8C-86787623E1D5}
BitComet BHO7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{00980C9D-751F-4A5F-B6CE-6D81998264FD}
BitComet DL Manager7HKEY_USERS\(SID)\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
BitComet DM Class7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
BitComet File Types7HKEY_CURRENT_USER\(SID)\Software\Classes\.bc!\: "BitComet"
BitComet GUID7HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\: "BitComet ClickCapture
BitComet Helper7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
BitComet Helper7HKEY_USERS\(SID)\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
BitComet IBcAgent7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E8A058D1-C830-437F-A029-10D777A8DD40}
BitComet IDownloadMan7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CFA2528-2725-491D-8E0D-E67AB5C5A17A}
BitComet IE DL Manage7HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions
BitComet IE Extension7HKEY_USERS\(SID)\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A}
BitComet IE Link 17HKEY_USERS\(SID)\Software\Microsoft\InternetExplorer\Down-loadUI: "{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
BitComet IE Link 27HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\DownloadUI:"{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}"
BitComet IIEClickCapt7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08F65A5-7F91-45D7-A119-12AC4AB3D229}
BitComet Inst. Path7HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPaths\BitComet.exe
BitComet Installation7HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Typelib\{66A8414F-F2E4-4766-BE09-8F72CDDACED4}
BitLocker Drive Encryption Driver ServiceXP7810SYSTEM\ControlSet001\services\ fvevol\Enum
BitLocker To Go7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\FveAutoUnlock\
BitLocker To GoXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\ FveAutoUnlock\
BitTorrent Clients7HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\(BitTorrent Client Name)
BitTorrent Compatabil7HKEY_USERS\(SID)\Software\Microsoft\WindowsNT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted\
BitTorrent Mag Links7HKEY_USERS\(SID)\Software \Classes\Magnet\shell\open\commsnd\:""C:\Program Files\(BitTorrent Client Name)\(BitTorrent Client Executable File.exe)" "%1""
BitTorrent MRUList7HKEY_USERS\(SID)\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent\OpenWithList
BitTorrent Recent7HKEY_USERS\(SID)\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.torrent
BitTorrent Reg Values7HKEY_LOCAL_MACHINE\SOFTWARE\Classes
BitTorrent Tracing 17HKEY_LOCAL_MACHINE\(SID)\SOFTWARE\Microsoft\Tracing\(BitTorrent Client Name)_RASMANCS
BitTorrent Tracing 27HKEY_LOCAL_MACHINE\(SID)\SOFTWARE\Microsoft\Tracing\(BitTorrent Client Name)_RASAPI32
Cached Passwords7SECURITY\Policy\Secrets\DefaultPassword/[CurrVal and OldVal]
Camera App10NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ RecentDocs\.jpg&ls=0&b=0
Camera Mounting7810SYSTEM\ControlSet001\Enum\USB\
CD Burning78NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ CD Burning\Drives\Volume\ Current Media
CD BurningXPNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ CD Burning\ Current Media /Disc Label
CDROM Enumeration ServiceXP7810SYSTEM\ControlSet001\services\ cdrom\Enum
Class GUID for HDD DriversXP7810SYSTEM\ControlSet001\Control\ Class\{4D36E967-E325-11CE- BFC1- 08002BE10318}
Class GUID for Storage VolumesXP7810SYSTEM\ControlSet001\Control\ Class\{71A27CDD-812A-11D0- BEC7-08002BE2092F}
Class GUID for USB Host Controllers and HubsXP7810SYSTEM\ControlSet001\Control\ Class\{36FC9E60-C465-11CF- 8056-444553540000}
Class GUID for Windows Portable Devices WPD7810SYSTEM\ControlSet001\Control\ Class\{EEC5AD98-8080-425F- 922A-DABF3DE3F69A}
Class IdentifiersXP7810SOFTWARE\Classes\CLSID
ClassesHKEY_CLASSES_ROOT
Clearing Page File at ShutdownXP7810SYSTEM\ControlSet###\Control\ Session Manager\Memory Management / ClearPageFileAtShutdown
Clearing PageFile at Shutdown7SYSTEM\ControlSet###\Control\Session Manager\Memory Management\ClearPageFileAtShutdown
Common Dialog10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\.vhd
Common Dialog 32 CID Size MRU App AccessXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ ComDlg32\CIDSizeMRU
Common Dialog 32 First Folder App Access78NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ ComDlg32\FirstFolder
Common Dialog 32 Last Visited MRU App AccessXPNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Common Dialog 32 Last Visited PIDL MRU App AccessXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ ComDlg32\LastVisitedPidlMRU
Common Dialog 32 Open Save document Access by ExtensionNTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ ComDlg32\OpenSaveMRU\
Common Dialog ComDlg32 AccessXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ ComDlg32\LastVisitedPidlMRULegacy
Common Dialog ComDlg32 AccessXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ ComDlg32\OpenSavePidlMRU\
Communications App E-Mail IDSettings.dat\
Communications App E-Mail User Namesettings.dat\LocalState\Platform / UserName
Communications App ID infoSettings.dat\RoamingState\\ Accounts
Computer NameXP7810SYSTEM\ControlSet###\Control\ ComputerName\ComputerName
Computer Name Active Computer NameXP7810SYSTEM\ControlSet###\Control\ ComputerName\ComputerName\ ActiveComputerName
Computer Name and Volume Serial NumberXP7810NTUSER.DAT\Software\Microsoft\ Windows Media\WMSDK\General
Converted WallpaperXP7810NTUSER.DAT\\Control Panel\Desktop
Cortana Search10NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ FileExts\.com/search?q=
Cortana Search10NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ RecentDocs\.&input=2&FORM=WNS BOX&cc=US&setlang=en- US&sbts=/ 0
Credential Provider FiltersHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\*
Credential Provider FiltersHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\*
Credential ProvidersHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\*
Credential ProvidersHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\*
Current ConfigurationHKEY_CURRENT_CONFIG
Current Control Set7SYSTEM\Select
Current Control SetXP7810SYSTEM\Select
Current Control Set Information7SYSTEM\Select\Current
Current Drive Enumeration ServiceXP7810SYSTEM\ControlSet001\services\ Disk\Enum
Current Theme7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Themes
Current USB Storage Enumeration ServiceXP7810SYSTEM\ControlSet001\services\ USBSTOR\Enum
Current Version InformationXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\
Currently Defined Printer7SYSTEM\ControlSet###\Control\Print\Printers
Currently Mounted Drives MRU7810SYSTEM\CurrentControlSet\Services\ Disk\Enum
Custom Group List by RID7SAM\Domains\Account\Aliases\
Custom Group Names7SAM\Domains\Account\Aliases\Names
DAP CategoriesXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\Category
DAP Context Menu 1XPHKEY_USERS\ S-1-5-21-1757981266-1708537768-725345543-500\Software\Microsoft\InternetExplorer\MenuExt
DAP Context Menu 2XPHKEY_USERS\ S-1-5-21-1757981266-1708537768-725345543-500\Software\Microsoft\InternetExplorer\MenuExt
