# Custom Key Set
## Internet Explorer Cookies
#%cookies%???.txt
## Run Keys and Startup Files
hkey_lmus\software\microsoft\windows\currentversion\run
hkey_lmus\software\microsoft\windows\currentversion\runonce
hkey_lmus\software\???\microsoft\windows\currentversion\run
hkey_lmus\software\???\microsoft\windows\currentversion\runonce
%bootdrv%documents and settings\???\start menu\programs\startup
%bootdrv%ntldr
%bootdrv%???.bat
%bootdrv%???.com
%bootdrv%???.dll
%bootdrv%???.exe
%bootdrv%???.ini
%bootdrv%???.lib
%bootdrv%???.pif
%bootdrv%???.scr
%bootdrv%???.sys
%bootdrv%???.vxd
%system%autoexec.nt
%system%config.nt
%windir%system.ini
%windir%win.ini
%windir%wininit.ini
## Important Executables and Driver Files
%programfiles%internet explorer\iexplore.exe
%system%???.bat
%system%???.com
&%system%???.dll
&%system%???.exe
%system%???.lib
%system%???.pif
%system%???.scr
%system%???.sys
%system%???.vxd
&%system%drivers
%system%drivers\etc
%system%gdi32.dll
%system%hal.dll
%system%lsass.exe
%system%mrt.exe
%system%msgina.dll
%system%ntdll.dll
%system%ntoskrnl.exe
%system%user32.dll
%system%userinit.exe
%system%winlogon.exe
%system%winsrv.dll
%windir%???.bat
%windir%???.com
%windir%???.dll
%windir%???.exe
%windir%???.lib
%windir%???.pif
%windir%???.scr
%windir%???.sys
%windir%???.vxd
%windir%hosts
!%windir%tasks\WpsUpdateTask_MarkJ.job
%windir%tasks
## Command Handlers and Associations
hkey_classes_root\*\shellex\contextmenuhandlers
hkey_classes_root\???\shell\???\command
hkey_classes_root\protocols\filter
hkey_classes_root\protocols\filter\class install handler
hkey_lmus\software\classes\???\shell\???\command
hkey_lmus\software\microsoft\command processor
## Internet Explorer Settings
#hkey_lmus\software\microsoft\internet explorer
hkey_lmus\software\microsoft\internet explorer\abouturls
hkey_lmus\software\microsoft\internet explorer\explorer bars
hkey_lmus\software\microsoft\internet explorer\extensions
hkey_lmus\software\microsoft\internet explorer\extensions\cmdmapping
hkey_lmus\software\microsoft\internet explorer\main
hkey_lmus\software\microsoft\internet explorer\main\featurecontrol
hkey_lmus\software\microsoft\internet explorer\main\featurecontrol\feature_localmachine_lockdown
hkey_lmus\software\microsoft\internet explorer\menuext
hkey_lmus\software\microsoft\internet explorer\search
hkey_lmus\software\microsoft\internet explorer\searchurl
hkey_lmus\software\microsoft\internet explorer\styles
hkey_lmus\software\microsoft\internet explorer\toolbar
hkey_lmus\software\microsoft\internet explorer\toolbar\shellbrowser
hkey_lmus\software\microsoft\internet explorer\toolbar\webbrowser
hkey_lmus\software\microsoft\internet explorer\urlsearchhooks
## OLE
hkey_lmus\software\microsoft\ole
## NT Startup Settings and Associations
hkey_lmus\software\microsoft\windows nt\currentversion\extensions
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping\system.ini
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping\system.ini\boot
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping\system.ini\boot\shell
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping\win.ini
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping\win.ini\load
hkey_lmus\software\microsoft\windows nt\currentversion\inifilemapping\win.ini\run
hkey_lmus\software\microsoft\windows nt\currentversion\windows
hkey_lmus\software\microsoft\windows nt\currentversion\windows\appinit_dlls
$hkey_lmus\software\microsoft\windows nt\currentversion\winlogon
hkey_lmus\software\microsoft\windows nt\currentversion\winlogon\???\???\dllname
hkey_lmus\software\microsoft\windows nt\currentversion\winlogon\gpextensions
hkey_lmus\software\microsoft\windows nt\currentversion\winlogon\notify
hkey_lmus\software\microsoft\windows nt\currentversion\winlogon\taskman
## Explorer Settings
hkey_lmus\software\microsoft\windows\currentversion\explorer
#hkey_lmus\software\microsoft\windows\currentversion\explorer\shell folders
hkey_lmus\software\microsoft\windows\currentversion\explorer\user shell folders
## Internet Zone Settings
hkey_lmus\software\microsoft\windows\currentversion\internet settings\zonemap\domains
hkey_lmus\software\microsoft\windows\currentversion\internet settings\zonemap\ranges
hkey_lmus\software\microsoft\windows\currentversion\internet settings\zones\0
hkey_lmus\software\microsoft\windows\currentversion\internet settings\zones\???\currentlevel
## Windows Startup Settings
hkey_lmus\software\microsoft\windows\currentversion\policies
hkey_lmus\software\microsoft\windows\currentversion\policies\explorer
hkey_lmus\software\microsoft\windows\currentversion\policies\network
hkey_lmus\software\microsoft\windows\currentversion\policies\system
hkey_lmus\software\microsoft\windows\currentversion\runonce\setup
