<?xml version="1.0" encoding="utf-8"?>
<Filters xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="filters.xsd">

  <!-- !!! DWORD QWORD values in Value="..." has to be specified as they are presented in regedit when you click "Modify binary data" on such parameters. -->
  <!-- !!! For example, 0x1 dword value is Value="01000000" -->

  <!-- Version: 2024-08-20T17:42:00.000Z-1724175770 -->

<!-- ############################################################################################################### -->
<!-- Part 1 -->
  <Registry Id="{E8C14080-5886-58AC-675C-886046BC1888}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9379EF4BBB}" Path="\registry\machine\software\microsoft\cryptography\certificatetemplatecache\*" />
  <Registry Id="{4E27A6E6-BEEC-BE02-CDB2-EEC6AC127EEE}" Path="\registry\machine\software\microsoft\dfrg\statistics\volume{*" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFD7BD238FFF}" Path="\registry\machine\software\microsoft\identitycrl\*" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8268DE3AAA}" Path="\registry\machine\software\microsoft\reliability analysis\*" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442C0278D444}" Path="\registry\machine\software\microsoft\windows nt\currentversion\print\printers\*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220AE056B222}" Path="\registry\machine\software\microsoft\windows\currentversion\diagnostics\diagtrack" />
  <Registry Id="{F9D25191-6997-69BD-786D-997157CD2999}" Path="\registry\machine\software\microsoft\windows\currentversion\waasassessment" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9379EF4BBB}" Path="\registry\machine\software\microsoft\windows\currentversion\windowsupdate\*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220AE056B222}" Path="\registry\machine\software\wow6432node\google\update*" />
  <Registry Id="{715AD919-E11F-E135-F0E5-11F9DF45A111}" Path="\registry\machine\system\controlset001\enum\acpi\*" />
  <Registry Id="{6049C808-D00E-D024-EFD4-00E8CE349000}" Path="\registry\machine\system\controlset001\services\tcpip\parameters*" />
  <Registry Id="{B59E1D5D-2553-2579-3429-553D1389E555}" Path="\registry\machine\software\microsoft\windows nt\currentversion\print\providers\client side rendering print provider\s*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220AE056B222}" Path="\registry\machine\software\microsoft\windows search\gather\windows\systemindex*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220AE056B222}" Path="\registry\machine\software\microsoft\windows search\usnnotifier\windows\catalogs\systemindex*" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFD7BD238FFF}" Path="\registry\machine\software\microsoft\windows\currentversion\appmodel\staterepository\cache\package\data*" />
  <Registry Id="{8BE787EE-03F7-F457-5377-5241943F7428}">
    <Process Path="?:\Program Files*Kaspersky Lab\*avp.exe" />
  </Registry>
  <Registry Id="{D03CDC33-584C-49AC-A8CC-A796E984C97D}">
    <Process Path="?:\Program Files*Kaspersky Lab\*klnagent.exe" />
  </Registry>
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFDFDFC4D90E}" Path="\REGISTRY\USER*Software\Google\Chrome\PreferenceMACs\Default\extensions.settings" />
  <Registry Id="{6049C808-D00E-D024-EFD4-00E0E0D5EA1F}" Path="\REGISTRY\USER*software\microsoft\windows\currentversion\explorer\userassist\{????????-????-????-????-????????????}\count" />
  <Registry Id="{C6AF2E6E-3664-368A-453A-6646463BD042}" Path="\REGISTRY\USER*local settings\software\microsoft\windows\currentversion\appcontainer\mappings\s-*" />
  <Registry Id="{D7B03F7F-4775-479B-564B-7757574C5186}" Path="\REGISTRY\USER*software\microsoft\vscommon\*" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424192E53}" Path="\REGISTRY\USER*software\microsoft\office\*\common\clienttelemetry\*" />
  <Registry Id="{2C0584C4-9CCA-9CE0-AB90-CCACAC91A6DB}" Path="\REGISTRY\USER*software\microsoft\windows\currentversion\search\flighting\*" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424192E53}" Path="\REGISTRY\USER*software\microsoft\internet explorer\lowregistry\audio\policyconfig\propertystore*" />
  <Registry Id="{2C0584C4-9CCA-9CE0-AB90-CCACAC91A6DB}" Path="\REGISTRY\USER*software\microsoft\visualstudio\telemetry\persistentpropertybag*" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352A3F64}" Path="\REGISTRY\USER*software\microsoft\volatile-keyroam-exclusive" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFDFDFC4D90E}" Path="\REGISTRY\USER*software\microsoft\windows nt\currentversion\hostactivitymanager*" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424192E53}" Path="\REGISTRY\USER*software\microsoft\windows\currentversion\contentdeliverymanager\health\placement-subscribedcontent*" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9B9B8095CA}" Path="\REGISTRY\USER*software\microsoft\windows\currentversion\search\jumplistdata" />
  <Registry Id="{A48D0C4C-1442-1468-2318-44242414422E}" Path="\REGISTRY\USER\software\microsoft\office\*common\languageresources\enabledlanguages" />
  <Registry Id="{715AD919-E11F-E135-F0E5-11F1F1E11FFB}" Path="\REGISTRY\USER\software\microsoft\office\*outlook\search\catalog" />
  <Registry Id="{1BF473B3-8095-CAD7-8BBB-93F98595CABB}" Path="*software\microsoft\windows\currentversion\group policy*" Name="displayname" />
  <Registry Id="{C6AF2E6E-3B40-7582-3666-4EA430407566}" Path="*software\microsoft\windows\currentversion\group policy*" Name="dspath" />
  <Registry Id="{F9D25191-6E73-A8B5-6999-71D76373A899}" Path="*software\microsoft\windows\currentversion\group policy*" Name="endtimehi" />
  <Registry Id="{F9D25191-6E73-A8B5-6999-71D76373A899}" Path="*software\microsoft\windows\currentversion\group policy*" Name="endtimelo" />
  <Registry Id="{D7B03F7F-4C51-8693-4777-5FB541518677}" Path="*software\microsoft\windows\currentversion\group policy*" Name="gpolink" />
  <Registry Id="{D7B03F7F-4C51-8693-4777-5FB541518677}" Path="*software\microsoft\windows\currentversion\group policy*" Name="gponame" />
  <Registry Id="{A48D0C4C-192E-5360-1444-2C821E2E5344}" Path="*software\microsoft\windows\currentversion\group policy*" Name="link" />
  <Registry Id="{C6AF2E6E-3B40-7582-3666-4EA430407566}" Path="*software\microsoft\windows\currentversion\group policy*" Name="lparam" />
  <Registry Id="{D7B03F7F-4C51-8693-4777-5FB541518677}" Path="*software\microsoft\windows\currentversion\group policy*" Name="options" />
  <Registry Id="{0AE362A2-7F84-B9C6-7AAA-82E87484B9AA}" Path="*software\microsoft\windows\currentversion\group policy*" Name="rsopstatus" />
  <Registry Id="{1BF473B3-8095-CAD7-8BBB-93F98595CABB}" Path="*software\microsoft\windows\currentversion\group policy*" Name="starttimehi" />
  <Registry Id="{1BF473B3-8095-CAD7-8BBB-93F98595CABB}" Path="*software\microsoft\windows\currentversion\group policy*" Name="starttimelo" />
  <Registry Id="{D7B03F7F-4C51-8693-4777-5FB541518677}" Path="*software\microsoft\windows\currentversion\group policy*" Name="version" />
  <Registry Id="{0AE362A2-7F84-B9C6-7AAA-82E87484B9AA}" Path="*software\microsoft\windows\currentversion\group policy*" Name="extension*" />
  <Registry Id="{B59E1D5D-2A3F-6471-2555-3D932F3F6455}" Path="*software\microsoft\windows\currentversion\group policy*" Name="last*" />
  <Registry Id="{6049C808-D5EA-1F2C-D000-E84EDAEA1F00}" Path="*software\microsoft\input\locales" Name="inputlocale" />
  <Registry Id="{6049C808-D00E-D024-EFD4-00E8CE349000}" Path="\registry\machine\software\microsoft\multimedia\audio\journal" Name="capture" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFD7BD238FFF}" Path="\registry\machine\software\microsoft\multimedia\audio\journal" Name="render" />
  <Registry Id="{4E27A6E6-BEEC-BE02-CDB2-EEC6AC127EEE}" Path="\registry\machine\software\microsoft\multimedia\audio\journal" Name="last*" />
  <Registry Id="{E8C14080-5886-58AC-675C-886046BC1888}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui" Name="idletime" />
  <Registry Id="{B59E1D5D-2553-2579-3429-553D1389E555}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui" Name="last*" />
  <Registry Id="{E8C14080-5886-58AC-675C-886046BC1888}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\facelogon" Name="credprovuncompletedinstances" />
  <Registry Id="{937CFB3B-0331-0357-1207-331BF167C333}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\sessiondata" Name="last*" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8268DE3AAA}" Path="\registry\machine\software\microsoft\windows\currentversion\bits" Name="perfmmfilename" />
  <Registry Id="{937CFB3B-0331-0357-1207-331BF167C333}" Path="\registry\machine\software\microsoft\windows\currentversion\mdm" Name="clienthealthlastsynctime" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8268DE3AAA}" Path="\registry\machine\software\microsoft\windows\currentversion\windowsupdate" Name="last*" />
  <Registry Id="{D7B03F7F-4775-479B-564B-775F35AB0777}" Path="\registry\machine\software\microsoft\windows\windows error reporting\debug" Name="storelocation" />
  <Registry Id="{937CFB3B-0331-0357-1207-331BF167C333}" Path="\registry\machine\software\wow6432node\google\update" Name="last*" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9379EF4BBB}" Path="\registry\machine\software\microsoft\ccm\ccmeval" Name="tasktimeoutcycles" />
  <Registry Id="{E8C14080-5886-58AC-675C-886046BC1888}" Path="\registry\machine\software\microsoft\windows nt\currentversion\superfetch\pfap" Name="usertime_*" />
  <Registry Id="{C6AF2E6E-3664-368A-453A-664E249AF666}" Path="\registry\machine\software\microsoft\windows\currentversion\wosc\client\persistent\clientstate*" Name="last*" />
  <Registry Id="{B59E1D5D-2553-2579-3429-55353525533D}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\audio\journal" Name="render" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9B9B8BB993}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\internet settings\wpad*" Name="wpaddecisiontime" />
  <Registry Id="{4E27A6E6-BEEC-BE02-CDB2-EECECEBEECC6}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Name="cdnconnectioncount" />
  <Registry Id="{D7B03F7F-4775-479B-564B-77575747755F}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Name="downlinkbps" />