DAP DL ActivityXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator
DAP Download DirXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\FileList\(Site/Server)\DownloadDir
DAP Download URLsXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\HistoryCombo
DAP FileListXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\FileList
DAP Host DataXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\FileList\HostsData
DAP Ignored SitesXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\FileList\(Site/Server)\BlackList
DAP Install/V/PathXPHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Download Accelerator Plus
DAP Protected URLsXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\FileList\(Site/Server)
DAP Proxy DataXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\Proxy
DAP Searched WordsXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\SearchTab
DAP Unique File IDXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\FileList\(Unique File ID)
DAP User CredentialsXPHKEY_USERS\SID\Software\SpeedBit\Download Accelerator\UserInfo
Defrag Last Run Time7810SOFTWARE\Microsoft\Dfrg\Statistics\ Volume/ LastRunTime
Disables (or stores if 1) clear-text creds8HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential
Disk Class Filter Driver stdcfltn10SYSTEM\ControlSet001\services\ stdcfltn
Display EnumerationXP7810SYSTEM\ControlSet001\Enum\ DISPLAY\\
Display Monitor Settings7SYSTEM\ControlSet###\Enum\Display
Display MonitorsXP7810SYSTEM\ControlSet###\Enum\Display
DLLs Loaded at Bootup7SYSTEM\ControlSet###\Control\SessionManager\KnownDLLs
DLLs Loaded at BootupXP7810SYSTEM\ControlSet###\Control\ SessionManager\KnownDLLs
Drives Mounted by UserXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ MountPoints2\
Dynamic DiskXP7SYSTEM\\ControlSet###\Services\ DMIO\Boot Info\Primary Disk Group
Dynamic Disk Identification7SYSTEM\ControlSet###\Services\DMIO\Boot Info\Primary Disk Group
Edge Browser Favorites, Edge Favorites10UsrClass.dat\Local Settings\Software\ Microsoft\Windows\CurrentVersion\ AppContainer\Storage\microsoft. microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FavOrder\Favorites\/ Order
Edge History Days to Keep10UsrClass.dat \Local Settings\Software\ Microsoft\Windows\CurrentVersion\ AppContainer\Storage\microsoft. microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\InternetSettings\ Url History / DaysToKeep
Edge Typed URLs10UsrClass.dat \ Local Settings\Software\ Microsoft\Windows\CurrentVersion\ App Container\Storage\microsoft. microsoftedge_8wekyb3d8bbwe\ MicrosoftEdge\TypedURLs
Edge Typed URLs Time10UsrClass.dat \ Local Settings\Software\Microsoft\ Windows\CurrentVersion\App Container\Storage\microsoft. microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsTime
Edge Typed URLs Visit Count10UsrClass.dat \ Local Settings\Software\ Microsoft\Windows\CurrentVersion\ App Container\Storage\microsoft. microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsVisitCount
EFSXP7810NTUSER.DAT\Software\Microsoft\ Windows NT\CurrentVersion\EFS\ CurrentKeys
EFS Attribute in File Explorer Green Color10NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ Advanced
Encrypted Page File7810SYSTSEM\ControlSet###\Control\ FileSystem / NtfsEncryptPagingFile
Event Log Restrictions7SYSTEM\ControlSet###\Services\EventLog\Application
Event Log RestrictionsXP7810SYSTEM\ControlSet###\Services\ EventLog\Application / RestrictGuest Access
Favorites10UsrClass.dat\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FavOrder\
File Access Windows Apps10UsrClass.dat\Local Settings\Software\ Microsoft\Windows\CurrentVersion\ AppModel\SystemAppData\\PersistedStorage ItemTable\ManagedByApp
File Associations for Immersive Apps/Windows Apps810UsrClass.dat\Local Settings\Software\ Microsoft\Windows\CurrentVersion\ AppModel\Repository\Packages\\App\Capabilities\ FileAssociations
File Extension Association Apps MRUXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ FileExts\.\OpenWithList
File Extension AssociationsXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\FileExts\.
File Extension Associations GlobalXP7810SOFTWARE\Classes\.ext
File Extensions Program AssociationXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ FileExts\./OpenWithProgids
File History810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\FileHistory
File History Home Group Settings810SOFTWARE\Microsoft\Windows\Current Version\FileHistory\HomeGroup\Target
File History Last Backup Time810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\FileHistory/ ProtectedUpToTime
File History User(s) Initiating810SYSTEM\ControlSet###\Services\fhsvc\ Parameters\Configs
Firewall EnabledXP7810SYSTEM\ControlSet###\Services\ SharedAccess\Parameters\ Firewall Policy\StandardProfile / EnableProfile
Firewall On or Off7SYSTEM\ControlSet###\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall
Floppy Disk InformationXPVSYSTEM\ControlSet###\Enum\FDC\
Folder Descriptions7810SOFTWARE\Microsoft\Windows\Current Version\Explorer\FolderDescriptions\
Folders Stream MRUsNTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\ Explorer\StreamMRU
FTP7NTUSER.DAT\Software\Microsoft\FTP\Accounts\
FTPXP7NTUSER.DAT\Software\Microsoft\FTP\ Accounts\
General Open/SavedXP7HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU
General Recent DocsXPHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
General Recent FilesXPHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
General USB Devices7HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
Google Chrome Last Browser Run TimeNTUSER.DAT\Software\Google\ Update\ClientState\{8A69D345- D564-463c-AFF1-A69D9Ec-AFF1-A69D9E530F96} / lastrun
Google Chrome VersionNTUSER.DAT\Software\Google\ Chrome\BLBeacon
Google Client History7NTUSER.DAT\Software\Google\NavClient\1.1\History
Google Client HistoryNTUSER.DAT\Software\Google\ NavClient\1.1\History
Google Update Date/TimeNTUSER.DAT\Software\Google\ Google Toolbar\GoogleUpdate / InstallTimestamp
Group MembershipsXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\Group Policy\ GroupMembership
Group MembershipsXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\Group Policy\
Group Names - DefaultXP7810SAM\SAM\Domains\Builtin\Aliases\ Names
Groups - DefaultXP7810SAM\SAM\Domains\Builtin\Aliases\
Groups Names User or App DefinedXP7810SAM\SAM\Domains\Account\Aliases\ Names
Groups Names User or App DefinedXP7810SAM\SAM\Domains\Account\Aliases\
History - Days to Keep10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Url History /DaysToKeep
History days to keep10UsrClass.dat\SOFTWARE\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppContainer\ Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\InternetSettings\Url History /DaysToKeep
Hive List PathsXP7810SYSTEM\ControlSet###\Control\ hivelist
Home Group7SYSTEM\ControlSet###\services\HomeGroupProvider\ServiceData
Home Group7810SYSTEM\ControlSet###\Services\Home GroupProvider\ServiceData\
Home Group Host7810NTUSER.DAT\SOFTWARE\Microsoft\ Windows\CurrentVersion\HomeGroup\ UIStatusCache
Home Group ID GUID7810SOFTWARE\Microsoft\Windows\ CurrentVersion\HomeGroup\HME\