hkey_lmus\software\microsoft\windows\currentversion\runonceex
hkey_lmus\software\microsoft\windows\currentversion\runservices
hkey_lmus\software\microsoft\windows\currentversion\runservicesonce
hkey_lmus\software\microsoft\windows\currentversion\runservicesonceex
hkey_lmus\software\policies\microsoft\windows\system\scripts
hkey_lmus\software\policies\microsoft\windows\system\scripts\logoff
hkey_lmus\software\policies\microsoft\windows\system\scripts\logon
hkey_lmus\software\policies\microsoft\windows\system\scripts\shutdown
hkey_lmus\software\policies\microsoft\windows\system\scripts\startup
## Installed ActiveX Components
hkey_local_machine\software\microsoft\active setup\installed components
hkey_local_machine\software\microsoft\active setup\installed components\???\stubpath
## Distribution Units
hkey_local_machine\software\microsoft\code store database\distribution units
## Security Settings
hkey_local_machine\software\microsoft\security center
hkey_local_machine\software\microsoft\windows nt\currentversion\accessibility\utility manager\???\application path
hkey_local_machine\software\microsoft\windows nt\currentversion\explorer\advanced
hkey_local_machine\software\microsoft\windows nt\currentversion\svchost
hkey_local_machine\software\microsoft\windows nt\currentversion\wow\boot
## Change or Removal of Installed Software
=hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache
## General Explorer Settings
hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced
hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects
hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks
## Other Windows Settings
hkey_local_machine\software\microsoft\windows\currentversion\internet settings\safesites
hkey_local_machine\software\microsoft\windows\currentversion\runex
hkey_local_machine\software\microsoft\windows\currentversion\shell extensions\approved
hkey_local_machine\software\microsoft\windows\currentversion\shellserviceobjectdelayload
hkey_local_machine\software\microsoft\windows\currentversion\url\defaultprefix
hkey_local_machine\software\microsoft\windows\currentversion\url\prefixes
hkey_local_machine\software\microsoft\windows\currentversion\windowsupdate
hkey_local_machine\software\policies\microsoft\windows\safer\codeidentifiers
hkey_local_machine\software\policies\microsoft\windows\windowsupdate
## Low-level Drivers and Services
hkey_local_machine\system\???\control
hkey_local_machine\system\???\control\lsa
hkey_local_machine\system\???\control\mprservices
hkey_local_machine\system\???\control\mprservices\???\dllname
hkey_local_machine\system\???\control\mprservices\???\entrypoint
hkey_local_machine\system\???\control\mprservices\???\stacksize
hkey_local_machine\system\???\control\session manager
hkey_local_machine\system\???\control\session manager\environment\comspec
hkey_local_machine\system\???\control\session manager\environment\path
hkey_local_machine\system\???\control\session manager\filerenameoperations
hkey_local_machine\system\???\control\session manager\knowndlls
hkey_local_machine\system\???\control\session manager\subsystems
hkey_local_machine\system\???\control\wow
!hkey_local_machine\system\???\services\AdobeFlashPlayerUpdateSvc
hkey_local_machine\system\???\services
hkey_local_machine\system\???\services\tcpip\parameters
#hkey_local_machine\system\???\services\???\imagepath
hkey_local_machine\system\???\services\vxd
hkey_local_machine\system\???\services\vxd\javasup
## TCP/IP Stack
hkey_local_machine\system\???\services\winsock2\parameters\???\???\???\librarypath
#hkey_local_machine\system\???\services\winsock2\parameters\???\???\???\packedcatalogitem
hkey_local_machine\system\???\services\winsock2\parameters\namespace_catalog5\catalog_entries
hkey_local_machine\system\???\services\winsock2\parameters\protocol_catalog9\catalog_entries
## Desktop Settings and Screen Savers
hkey_users\???\control panel\desktop\scrnsave.exe
## File Extensions
#hkey_users\???\software\microsoft\windows\currentversion\explorer\fileexts
#hkey_users\???\software\microsoft\windows\currentversion\explorer\fileexts\???\application
## Additional Security
%system%ctfmon.exe
%system%tasks
hkey_classes_root\.lnk\shellnew
hkey_classes_root\.bfc\shellnew
hkey_classes_root\applications\iexplore.exe\shell\???\command
hkey_classes_root\clsid\{871c5380-42a0-1069-a2ea-08002b30309d}\shell\???\command
hkey_lmus\software\classes\folder\shellex\columnhandlers
hkey_lmus\software\classes\shellscrap
hkey_lmus\software\clients\startmenuinternet\iexplore.exe\shell\???\command
hkey_lmus\software\microsoft\windows nt\currentversion\aedebug
hkey_lmus\software\microsoft\windows nt\currentversion\drivers32
