regf"'"'A; C:\Users\exploitfil1\ntuser.dat(PQ~aPVq(PQ~aPVq)PQ~aPVqrmtm0A4HvLE>"' y"FCf`~pS @hbinA;pnk,, v(839CsiTool-CreateHive-{00000000-0000-0000-0000-000000000000}91Enk x<& XBYQ Environment?nk e, ( &!SoftwareEUDC.TTEftnk AdJ$xyh8 MicrosoftlfPowenk oXU&Hh.hWindowsvkemNodeSlotlf8'HandlfbTrusHskHv#l$? ذĤi 2??  0sk$? ذĤi 2??  0sk0N$? ذĤi 2??  Onk FWƱ$pVh8!CurrentVersionnk 2-$(X, 8$!Explorernk x<&`(Z(L!User Shell Foldersvk,@Desktop%USERPROFILE%\Desktopvk 8Local AppData%USERPROFILE%\AppData\LocalvkStartup`%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupvktCookies%USERPROFILE%\AppData\Local\Microsoft\Windows\INetCookiesEUDC.TTE9vknhSendTo%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTovk0 Personal%USERPROFILE%\Documentsvk NetHoodvknx Recent%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recentvk 0 Favorites%USERPROFILE%\Favoritesvk(8 My Musicvk . My Pictures%USERPROFILE%\Picturesvk v Start Menu%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menuvk* My Video x%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts%USERPROFILE%\Musicvk ProgramsEUDC.TTE%USERPROFILE%\Videosvkp Cache%USERPROFILE%\AppData\Local\Microsoft\Windows\INetCachevk&0{374DE290-123F-4565-9164-39C4925E467B}p%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\ProgramsvklXHistory%USERPROFILE%\AppData\Local\Microsoft\Windows\Historyvk<pAppDatavkBTMPh %USERPROFILE%\Downloadsvk tpTemplates%USERPROFILE%\AppData\Roaming\Microsoft\Windows\TemplatesEUDC.TTEhbinvkDisableAutoplayvklf`\Pref%USERPROFILE%\AppData\Roaming%USERPROFILE%\AppData\Local\TempvkBTEMP%USERPROFILE%\AppData\Local\Tempnk Q<& xQX Control Panelnk g;& D%Gv,!Consolenk ;& ?"Systemlf9328936949p950lfMicr`Powenk ;& {X AppEventsnk x<& pX!EUDCnk X;& !Networknk x<& (*!932nk x<& (*949nk x<&p (*950lfCurrlf AppECons`ContEnviEUDCxKeybhNetwȝPrinSoftSystnk x<&(*!936vkhSystemDefaultEUDCFontvk0SystemDefaultEUDCFontvk SystemDefaultEUDCFontvkSystemDefaultEUDCFontnk Hw(CHMinenk H&`!Policiesnk H&0$! Microsoft nk H&0Powernk H&`0 PowerSettingslf8SoftlfMicr'nk H&0!Windowsnk CfC0 !SystemCertificatesnk H&@0"!CurrentVersionnk H&0 Internet Settingslf`IntelfCachlf05.0CachvklfSyst@Windnk H&`0 !5.0nk H&`0!Cachenk H&00!Cachenk u;&x!WABnk X;&l!OsklfxLCounlf'Medink X;&xv  Assistancenk x<& oX! Windows NT nk X;&i!ScreenMagnifiernk X;&i Narratornk x<&iX Wispnk x<&gX$Command Processornk } p%X&?Internet Explorernk X;&Internet Connection Wizardnk x:yk`X B0Windows Error Reporting5.0Windfnk :8 ServerManagerhbin@nk ;&?@*!Networknk ;& @?!NetworkLocationWizardlfx@Netwvk ShowCountvk HistoryNoDup@cvk FullScreenvkFontSizelfuPrivvk ScrollScalevkExtendedEditKeyCustom0 102 204vk CursorSizevk FontFamilyvk ScreenColorsvkTrimLeadingZerosvk PopupColorsBvk PWindowSizevk LoadConImevkWordDelimiters`cvk QuickEditvk ColorTable00B0 0 0vk ColorTable10vk ColorTable01BlfxH%SysI%Sysvk ColorTable11vk ColorTable02BvkJFaceNamevk ColorTable12vk ColorTable03Bvk ColorTable14HDvk ColorTable13vkEnableColorSelectionBvk ColorTable04Dvk ColorTable15BvkExtendedEditKeyvk ColorTable05Bvk ColorTable06Cvk ColorTable07EvkNumberOfHistoryBuffersvkP,ScreenBufferSizevk ColorTable08Avk ColorTable09(Cvk FontWeight0Evk InsertModeBvk PopupColorsHDvk 6FontFamily(F0 0 0vk2HistoryBufferSizeBBhAHAAAB8B`BBBCBXC(CCC DCDHDEDD0E`EEEEF(FPFFFFFGpA Gpnk g;& L ;%SystemRoot%_System32_WindowsPowerShell_v1.0_powershell.exepnk g;& K !;%SystemRoot%_SysWOW64_WindowsPowerShell_v1.0_powershell.exe vk QuickEditvk $VColorTable05vkx ScreenBufferSizevk x2WindowSizevkLFaceNamevk ColorTable06vk FontWeightvk PopupColorsJvk VScreenColorsLucida ConsoleHGpGIIIJXJJJpDvk 6FontFamilyvk QuickEditvk $VColorTable05vkx ScreenBufferSizevk x2WindowSizevk ColorTable06vk FontWeightvkPskWindowpupvk VScreenColorsLucida ConsoleJPKxKKKKL@LL8Jnk ,`.X(*4 Desktopnk Q<&`@(! Input Method nk Q<&`(((!Mousenk &` o(( !Cursorsnk Q<&`(2!Keyboardnk Q<&`oPd("$!PowerCfgnk x!D`g a( Appearancenk Q<&` 8ahZ(&  Accessibility0 0 0