Home Group Info7810SYSTEM\ControlSet###\Services\ HomeGroupProvider\ServiceData\
Home Group Initiated7810SOFTWARE\Microsoft\Windows\ CurrentVersion\HomeGroup\HME
Home Group Members7810SYSTEM\ControlSet###\Services\Home GroupProvider\ServiceData\\ Members\
Home Group Members MAC Address(es)7810SOFTWARE\Microsoft\Windows\ CurrentVersion\HomeGroup\HME\\ Members
Home Group Network Locations Home7810SOFTWARE\Microsoft\Windows\Current Version\HomeGroup\NetworkLocations\ Home
Home Group Network Locations Work7810SOFTWARE\Microsoft\Windows\Current Version\HomeGroup\NetworkLocations\ Work
Home Group Sharing Preferences7810SOFTWARE\Microsoft\Windows\ CurrentVersion\HomeGroup\HME\\SharingPreferences\
Home Group Sharing Preferences7810SOFTWARE\Microsoft\Windows\ CurrentVersion\HomeGroup\ SharingPreferences\\
Human Interface Devices7SYSTEM\ControlSet###\Enum\HID
Human Interface DevicesXP7810SYSTEM\ControlSet###\Enum\HID
ICQNTUSER.DAT\Software\Mirabilis\ICQ\*
ICQ InformationSOFTWARE\Mirabilis\ICQ\Owner
ICQ Last UserNTUSER.DAT\Software\Mirabilis\ICQ\ Owners - LastOwner
ICQ NicknameNTUSER.DAT\Software\Mirabilis\ICQ\ Owners\UIN - Name
ICQ Registered UsersNTUSER.DAT\Software\Mirabilis\ICQ\ Owners\UIN
IDE Device Information7SYSTEM\ControlSet###\Enum\IDE\
IDE Device InformationXP7810SYSTEM\ControlSet###\Enum\IDE\
IDE EnumerationXP7810SYSTEM\ControlSet001\Enum\ IDE\\
Identity10settings.dat\LocalState\HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Identities\
Identity Live Account10NTUSER\SOFTWARE\Microsoft\15.0\Common\Identity\Identities\
IDM Incomplete DLsXPHKEY_CURRENT_USER\Software\DownloadManager\Queue
IDM Install, ProxyXPHKEY_CURRENT_USER\Software\DownloadManager
IDM InstallationXPKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Download Manager
IDM Offline BrowsingXPHKEY_CURRENT_USER\Software\DownloadManager\GrabberSts\Projects
IDM PasswordsXPHKEY_CURRENT_USER\Software\DownloadManager\Passwords\(URL)
IDM Total DL CountXPHKEY_CURRENT_USER\Software\DownloadManager\maxID
IE 6 Auto Logon and password7NTUSER.DAT\Software\Microsoft\Protected Storage\System Provider\SID\Internet Explorer\Internet Explorer\- URL: StringData
IE 6 Clear Browser History7NTUSER.DAT\Software\Microsoft\Internet Explorer\Privacy\ClearBrowserHistoryOnExit
IE 6 Default Download Directory7NTUSER.DAT\Software\Microsoft\Internet Explorer
IE 6 Favorites List7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\
IE 6 Settings7NTUSER.DAT\Software\Microsoft\Internet Explorer\Main
IE 6 Typed URLs7NTUSER.DAT\Software\Microsoft\Internet Explorer\Typed URLs
IE Auto Complete Form DataNTUSER.DAT\Software\Microsoft\ Protected Storage System Provider
IE Auto Logon and PasswordNTUSER.DAT\Software\Microsoft\ Protected Storage System Provider\ SID\Internet Explorer\Internet Explorer
IE Cleared Browser History on Exit on/offNTUSER.DAT\Software\Microsoft\ Internet Explorer\ Privacy / ClearBrowserHistoryOnExit
IE Default Download DirectoryNTUSER.DAT\Software\Microsoft\ Internet Explorer
IE Favorites ListXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ MenuOrder\ Favorites / Order
IE History StatusXP78NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Internet Settings\ 5.0\Cache\Extensible Cache\
IE IntelliFormsNTUSER.DAT\Software\Microsoft\ Internet Explorer\ IntelliForms
IE Preferences, IE SettingsNTUSER.DAT\Software\Microsoft\ Internet Explorer\ Main
IE Protected StorageXPHKEY_CURRENT_USER\SOFTWARE\Microsoft\ProtectedStorageSystemProvider
IE Search TermsNTUSER.DAT\Software\Microsoft\Protected Storage System Provider\SID\Internet Explorer\Internet Explorer - q:StringIndex
IE Typed URLsNTUSER.DAT\Software\Microsoft\Internet Explorer\TypedURLs
IE Typed URLs TimeNTUSER.DAT\Software\Microsoft\ Internet Explorer\TypedURLsTime
IE URL History Days to KeepNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Internet Settings\UrlHistory / DaysToKeep
IE Web Form DataNTUSER.DAT\Software\Microsoft\Protected Storage System Provider\SID\Internet Explorer\Internet Explorer -
IE/Edge Auto Passwd10HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
If hidden from timeline view, key is present10HKCU\Software\Microsoft\Windows\CurrentVersion\ActivityDataModel\ActivityAccountFilter\
IM Contact ListNTUSER.DAT\Software\Microsoft\ MessengerService\ListCache\.NET Messenger Service
IM File SharingNTUSER.DAT\Software\Microsoft\ MSNMessenger\FileSharing - Autoshare
IM File TransfersNTUSER.DAT\Software\Microsoft\ Messenger Service - FtReceiveFolder
IM File TransfersNTUSER.DAT\Software\Microsoft\ MSNMessenger\- FTReceiveFolder
IM Last UserNTUSER.DAT\Software\Microsoft\ MessengerService\ListCache\.NET Messenger Service - IdentityName
IM Logging EnabledNTUSER.DAT\Software\Microsoft\MSN Messenger\PerPassportSettings\ ##########\- MessageLoggingEnabled
IM Message HistoryNTUSER.DAT\Software\Microsoft\MSN Messenger\PerPassportSettings\ ##########\- MessageLog Path
IM MSN MessengerNTUSER.DAT\Software\Microsoft MessengerService\ ListCache\.NET MessengerService\*
IM Saved Contact ListNTUSER.DAT\Software\Microsoft\ Messenger Service - ContactListPath
IMV UsageNTUSER.DAT\Software\Yahoo\Pager\ IMVironments (global value)
IMVs MRU listSNTUSER.DAT\Software\Yahoo\Pager\ profiles\screen name\IMVironments
Index Locations for local searches7810SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\#> /URL
Indexed Folders7810SOFTWARE\Microsoft\Window Search\ CrawlScopeManager\ Windows\ SystemIndex\ WorkingSetRules\#>/ URL
Installed ApplicationXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\App Paths\
Installed ApplicationsXP7810SOFTWARE\
Installed Applications7810SOFTWARE\Wow6432Node\
Installed Applications7810SOFTWARE\Wow6432Node\Microsoft\ Windows\CurrentVersion\SharedDLLs
Installed AppsHKEY_LOCAL_ MACHINE\SOFTWARE\Microsoft\WindoWs\CurrentVersion\(AppPaths)
Installed Default Internet BrowsersXP7810SOFTWARE\Clients\StartMenuInternet / default
Installed Internet BrowserXP7810SOFTWARE\Clients\StartMenuInternet\
Installed Metro Apps - Per Computer810SOFTWARE\Software\Microsoft\ Windows\CurrentVersion\Appx\AppxAll UserStore\Applications\
Installed Metro Apps Per User810SOFTWARE\Software\Microsoft\ Windows\CurrentVersion\Appx\AppxAllU serS tore\\
Installed Printers Properties7SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\
Installed Windows Apps810UsrClass.dat\Local Settings\Software\ Microsoft\Windows\CurrentVersion\ AppContainer\Storage
Interface class GUID7810SYSTEM\ControlSet001\Control\ DeviceClasses\ {10497b1b- ba51- 44e5-8318-a65c837b6661}
Internet Explorer 1HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
Internet Explorer 27HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\TypedUrls
iPhone, iPad Mounting810SYSTEM\ControlSet001\Enum\USB\
Jump List on Taskbar7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\[Taskband Favorites and FavoritesResolve]
Jump List on Taskbar7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ Taskband / Favorites and FavoritesResolve
Jumplist SettingsHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
KazaaNTUSER.DAT\Software\Kazaa\*
KaZaA CredentialsXPHKEY_USERS\USER_HDD003_A\Software\KAZAA\UserDetails