  <Registry Id="{937CFB3B-0331-0357-1207-33131303311B}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Name="downloadmonthlycdnbytes" />
  <Registry Id="{4E27A6E6-BEEC-BE02-CDB2-EECECEBEECC6}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Name="lanconnectioncount" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFDFDFCFFDD7}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Name="normaldownloadcount" />
  <Registry Id="{B59E1D5D-2553-2579-3429-55353525533D}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Name="uplinkbps" />
  <Registry Id="{F9D25191-6997-69BD-786D-997157CD2999}" Path="\REGISTRY\MACHINE\SECURITY\RXACT" Name="log" />
  <Registry Id="{937CFB3B-0331-0357-1207-331BF167C333}" Path="\registry\machine\software\microsoft\remediation\localstate\telemetry" Name="globaleventcounter" />
  <Registry Id="{4E27A6E6-BEEC-BE02-CDB2-EEC6AC127EEE}" Path="\registry\machine\software\microsoft\sms\client\internet facing" Name="internet mp *" />
  <Registry Id="{6049C808-D00E-D024-EFD4-00E8CE349000}" Path="\registry\machine\software\microsoft\sms\mobile client\applicationcatalog" Name="msedgesitelistlastversion" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9B9B8BB909}" Path="\registry\user\*software\jetbrains\resharperplatformvs*" Name="enitityusage" />
  <Registry Id="{937CFB3B-0331-0357-1207-331313033181}" Path="\registry\user\*software\jetbrains\resharperplatformvs*" Name="licenseconflictstats" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8A8A7AA8F8}" Path="\registry\user\*software\microsoft\office\*" Name="count" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8A8A7AA8F8}" Path="\registry\user\*software\microsoft\office\*" Name="en-us" />
  <Registry Id="{715AD919-E11F-E135-F0E5-11F1F1E11F6F}" Path="\registry\user\*software\microsoft\office\*" Name="imwindowrect" />
  <Registry Id="{6049C808-D00E-D024-EFD4-00E0E0D00E5E}" Path="\registry\user\*software\microsoft\office\*" Name="roamingconfigurablesettings" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\microsoft\office\*" Name="00??????" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\microsoft\office\*" Name="01??????" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\microsoft\office\*" Name="11??????" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8A8A7AA8F8}" Path="\registry\user\*software\microsoft\office\*" Name="last*" />
  <Registry Id="{715AD919-E11F-E135-F0E5-11F1F1E11F6F}" Path="\registry\user\*software\microsoft\office\*" Name="roaminglast*" />
  <Registry Id="{F9D25191-6997-69BD-786D-9979796997E7}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\sessioninfo\?\applicationviewmanagement\w32:00000*" Name="virtualdesktop" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352553A3}" Path="\registry\user\*software\tortoisegit\history\commit" Name="logmsgs*" />
  <Registry Id="{937CFB3B-0331-0357-1207-331313033181}" Path="\registry\user\*software\microsoft\fusion" Name="downloadcachesize*" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\microsoft\onedrive*" Name="odsucheckforupdateendtime" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\microsoft\onedrive*" Name="standaloneupdatersafemode" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352553A3}" Path="\registry\user\*software\microsoft\onedrive*" Name="ecsconfiguration*" />
  <Registry Id="{F9D25191-6997-69BD-786D-9979796997E7}" Path="\registry\user\*software\microsoft\onedrive*" Name="last*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220202F22070}" Path="\registry\user\*software\microsoft\windows\currentversion\contentdeliverymanager\subscriptions\*" Name="acceleratecacherefreshlastdetected" />
  <Registry Id="{E8C14080-5886-58AC-675C-8868685886D6}" Path="\registry\user\*software\microsoft\windows\currentversion\contentdeliverymanager\subscriptions\*" Name="updatedrivenbyexpiration" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352553A3}" Path="\registry\user\*software\microsoft\windows\currentversion\contentdeliverymanager\subscriptions\*" Name="last*" />
  <Registry Id="{C6AF2E6E-3664-368A-453A-6646463664B4}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\comdlg32\*" Name="mrulistex" />
  <Registry Id="{715AD919-E11F-E135-F0E5-11F1F1E11F6F}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\featureusage\appbadgeupdated" Name="microsoft.office.*" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352553A3}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\recentdocs*" Name="mrulistex" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8A8A7AA8F8}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\zones\*" Name="flags" />
  <Registry Id="{1BF473B3-8BB9-8BDF-9A8F-BB9B9B8BB909}" Path="\registry\user\*software\microsoft\windows\currentversion\search\flighting" Name="cachedfeaturestring" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFDFDFCFFD4D}" Path="\registry\user\*software\microsoft\windows\currentversion\search\flighting" Name="current" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424144292}" Path="\registry\user\*software\microsoft\windows\currentversion\search\flighting" Name="rotateflight" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220202F22070}" Path="\registry\user\*software\tortoisegitmerge\tortoisegitmerge\workspace\mfctoolbarparameters" Name="commandsusage" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424144292}" Path="\registry\user\*software\microsoft\internet explorer\domstorage\*" Name="total" />
  <Registry Id="{E8C14080-5886-58AC-675C-8868685886D6}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows messaging subsystem\profiles\outlook*" Name="00??????" />
  <Registry Id="{E8C14080-5886-58AC-675C-8868685886D6}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows messaging subsystem\profiles\outlook*" Name="11??????" />
  <Registry Id="{5F38B7F7-CFFD-CF13-DEC3-FFDFDFCFFD4D}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Name="blocked" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Name="count" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352553A3}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Name="loadtimearray" />
  <Registry Id="{2C0584C4-9CCA-9CE0-AB90-CCACAC9CCA1A}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Name="time" />
  <Registry Id="{2C0584C4-9CCA-9CE0-AB90-CCACAC9CCA1A}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Name="type" />
  <Registry Id="{6049C808-D00E-D024-EFD4-00E0E0D00E5E}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\connections" Name="defaultconnectionsettings" />
  <Registry Id="{0AE362A2-7AA8-7ACE-897E-AA8A8A7AA8F8}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\connections" Name="savedlegacysettings" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424144292}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\wpad\*" Name="wpaddecisiontime" />
  <Registry Id="{937CFB3B-0331-0357-1207-331BF167C333}" Path="\registry\machine\software\microsoft\microsoft sql server\*mssqlserver" Name="uptime_time_utc" />
  <Registry Id="{D7B03F7F-4775-479B-564B-775F35AB0777}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Name="outlookfiles" />
  <Registry Id="{D7B03F7F-4775-479B-564B-775F35AB0777}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Name="productfiles" />
  <Registry Id="{F9D25191-6997-69BD-786D-997157CD2999}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Name="outlookdvextensionsfilesintl_*" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442C0278D444}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Name="productnonbootfilesintl_*" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442C0278D444}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Name="spellingandgrammarfiles_*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220AE056B222}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{????????-????-????-????-????????????}" Name="count" />
  <Registry Id="{715AD919-E11F-E135-F0E5-11F9DF45A111}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{????????-????-????-????-????????????}" Name="from" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442C0278D444}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{????????-????-????-????-????????????}" Name="version" />
  <Registry Id="{4E27A6E6-BEEC-BE02-CDB2-EEC6AC127EEE}" Path="\registry\machine\system\controlset*services\sharedaccess\epoch" Name="epoch" />
  <Registry Id="{C6AF2E6E-3664-368A-453A-664E249AF666}" Path="\registry\machine\software\realtek\realtekeffects" Name="{????????-*????????????}*" />
  <Registry Id="{826BEA2A-F220-F246-01F6-220202F22070}" Path="\registry\user\*software\microsoft\office\*startupitems" Name="?" />
  <Registry Id="{937CFB3B-0331-0357-1207-331313033181}" Path="\registry\user\*software\microsoft\office\*startupitems" Name="??" />
  <Registry Id="{A48D0C4C-1442-1468-2318-442424144292}" Path="\registry\user\*software\microsoft\office\*startupitems" Name="???" />
  <Registry Id="{B59E1D5D-2553-2579-3429-5535352553A3}" Path="\registry\user\*software\microsoft\office\*startupitems" Name="????" />
  <Registry Id="{3D1695D5-ADDB-ADF1-BCA1-DDBDBDADDB2B}" Path="\registry\user\*software\policies\microsoft\windows\currentversion\internet settings\lockdown_zones\*" Name="????" />
  <Registry Id="{C6AF2E6E-3664-368A-453A-664E249AF666}" Path="\registry\machine\software\microsoft\officesoftwareprotectionplatform\data*" Name="?" />

<!-- ############################################################################################################### -->
<!-- Part 2 -->
<!-- Part 2 2022-10-06T14:15:00.000Z-1665065734 *count* removed -->
	<Registry Id="{C8713ACE-6D77-09CA-F3A99A700A0B39B1}" Path="*software\microsoft\windows\currentversion\group policy*" Value="????0000" />
	<Registry Id="{2D9E8E55-2BE0-153A-0BB7B6D1AB00DFFD}" Path="*software\microsoft\windows\currentversion\group policy*" Value="????000000000000" />
	<Registry Id="{9E29E143-EA8E-7DFB-3EA014868C6819E3}" Path="*software\microsoft\windows\currentversion\group policy*" Value="??00??000000" />
	<Registry Id="{3E86D9AA-1006-83FE-C6CE884B84D7CA01}" Path="*software\microsoft\input\locales" Value="????0000" />
	<Registry Id="{BE141358-F2E7-CAD7-EDFDD22A7981C755}" Path="*software\microsoft\input\locales" Value="????000000000000" />
	<Registry Id="{8F3723FF-546E-571C-CFC25F3E0AD5F5BD}" Path="*software\microsoft\input\locales" Value="??00??000000" />