hkey_lmus\software\microsoft\windows nt\currentversion\image file execution options
hkey_lmus\software\microsoft\windows nt\currentversion\image file execution options\???\debugger
hkey_lmus\software\microsoft\windows nt\currentversion\terminal server\install\software\microsoft\windows\currentversion\run
hkey_lmus\software\microsoft\windows nt\currentversion\terminal server\install\software\microsoft\windows\currentversion\runonce
hkey_lmus\software\microsoft\windows nt\currentversion\terminal server\install\software\microsoft\windows\currentversion\runonceex
hkey_lmus\software\microsoft\windows\currentversion\app paths\???\
hkey_lmus\software\microsoft\windows\currentversion\explorer\advanced
hkey_lmus\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden
hkey_lmus\software\microsoft\windows\currentversion\explorer\advanced\folder\superhidden
hkey_lmus\software\microsoft\windows\currentversion\explorer\advanced\folder\superhidden\policy\dontshowsuperhidden
hkey_lmus\software\microsoft\windows\currentversion\explorer\devicenotificationcallbacks
hkey_lmus\software\microsoft\windows\currentversion\explorer\mountpoints\???\shell\???\command
hkey_lmus\software\microsoft\windows\currentversion\explorer\mountpoints2\???\shell\???\command
hkey_lmus\software\microsoft\windows\currentversion\explorer\mycomputer\???\
hkey_lmus\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers
hkey_lmus\software\microsoft\windows\currentversion\group policy\scripts
hkey_local_machine\system\???\control\bootverificationprogram
hkey_local_machine\system\???\control\class\{4d36e96b-e325-11ce-bfc1-08002be10318}\upperfilters
hkey_local_machine\system\???\control\print\monitors
hkey_local_machine\system\???\control\safeboot
hkey_local_machine\system\???\control\safeboot\minimal
hkey_local_machine\system\???\control\safeboot\network
hkey_local_machine\system\???\control\safeboot\option
hkey_local_machine\system\???\control\securityproviders
hkey_local_machine\system\???\control\terminal server\wds\rdpwd\startupprograms
## Creer List Additions
hkey_lmus\software\billp studios\winpatrol\class\exefile
hkey_lmus\software\billp studios\winpatrol\options\filetypes
hkey_lmus\software\classes\???\shell
hkey_lmus\software\classes\???\shell\???\ddeexec
hkey_lmus\software\classes\???\shellex\background\propertysheethandlers
hkey_lmus\software\classes\???\shellex\columnhandlers
hkey_lmus\software\classes\???\shellex\contextmenuhandlers
hkey_lmus\software\classes\???\shellex\copyhookhandlers
hkey_lmus\software\classes\???\shellex\dragdrophandlers
hkey_lmus\software\classes\???\shellex\propertysheethandlers
hkey_lmus\software\classes\clsid\{clsid}\implemented categories\{00021494-0000-0000-c000-000000000046}
hkey_lmus\software\classes\protocols\filter
hkey_lmus\software\classes\protocols\filter\???\clsid
hkey_lmus\software\classes\protocols\handler
hkey_lmus\software\classes\protocols\handler\???\clsid
hkey_lmus\software\microsoft\active setup\installed components
hkey_lmus\software\microsoft\command processor\autorun
hkey_lmus\software\microsoft\ctf\langbaraddin
hkey_lmus\software\microsoft\internet explorer\download\checkexesignatures
hkey_lmus\software\microsoft\windows nt\currentversion\accessibility\configuration
hkey_lmus\software\microsoft\windows nt\currentversion\terminal server\install
hkey_lmus\software\microsoft\windows nt\currentversion\windows\load
hkey_lmus\software\microsoft\windows nt\currentversion\windows\notify
hkey_lmus\software\microsoft\windows nt\currentversion\windows\programs
hkey_lmus\software\microsoft\windows nt\currentversion\windows\shell
hkey_lmus\software\microsoft\windows nt\currentversion\winlogon\shell
hkey_lmus\software\microsoft\windows\currentversion\explorer\fileexts\???\userchoice\progid
hkey_lmus\software\microsoft\windows\currentversion\explorer\shell folders
hkey_lmus\software\microsoft\windows\currentversion\group policy
hkey_lmus\software\microsoft\windows\currentversion\policies\explorer\notrayitemsdisplay
hkey_lmus\software\microsoft\windows\currentversion\policies\explorer\run
hkey_lmus\software\microsoft\windows\currentversion\policies\system\shell
hkey_lmus\software\microsoft\windows\currentversion\shell extensions\approved
hkey_lmus\software\microsoft\windows\currentversion\shellserviceobjectdelayload
hkey_lmus\software\policies\microsoft\internet explorer
hkey_lmus\software\policies\microsoft\windows
hkey_lmus\software\policies\microsoft\windows\currentversion\internet settings
hkey_local_machine\software\microsoft\windows\currentversion\policies\system\disableregistrytools
hkey_local_machine\software\microsoft\windows\currentversion\policies\system\enableinstallerdetection
hkey_local_machine\software\microsoft\windows\currentversion\run\hostmanager