LANDesk softmon utility monitors application executionHKLM\SOFTWARE\[Wow6432Node]\LANDesk\ManagementSuite\WinClient\SoftwareMonitoring\MonitorLog\
Last Accessed Date and Time settingXP7810SYSTEM\ControlSet###\Control\ FileSystem\NtfsDisableLastAccess Update Value
Last Defrag10SOFTWARE\Microsoft\Dfrg\Statistics\Volume
Last Failed Login7SAM\Domains\Account\Users\F Key
Last Logged on User7810SOFTWARE\Microsoft\Windows\ CurrentVersion\Authentication\LogonUI
Last Logon Time7SAM\Domains\Account\Users\F Key
Last Theme7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Themes\Last Theme
Last Time Password Changed7SAM\Domains\Account\Users\F Key
Last Visited MRUXPNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Last Visited MRU7810NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
Last-Visited MRUXPNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\ LastVisitedMRU
Last-Visited MRU7810NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
Links a ConnectedDevicePlatform PlatformDeviceId to the name, type, etc of the device10HKCU\Software\Microsoft\Windows\CurrentVersion\TaskFlow\DeviceCache
Live Account ID10NTUSER.DAT\SOFTWARE\Microsoft\Office\15.0\Common\Identity\Identities\_LiveId
Live Account ID10NTUSER.DAT\SOFTWARE\Microsoft\IdentityCRL\UserExtendedProperties\/ cid
Live Account ID10NTUSER.DAT\SOFTWARE\Microsoft\AuthCookies\Live\Default\CAW / Id
Local Group List by RID7SAM\Domains\Builtin\Aliases\
Local Group Names7SAM\Domains\Builtin\Aliases\Names
Local Groups Identifiers7SAM\Domains\Builtin\Aliases\Names
Local Searches from Search CharmNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ SearchHistory\Microsoft.Windows. FileSearch App
Local SettingsUsrClass.dat
Local User NamesXP7810SAM\SAM\Domains\Account\Users\ Names
Local User Security Identifiers7SAM\Domains\Account\Users\Names
Logged In WinlogonXP7810SOFTWARE\\Microsoft\Windows NT\ CurrentVersion\Winlogon
Logon Banner Caption and MessageXP810SOFTWARE\\Microsoft\Windows\ CurrentVersion\Policies\System / LegalNoticeCaption and LegalNoticeText
Logon Banner Message7SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText
Logon Banner Title7SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption
LPT Device Information7SYSTEM\ControlSet###\Enum\LPTENUM\
LPT Device InformationXP7810SYSTEM\ControlSet###\Enum\ LPTENUM\
LPTENUM EnumerationXP7810SYSTEM\ControlSet001\Enum\ LPTENUM\\
Machine SID Location7SAM\Domains\Account/V
Machine SID LocationXP7810SAM\SAM\Domains\Account / V
Map Network Drive MRUXP7NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\Map Network Drive MRU
Media Player 10 Recent List7NTUSER.DAT\Software\Microsoft\MediaPlayer\Player\RecentFileList
Media Player Recent ListXPNTUSER.DAT\Software\Microsoft\ MediaPlayer\Player\RecentFileList
Memory Saved During CrashXP7810SYSTEM\ControlSet###\Control\ CrashControl / DumpFile
Memory Saved During Crash EnabledXP7810SYSTEM\ControlSet###\Control\ CrashControl / CrashDumpEnabled
Memory Saved Path During Crash7SYSTEM\ControlSet###\Control\CrashControl\DumpFile
Memory Saved While Crash Detail7SYSTEM\ControlSet###\Control\CrashControl\CrashDumpEnabled
Messenger ContactsXPHKEY_USERS\Software\Microsoft\InternetExplorer\TypedUrls
Microsoft Access 2007 MRU7NTUSER.DAT\Software\Microsoft\Office\12.0\Access\Settings
Microsoft Access 2007 MRU Date7NTUSER.DAT\Software\Microsoft\Office\12.0\Access\Settings
Monitors Currently Attached810SYSTEM\ControlSet001\services\ monitor\Enum
Mounted DevicesXP7810SYSTEM\MountedDevices
Mounted DevicesXP7810SYSTEM\MountedDevices
MRU Live Account10NTUSER\SOFTWARE\Microsoft\Office\15.0\Word\User MRU\LiveId#>\File MRU
MRU Non Live Account10NTUSER\SOFTWARE\Microsoft\Office\15.0\Word\File MRU
MRUs Common Dialog7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersions\Explorer\ComDlg32
mTorrent Build7HKEY_USERS\(SID)\Software\BitTorrent\(BitTorrent Client Name)\
mTorrent File Types7HKEY_CURRENT_USER\(SID)\Software\Classes\.btsearch\: "mTorrent"
mTorrent Install Path7HKEY_USERS\(SID)\Software\Classes\Applications\mTorrent.exe\shell\open\command
MuiCache Post Vista7810UsrClass.dat\Local Settings\Software\ Microsoft\Windows\Shell\MuiCache
MuiCache Post Vista7810UsrClass.dat\Local Settings\MuiCache\#\ 52C64B7E
MUICache VistaNTUSER.DAT\Software\Microsoft\ Windows\Shell\MUICache
MuiCache XPXPNTUSER.DAT\Software\Microsoft\ Windows\ShellNoRoam\MUICache
Network - Computer DescriptionXPNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ ComputerDescriptions
Network - Mapped Network Drive MRUXPNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Map Network Drive MRU
Network CardsXP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\ NetworkCards\#
Network History7810SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged
Network History7810SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed
Network History7810SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cach
Network Workgroup Crawler7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WorkgroupCrawler\Shares
Network Workgroup CrawlerXPNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ WorkgroupCrawler\Shares
Nikon View Photo Editor MRUNTUSER.DAT\Software\Nikon\ NikonViewEditor\6.0\Recent File List
NTUSER InfoHKEY_USERS\
Number of Processors in System7SYSTEM\ControlSet###\Control\Session Manager\Environment\NUMBER_OF_PROCESSORS
Number of Processors in SystemXP7810SYSTEM\ControlSet###\Control\ Session Manager\Environment / NUMBER_OF_PROCESSORS
Office Access 2007 MRUNTUSER.DAT\Software\Microsoft\Office\12.0\Access\ Settings
Office Access 2007 MRU DatesNTUSER.DAT\Software\Microsoft\Office\12.0\Access\Settings
Office Access MRUNTUSER.DAT\Software\Microsoft\Office\\\Access\File MRU
Office Access Recent DatabasesNTUSER.DAT\Software\Microsoft\Office\\ Common\Open Find\ Microsoft Office Access\Settings\File New Database\File Name MRU
Office Access Trusted Documents RUNTUSER.DAT\Software\Microsoft\Office\\Access\Security\Trusted Documents\TrustRecords
Office Access Trusted Locations MRUNTUSER.DAT\Software\Microsoft\ Office\Access\Security\ Trusted Locations\Location2
Office Excel Autosave (File Recovery)NTUSER.DAT\Software\Microsoft\ Office\ver#\Excel\ Resiliency\ Document Recovery\
Office Excel MRUNTUSER.DAT\Software\Microsoft\ Office\\Excel\File MRU
Office Excel MRU Live AccountNTUSER.DAT\Software\Microsoft\ Office\\Excel\User MRU\LiveId_\File MRU
Office Excel Place MRUNTUSER.DAT\Software\Microsoft\ Office\\Excel\Place MRU
Office Excel Place MRU Live AccountNTUSER.DAT\Software\Microsoft\ Office\\Excel\User MRU\LiveId_\Place MRU
Office Excel Recent SpreadsheetsNTUSER.DAT\Software\Microsoft\office\\Common\Open Find\ Microsoft Office Excel\Settings\ Save As\File Name MRU
Office Excel Trusted Documents MRUNTUSER.DAT\Software\Microsoft\ Office\\Excel\Security\Trusted Documents
Office Excel Trusted Locations MRUNTUSER.DAT\Software\Microsoft\ Office\\Excel\Security\Trusted Locations
Office PowerPoint Autosave (File Recovery)NTUSER.DAT\Software\Microsoft\ Office\\ PowerPoint\Resiliency\ DocumentRecovery\
Office PowerPoint MRUNTUSER.DAT\Software\Microsoft\ Office\ver#\PowerPoint\ FileMRU