	<Registry Id="{5F2535C3-C18A-A227-932F1C41CCBDD608}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\CLASS\{*" Value="????0000" />
	<Registry Id="{30E13DB1-5A4E-EA24-1157DAB50E6ED884}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\CLASS\{*" Value="????000000000000" />
	<Registry Id="{C2C61ABF-FCA8-A3CE-21AE86494488A7A4}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\CLASS\{*" Value="??00??000000" />
	<Registry Id="{2C244F82-5967-F351-4D109AD4AF71BE86}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{*" Value="????0000" />
	<Registry Id="{58F1D18E-F16B-3719-9DFF9FA3AAB472EE}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{*" Value="????000000000000" />
	<Registry Id="{29A6A842-FF2D-5ABC-43C69478398292F4}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{*" Value="??00??000000" />
	<Registry Id="{DC89B8F6-1CCA-AACE-093C1D4A21F65991}" Path="\registry\machine\software\microsoft\multimedia\audio\journal" Value="????0000" />
	<Registry Id="{449C179D-8597-B73C-5DC64CA8A5F54078}" Path="\registry\machine\software\microsoft\multimedia\audio\journal" Value="????000000000000" />
	<Registry Id="{9D1D76E6-1217-2025-706C29B55A80AE67}" Path="\registry\machine\software\microsoft\multimedia\audio\journal" Value="??00??000000" />
	<Registry Id="{FBE182FE-AA40-E585-E7C366BF50CC323D}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui" Value="????0000" />
	<Registry Id="{38C6F273-F2D1-BE6A-0C66A3A90172E20D}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui" Value="????000000000000" />
	<Registry Id="{BFD02C53-C442-FE18-2E4E6D5BCEF0EED5}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui" Value="??00??000000" />
	<Registry Id="{9752EF06-784A-6B50-9FDD460EB511B5E9}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\facelogon" Value="????0000" />
	<Registry Id="{0BA8F4AE-A7D7-9F49-4D7DEE37A0064692}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\facelogon" Value="????000000000000" />
	<Registry Id="{A31E4BEC-4D25-3CD6-D6E9D7871780E9CD}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\facelogon" Value="??00??000000" />
	<Registry Id="{566DCB1B-3769-4CBC-FB4FDA94533AEAE0}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\sessiondata" Value="????0000" />
	<Registry Id="{D8C4A6DF-6C6C-D426-C613D0ADAB076ECB}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\sessiondata" Value="????000000000000" />
	<Registry Id="{AD173560-040F-E839-BD5C69843396EA3F}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\sessiondata" Value="??00??000000" />
	<Registry Id="{14977AC2-FFB1-AED0-B6456705EC9B36FD}" Path="\registry\machine\software\microsoft\windows\currentversion\bits" Value="????0000" />
	<Registry Id="{CF7BE35D-3F40-6DFE-84A7EB14309A33B4}" Path="\registry\machine\software\microsoft\windows\currentversion\bits" Value="????000000000000" />
	<Registry Id="{B4B7FD9C-3C05-F979-CE7C91C4CE6BBDE5}" Path="\registry\machine\software\microsoft\windows\currentversion\bits" Value="??00??000000" />
	<Registry Id="{AD49B87E-873E-5489-340859ECCAA96B00}" Path="\registry\machine\software\microsoft\windows\currentversion\component based servicing\tirunning" Value="????0000" />
	<Registry Id="{ABAA33A9-FB61-ACA9-8981C1663CA6FDD5}" Path="\registry\machine\software\microsoft\windows\currentversion\component based servicing\tirunning" Value="????000000000000" />
	<Registry Id="{1272B77E-7C06-4605-3857A70F67AF34B7}" Path="\registry\machine\software\microsoft\windows\currentversion\component based servicing\tirunning" Value="??00??000000" />
	<Registry Id="{A5B9BBF7-7694-674F-9E85B8DF08EAF6D6}" Path="\registry\machine\software\microsoft\windows\currentversion\mdm" Value="????0000" />
	<Registry Id="{3481E031-7FD7-3B30-E14C031C6B096DD8}" Path="\registry\machine\software\microsoft\windows\currentversion\mdm" Value="????000000000000" />
	<Registry Id="{D077B256-FA98-5F04-32EE799548978680}" Path="\registry\machine\software\microsoft\windows\currentversion\mdm" Value="??00??000000" />
	<Registry Id="{BCDA89E4-9E5C-F4E7-4BB08A759A272191}" Path="\registry\machine\software\microsoft\windows\currentversion\windowsupdate" Value="????0000" />
	<Registry Id="{021D8484-4A36-408A-1657799F88E0A461}" Path="\registry\machine\software\microsoft\windows\currentversion\windowsupdate" Value="????000000000000" />
	<Registry Id="{BF975D7B-117D-20DB-0023C87A3CFE9E55}" Path="\registry\machine\software\microsoft\windows\currentversion\windowsupdate" Value="??00??000000" />
	<Registry Id="{4545D5C2-3F02-5E3A-14230C491BEB22F6}" Path="\registry\machine\software\microsoft\windows\windows error reporting\debug" Value="????0000" />
	<Registry Id="{D0A7EE25-53F4-8926-9ABB2D61F0595BAD}" Path="\registry\machine\software\microsoft\windows\windows error reporting\debug" Value="????000000000000" />
	<Registry Id="{589F49E4-01CE-0635-70C254B0D9F2A47F}" Path="\registry\machine\software\microsoft\windows\windows error reporting\debug" Value="??00??000000" />
	<Registry Id="{2CB2BA42-CD55-7EE5-0D6DA4C89F96DC27}" Path="\registry\machine\software\microsoft\ccm\ccmeval" Value="????0000" />
	<Registry Id="{16490A80-E45A-74F6-C7E6B747D87501D8}" Path="\registry\machine\software\microsoft\ccm\ccmeval" Value="????000000000000" />
	<Registry Id="{490FBEA1-E0BC-3FF0-922C386209CD38DA}" Path="\registry\machine\software\microsoft\ccm\ccmeval" Value="??00??000000" />
	<Registry Id="{1FC73661-6956-07B5-4A87E873DEC6D9ED}" Path="\registry\machine\software\microsoft\windows nt\currentversion\superfetch\pfap" Value="????0000" />
	<Registry Id="{C005CE5D-4841-FA2D-FA2D2C91F1773FAD}" Path="\registry\machine\software\microsoft\windows nt\currentversion\superfetch\pfap" Value="????000000000000" />
	<Registry Id="{D7638AEF-E2BC-4CA7-BF51456324A20725}" Path="\registry\machine\software\microsoft\windows nt\currentversion\superfetch\pfap" Value="??00??000000" />
	<Registry Id="{DA01E4DD-3B4B-804B-E0CEF4918C0A0F78}" Path="\registry\machine\software\microsoft\windows\currentversion\wosc\client\persistent\clientstate*" Value="????0000" />
	<Registry Id="{FAAABBA1-217D-AFE7-2B76F995948F2485}" Path="\registry\machine\software\microsoft\windows\currentversion\wosc\client\persistent\clientstate*" Value="????000000000000" />
	<Registry Id="{A3AB7CF9-D361-248B-E294F9B4BAFA3B8C}" Path="\registry\machine\software\microsoft\windows\currentversion\wosc\client\persistent\clientstate*" Value="??00??000000" />
	<Registry Id="{E3CE3673-2A44-CCE8-8A71E07811359AD4}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\audio\journal" Value="????0000" />
	<Registry Id="{4C41C54D-7945-8CF1-FAC82D591482DA52}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\audio\journal" Value="????000000000000" />
	<Registry Id="{DC7D65E6-81BE-7D28-A9D41D2CE684D1C9}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\audio\journal" Value="??00??000000" />
	<Registry Id="{F47626BE-4C6F-588F-908E696FD988AD04}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\internet settings\wpad*" Value="????0000" />
	<Registry Id="{D56B543F-7624-4667-E7D4F18B73F882EC}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\internet settings\wpad*" Value="????000000000000" />
	<Registry Id="{9CDB12E7-54FD-E90F-91F843D3936ADB70}" Path="\registry\user\s-1-5-19\software\microsoft\windows\currentversion\internet settings\wpad*" Value="??00??000000" />
	<Registry Id="{B39E18DB-207B-119E-C4E49E945BDB5CF7}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Value="????0000" />
	<Registry Id="{5720AB0E-1932-1643-75CECA0B1D624554}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Value="????000000000000" />
	<Registry Id="{07256AA3-6A17-779C-35BF8E9859EC38AD}" Path="\registry\user\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\usage" Value="??00??000000" />
	<Registry Id="{0A7904BF-6AB8-4C55-47787C0AE67FDD7F}" Path="\REGISTRY\MACHINE\SECURITY\RXACT" Value="????0000" />
	<Registry Id="{AEC23725-E7A7-886D-D40C740606301968}" Path="\REGISTRY\MACHINE\SECURITY\RXACT" Value="????000000000000" />
	<Registry Id="{5DE90B95-A193-99C8-A030BACE651D6678}" Path="\REGISTRY\MACHINE\SECURITY\RXACT" Value="??00??000000" />
	<Registry Id="{1BCFCA06-1F6A-0028-877EBF2A991601B8}" Path="\registry\machine\software\microsoft\remediation\localstate\telemetry" Value="????0000" />
	<Registry Id="{13625183-9CDC-9E30-326B0108F96D9546}" Path="\registry\machine\software\microsoft\remediation\localstate\telemetry" Value="????000000000000" />
	<Registry Id="{06ECC4D1-1642-3911-B3FE18EFDBE16730}" Path="\registry\machine\software\microsoft\remediation\localstate\telemetry" Value="??00??000000" />
	<Registry Id="{B58F7CE8-36F1-0DEA-74A83BBF6134FD3A}" Path="\registry\machine\software\microsoft\sms\client\internet facing" Value="????0000" />
	<Registry Id="{580B8002-092C-F1C9-E4364F300E1A32F1}" Path="\registry\machine\software\microsoft\sms\client\internet facing" Value="????000000000000" />
	<Registry Id="{629D8B8A-816E-E520-900EAC774C3EA3AF}" Path="\registry\machine\software\microsoft\sms\client\internet facing" Value="??00??000000" />
	<Registry Id="{62C65276-885B-1F61-5F6B0601E46FEB7A}" Path="\registry\machine\software\microsoft\sms\mobile client\applicationcatalog" Value="????0000" />
	<Registry Id="{41FF1683-F115-FC69-3CE9CD210FE274DE}" Path="\registry\machine\software\microsoft\sms\mobile client\applicationcatalog" Value="????000000000000" />
	<Registry Id="{60E1C260-9678-4835-95EF1785FAC0EF56}" Path="\registry\machine\software\microsoft\sms\mobile client\applicationcatalog" Value="??00??000000" />
	<Registry Id="{6AE742B6-A3E8-1287-65C33EF95CC08517}" Path="*\software\wow6432node\google\update*" Value="????0000" />
	<Registry Id="{3DED1C41-3CD0-FC26-0E186CA7EB4025BD}" Path="*\software\wow6432node\google\update*" Value="????000000000000" />
	<Registry Id="{054F6CA7-4269-60F7-F1FF894E892017D3}" Path="*\software\wow6432node\google\update*" Value="??00??000000" />
	<Registry Id="{F4167D69-73CC-C21F-C6A2EB1C5A81CA46}" Path="*\software\google\update*" Value="????0000" />
	<Registry Id="{A3FCBF1F-B3DB-4444-0437B2233AC65B7C}" Path="*\software\google\update*" Value="????000000000000" />
	<Registry Id="{5A2CE881-31B4-B25B-0A217231C9F9A925}" Path="*\software\google\update*" Value="??00??000000" />
	<Registry Id="{803800D3-28D4-4755-968936AAD771275E}" Path="\registry\user\*software\jetbrains\resharperplatformvs*" Value="????0000" />
	<Registry Id="{45159C37-664C-6EF1-B47122921F076DB0}" Path="\registry\user\*software\jetbrains\resharperplatformvs*" Value="????000000000000" />
	<Registry Id="{41A3C616-D5CA-E960-EFBADB94DB740258}" Path="\registry\user\*software\jetbrains\resharperplatformvs*" Value="??00??000000" />
	<Registry Id="{DB91B50E-1FB4-FF52-F45F667CFC046A7F}" Path="\registry\user\*software\microsoft\office\*" Value="????0000" />
	<Registry Id="{F97919E3-152A-EAAF-24E8B463E74D6730}" Path="\registry\user\*software\microsoft\office\*" Value="????000000000000" />
	<Registry Id="{EB54EA7F-6781-5421-1B2F06AA9BFCC7DE}" Path="\registry\user\*software\microsoft\office\*" Value="??00??000000" />
	<Registry Id="{FCDC617A-A235-09B6-E9DB65C93B501540}" Path="\registry\user\*software\microsoft\windows\currentversion\activitydatamodel\readerrevisioninfo" Value="????0000" />
	<Registry Id="{13540DD6-CA69-ED6E-BC44557CBDE35CD7}" Path="\registry\user\*software\microsoft\windows\currentversion\activitydatamodel\readerrevisioninfo" Value="????000000000000" />
	<Registry Id="{CA69E1AA-115A-9C54-76BED30A163BB949}" Path="\registry\user\*software\microsoft\windows\currentversion\activitydatamodel\readerrevisioninfo" Value="??00??000000" />
	<Registry Id="{65399EEE-D238-179C-649E9FEA3603838D}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\sessioninfo\?\applicationviewmanagement\w32:00000*" Value="????0000" />
	<Registry Id="{870D33E6-4856-8EEE-1E7FA63A5D4E9392}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\sessioninfo\?\applicationviewmanagement\w32:00000*" Value="????000000000000" />
	<Registry Id="{BECD1589-8740-3F7F-17AA1FB5D2BC72EF}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\sessioninfo\?\applicationviewmanagement\w32:00000*" Value="??00??000000" />
	<Registry Id="{1CBA2831-2F2B-BBDE-328A60C765352238}" Path="\registry\user\*software\tortoisegit\history\commit" Value="????0000" />
	<Registry Id="{74B6A422-CDA6-3260-D4FD7BD6B9FC195B}" Path="\registry\user\*software\tortoisegit\history\commit" Value="????000000000000" />
	<Registry Id="{FFF4595D-E505-3218-0FE976016BE66C38}" Path="\registry\user\*software\tortoisegit\history\commit" Value="??00??000000" />
	<Registry Id="{D625D70E-7F7B-A934-E6E0C0F0325D4D86}" Path="\registry\user\*software\microsoft\fusion" Value="????0000" />
	<Registry Id="{42BB1D3E-0BA2-DCC8-0D1231B1CED6BDB5}" Path="\registry\user\*software\microsoft\fusion" Value="????000000000000" />
	<Registry Id="{41D4DB54-B655-5398-1973647DA577DB3A}" Path="\registry\user\*software\microsoft\fusion" Value="??00??000000" />
	<Registry Id="{FFE8E820-AF24-2A70-0F5297178F2FC2AE}" Path="\registry\user\*software\microsoft\onedrive*" Value="????0000" />
	<Registry Id="{2D5F728E-3AD7-A929-0C7DFE3C8729D93E}" Path="\registry\user\*software\microsoft\onedrive*" Value="????000000000000" />
	<Registry Id="{ECCCDA6A-FBE6-F978-113F777C2A774A44}" Path="\registry\user\*software\microsoft\onedrive*" Value="??00??000000" />
	<Registry Id="{FCC2159E-092C-09F9-8EF7F4826393120C}" Path="\registry\user\*software\microsoft\windows\currentversion\contentdeliverymanager\subscriptions\*" Value="????0000" />
	<Registry Id="{54BD8849-2FF5-F695-A6816327E57F2BCF}" Path="\registry\user\*software\microsoft\windows\currentversion\contentdeliverymanager\subscriptions\*" Value="????000000000000" />
	<Registry Id="{587A57E7-7757-A5DE-FDFFC81BB69C28D3}" Path="\registry\user\*software\microsoft\windows\currentversion\contentdeliverymanager\subscriptions\*" Value="??00??000000" />
	<Registry Id="{C2BF6398-1B2F-2B1B-7B325123CBB0C417}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\comdlg32\*" Value="????0000" />
	<Registry Id="{31FC044B-4179-DB63-0553A430C2C3A0FE}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\comdlg32\*" Value="????000000000000" />
	<Registry Id="{1FEDB815-1D11-CF9B-A7D17D67A62C8837}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\comdlg32\*" Value="??00??000000" />
	<Registry Id="{EE959FC7-0156-7BB2-85F1391C5CECF9EA}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\featureusage\appbadgeupdated" Value="????0000" />
	<Registry Id="{395B36D6-DA6C-C9C9-B14570B279B598E7}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\featureusage\appbadgeupdated" Value="????000000000000" />
	<Registry Id="{1186A878-699E-545F-58E95025592B0A6E}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\featureusage\appbadgeupdated" Value="??00??000000" />
	<Registry Id="{8F77F122-88AB-0216-F1E3F69767441A7A}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\recentdocs*" Value="????0000" />
	<Registry Id="{69BCBE19-E49A-BD9E-735E5264EC53B13B}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\recentdocs*" Value="????000000000000" />
	<Registry Id="{903DB78B-8642-A9AD-FE01371EC1857875}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\recentdocs*" Value="??00??000000" />
	<Registry Id="{F955C485-C9DA-8CA4-EC243B2864E58198}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\zones\*" Value="????0000" />
	<Registry Id="{16CB23CC-3082-0B6B-83407CF3B69FAFD9}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\zones\*" Value="????000000000000" />
	<Registry Id="{D340C06F-F2B6-A30B-42E9C9E95B716B6C}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\zones\*" Value="??00??000000" />
	<Registry Id="{436EA455-1D5E-41E7-9A87279C0AE13634}" Path="\registry\user\*software\microsoft\windows\currentversion\search\flighting" Value="????0000" />
	<Registry Id="{53795842-5C2C-A7DF-D7E3642ED21C29CC}" Path="\registry\user\*software\microsoft\windows\currentversion\search\flighting" Value="????000000000000" />
	<Registry Id="{0CD56609-B4EA-B002-359833AC49A5F8D4}" Path="\registry\user\*software\microsoft\windows\currentversion\search\flighting" Value="??00??000000" />
	<Registry Id="{EB464DC5-E372-8463-C2E50CA33D344151}" Path="\registry\user\*software\tortoisegitmerge\tortoisegitmerge\workspace\mfctoolbarparameters" Value="????0000" />
	<Registry Id="{A4993FBD-E5CE-F386-E7D391C6C511F128}" Path="\registry\user\*software\tortoisegitmerge\tortoisegitmerge\workspace\mfctoolbarparameters" Value="????000000000000" />
	<Registry Id="{3FCD1394-D58F-F9DF-E54A6AEA8712945F}" Path="\registry\user\*software\tortoisegitmerge\tortoisegitmerge\workspace\mfctoolbarparameters" Value="??00??000000" />
	<Registry Id="{4C21EEDB-4B81-D289-B637FA586AD42208}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows messaging subsystem\profiles\outlook*" Value="????0000" />
	<Registry Id="{1565DAB7-F93C-FD41-A7A6564EDAF92C5B}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows messaging subsystem\profiles\outlook*" Value="????000000000000" />
	<Registry Id="{C42C7C04-E7CC-44DB-2B440D0AF07F2E9E}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows messaging subsystem\profiles\outlook*" Value="??00??000000" />
	<Registry Id="{CEFBE132-1C4F-1956-8CCC49896C40279F}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Value="????0000" />
	<Registry Id="{6F87F2C9-8876-25CC-E9EE102F9AA3ACDB}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Value="????000000000000" />
	<Registry Id="{01DDD7CC-B51C-A875-52E6D14E6C0DA772}" Path="\registry\user\*software\microsoft\windows\currentversion\ext\stats\{*" Value="??00??000000" />
	<Registry Id="{C02C4609-9328-D07F-508313BA3C6D4491}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\connections" Value="????0000" />
	<Registry Id="{D5B99FC0-4DD6-8B47-C383BB7CDAFA612D}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\connections" Value="????000000000000" />
	<Registry Id="{529446FD-6E84-EE69-9A439004BF1795C4}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\connections" Value="??00??000000" />
	<Registry Id="{58524E6F-139D-2BEA-81DFD40F8C92AF57}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\wpad\*" Value="????0000" />
	<Registry Id="{6C5081F4-7EAF-B306-533033295BD9FD1C}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\wpad\*" Value="????000000000000" />
	<Registry Id="{5E5B701C-6304-62C3-30ACBC3C640C6CE9}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings\wpad\*" Value="??00??000000" />
	<Registry Id="{2AED028A-B9FE-C4F7-9F889A7F7474E692}" Path="*\internet explorer\domstorage\*" Value="????????" />
	<Registry Id="{614E8300-BA55-68CE-506D4F3854236602}" Path="*\internet explorer\domstorage\*" Value="????????????????" />
	<Registry Id="{4078154E-0790-FAF6-1EC307A89BBCCC71}" Path="\registry\machine\software\microsoft\microsoft sql server\*mssqlserver" Value="????0000" />
	<Registry Id="{1FC08024-3E5B-2429-7AE79F58865AF281}" Path="\registry\machine\software\microsoft\microsoft sql server\*mssqlserver" Value="????000000000000" />
	<Registry Id="{30BCD79A-4F0C-35F7-C051EDB1DCCC45F6}" Path="\registry\machine\software\microsoft\microsoft sql server\*mssqlserver" Value="??00??000000" />
	<Registry Id="{FC30B70B-C218-43B5-7A10A5D0BFF32D36}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Value="????0000" />
	<Registry Id="{9B052DF9-192A-7688-F46DFB3567768C52}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Value="????000000000000" />
	<Registry Id="{6CFA5ED7-482F-9EF5-CC74376F54A7D750}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products*\usage" Value="??00??000000" />
	<Registry Id="{CA527C87-0B1E-C6FC-F71FB5A94F70985F}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{*}" Value="????0000" />
	<Registry Id="{4A127D10-0765-8EE3-84D0121F759CAE20}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{*}" Value="????000000000000" />
	<Registry Id="{8C280423-287A-0BB3-B9733D2C2591D271}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{*}" Value="??00??000000" />
	<Registry Id="{86838719-277C-6515-3843AB8A853D9774}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{*}" Value="%kl_undef%" />
	<Registry Id="{6D65FF8B-FBC4-21E7-BF4BE5C8473063A1}" Path="\registry\machine\system\controlset001\services\asp.net*names" Value="????0000" />
	<Registry Id="{AE8EB602-A4DE-EBE1-BBBE49B5476F7D50}" Path="\registry\machine\system\controlset001\services\asp.net*names" Value="????000000000000" />
	<Registry Id="{C88AEA79-8F9A-5D7F-7F6199134BD2E1F8}" Path="\registry\machine\system\controlset001\services\asp.net*names" Value="??00??000000" />
	<Registry Id="{628B0494-F6BE-2DBC-94452D190F2C8E6C}" Path="\registry\machine\system\controlset*services\sharedaccess\epoch" Value="????0000" />
	<Registry Id="{AFD6FB20-7C3F-711A-97AA89EE94DA6DBB}" Path="\registry\machine\system\controlset*services\sharedaccess\epoch" Value="????000000000000" />
	<Registry Id="{A406E3D9-045C-50C1-C5A850B6228FBBC5}" Path="\registry\machine\system\controlset*services\sharedaccess\epoch" Value="??00??000000" />
	<Registry Id="{64E0A353-7B90-A8D6-A4518E27E5AF80F4}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranet*" Value="00a6caf610ff" />
	<Registry Id="{76EEEF18-580C-F5A8-3600268A5630D12E}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranet*" Value="30f70dcaca7f" />
	<Registry Id="{EB52307D-E8BD-BA6B-087AFACD02430DF3}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranet*" Value="e25f45127864" />
	<Registry Id="{78498519-7C0E-F54A-F9BE719458795C24}" Path="*\cache\*" Value="?" />
	<Registry Id="{CD13B29F-D5C5-A803-5D2915C6484D106E}" Path="*\cache\*" Value="??" />
	<Registry Id="{02F3E8C0-A9D1-776C-85B9A57C7B75133A}" Path="*\cache\*" Value="???" />
	<Registry Id="{90274D31-3158-982E-7C165AC0FB75E32F}" Path="*\cache\*" Value="????" />
	<Registry Id="{14FF85D9-E4AC-2A7B-595770F9AF2BA213}" Path="*\cache\*" Value="?????" />
	<Registry Id="{67A2E850-6D3F-75C4-7BC6CBF53B1B3848}" Path="*\cache\*" Value="??????" />
	<Registry Id="{233D14A3-DD62-EFCE-765F4509F694FC13}" Path="*\cache\*" Value="???????" />
	<Registry Id="{A3F8CF1C-722C-F331-D5216366C5FDC847}" Path="*\cache\*" Value="????????" />
	<Registry Id="{DD008699-5247-373E-18712701492A1FE9}" Path="*\cache\*" Value="?????????" />
	<Registry Id="{41CA0B0C-5C1F-B4AF-23D6BBBE3A642087}" Path="*\cache\*" Value="??????????" />
	<Registry Id="{F1A325B0-8755-8F2F-3295E6EF26EBDC50}" Path="*\cache\*" Value="???????????" />
	<Registry Id="{782B5AEF-C5C4-EEF7-BD824F536FF3099A}" Path="*\cache\*" Value="????????????" />
	<Registry Id="{2806390C-55AC-7C88-90E3A23CCDE8C0E9}" Path="\registry\user\*\local settings\muicache\*\????????" Name="@%systemroot%\system32\*" />
	<Registry Id="{641F6F1E-C4DC-75DC-FE8D13C8AF8762D2}" Path="\registry\user\*\local settings\muicache\*\????????" Name="*%windir%\system32\*" />
	<Registry Id="{EA180A41-E9D3-897E-B77EF2DE43FE831C}" Path="\registry\user\*\local settings\muicache\*\????????" Name="@c:\windows\*" />
	<Registry Id="{E3FB50AB-CA3A-72D8-702D987AA290C5A5}" Path="\registry\user\*\local settings\muicache\*\????????" Name="@c:\program files*\common files\system\*" />
	<Registry Id="{52BFE76C-B743-21AA-AE76EDC8B0D2C89A}" Path="\registry\user\*\local settings\muicache\*\????????" Name="@ieframe.dll*" />
	<Registry Id="{F69F1E53-2991-739A-C9646E22A15DFFFE}" Path="\registry\user\*\local settings\muicache\*\????????" Name="@sendmail.dll*" />
	<Registry Id="{013D2EEF-26B0-CB4F-74BE30D378E10A36}" Path="\registry\user\*\local settings\muicache\*\????????" Name="@zipfldr.dll*" />
	<Registry Id="{B1FEC8A1-D546-3BF5-7C87481073A8AEF6}" Path="*\thememanager" Name="lastloadeddpi" />
	<Registry Id="{881EAFCE-7BEB-1D5B-C766842BD607F15C}" Path="*\thememanager" Name="lastuserlangid" />
	<Registry Id="{1C967AAF-D3B3-924A-B4417BF4BBE82A82}" Path="*\thememanager" Name="loadedbefore" />
	<Registry Id="{C7BB2280-4A35-00B3-E67120742559CD2E}" Path="*\thememanager" Name="themeactive" />
	<Registry Id="{72CB024F-4C7A-2011-5E7F10A4A2F73AC3}" Path="\registry\user\*\software\microsoft\windows\currentversion\internet settings\zonemap" Name="autodetect" />
	<Registry Id="{85B3C522-13AF-D6C8-8E663E16C6846BA5}" Path="\registry\user\*\software\microsoft\windows\currentversion\internet settings\zonemap" Name="uncasintranet" />
	<Registry Id="{6D6FD010-EA12-4F85-BC637D71C1A47BA4}" Path="\registry\user\*\software\microsoft\windows\currentversion\internet settings\zonemap" Name="proxybypass" />
	<Registry Id="{9933B535-9E2C-A691-BEDA546BE641CD72}" Path="\registry\machine\software\wow6432node\microsoft\directdraw\mostrecentapplication" Name="id" />
	<Registry Id="{E87A4391-5E25-C8D4-4D67B5C7FA9C55C3}" Path="\registry\machine\software\wow6432node\microsoft\directdraw\mostrecentapplication" Name="name" />
	<Registry Id="{3A96EA84-F6D3-888C-E0E0A6CEF3A70636}" Path="\registry\user\*\software\google\chrome*" Name="state" />
	<Registry Id="{F00C9A99-7E96-BD5C-ECB5E57C3F8CAD0B}" Path="\registry\user\*\software\google\chrome*" Name="statuscodes" />
	<Registry Id="{22EAFFB9-F0B3-99F3-AFE35EE85939718C}" Path="\registry\user\*\software\google\chrome*" Name="usagestatsinsample" />
	<Registry Id="{37126B5C-69D2-0916-CFD892B00000F434}" Path="\registry\user\*\software\google\chrome*" Name="user_experience_metrics.stability.exited_cleanly" />
	<Registry Id="{320A5317-396E-9214-EE607A87249AF82B}" Path="*\software\wow6432node\google\update*" Name="lastrun" />
	<Registry Id="{1AEED561-DAF8-D9C5-F4E5BD5C27D219F7}" Path="*\software\wow6432node\google\update*" Name="metricsid*" />
	<Registry Id="{1A9B7B8E-F65F-14B3-FCCC0FBB7A36B7B0}" Path="*\software\google\update*" Name="lastrun" />
	<Registry Id="{9DC6E826-1690-7A97-2B863058887DCD38}" Path="*\software\google\update*" Name="metricsid*" />
	<Registry Id="{0B4301CF-FE1A-D84C-21E3435329A56E7C}" Path="\registry\user\*\software\microsoft\internet explorer\main*" Name="fullscreen" />
	<Registry Id="{C59AF8DE-42B1-C7B7-3B6B84352049A16B}" Path="\registry\user\*\software\microsoft\internet explorer\main*" Name="window_placement" />
	<Registry Id="{B4B71F4F-C44E-EFD4-E4F335905B83C872}" Path="\registry\user\*\software\microsoft\calc" Name="window_placement" />
	<Registry Id="{A48423CC-0DFB-2455-0F72E982D154FF17}" Path="\registry\user\*\software\microsoft\internet explorer\*" Name="downloadretries" />
	<Registry Id="{C86349A7-5FAE-9B28-E274117001621F15}" Path="\registry\user\*\software\microsoft\internet explorer\*" Name="compatibilityflags" />
	<Registry Id="{65E4E877-8224-CD0D-4127942E66082B6C}" Path="\registry\user\*\software\microsoft\internet explorer\*" Name="schedule" />
	<Registry Id="{79475BAC-50EC-7699-6205B2212A98D913}" Path="\registry\user\*\software\microsoft\internet explorer\*" Name="state" />
	<Registry Id="{4FD30D21-BC92-170B-0F034FCF950089FC}" Path="\registry\user\*\software\microsoft\internet explorer\*" Name="mfv" />
	<Registry Id="{9BF82733-D167-A6A6-F047C6BC2A6E9528}" Path="\registry\machine\software\microsoft\windows nt\currentversion\schedule\taskcache\tasks\{*" Name="dynamicinfo" />
	<Registry Id="{7832DDCF-8549-556E-8AB09A0DE624DB79}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\*\ndis.sys.mui*" />
	<Registry Id="{C11CE1F3-022F-39E7-1F030E8E12DB9F7C}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\advapi32.dll[mofresourcename]" />
	<Registry Id="{1A571B8D-59AA-1897-FA00198C3A882719}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\acpi.sys[acpimofresource]" />
	<Registry Id="{3834A040-ADDC-7456-02721A2AF2FA00D8}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\*\acpi.sys.mui[acpimofresource]" />
	<Registry Id="{0C81D032-D7FE-1487-1246770EA5A1B38D}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\*\intelppm.sys.mui[processorwmi]" />
	<Registry Id="{1D59D79F-5CC4-39AB-44DA8651EFFC99CA}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\*\mssmbios.sys.mui[mofresource]" />
	<Registry Id="{DB139FA0-9490-97B1-D4EFAAB9DE3EC651}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\*\ndis.sys.mui[mofresourcename]" />
	<Registry Id="{25CD82F6-EDCD-5EC4-AEA932F93639EDD4}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\intelppm.sys[processorwmi]" />
	<Registry Id="{18B837E0-A2C3-1F15-6964BD6EC7B3478A}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\lsi_sas.sys[mofresource]" />
	<Registry Id="{A001FC3B-F535-8595-73E995BAB9038E79}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\monitor.sys[monitorwmi]" />
	<Registry Id="{EF34E79B-1164-2FC6-0F3325678161DE37}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\mssmbios.sys[mofresource]" />
	<Registry Id="{494D9D0D-974B-124C-2D63308811599A1A}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\drivers\ndis.sys[mofresourcename]" />
	<Registry Id="{287E0FEA-FD25-A182-F73658B005BCA551}" Path="\registry\machine\software\microsoft\wbem\wdm*" Name="c:\windows\system32\*\advapi32.dll.mui[mofresourcename]" />
	<Registry Id="{FB16F9E8-FF90-D2A6-817E2446C2D992F0}" Path="\registry\user\*\software\microsoft\windows\currentversion\ext\stats\{????????-????-????-????-????????????}\iexplore" Name="navtimearray" />
	<Registry Id="{8E853539-FBE6-20B3-3713279413F203A2}" Path="\registry\machine\software\microsoft\systemcertificates\authroot\autoupdate" Name="*lastsynctime" />
	<Registry Id="{1DA38168-6412-37D6-20F555FB60FC4DF0}" Path="\registry\user\*\local settings\software\microsoft\windows\shell\bags\128\shell\{*" Name="vid" />
	<Registry Id="{0F0E4BB0-70E4-A855-B0FA864FA7C87213}" Path="\registry\user\*\software\microsoft\windows\currentversion\internet settings\zones" Name="securitysafe" />
	<Registry Id="{501DDE23-6C57-3777-FCE1C2AAD384A6CE}" Path="*\device parameters" Name="recyclable" />
	<Registry Id="{71BBB275-40D9-8EA4-8995CA674F3D8162}" Path="\registry\machine\system\controlset001\services\netbt\parameters\interfaces\tcpip_{*" Value="%kl_undef%" />
	<Registry Id="{3982AC67-E90F-95C2-189FC1E2035FACC9}" Path="\registry\user\*\software\google\chrome\browserexitcodes" Value="%kl_undef%" />
	<Registry Id="{E70EA334-1ED5-0D97-FB661DAA937D4C6C}" Path="\REGISTRY\USER\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\*" Value="%kl_undef%" />
	<Registry Id="{8E98BE8D-F922-1DE2-17AB199D3BA12C83}" Path="\registry\machine\software\microsoft\wbem\wdm*" Value="?c00?f00?700?400?100?400?500?400?900?d00?500*" />
	<Registry Id="{C3BE47A1-152C-C7D1-2D57AE5D109DCFC2}" Name="DhcpNodeType" Value="????0000" />
	<Registry Id="{F49302FC-7F2A-C54C-B08C5A5CDD6AD473}" Name="DhcpNodeType" Value="????000000000000" />
	<Registry Id="{66AD73ED-C59C-42A9-C92179C4860C4328}" Name="NextLogonCacheable" Value="????0000" />
	<Registry Id="{BF89C955-875A-269D-7AFBDC1B976E7D49}" Name="NextLogonCacheable" Value="????000000000000" />
	<Registry Id="{80E799D5-CEFF-1DFB-AA365AA4C96C83B5}" Name="*{????????-????-????-????-????????????}*" Value="????0000" />
	<Registry Id="{6CE5FC1A-B0D7-1639-EC6B114F4D32FD76}" Name="*{????????-????-????-????-????????????}*" Value="????000000000000" />
	<Registry Id="{A4AFCF6F-1AF8-569B-CD4360019B1E6FF7}" Name="????-?????????????????" Value="????0000" />
	<Registry Id="{A734AE6F-7297-B26B-CC3914996E0F87D6}" Name="????-?????????????????" Value="????000000000000" />
	<Registry Id="{1B3BB15B-5E92-33E6-B6F14A86D61805BC}" Name="???-?????????????????" Value="????0000" />
	<Registry Id="{BE8C0B0C-C18C-EED1-075B5FC416CDA9AC}" Name="???-?????????????????" Value="????000000000000" />
	<Registry Id="{16EDB200-A57D-580B-73328132433DB9C4}" Name="can close" Value="????0000" />
	<Registry Id="{0D7C4981-975D-5C70-F6FF1004A81F06C6}" Name="can close" Value="????000000000000" />
	<Registry Id="{2D7D27D5-D299-2168-6FE410539343DCC3}" Name="compatibilityflags" Value="????0000" />
	<Registry Id="{6E40AE65-859E-320C-984AC289A9470F35}" Name="compatibilityflags" Value="????000000000000" />
	<Registry Id="{8F95ACA1-A156-DB8C-50150DE4BD33FF3C}" Name="cvlistttl" Value="????0000" />
	<Registry Id="{5B2829C8-CECC-F56C-E28D3BCE0B40D3BB}" Name="cvlistttl" Value="????000000000000" />
	<Registry Id="{0BFEF488-BAF5-CEA6-2A9544D0D5EF4CBB}" Name="cvlistxmlversionlow" Value="????0000" />
	<Registry Id="{B9EA0A27-417F-CA49-C13BF35F413AF29B}" Name="cvlistxmlversionlow" Value="????000000000000" />
	<Registry Id="{F7CD41BC-BDDB-F22A-EDBFB3FC633E7957}" Name="devicekind" Value="????0000" />
	<Registry Id="{E58F5DE7-1D60-BC2E-88441BB3D6C7010C}" Name="devicekind" Value="????000000000000" />
	<Registry Id="{E912EBED-2DEB-6E1F-11F94D333ABE7CF0}" Name="downloadretries" Value="????0000" />
	<Registry Id="{D0C0FD72-3960-9F0A-E36EF4503CD79025}" Name="downloadretries" Value="????000000000000" />
	<Registry Id="{65BB6CBA-3E8A-886D-D03B785AABCD50CF}" Name="drive type" Value="????0000" />
	<Registry Id="{74869781-B442-EDC6-42DECE5AC5DC2367}" Name="drive type" Value="????000000000000" />
	<Registry Id="{70319729-879F-47C1-DAE826134E4278CC}" Name="drivenumber" Value="????0000" />
	<Registry Id="{65B17804-A03A-043D-6A14E1D03E72F956}" Name="drivenumber" Value="????000000000000" />
	<Registry Id="{F519B983-A15D-8908-C389B70097913EFF}" Name="fontsmoothingtype" Value="????0000" />
	<Registry Id="{AB4773BD-DE29-81CA-448FE113FEC2D8A0}" Name="fontsmoothingtype" Value="????000000000000" />
	<Registry Id="{6982DE6A-C112-61F5-164F8F5E893E9504}" Name="groupbydirection" Value="????0000" />
	<Registry Id="{6CFDC156-911A-5B73-04367D5F21DE93FE}" Name="groupbydirection" Value="????000000000000" />
	<Registry Id="{586E2B47-4EDD-C3D4-873CBE94A5BC3D5F}" Name="groupbykey:pid" Value="????0000" />
	<Registry Id="{77F08CFE-0202-8105-EEA6EA87B3778458}" Name="groupbykey:pid" Value="????000000000000" />
	<Registry Id="{63D7CDE1-2311-97D9-54EC87F5DDADEC2D}" Name="groupview" Value="????0000" />
	<Registry Id="{E6622B6F-4AA3-3FBB-5FD8FEE7C49EA948}" Name="groupview" Value="????000000000000" />
	<Registry Id="{E010063A-67C9-04AE-134058CE21579D31}" Name="hotkey" Value="????0000" />
	<Registry Id="{4F586B74-2C08-1898-98223B9084B89C8B}" Name="hotkey" Value="????000000000000" />
	<Registry Id="{4287CE8B-8DCD-334D-19A663D31A7965D3}" Name="isimapidataburnsupported" Value="????0000" />
	<Registry Id="{6051A596-A676-7A19-43054BFB58C76D21}" Name="isimapidataburnsupported" Value="????000000000000" />
	<Registry Id="{37093B18-85E4-1E61-7784BB6827D15E32}" Name="isimapierasesupported" Value="????0000" />
	<Registry Id="{A73B0FC6-4CC3-2F88-66F8DEA8B16D30F1}" Name="isimapierasesupported" Value="????000000000000" />
	<Registry Id="{88C79785-FA61-9166-F8CF66B459FCFA9F}" Name="istabletpc" Value="????0000" />
	<Registry Id="{FBE80282-D446-863F-C42FF9B600C1CD03}" Name="istabletpc" Value="????000000000000" />
	<Registry Id="{C9B0C0A8-DAA9-BD66-AAAE7729EED43D87}" Name="live fs" Value="????0000" />
	<Registry Id="{835E5D8B-8F4E-CD33-27E8B7B56E4B5B2A}" Name="live fs" Value="????000000000000" />
	<Registry Id="{12D6F862-DCEF-4340-341E0F261FA90C32}" Name="logicalviewmode" Value="????0000" />
	<Registry Id="{0AA7E07D-0197-1901-2AC966D43F2C1767}" Name="logicalviewmode" Value="????000000000000" />
	<Registry Id="{AD5ED1A9-DA4B-A8DC-AAD646DCC38BFCCD}" Name="mode" Value="????0000" />
	<Registry Id="{72D0E896-0788-952E-04DFBBD4C0170F30}" Name="mode" Value="????000000000000" />
	<Registry Id="{AAAB8A6A-6563-D1C1-A55E136B0D0C7420}" Name="nextlogoncacheable" Value="????0000" />
	<Registry Id="{98F12B62-6330-C01F-EC3197C318DB93E6}" Name="nextlogoncacheable" Value="????000000000000" />
	<Registry Id="{55FD649D-E6FE-326B-A3034782031C01C8}" Name="printeronline" Value="????0000" />
	<Registry Id="{FBC351F4-E70D-F315-32A654171398AE71}" Name="printeronline" Value="????000000000000" />
	<Registry Id="{E91FB503-1668-7096-2835A519179DB05B}" Name="proxyenable" Value="????0000" />
	<Registry Id="{7CF8F45A-7CFF-6C7B-C0DC82C73BCCB7BE}" Name="proxyenable" Value="????000000000000" />
	<Registry Id="{E70B2FD7-0880-D310-282F36FF1F939D53}" Name="rev" Value="????0000" />
	<Registry Id="{91D221DB-A0BC-C99C-3B8A8E9F96501E8A}" Name="rev" Value="????000000000000" />
	<Registry Id="{F53A4C54-56BA-CC28-32D6C5DD52C632B7}" Name="schedule" Value="????0000" />
	<Registry Id="{4E0CC705-8A04-AFC6-815A9C5718464323}" Name="schedule" Value="????000000000000" />
	<Registry Id="{AD8AA407-AC92-A5E2-3486EEE77E5D7543}" Name="set" Value="????0000" />
	<Registry Id="{C7A965AE-EAA9-2C2C-CFA3020D40B8B812}" Name="set" Value="????000000000000" />
	<Registry Id="{7C7A14E8-B648-56FF-21FBF5D1AE7249C6}" Name="state" Value="????0000" />
	<Registry Id="{620298E6-23A1-BB10-75F7605ADF6730B7}" Name="state" Value="????000000000000" />
	<Registry Id="{D27FBA45-068D-3CB5-BCF369020971BA27}" Name="uncasintranet" Value="????0000" />
	<Registry Id="{A35F010F-50BF-9D43-55126A3F4E4CA695}" Name="uncasintranet" Value="????000000000000" />
	<Registry Id="{8DC963A7-65F2-A6B4-4B1C0F6ECE03125A}" Name="usagestatsinsample" Value="????0000" />
	<Registry Id="{E503E4E6-2A8B-7487-CD7DA253E653184D}" Name="usagestatsinsample" Value="????000000000000" />
	<Registry Id="{3252EF44-AE4E-4879-543C65D311DED768}" Name="user_experience_metrics.stability.exited_cleanly" Value="????0000" />
	<Registry Id="{06032476-4BBC-E3A1-D999F1BC29954CE6}" Name="user_experience_metrics.stability.exited_cleanly" Value="????000000000000" />
	<Registry Id="{76378C3F-3909-45FF-151768D577326EBF}" Name="userselecteddefault" Value="????0000" />
	<Registry Id="{0BF9C505-DF2A-1D77-5DC92FACAEB40E72}" Name="userselecteddefault" Value="????000000000000" />
	<Registry Id="{4E52CA1A-6433-5EA5-3DAF1648775855F8}" Name="wflags" Value="????0000" />
	<Registry Id="{68A642E6-391B-3CF6-F45C521AA983ACF8}" Name="wflags" Value="????000000000000" />
	<Registry Id="{98D91E19-31B2-3174-73AB46C3B1D13BFD}" Name="winpos*" Value="????0000" />
	<Registry Id="{296FA2AE-0CBD-A5D7-2F94F79252E2A33B}" Name="winpos*" Value="????000000000000" />
	<Registry Id="{5E90AF8D-02FF-25AF-D8FC93E6BE3DC051}" Path="*\NGenService\*" Name="Priority" Value="????0000" />
	<Registry Id="{BC1D11EA-16D3-5223-1F36BA4241083B49}" Path="*\NGenService\*" Name="Priority" Value="????000000000000" />
	<Registry Id="{B91A2877-1574-B637-53DECC9A920507F9}" Path="*\NGenService\*" Name="Scenario" Value="????0000" />
	<Registry Id="{551BDC8F-0440-75A7-D5CEDF112CE04134}" Path="*\NGenService\*" Name="Scenario" Value="????000000000000" />
	<Registry Id="{8CA1C304-AED6-2A31-3344B003120F0467}" Path="*\NGenService\*" Name="Status" Value="????0000" />
	<Registry Id="{D0F36DA8-38DA-A4D9-15705498624BF9F8}" Path="*\NGenService\*" Name="Status" Value="????000000000000" />
	<Registry Id="{4D450568-A50C-A88D-4A88F29359181EAB}" Path="*\NGenService\*" Name="attempts" Value="????0000" />
	<Registry Id="{7C914D67-D9E6-1EEC-C0BD7420BF7CA944}" Path="*\NGenService\*" Name="attempts" Value="????000000000000" />
	<Registry Id="{AEA585A9-9282-B9A4-7A2BEF93D2E0646A}" Name="Config" Path="*\NGenService\*" Value="*?600?300?e002e00?500?800?5000000" />
	<Registry Id="{BABE516B-8C98-ADC9-4D1613734BD94882}" Name="Config" Path="*\NGenService\*" Value="*2f00?400?f00?f00?c00?3002f00?400?600?300?300?f00?e00?600?900?7002e00?500?800?5000000" />
	<Registry Id="{9A8B948D-12AC-1ECA-626AF6466EEF958F}" Name="Config" Path="*\NGenService\*" Value="2f00????????2e00????2f00?400?600?300?e00?f00?0002e00?500?800?5000000" />
	<Registry Id="{33AA17F4-7F75-DCF7-E8BA159D9BE415C2}" Path="*\CurrentVersion\Devices" Value="?700?900?e00?300?000?f00?f00?c002c00*" />
	<Registry Id="{9ABE7A6E-9EA9-35AC-CD36490BCCF8A5B2}" Path="*\currentversion\printerports" Value="?700?900?e00?300?000?f00?f00?c002c00*" />
	<Registry Id="{7072CBCC-65CC-B4ED-3BC5BC03678F6D50}" Name="fflags" Value="????????" />
	<Registry Id="{3C78345F-2379-AE60-ADBFF37F6D591CA3}" Name="fflags" Value="????????????????" />
	<Registry Id="{A594A5C3-724C-2947-F0E16356ECECE709}" Name="MaxPos*" Value="????????" />
	<Registry Id="{989252AC-356D-F562-328770417731F172}" Name="MaxPos*" Value="????????????????" />
	<Registry Id="{AF1DD464-3709-B456-AA7BF64B067BB207}" Name="MinPos*" Value="????????" />
	<Registry Id="{3CB096D2-95C7-67E3-B94C504AEDB02B54}" Name="MinPos*" Value="????????????????" />
	<Registry Id="{15475E6E-28DD-5FF5-3D21C4B0EC233765}" Name="dodownloadmode" Value="????????" />
	<Registry Id="{BC3C0733-C2A4-FCC8-B7A109DCA859DEA8}" Name="dodownloadmode" Value="????????????????" />
	<Registry Id="{5735B865-EAF2-244C-E37DDB0D34E24D83}" Name="dodownloadmode" Value="??00??00??00??000000" />
	<Registry Id="{5A00133C-DBCE-5526-E344EC50A76D999F}" Name="dodownloadmode" Value="30000000" />
	<Registry Id="{B1D8C3DD-9B6A-A2AE-2D50BAB1EE45D218}" Name="dodownloadmode" Value="3?003?003?003?00*" />
	<Registry Id="{6346790D-BE12-A10F-BD035A6AF5E6B261}" Name="downloadmode_backcompat" Value="????????" />
	<Registry Id="{8049CDA3-D251-FFDF-6063BF140E88A5F0}" Name="downloadmode_backcompat" Value="????????????????" />
	<Registry Id="{41AF49B5-C85F-2569-3E581EAE30322277}" Name="downloadmode_backcompat" Value="??00??00??00??000000" />
	<Registry Id="{95CF2245-3BCE-21CE-1B9CA3CF037B1899}" Name="downloadmode_backcompat" Value="30000000" />
	<Registry Id="{1F88D625-3E9C-9E39-AB274E32BBBF21D4}" Name="downloadmode_backcompat" Value="3?003?003?003?00*" />
	<Registry Id="{BBD4F02B-E631-07ED-8D64CBF89CD976C6}" Name="downloadmonthly*" Value="????????" />
	<Registry Id="{89DE4798-FF92-9DDC-5EADE260B6337C3B}" Name="downloadmonthly*" Value="????????????????" />
	<Registry Id="{BC1D3A8C-0360-71F1-B6B5FA0596C49954}" Name="downloadmonthly*" Value="??00??00??00??000000" />
	<Registry Id="{18698DBB-C9A2-0D7E-370F15A6685767BC}" Name="downloadmonthly*" Value="30000000" />
	<Registry Id="{1D8BD824-8373-E22C-AB3571E2F0907F64}" Name="downloadmonthly*" Value="3?003?003?003?00*" />
	<Registry Id="{63465221-30A1-1C5B-83DFE12CF9C22100}" Name="uploadmonthly*" Value="????????" />
	<Registry Id="{CFE08F3F-7CDE-C109-E3F03CF980676DE3}" Name="uploadmonthly*" Value="????????????????" />
	<Registry Id="{6743599E-2113-5416-B641E04E66004EBE}" Name="uploadmonthly*" Value="??00??00??00??000000" />
	<Registry Id="{A678AEE3-B593-1C84-51AEE5E70E19154E}" Name="uploadmonthly*" Value="30000000" />
	<Registry Id="{65BEC292-E5F2-3B69-728ECE55EB2220DD}" Name="uploadmonthly*" Value="3?003?003?003?00*" />
	<Registry Id="{CC87D8F1-0CAC-EC73-3393C7D366402EF7}" Name="monthid" Value="????????" />
	<Registry Id="{248C83A4-7F7D-F40D-457D6ABD49E84616}" Name="monthid" Value="????????????????" />
	<Registry Id="{7F1B8D9D-B5C3-661B-EB287A48CFECE807}" Name="monthid" Value="??00??00??00??000000" />
	<Registry Id="{973B2D87-41FF-4D7A-94DC7321985B3228}" Name="monthid" Value="30000000" />
	<Registry Id="{AC2D56EF-A989-BB7E-3DD894D34D04AD64}" Name="monthid" Value="3?003?003?003?00*" />
	<Registry Id="{DF5C2B94-767D-3DF2-F4A6494F2922A2F2}" Name="globaleventcounter" Value="????????" />
	<Registry Id="{3CDBD10B-441E-086A-8B5C6F8660891BE1}" Name="globaleventcounter" Value="????????????????" />
	<Registry Id="{4FF55BBA-6F72-103E-3815B1ED09CEDE30}" Name="globaleventcounter" Value="??00??00??00??000000" />
	<Registry Id="{1F833AD8-DB26-09CC-682BAA078339DA20}" Name="globaleventcounter" Value="30000000" />
	<Registry Id="{98DB53DF-AE70-357E-763BC6E477E1C6CA}" Name="globaleventcounter" Value="3?003?003?003?00*" />
	<Registry Id="{2DBD6EEC-F3B6-2EF1-02E7DEBB79791B08}" Name="Performance Refreshed" Value="????????" />
	<Registry Id="{33152D14-2814-15C3-37C3676B664A3A56}" Name="Performance Refreshed" Value="????????????????" />
	<Registry Id="{1EB9DB91-146C-2555-536AE3A3D2724345}" Name="intranetname" Value="????????" />
	<Registry Id="{CEBD814E-6FBB-D64C-FEEEF8785E13F0CD}" Name="intranetname" Value="????????????????" />
	<Registry Id="{D1380161-99C0-9E5D-690F12D64611564A}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\cd burning\*" />
	<Registry Id="{799D3BC8-A75A-8BD9-3663341B851A2F11}" Path="*\shell\bagmru" Name="mrulistex" />
	<Registry Id="{EAF18EB0-ECC5-16E2-B3AF75B61C95C52A}" Path="*\shell\bagmru" Name="nodeslots" />
	<Registry Id="{2684D102-8572-6194-9883840F171D99EF}" Path="*\shell\bags\allfolders\shell" Name="navbar" />
	<Registry Id="{F168644F-1C41-628C-9E0C734484739977}" Path="\registry\machine\sam\sam\domains\*" Name="?" />
	<Registry Id="{B7F67A3C-BF7C-39A6-1C2FAA27FA195189}" Path="\registry\machine\software\microsoft\.netframework\ngenqueuemsi\win??\default\???????" Name="%kl_undef%" />
	<Registry Id="{3ACB30C7-8BCB-AA70-1A882FA55E123373}" Path="*\NGenService\*" Name="%kl_undef%" />
	<Registry Id="{7D9B8923-40CA-1D41-FE4B7DE9331BEE56}" Path="\registry\user\.default\software\microsoft\windows\currentversion\explorer\discardable\postsetup\component categories*" Value="????0000" />
	<Registry Id="{7BA6EBD2-7CCD-67BC-8C866CEF4BB2F381}" Path="\registry\user\.default\software\microsoft\windows\currentversion\explorer\discardable\postsetup\component categories*" Value="????000000000000" />
	<Registry Id="{F00039DE-3B7A-D271-2C75B080F03A5BF9}" Path="\registry\user\.default\software\microsoft\windows\currentversion\explorer\discardable\postsetup\component categories*" Value="%kl_undef%" />
	<Registry Id="{3DCD6D81-E932-502A-A519CB4AD2EB2AEE}" Path="\registry\user\.default\software\microsoft\windows\currentversion\ext*" Value="????0000" />
	<Registry Id="{E4FE8AE3-4E88-A7AA-1D042873B5C9AD8D}" Path="\registry\user\.default\software\microsoft\windows\currentversion\ext*" Value="????000000000000" />
	<Registry Id="{01BA236C-685B-D59E-B993E07FAB3E323D}" Path="\registry\user\.default\software\microsoft\windows\currentversion\ext*" Value="%kl_undef%" />
	<Registry Id="{63CE2F9B-EFA5-7595-7AA16B368AA585D5}" Path="*\internet explorer\lowregistry\domstorage\*" Value="????????" />
	<Registry Id="{CC604D73-98A1-5A35-437A3DDDFF919856}" Path="*\internet explorer\lowregistry\domstorage\*" Value="????????????????" />
	<Registry Id="{1E1C2B30-2C18-33DE-4BB002EA848728BD}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{*}" Value="*3?007C007C000000" />
	<Registry Id="{F63BB970-776E-44B8-6C5ABC74AA9847B5}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\deployment\package\*{*}" Value="*3?007C000000" />
	<Registry Id="{66EA4F5E-14B3-B4DE-ECC5E30A82EF0DDA}" Path="*\NGenService\*" Name="Config" Value="*?600?300?e002e00?500?800?5000000" />
	<Registry Id="{61F99D14-5537-8B44-59ABE6D12F7C0D23}" Name="insights" Value="01000000*" />
	<Registry Id="{954264B4-04BE-8FA6-7B52767E9286D810}" Path="\registry\machine\software\classes\local settings\software\microsoft\windows\currentversion\appmodel\packagerepository\*" Value="%kl_undef%" />
	<Registry Id="{D7E14439-46F3-4A79-48FEF65C74F5A684}" Path="\registry\machine\software\microsoft\windows\currentversion\appmodel\staterepository\cache\*" Value="%kl_undef%" />
	<Registry Id="{976F5939-03E2-7864-FEC5C6A1CA7BBA44}" Path="\registry\machine\software\microsoft\windows\currentversion\group policy\serviceinstances\*" Value="%kl_undef%" />
	<Registry Id="{4C2BDFD5-CEE6-DA6B-A573D1C19633E51C}" Path="\registry\machine\software\microsoft\windows\currentversion\group policy\state\*\gplink-list*" Value="%kl_undef%" />
	<Registry Id="{AC2C031E-B863-7976-FBBF1BF7693431EF}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranetauth*" Name="failures" Value="ffffffff" />
	<Registry Id="{F5223CD0-1455-F782-B476E694B37CE129}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranetauth*" Name="failures" Value="ffffffff00000000" />
	<Registry Id="{D81126FA-C1FD-51C7-7348581D215DFCCB}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranetauth*" Name="successes" Value="00000000" />
	<Registry Id="{D6B4870B-C8AF-4538-52685F186CC2A94E}" Path="\registry\machine\software\microsoft\windows nt\currentversion\networklist\nla\cache\intranetauth*" Name="successes" Value="0000000000000000" />
	<Registry Id="{70366043-F45F-1C79-C5669542E19C1D45}" Path="\registry\machine\software\microsoft\windows nt\currentversion\schedule\taskcache\tasks\{*" Name="schema" />
	<Registry Id="{32D18CB2-184C-010A-E985EB4D021010D2}" Path="\registry\machine\software\microsoft\windows nt\currentversion\schedule\taskcache\tasks\{*" Name="description" />
	<Registry Id="{BB27706C-0592-6965-9D32F65BDB0456AD}" Path="\registry\machine\software\microsoft\windows search\tracing\eventthrottlestate" Name="0000????" />
	<Registry Id="{0CE6DD75-D9B6-636C-96CAC03F764F21FD}" Path="\registry\machine\software\microsoft\windows\currentversion\diagnostics\diagtrack\*" Value="????0000" />
	<Registry Id="{B5CA3EAD-7045-96EF-76976020ED970F20}" Path="\registry\machine\software\microsoft\windows\currentversion\diagnostics\diagtrack\*" Value="????000000000000" />
	<Registry Id="{692C4C40-3999-C4C1-99F2D819A8056093}" Path="\registry\machine\software\microsoft\windows\currentversion\diagnostics\diagtrack\*" Value="%kl_undef%" />
	<Registry Id="{0BDB4BB0-73C4-A872-483585081E51D503}" Name="criticalextensions" Value="0000" />
	<Registry Id="{91E561E5-4844-2CD7-69A6E59639AE8C73}" Name="description" Value="0000" />
	<Registry Id="{46983F1F-3C4A-8D66-33A4D838A92E18D2}" Name="supportedcsps" Value="0000" />
	<Registry Id="{78528CF1-DE55-9521-71CEE2AE413A367B}" Name="wql-id" Value="0000" />
	<Registry Id="{17483C40-6628-C296-C73A45B3B1052E51}" Path="\registry\machine\software\microsoft\windows\currentversion\vfuprovider" Name="starttime" />
	<Registry Id="{601A63A5-42F3-AD57-6FFCD3A62520AE82}" Path="\registry\machine\software\microsoft\windowsupdate\ux\statevariables" Name="lastattemptedreboottime" />
	<Registry Id="{CBF4DBC6-9FA7-321C-904103464181399A}" Path="*\registry\machine\software\microsoft\fusion\nativeimagesindex\*" Value="%kl_undef%" />
	<Registry Id="{7E6A2DC2-BC36-52F7-1244F304009262B9}" Path="*\registry\machine\software\microsoft\fusion\nativeimagesindex\*" Value="0000" />
	<Registry Id="{68B96FAC-1EE8-22F7-19F7656120906BDC}" Path="*PersistedStorageItemTable*" Value="%kl_undef%" />
	<Registry Id="{0E1C8D85-6FC4-018A-A60F5156B619E80B}" Path="*PersistedStorageItemTable*" Value="0000" />
	<Registry Id="{E74BBBD3-76E8-A51C-AD32C8F418294FA8}" Name="rebootscheduledbyuser" Value="%kl_undef%" />
	<Registry Id="{D87BB887-561F-C56B-B0624A4B5A030837}" Name="scheduledrebootfailed" Value="%kl_undef%" />
	<Registry Id="{2B592D61-C699-EAF9-192B86DD3C16A650}" Path="\registry\machine\system\controlset001\services\sharedaccess\epoch2" Name="epoch" />
	<Registry Id="{EE0FF82F-68DA-8231-E0314BD3E23F9F3F}" Path="\registry\machine\system\controlset001\services\w32time\securetimelimits*" Name="securetime*">
		<Process Path="*\System32\lsass.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{71156918-9A8D-6036-56B18018BC18C496}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="DisplayName">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{EBD170A8-4AD8-87E4-14A2563E5D9636BF}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="ExtKeyUsageSyntax">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{B0D3062A-D99D-125F-F39CDAF1C0FF5FCB}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="Flags">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{21EED611-F621-74F6-481961FB71FEFA17}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="KeySpec">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{C321B148-13DB-1E9A-7725868E5B5B5B25}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="KeyUsage">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{A3615DF7-82C2-A4A8-151A3ADC64F2379B}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="RenewalOverlap">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{71BF63EB-CFD4-8B97-0531AE7242EBADFF}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="Revision">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{7C60473E-4657-C2EC-D6634F14B3FB87C7}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="Timestamp">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{550684CA-55F5-314E-C867CC04FF7D8F94}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\*" Name="TimestampAfter">
		<Process Path="*\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="taskhostw.exe" />
		</Process>
	</Registry>
	<Registry Id="{2663FFB9-049C-6F7F-34F0318BC8C148BB}" Path="*\vmware\*">
		<Process>
			<Signature Subject="*VMware*" />
		</Process>
	</Registry>
	<Registry Id="{2F3EC7A6-869B-63D3-150E6508E0FC4DCE}" Path="*\Health\*">
		<Process>
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7A1582BB-C166-DCFF-EE4973271ED73E43}" Name="lastupdatedtime" />
	<Registry Id="{7EF94EA2-C765-DB5D-680370335708D9E6}" Name="*language*" />
	<Registry Id="{9E37D6CB-95A9-847C-48A405F82AC998C4}" Name="waseveractivated" />
	<Registry Id="{EDFDA637-9F00-4575-1E9A1FF24943D78B}" Name="itbar7layout" />
	<Registry Id="{98FC9DE0-B0C5-FB2C-ADA04A10EF3740E2}" Name="index" />
	<Registry Id="{EE82C02D-4BA0-2A84-717906AB02EAEA7A}" Name="vpninstalled" />
	<Registry Id="{9737FA7E-40B8-AFCB-D711236E0B706C99}" Name="vpnisfb" />
	<Registry Id="{8D8F5A72-EE15-2E3F-0AEBD68941BCA351}" Name="sequence" />
	<Registry Id="{DDBD03C9-1784-EED5-BC918CA216B072EC}" Name="regfile*" />
	<Registry Id="{D1142C0C-333D-381E-978A92376DE99FAD}" Name="mrulistex" />
	<Registry Id="{5C2B73AC-2B07-7657-C2A3F9565BD871ED}" Name="branchreadinesslevel" />
	<Registry Id="{074A91FD-485F-5B79-39A9E5E33FE03436}" Name="isdisabledualscanconfigured" />
	<Registry Id="{BD50DCE1-75D7-00E1-22725106AC849605}" Name="uniqueid" />
	<Registry Id="{F22433D0-F3AB-564E-38AEB6A60056CF52}" Name="keyboardlayout" />
	<Registry Id="{E1BCE095-7918-DBF2-73B7401F76639495}" Name="*size*" />
	<Registry Id="{0F8D482D-FA79-9541-A9EEFFB438414EE3}" Name="keyspec" />
	<Registry Id="{AD07CD14-866D-A9F6-3A29B4F88D3E20E2}" Name="*bytes" />
	<Registry Id="{61F66B3C-F932-08B9-99E92DDF4D1384AD}" Name="revision" />
	<Registry Id="{4DEF7958-27D9-7BC8-B3DAF5834745F55C}" Name="installprogresspercent" />
	<Registry Id="{B293782B-9F61-F8AD-4D60D3C274761650}" Name="*color*" />
	<Registry Id="{689E7DD6-A562-BE22-7C19459E9098F354}" Name="mspki-*" />
	<Registry Id="{9FEFD659-64E4-D60F-C052806FCB851753}" Name="installtimeremainingms" />
	<Registry Id="{A16C84A8-0FDA-7F97-FB56CF74C5063F15}" Name="isfloating" />
	<Registry Id="{F4DC869B-8E1B-A5C5-C25EE17BCCDE6720}" Name="parentwnd" />
	<Registry Id="{F01784B3-DEA3-A345-FC87D8C132E5492E}" Name="anyabovelockappsactive" />
	<Registry Id="{B6C3B6CC-DEB1-8CF0-B08A4022ADA46698}" Name="status" />
	<Registry Id="{C3B801D5-94B1-2EBB-31330B6F9B8A80A5}" Name="highcontrastenablednew" />
	<Registry Id="{D507336F-70DB-FB97-FFFFCDD9D0D83D98}" Name="*.isdelegate" />
	<Registry Id="{6A44F012-2BC4-6F7A-02240B397C9C53CA}" Name="*.ispst" />
	<Registry Id="{8B2EBB42-C3AE-7458-991F98A46B7AF090}" Name="*.ispublic" />
	<Registry Id="{C169712C-3338-EDE5-B3989BA60DF9709E}" Name="*.vstemplate" />
	<Registry Id="{2F63A5B1-0902-2C23-5CDD2F067C5FA292}" Name="*.isexchange" />
	<Registry Id="{3DBAA346-6E58-F6E9-3907CF9B496B33C1}" Name="*.iscached" />
	<Registry Id="{9E6857CC-71BD-11BB-E7886C0B3A8389BA}" Name="firstrun" />
	<Registry Id="{4BCE07B8-8FEA-9A53-BC949DBB23F07604}" Name="beepenabled" />
	<Registry Id="{9C9AE61B-5E72-7D73-2AE973E4B64A5D82}" Name="belldeiconify" />
	<Registry Id="{2B5E8E27-09E4-F1A7-DE806866C33608E5}" Name="bitmap*" />
	<Registry Id="{669AEEB2-80D6-AF48-430487F853071148}" Name="blockedinput" />
	<Registry Id="{21A28809-91EE-A3A2-D7ECBE5D549C1DF8}" Name="*height*" />
	<Registry Id="{A55272AA-DCF0-DD31-6D676B16A44B1E55}" Name="*width*" />
	<Registry Id="{EFF8A2DE-8B85-8B95-B99AD9442BF9E500}" Name="bold" />
	<Registry Id="{0E1A91FE-855C-DCDC-7CAF23378E110AF2}" Name="bootfilesoptimized" />
	<Registry Id="{70285DC9-A54C-3E9F-4C15D192A1CCDD3F}" Name="brcmstack" />
	<Registry Id="{25C81155-5B53-1D02-1EEAE45CDE932AE4}" Name="breverse" />
	<Registry Id="{3DF3F619-7923-9678-D2C966656A78A903}" Name="broadcomfeatures" />
	<Registry Id="{DEF57E82-3FB7-E5A9-E113BCF049F9C828}" Name="*\telegram desktop\telegram.exe" />
	<Registry Id="{6AE59F0B-8DC6-840A-854C60F818919E5B}" Name="dhcpv6maxleaseexpiretime" />
	<Registry Id="{0B0C6C28-3473-FAD7-B6F9BF4309CBDD9D}" Name="*.teams.teams*" />
	<Registry Id="{99BF42A4-024C-077D-7F980709551A975C}" Name="nodeslot" />
	<Registry Id="{EEEE92AA-BA7E-67CE-A1BFFAAC6933E721}" Name="d3d*" />
	<Registry Id="{DF264E0D-7805-4808-09FB21721054343A}" Name="defer*" />
	<Registry Id="{F27D94CE-7A81-96EC-6E704062D47E27E6}" Name="supportedcsps" Value="?500?400?f00?b00?500?e002000?200?100?300?5002000?300?200?900?000?400?f00?700?200?100?000?800?900?3002000?000?200?f00?600?900?400?500?200*" />
	<Registry Id="{E6D5F547-694E-587A-94E24E1754FEB975}" Name="supportedcsps" Value="?d00?900?300?200?f00?300?f00?600?400*" />
	<Registry Id="{D284FC6E-FB75-DE0D-2322BB1FD9648F34}" Name="supportedcsps" Value="?300?100?600?500?e00?500?400*" />
	<Registry Id="{C9BC7D2F-670F-357E-BC736EB4B0321339}" Name="*DeferralInDays" Value="1e000000*" />
	<Registry Id="{95363AC0-89B8-039E-C00EB5685496CFF4}" Name="*DeferralInDays" Value="3c000000*" />
	<Registry Id="{E2944F85-17FA-8A18-C3262ED2A09DB973}" Name="flags" Value="09000000*" />
	<Registry Id="{D55E800B-8BC6-7804-9626701A9FD2C06A}" Name="current" Value="01000000*" />
	<Registry Id="{699F55ED-A703-55BC-280F46D74E465D0F}" Name="allow*" Value="00*" />
	<Registry Id="{F18966A9-6B97-357C-10F830FE39D28510}" Name="disabled" Value="00*" />
	<Registry Id="{9A2B16BC-1079-42FE-52D7C2030F991F55}" Name="paused*" Value="00*" />
	<Registry Id="{2DD0593E-8139-9C35-0F6F67999A7F928B}" Name="isdefer*" Value="00*" />
	<Registry Id="{8E24E52D-E694-613C-7F44D1FD66AE81F2}" Name="iswufb*" Value="00*" />
	<Registry Id="{CAF2841F-8C00-C3D1-5825B5010C5F1A97}" Name="enterpriseconfiguredfavoritesstate" Value="00*" />
	<Registry Id="{8B2B5CC3-AE8F-3F90-E11E4A3B7BA35C9B}" Name="*enforce*" Value="00*" />
	<Registry Id="{4BBFB756-ADEF-7137-87A4EC9068BF8A48}" Name="completed" Value="01*" />
	<Registry Id="{5896BE2B-37DD-7086-7B75B17C397ECAE7}" Name="useprojecttargetframeworkversionintooltip" Value="01*" />
	<Registry Id="{259C01BA-36AD-CF46-0B14523A91B73402}" Name="enabled" Value="01*" />
	<Registry Id="{4ED45A2B-3949-0498-0469FFB8F3797721}" Name="%kl_undef%" Value="0?000000" />
	<Registry Id="{25E1690D-1A8A-1555-CC9B45BF02DBB33D}" Name="%kl_undef%" Value="0?00000000000000" />
	<Registry Id="{BF086C3F-5CEE-D1E9-7F7467EA83407FD0}" Name="%kl_undef%" Value="23*" />
	<Registry Id="{5E4D3A43-5D9E-E7C4-A76355872DBAE5D3}" Name="%kl_undef%" Value="5f*" />
	<Registry Id="{9C504017-9492-13DB-73FBA357F5510707}" Name="%kl_undef%" Value="7b?3?5?6?2?1?3?6?4?d?8?7?3?3?d?4?7?3?1?d*" />
	<Registry Id="{1167F992-889A-81D6-6BB06D02DC22711E}" Name="%kl_undef%" Value="7b30303032303432342d303030302d30303030*" />
	<Registry Id="{D6B1FED0-C8D8-E13E-C2103A35803C36B6}" Name="%kl_undef%" Value="7b?2?2?5?5383834382d*" />
	<Registry Id="{D6DD0BF6-744E-0898-D9EF8ADD01B42988}" Name="%kl_undef%" Value="??" />
	<Registry Id="{33EAE2A6-015F-5604-3196DE4B00F031C3}" Name="%kl_undef%" Value="????" />
	<Registry Id="{8EF7B9AD-E48E-19EA-D71733743584B90B}" Name="%kl_undef%" Value="??????" />
	<Registry Id="{9FBD427E-6303-879E-208DD0BC2CC6A6E9}" Name="%kl_undef%" Value="????????" />
	<Registry Id="{8294F277-2200-BC06-F61EE01FDDD51536}" Name="%kl_undef%" Value="3?3?3?3?3?0000" />
	<Registry Id="{7177DFAF-6DBD-2A61-5E8183A537F67527}" Name="%kl_undef%" Value="3?3?3?3?3?3?0000" />
	<Registry Id="{8D60FBD1-A655-3A9D-7008E8BB3F6A29CC}" Name="%kl_undef%" Value="*?d00?900?300?200?f00?300?f00?600?400*" />
	<Registry Id="{E645946C-1A0E-76EC-E985C518B2B314B3}" Name="%kl_undef%" Value="*?d00?f00?a00?900?c00?c00?100*" />
	<Registry Id="{18978E51-D396-3E69-BCCFAE6383248777}" Name="%kl_undef%" Value="?400?500?200?500?700?700?500?2002000*" />
	<Registry Id="{67AF2895-C12C-A248-8A22D7794F664506}" Name="%kl_undef%" Value="?600?900?c00?500?300?900?e00?300*" />
	<Registry Id="{BF7E95A7-2586-04BB-F126B047C08F9966}" Name="%kl_undef%" Value="?300?900?e00?300*" />
	<Registry Id="{6497FBFC-52FF-ED17-AF40DD0AF1EFC909}" Name="%kl_undef%" Value="*?600?900?300?500?100?c00*" />
	<Registry Id="{F61E13DF-C51C-537C-F7FA87C2C9B01286}" Path="*\Interface\{*" Value="?900*" />
	<Registry Id="{2B6562BD-2BB9-6496-9E8097FF6FD25FD4}" Path="*photos*" Value="*2e00?000?e00?700*" />
	<Registry Id="{12CE9ABD-029B-EEE5-B303E541A8BE4CC3}" Path="*photos*" Value="*2e00?a00?000?700*" />
	<Registry Id="{42C45F2A-A5E9-98BA-5DC1801C77DACDDE}" Path="*photos*" Value="*2e00?200?d00?000*" />
	<Registry Id="{84EF7FAA-B91E-57CE-35783FECD8FFC550}" Path="*photos*" Value="??" />
	<Registry Id="{3DFC4BC8-F9C5-7BE3-DF614C42F37F33EA}" Path="*photos*" Value="????" />
	<Registry Id="{5B2B11C2-7624-FA50-4C4918BFDF654537}" Path="*photos*" Value="??????" />
	<Registry Id="{A98E4DD7-8373-C3D6-FD69CB51D64E23BD}" Path="*photos*" Value="????????" />
	<Registry Id="{4817117D-691E-8D9C-EDAD9DE05311DDED}" Path="*photos*" Value="????????????????" />
	<Registry Id="{2677733D-FFE3-A9FF-C461E3D3CE9B2F50}" Name="storechange*" Value="????????" />
	<Registry Id="{9F7F22E0-3D01-26D6-E2E7746FB77156F2}" Name="storechange*" Value="????????????????" />
	<Registry Id="{D3435950-405A-FACD-03CF360A64E4DCE2}" Name="?" Value="????????" />
	<Registry Id="{2D0B7C60-6DD4-83F1-D1B8B94B90F805FC}" Name="?" Value="????????????????" />
	<Registry Id="{D8610CE4-1FB6-E6AB-F02A95677C1659FE}" Name="??" Value="????????" />
	<Registry Id="{5C9D3725-9D00-B36B-37D41BAFAE57C9D9}" Name="??" Value="????????????????" />
	<Registry Id="{30A5E8BE-841D-1A48-33EF69E35117F9D7}" Name="???" Value="????????" />
	<Registry Id="{117C6105-E0D4-5220-F290E83EAFE5A33B}" Name="???" Value="????????????????" />
	<Registry Id="{F52CA291-D848-567F-743B157ABC9D4C27}" Name="startnesting" Value="????????" />
	<Registry Id="{4671890A-7D7C-BA56-116B0165A17B1770}" Name="startnesting" Value="????????????????" />
	<Registry Id="{11B0F935-995E-AFA8-F36CE00F33EC42DC}" Name="*\config.msi\*" Value="????????" />
	<Registry Id="{2E387D08-DCB7-E67E-43D015BABD93E2CC}" Name="*\config.msi\*" Value="????????????????" />
	<Registry Id="{C646E6AD-F8A5-DA0C-7DC4486F16380858}" Name="*package*" Value="????????" />
	<Registry Id="{1D861A95-D0E6-346F-4BEAEF62BD134118}" Name="*package*" