-
\Device\KsecDD
-
C:\Users\user\AppData\Roaming\!#_RESTORE_FILES_#!.inf
-
\??\MountPointManager
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d35f944c-ffec-11e6-bdeb-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d35f944c-ffec-11e6-bdeb-806e6f6e6963}\Generation
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c4-ccb0-11e5-b7bd-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c4-ccb0-11e5-b7bd-806e6f6e6963}\Generation
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c5-ccb0-11e5-b7bd-806e6f6e6963}\Data
-
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c5-ccb0-11e5-b7bd-806e6f6e6963}\Generation
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c6-ccb0-11e5-b7bd-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c6-ccb0-11e5-b7bd-806e6f6e6963}\Generation
-
Show More 3
-
kernel32.dll.InitializeCriticalSectionEx
-
kernel32.dll.FlsAlloc
-
kernel32.dll.FlsSetValue
-
kernel32.dll.FlsGetValue
-
kernel32.dll.LCMapStringEx
-
-
kernel32.dll.FlsFree
-
kernel32.dll.InitOnceExecuteOnce
-
kernel32.dll.CreateEventExW
-
kernel32.dll.CreateSemaphoreW
-
kernel32.dll.CreateSemaphoreExW
-
kernel32.dll.CreateThreadpoolTimer
-
kernel32.dll.SetThreadpoolTimer
-
kernel32.dll.WaitForThreadpoolTimerCallbacks
-
kernel32.dll.CloseThreadpoolTimer
-
kernel32.dll.CreateThreadpoolWait
-
kernel32.dll.SetThreadpoolWait
-
kernel32.dll.CloseThreadpoolWait
-
kernel32.dll.FlushProcessWriteBuffers
-
kernel32.dll.FreeLibraryWhenCallbackReturns
-
kernel32.dll.GetCurrentProcessorNumber
-
kernel32.dll.CreateSymbolicLinkW
-
kernel32.dll.GetTickCount64
-
kernel32.dll.GetFileInformationByHandleEx
-
kernel32.dll.SetFileInformationByHandle
-
kernel32.dll.InitializeConditionVariable
-
kernel32.dll.WakeConditionVariable
-
kernel32.dll.WakeAllConditionVariable
-
kernel32.dll.SleepConditionVariableCS
-
kernel32.dll.InitializeSRWLock
-
kernel32.dll.AcquireSRWLockExclusive
-
kernel32.dll.TryAcquireSRWLockExclusive
-
kernel32.dll.ReleaseSRWLockExclusive
-
kernel32.dll.SleepConditionVariableSRW
-
kernel32.dll.CreateThreadpoolWork
-
kernel32.dll.SubmitThreadpoolWork
-
kernel32.dll.CloseThreadpoolWork
-
kernel32.dll.CompareStringEx
-
kernel32.dll.GetLocaleInfoEx
-
api-ms-win-core-synch-l1-2-0.dll.InitializeConditionVariable
-
api-ms-win-core-synch-l1-2-0.dll.SleepConditionVariableCS
-
api-ms-win-core-synch-l1-2-0.dll.WakeAllConditionVariable
-
kernel32.dll.AreFileApisANSI
-
kernel32.dll.EnumSystemLocalesEx
-
kernel32.dll.GetDateFormatEx
-
kernel32.dll.GetTimeFormatEx
-
kernel32.dll.GetUserDefaultLocaleName
-
kernel32.dll.IsValidLocaleName
-
kernel32.dll.LCIDToLocaleName
-
kernel32.dll.LocaleNameToLCID
-
advapi32.dll.SystemFunction036
-
cryptbase.dll.SystemFunction001
-
cryptbase.dll.SystemFunction002
-
cryptbase.dll.SystemFunction003
-
cryptbase.dll.SystemFunction004
-
cryptbase.dll.SystemFunction005
-
cryptbase.dll.SystemFunction028
-
cryptbase.dll.SystemFunction029
-
cryptbase.dll.SystemFunction034
-
cryptbase.dll.SystemFunction036
-
cryptbase.dll.SystemFunction040
-
cryptbase.dll.SystemFunction041
-
cryptsp.dll.CryptAcquireContextA
-
cryptsp.dll.CryptEncrypt
-
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
-
setupapi.dll.CM_Get_Device_Interface_List_ExW
-
comctl32.dll.#386
-
Show More 61
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\DECRYPTINFO
-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\a9f315251fdbeaa49965d86977518adbbd1d7a2c.exe
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d35f944c-ffec-11e6-bdeb-806e6f6e6963}\
-
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d35f944c-ffec-11e6-bdeb-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d35f944c-ffec-11e6-bdeb-806e6f6e6963}\Generation
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c4-ccb0-11e5-b7bd-806e6f6e6963}\
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c4-ccb0-11e5-b7bd-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c4-ccb0-11e5-b7bd-806e6f6e6963}\Generation
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c5-ccb0-11e5-b7bd-806e6f6e6963}\
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c5-ccb0-11e5-b7bd-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c5-ccb0-11e5-b7bd-806e6f6e6963}\Generation
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c6-ccb0-11e5-b7bd-806e6f6e6963}\
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c6-ccb0-11e5-b7bd-806e6f6e6963}\Data
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{2400a2c6-ccb0-11e5-b7bd-806e6f6e6963}\Generation
-
Show More 11
a9f315251fdbeaa49965d86977518adbbd1d7a2c