Office PowerPoint MRU Live AccountNTUSER.DAT\Software\Microsoft\ Office\\PowerPoint\User MRU\ LiveId_\File MRU
Office PowerPoint Place MRUNTUSER.DAT\Software\Microsoft\ Office\\PowerPoint \Place MRU
Office PowerPoint Place MRU Live AccountNTUSER.DAT\Software\Microsoft\ Office\\PowerPoint\User MRU\ LiveId_\Place MRU
Office PowerPoint Recent PPTsNTUSER.DAT\Software\Microsoft\ office\ver#\ Common\Open Find\ Microsoft Office PowerPoint\Settings\ Save As\File Name MRU
Office PowerPoint Trusted Documents MRUNTUSER.DAT\Software\Microsoft\ Office\\PowerPoint\Security\ Trusted Documents\TrustRecords
Office PowerPoint Trusted Locations MRUNTUSER.DAT\Software\Microsoft\ Office\\PowerPoint\Security\ Trusted Locations\Location#
Office Publisher MRUNTUSER.DAT\Software\Microsoft\ Office\\Publisher\File MRU
Office Publisher Recent DocumentsNTUSER.DAT\Software\Microsoft\ office\\ Common\Open Find\ Microsoft Office Publisher\Settings\ Save As\File Name MRU
Office Word Autosave (File Recovery)NTUSER.DAT\Software\Microsoft\ Office\\Word\Resiliency\ Document Recovery\
Office Word MRUNTUSER.DAT\Software\Microsoft\ Office\\Word\File MRU
Office Word MRU Live AccountNTUSER.DAT\Software\Microsoft\ Office\\Word\User MRU\ LiveId_\File MRU
Office Word OneDrive Synch Roaming Identities10NTUSER.DAT\Software\Microsoft\ Office\\Common\Roaming\ Identities\Settings\1133\\ ListItems\\
Office Word Place MRUNTUSER.DAT\Software\Microsoft\ Office\\Word\Place MRU
Office Word Place MRU Live AccountNTUSER.DAT\Software\Microsoft\ Office\\Word\User MRU\ LiveId_\Place MRU
Office Word Reading LocationsNTUSER.DAT\Software\Microsoft\ Office\\Word\Reading Locations\Document#
Office Word Recent DocsNTUSER.DAT\Software\Microsoft\ office\\ Common\Open Find\ Microsoft Office\Word\Settings\Save As\File Name MRU
Office Word Trusted Documents MRUNTUSER.DAT\Software\Microsoft\Office\\Word\Security\Trusted Documents
Office Word Trusted Locations MRUNTUSER.DAT\Software\Microsoft\ Office\14.0\Word\Security\Trusted Locations\Location#
Office Word User InfoNTUSER.DAT\Software\Microsoft\ office\\Common\UserInfo
OneDrive App Info10NTUSER.DAT\SOFTWARE\Microsoft\ OneDrive
OneDrive User ID and Login URL10NTUSER.DAT\SOFTWARE\Microsoft\ AuthCookies\Live\Default\CAW
OneDrive User ID Associated with User10NTUSER.DAT\SOFTWARE\Microsoft\ IdentityCRL\UserExtendedProperties\/ cid
OneDrive User ID, Live ID10NTUSER.DAT\SOFTWARE\Microsoft\ Office\\Common\Identity\Identities\_LiveId
OneNote User Information10Settings.dat\LocalState\ HKEY_CURRENT_USER\Software\ Microsoft\Office\16.0\Common\ Identity\Identities\_LiveId
Open/Save MRUNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Open/Save MRU7810NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePIDlMRU
Open/Save MRUXPNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Outlook 2007 Account Passwords7NTUSER.DAT\Software\Microsoft\Protected Storage SystemProvider\SID\Identification\INETCOMM Server Passwords
Outlook 2007 Recent Attachments7NTUSER.DAT\Software\Microsoft\office\version\Common\Open Find\Microsoft Office Outlook\Settings\Save Attachment\File Name MRU
Outlook 2007 Temp file location7NTUSER.DAT\Software\Microsoft\Office\version\Outlook\Security
Outlook Account PasswordsNTUSER.DAT\Software\Microsoft\ Protected Storage System Provider\SID\ Identification\INETCOMM Server Passwords
Outlook AccountsXPHKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager
Outlook Recent AttachmentsNTUSER.DAT\Software\Microsoft\ office\version\ Common\Open Find\ Microsoft Office Outlook\Settings\Save Attachment\File Name MRU
Outlook SettingsXPHKEY_USERS\(User_ID)\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts\
Outlook Temporary Attachment DirectoryNTUSER.DAT\Software\Microsoft\Office\version\ Outlook\Security
Pagefile ControlXP7810SYSTEM\ControlSet###\Control\ Session Manager\Memory Management
Pagefile Settings7SYSTEM\ControlSetXXX\Control\Session Manager\Memory Management
Paint MRU7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
Paint MRU ListXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Applets\ Paint\Recent File List
PAP Device Interface7810SYSTEM\ControlSet001\Control\ DeviceClasses\{f33fdc04- d1ac-4e8e- 9a30-19bbd4b108ae}
Partition Management Driver ServiceXP7810SYSTEM\ControlSet001\services\ partmgr\Enum
Password Face Enabled10SOFTWARE\Software\Microsoft\ Windows\CurrentVersion\ Authentication\LogonUI\FaceLogon\
Password Fingerprint Enabled810SOFTWARE\Software\Microsoft\ Windows\CurrentVersion\ Authentication\LogonUI\ FingerprintLogon\
Password Hint7SAM\Domains\Account\Users\\F_Value\UserPasswordHint
Password Hint XPXPSOFTWARE\Microsoft\Windows\ CurrentVersion\Hints\
Password Picture Gesture810SOFTWARE\Software\Microsoft\ Windows\CurrentVersion\ Authentication\LogonUI\PicturePassword\/ bgPath
Password PIN Enabled810SOFTWARE\Software\Microsoft\ Windows\CurrentVersion\ Authentication\LogonUI\ PINLogonEnrollment\
Passwords Cached Logon Password MaximumXPSOFTWARE\Microsoft\Windows NT\ CurrentVersion\Winlogon
PCI Bus Device Information7SYSTEM\ControlSet###\Enum\PCI
PCI Bus Device InformationXP7810SYSTEM\ControlSet###\Enum\PCI
PCI EnumerationXP7810SYSTEM\ControlSet001\Enum\ PCI\\
Photos App Associated User10Settings.dat\LocalState\OD\
Place MRU10NTUSER\SOFTWARE\Microsoft\Office\15.0\Word\User MRU\LiveId#>\Place MRU
POP3 PasswordsXPNTUSER.DAT\Software\Microsoft\Internet Account Manager\Accounts\0000000#
POP3 PasswordsXPNTUSER.DAT\Software\Microsoft\ Internet Account Manager\Accounts\ 0000000#
Portable Operating System Drive810SYSTEM\ControlSet001\Control / PortableOperatingSystem
PowerPoint 2007 Autosave Info7NTUSER.DAT\Software\Microsoft\Office\12.0\PowerPoint\Resiliency\DocumentRecovery\
PowerPoint 2007 MRU7NTUSER.DAT\Software\Microsoft\Office\12.0\PowerPoint\File MRU
Prefetch Information7SYSTEM\ControlSet###\Control\Session Manager\Memory Management\PrefetchParameters\EnablePrefetcher
Pre-Logon Access ProviderHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers\*
Pre-Logon Access ProviderHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers\*
Printer DefaultXP7810NTUSER.DAT\Software\Microsoft\ Windows NT\CurrentVersion\Windows\ Devices
Printer DefaultXP7810NTUSER.DAT\printers\DevModesPer User and DevModes#
Printer Information7SYSTEM\ControlSet###\Control\Print\Environments\WindowsNTx86\Drivers\Version#
Printer Properties for Installed PrintersXP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\Print\Printers\
Product ID7SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
Product Name7SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
Profile listXP7810SOFTWARE\\Microsoft\Windows NT\ CurrentVersion\ProfileList
Program Compatibility Assistant (PCA) Archive for Apps8NTUSER.DAT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Program Compatibility Assistant (PCA)Tracking of User Launched Applications810NTUSER.DAT\Software\Microsoft\ Windows NT\CurrentVersion\ AppCompatFlags\Compatibility Assistant\Store
Program Compatibility Assistant Archive for Apps7SOFTWARE\Software\Microsoft\ Windows NT\CurrentVersion\AppCompatFlags\Layers
Publisher 2007 MRU7NTUSER.DAT\Software\Microsoft\Office\12.0\Publisher\Recent File List
Reading Locations10NTUSER\SOFTWARE\Microsoft\Office\15.0\Word\Reading Locations
ReadyBoost Attachments7SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmt\
ReadyBoost Attachments, USB Identification7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\ EMDMgmt\
ReadyBoost Driver810SYSTEM\ControlSet001\services\ rdyboost\Enum
Recent Docs10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.&input=
Recent Docs MRU Recent DocumentsXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ RecentDocs\
Recent Documents7HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Recent DocumentsHKEY_ CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
RecentApps10NTUSER.DAT\Software\Microsoft\Windows\Current Version\Search\RecentApps
RecentDocs10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
RecentDocs10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.iso
RecentDocs10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.vhd
RecentDocs for .jpg10NTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.jpg
RecentDocs for .jpg10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.jpg&ls=0&b=0
Recycle Bin Info10NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\
Recycle Bin Info7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ BitBucket\Volume\
Recycle Bin Info XPXPSOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\BitBucket\
References devices, services, drivers enabled for Safe Mode.HKLM\System\CurrentControlSet\Control\SafeBoot
Regedit - FavoritesXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\ Applets\Regedit\ Favorites
Regedit - Last Key SavedXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Applets\ Regedit / LastKey
Regedit Last Key Saved10NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\LastKey
Register.com search10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts / .com
Registered Applications7810SOFTWARE\RegisteredApplications /
Registered Organization7SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
Registered Owner7SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
Registry Windows 7 32 Bit Shim Cache7HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatCache\AppCompatCache
Registry Windows 7 List Mounted Devices7HKLM\System\MountedDevices\
Registry Windows 7 Network Adapter Configuration7HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\(interface-name)\
Registry Windows 7 Network List Profiles7HKLM\Software\Microsoft\WindowsNT\CurrentVersion\NetworkList\Profiles\{GUID}\
Registry Windows 7 List Applications Installed7HKLM\Software\Microsoft\Windows\CurrentversionXUninstall\{Application. Name)
Registry Windows 7 Security Audit Policies7HKLM\Security\Policy
Registry Windows 7 Time Zone Information7HKLM\System\CurrentControlSet\Control\TimeZonelnformation
Registry Windows 7 User Profile Logon7HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ProfileList\{SID}\
Registry Windows 7 Winlogon shell7HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Remote DesktopXP7810SYSTEM\ControlSet###\Control\ Terminal Server / fDenyTSConnections
Remote Desktop Information7SYSTEM\ControlSet###\Control\Terminal Server\fDenyTSConnections
Roaming Identities (1125 PowerPoint, 1133 Word, 1141 Excel)10NTUSER.DAT\SOFTWARE\Microsoft\Office\15.0\Common\Roaming\Identities\\
Run Box Recent commands7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
Run MRUXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ RunMRU
Run subkey - Active10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run / OneDrive
Run, StartupXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Run
Screen Saver Enabled7NTUSER.DAT\Control Panel\Desktop/ScreenSaveActive
Screen Saver EnabledXP7810NTUSER.DAT\Control Panel\Desktop / ScreenSaveActive
Screen Saver Password Enabled7NTUSER.DAT\Control Panel\Desktop/ScreenSaverIsSecure
Screen Saver Secure Password EnabledXP7810NTUSER.DAT\Control Panel\Desktop / ScreenSaverIsSecure
Screen Saver Timeout7NTUSER.DAT\Control Panel\Desktop/ScreenSaveTimeOut
Screen Saver TimeoutXP7810NTUSER.DAT\Control Panel\Desktop / ScreenSaveTimeOut
Screen Saver Wallpaper7NTUSER.DAT\Control Panel\Desktop/WallPaper
Screen Savers and WallpaperXP7810NTUSER.DAT\Control Panel\Desktop\
SCSI Device Information7SYSTEM\ControlSet###\Enum\SCSI
SCSI Device InformationXP7810SYSTEM\ControlSet###\Enum\SCSI
SCSI Enumeration7810SYSTEM\ControlSet001\Enum\ SCSI\\
Search Charm Entries for Internet Addresses and SitesNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ SearchHistory\DefaultBrowser_ NOPUBLISHERID!Microsoft.Internet Explorer. Default
Search WordWheelQuery710NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
Serial Port Device Information7SYSTEM\ControlSet###\Enum\SERENUM
ServicesXP7810SYSTEM\ControlSet###\Services
Services List7SYSTEM\ControlSet###\Services
Session Manager ExecuteHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager
Shared data to: e-mail10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU
Shared Folders, Shared PrintersXP7810SYSTEM\ControlSet###\Services\ LanmanServer\ Shares /
Shared Photos10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU
Shared photos10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharingMFU
Sharing MFU10NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ SharingMFU
Shell Bags10NTUSER.DAT\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Shell Bags7810UsrClass.dat\Local\Settings\Software\ Microsoft\Windows\Shell\Bags
Shell Bags7810NTUSER.DAT\Software\Microsoft\ Windows\Shell\Bags\1\Desktop
Shell BagsUsrClass.dat\Local\Settings\Software\ Microsoft\Windows\Shell\BagMRU
Shell Execute HooksHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\*
Shell Execute HooksHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\*
Shell ExtensionsHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Shell ExtensionsHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Shell ExtensionsHKEY_USERS\%SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Shell ExtensionsHKEY_USERS\%SID%\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Shell Load and RunHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Shell Load and RunHKEY_CURRENT_USER\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows
ShellBagsXPNTUSER.DAT\Software\Microsoft\ Windows\Shell\ BagMRU
ShellBagsXPNTUSER.DAT\Software\Microsoft\ Windows\Shell\ Bags
ShellBagsXPNTUSER.DAT\Software\Microsoft\ Windows\Shell\ShellNoRoam\ BagMRU
ShellBagsXPNTUSER.DAT\Software\Microsoft\ Windows\Shell\ShellNoRoam\Bags
Shim CacheXPHKLM\SYSTEM\CurrentControlSet\Control\SessionManager\AppCompatibility\AppCompatCache
ShimcacheXPSYSTEM\CurrentControlSet\Control\SessionManager\AppCompatibility
Shimcache7810SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache
Shutdown Time7SYSTEM\ControlSetXXX\Control\Windows\ShutdownTime
Shutdown TimeXP7810SYSTEM\ControlSet###\Control\ Windows / ShutdownTime
SkyDrive E-Mail Account Name8Settings.dat\LocalState\Platform
SkyDrive User Name8settings.dat\RoamingState
Skype App Install10HKEY_CLASSES_ROOT\ActivatableClasses\Package\Microsoft.SkypeApp_3.2.1.0_x86__kzf8qxf38zg5c
Skype Assoc. Files 110HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-skype
Skype Assoc. Files 210HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.skype
Skype Assoc. Files 310HKEY_CURRENT_USER\SOFTWARE\Classes\.skype
Skype Assoc. Files 410HKEY_CLASSES_ROOT\.skype
Skype Cached IP DataHKEY_CURRENT_USER\Software/SKYPE/PHONE/LIB/Connection/HOSTCACHE
Skype Install Path10HKEY_CURRENT_USER\SOFTWARE\Skype\Phone
Skype Installation10HKEY_CLASSES_ROOT\AppX(RandomValue)
Skype Language10HKEY_CURRENT_USER\SOFTWARE\Skype\Phone\UI\General
Skype Process Name10HKEY_LOCAL_MACHINE\SOFTWARE\IM Providers\Skype
Skype Update App ID10HKEY_CLASSES_ROOT\AppID\{27E6D007-EE3B-4FF7-8AE8-28EF0739124C}
Skype User CID8settings.dat\LocalState / skype.account.name
Skype User List10HKEY_CURRENT_USER\SOFTWARE\Skype\Phone\Users\
Skype User Name E-Mailsettings.dat\LocalState / skype.liveuser.CID
Skype Version 110HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\(UID)\(UID)
Skype Version 210HKEY_CLASSES_ROOT\Installer\Products\74A569CF9384AC046B81814F680F246C
SRUMSOFTWARE\Microsoft\WindowsNT\CurrentVersion\SRUM\Extensions {d10ca2fe-6fcf-4f6d-848e-b2e99266fa89} = Application Resource Usage Provider C:\Windows\System32\SRU\
SRUM Resource Usage History7810SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SRUM\Extensions
Start and File Explorer Searches entered by user7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ WordWheelQuery
Start Menu Program ListNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ MenuOrder\ Programs\
Start Searches Entered by User7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
Start Searches entered by userNTUSER.DAT\Software\Microsoft\ SearchAssistant\ ACMru\5###
Startup LocationXP7810SOFTWARE\Microsoft\Command Processor / AutoRun
Startup LocationXP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\Winlogon/Userinit
Startup LocationXP7810SYSTEM\ControlSet###\Control\ SessionManager\BootExecute
Startup SoftwareXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\RunOnce
Startup Software RunXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\Run
Startup Software Run OnceXP7810SOFTWARE\\Microsoft\Windows\ CurrentVersion\RunOnce
Storage Class DriversXP7810SYSTEM\ControlSet001\Control\ DeviceClasses\ {53f56307- b6bf-11d0- 94f2-00a0c91efb8b}
Storage Device InformationXP7810SYSTEM\ControlSet###\Enum\ STORAGE
STORAGE EnumerationXP7810SYSTEM\ControlSet001\Enum\ STORAGE\Volume\\
Storage Spaces Drive ID810SYSTEM\ControlSet###\Services\ spaceport\Parameters
System Restore InfoXP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\ SystemRestore
System Restore Information7SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SystemRestore
TaskBar Application List10NTUSER.DAT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Taskband / FavoritesResolve
TCPIP Data, Domain Names, Internet Connection InfoXP7810SYSTEM\ControlSet###\Services\ Tcpip\Parameters\Interfaces\
TCPIP Network CardsXP7810SYSTEM\ControlSet###\Services\ Tcpip\Parameters\Interfaces\
TechSmith SnagIt MRUNTUSER.DAT\Software\TechSmith\ SnagIt\\Recent Captures
Theme Current ThemeXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Themes / CurrentTheme
Theme Last ThemeNTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Themes\ Last Theme
Time Sync with Internet Servers7SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime\Servers
Time Synch with Internet ChoicesXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\DateTime\Servers
Time Synch with Internet EnabledXP7810SYSTEM\ControlSet###\Services\ W32Time\Parameters / Type
Time Synch with Internet ServersXP7810SOFTWARE\Microsoft\Windows\ CurrentVersion\DateTime\Servers
Time Zone InformationXP7810SYSTEM\ControlSet###\Control\ TimeZoneInformation
Trusted Documents10NTUSER\SOFTWARE\Microsoft\Office\15.0\Word\Security\Trusted Documents\TrustRecords
Trusted Locations10NTUSER\SOFTWARE\Microsoft\Office\15.0\Word\Security\Trusted Locations
Turn off UAC Behavior7SOFTWARE\Microsoft\Widows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
Turn off UAC Behavior7810SOFTWARE\Microsoft\Windows\ CurrentVersion\Policies\System / ConsentPromptBehaviorAdmin
Typed Paths in Windows Explorer7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
Typed Paths into Windows Explorer or File Explorer7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ TypedPaths
TypedURLs10UsrClass.dat\SOFTWARE\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppContainer\ Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLs
TypedURLs10NTUSER.DAT\SOFTWARE\Microsoft\Internet Explorer\TypedURLs
TypedURLs Hyperlink10NTUSER.DAT\SOFTWARE\Microsoft\Internet Explorer\TypedURLs
TypedURLsTime10UsrClass.dat\SOFTWARE\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppContainer\ Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLs
TypedURLsTime10NTUSER.DAT\SOFTWARE\Microsoft\Internet Explorer\TypedURLsTime
TypedURLsVisitCount10UsrClass.dat\SOFTWARE\LocalSettings\Software\Microsoft\Windows\CurrentVersion\AppContainer\ Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\TypedURLsVisitCount
UAC On or OffSOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
UAC On or Off7810SOFTWARE\Microsoft\Windows\ CurrentVersion\Policies\System / EnableLUA
UMB Bus Driver Interface7810SYSTEM\ControlSet001\ Control\DeviceClasses\{65a9a6cf- 64cd-480b-843e-32c86e1ba19f}
USB Device ClassesXP7810SYSTEM\ControlSet###\Control\ DeviceClasses\{53f56307-b6bf-11d0- 94f2-00a0c91efb8b}\/ DeviceInstance
USB Device Containers810SYSTEM\ControlSet###\Control\Device Containers\\ BaseContainers\
USB Device Information Values7810SYSTEM\ControlSet001\Enum\USB\\
USB Device InterfaceXP7810SYSTEM\ControlSet001\ Control\DeviceClasses\{a5dcbf10-6530-11d2-901f-00c04fb951ed}
USB EnumerationXP7810SYSTEM\ControlSet001\Enum\USB
USB First Install Date7810SYSTEM\ControlSet###\Enum\ USBSTOR\\\ Properties\{83da6326-97a6-4088-9453- a1923f573b29}\00000064\00000000/ Data
USB Install Date7810SYSTEM\ControlSet###\Enum\ USBSTOR\\\ Properties\{83da6326-97a6-4088-9453- a1923f573b29}\00000065\00000000/ Data
USB Last Arrival Date810SYSTEM\ControlSet###\Enum\ USBSTOR\\\ Properties\{83da6326-97a6-4088-9453- a1923f573b29}\0066
USB Last Removal Date810SYSTEM\ControlSet###\Enum\ USBSOR\\\ Properties\ {83da6326-97a6-4088-9453- a1923f573b29}\0067
USB Logged On User at Time of AccessXP7810NTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ MountPoints2\
USB ROM DescriptorsHKEY_LOCAL_MACHINE\USBSTOR\
USB to Volume Serial Number7SOFTWARE\Microsoft\WindowsNT\CurrentVersion\EMDMgmt
USB Windows Portable Devices7810SOFTWARE\Microsoft\Windows Portable Devices\Devices
USBPRINTXP7810SYSTEM\ControlSet001\Enum\ USBPRINT\\
USBS Hub InformationXP7810SYSTEM\ControlSet001\services\ usbhub\Enum
USBSTOR Container ID7810SYSTEM\ControlSet###\Enum\ USBSTOR\\/ ContainerID
USBSTOR Drive IdentificationXP7810SYSTEM\ControlSet###\Enum\ USBSTOR\\
USBSTOR EnumerationXP7810SYSTEM\ControlSet###\Enum\ USBSTOR\\
USBSTOR Parent ID Prefix (PIP)SYSTEM\ControlSet###\Enum\ USBSTOR\\/ ParentIdPrefix
User Account Expiration7SAM\Domains\Account\Users\F Key
User Account StatusXP7810SAM\SAM\Domains\Account\Users\/ V
User Information F ValueXP7810SAM\SAM\Domains\Account\Users\/ F
User Information V ValueXP7810SAM\SAM\Domains\Account\Users\/ V
User Information ValuesXP7810SAM\SAM\Domains\Account\Users\
User Live Accounts810SAM\SAM\Domains\Account\Users\/ F
User Logon Account Hidden on Startup7810SAM\SAM\Domains\Account\Users\/ UserDontShowInLogonUI
User Logon Account Hidden on Startup7810SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ SpecialAccounts\UserList /
User Mode Bus EnumeratorV7810SYSTEM\ControlSet001\services\ umbus\Enum
User Name and SIDXP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\ProfileList\
User Password HintV810SAM\SAM\Domains\Account\Users\/ UserPasswordHint
User Password Hint XPXPSOFTWARE\Microsoft\Windows NT\ CurrentVersion\ProfileList\
UserAssistXPNTUSER.DAT\Software\Microsoft\ Windows\ CurrentVersion\Explorer\ UserAssist\
UserAssist7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ UserAssist\
UserAssistNTUSER.DAT\Software\Microsoft\Windows\Currentversion\Explorer\UserAssist\{GUID}\Coun
UsrClass InfoHKEY_USERS\_Classes
VMware Player Recents ListNTUSER.DAT\Software\VMware, Inc.\VMWare Player\VMplayer\Window position
Volume Device Interface ClassXP7810HKLM\SYSTEM\ControlSet001\ Control\Device Classes\{53f5630d- b6bf-11d0-94f2-00a0c91efb8b}
Volume Shadow Copy service driverXP7810SYSTEM\ControlSet001\services\ volsnap\Enum
Vuze Install Path 17HKEY_USERS\(SID)\Software\Azureus
Vuze Install Path 27HKEY_LOCAL_MACHINE\SOFTWARE\Azureus
Vuze Install4j7HKEY_LOCAL_MACHINE\SOFTWARE\ej-technologies\install4j\installations\allinstdirs8461-7759-5462-8226
Vuze install4jprogram7HKEY_USERS\(SID)\Software\ej-technologies\exe4j\pids
Vuze Installer7HKEY_LOCAL_MACHINE\SOFTWARE\ej-technologies\install4j\installations\instdir8461-7759-5462-8226
Windows Explorer Settings7NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Windows Explorer SettingsXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced
Windows Portable Devices7810SOFTWARE\Microsoft\Windows Portable Devices\Devices\
WindowsBootVerificationProgramHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\BootVerificationProgram
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Setup\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx\*
WindowsRunKeysHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Microsoft\Windows\CurrentVersion\Run\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Microsoft\Windows\CurrentVersion\RunOnce\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Setup\*
WindowsRunKeysHKEY_USERS\%SID%\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx\*
WindowsRunServicesHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\*
WindowsRunServicesHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\*
WindowsRunServicesHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce\*
WindowsRunServicesHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices\*
WindowsSystemPolicyShellHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
WindowsSystemPolicyShellHKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\System
WindowsWinlogonNotifyHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\*
WindowsWinlogonNotifyHKEY_USERS\%SID%\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\*
WindowsWinlogonShellHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
WindowsWinlogonShellHKEY_USERS\%SID%\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
WindowsWinlogonShell (GINA DLL)HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
WindowsWinlogonShell (GINA DLL)HKEY_USERS\%SID%\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Winlogon Userinit7HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Userinit
Winlogon UserinitHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Winlogon UserinitHKEY_USERS\%SID%\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
WinRARNTUSER.DAT\Software\WinRAR\Dialog EditHistory\ArcName
WinRARNTUSER.DAT\Software\WinRAR\ DialogEditHistory\ExtrPath
WinRAR Extracted Files MRUNTUSER.DAT\Software\WinRAR\ ArcHistory
WinZip 11.1 Accessed Archives7NTUSER.DAT\Software\Nico Mak Computing\filemenu/filemenu##
WinZip 11.1 Extraction MRU7NTUSER.DAT\Software\Nico Mak Computing\Extract/extract#
WinZip 11.1 Registered User7NTUSER.DAT\Software\Nico Mak Computing\WinIni/Name 1
WinZip 11.1 Temp File7NTUSER.DAT\Software\Nico Mak Computing\Directories/ZipTemp
WinZip Accessed ArchivesNTUSER.DAT\Software\Nico Mak Computing\filemenu / filemenu##
WinZip Extraction MRUNTUSER.DAT\Software\Nico Mak Computing\ Extract / extract#
WinZip Location Extracted ToNTUSER.DAT\Software\Nico Mak Computing\ Directories / ExtractTo
WinZip Registered UserNTUSER.DAT\Software\Nico Mak Computing\ WinIni / Name 1
WinZip Temp FileNTUSER.DAT\Software\Nico Mak Computing\ Directories / ZipTemp
WinZip Zip Creation LocationNTUSER.DAT\Software\Nico Mak Computing\ Directories / AddDir
WinZip Zip Creation LocationNTUSER.DAT\Software\Nico Mak Computing\ Directories / DefDir
Wireless associations to SSIDs by user7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Internet Settings\Wpad\
Wireless Connections Post XP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\ NetworkList\Profiles\
Wireless Post XP7810SOFTWARE\Microsoft\Windows NT\ CurrentVersion\ NetworkList\ Signatures\Managed(or Unmanaged)\
Wireless XPXPSOFTWARE\Microsoft\WZCSVC\ Parameters\Interfaces\{0E271E68-9033- 4A25-9883-A020B191B3C1} /Static#####
Wireless XPXPSOFTWARE\Microsoft\EAPOL\ Parameters\Interfaces\{0E271E68-9033- 4A25-9883-A020B191B3C1} / #
WordPad MRUXP7810NTUSER.DAT\Software\Microsoft\ Windows\CurrentVersion\Applets\ Wordpad\Recent File List
WPD Bus Enum Enumeration810SYSTEM\ControlSet001\Enum\ SWD\WPDBUSENUM
WPD Bus Enum Root Enumeration User Mode Bus Drive Enumeration7810SYSTEM\ControlSet001\Enum\ WpdBusEnumRoot\UMB\
WPD Device Interface7810SYSTEM\ControlSet001\ Control\DeviceClasses\{6ac27878- a6fa-4155-ba85-f98f491d4f33}
Write Block USB Devices7SYSTEM\ControlSet###\Control\storageDevicePolicies\
Write Block USB DevicesXP78SYSTEM\ControlSet###\Control\ StorageDevicePolicies / WriteProtect
XP Search Assistant historyXPNTUSER.DAT\Software\Microsoft\Search Assistant\ACMru\####
Yahoo Chat RoomsNTUSER.DAT\Software\Yahoo\Pager\ profiles\\Chat
Yahoo!NTUSER.DAT\Software\Yahoo\Pager\ Profiles\*
Yahoo! File TransfersNTUSER.DAT\Software\Yahoo\Pager\ File Transfer
Yahoo! File TransfersNTUSER.DAT\Software\Yahoo\Pager\ profiles\screen name \ FileTransfer
Yahoo! IdentitiesNTUSER.DAT\Software\Yahoo\Pager\ profiles\screen name / All Identities, Selected Identities
Yahoo! Last UserNTUSER.DAT\Software\Yahoo\ Pager - Yahoo! User ID
Yahoo! Message ArchivingNTUSER.DAT\Software\Yahoo\Pager\ profiles\screen name\Archive
Yahoo! PasswordNTUSER.DAT\Software\Yahoo\ Pager - EOptions string
Yahoo! Recent ContactsNTUSER.DAT\Software\Yahoo\Pager\ profiles\screen name\IMVironments\ Recent
Yahoo! Saved PasswordNTUSER.DAT\Software\Yahoo\ Pager - Save Password
Yahoo! Screen NamesNTUSER.DAT\Software\Yahoo\Pager\ profiles\screen name
YserverNTUSER.DAT\Software\Yahoo\Yserver
DescriptionXPVistaWin 7Win 8Win 10key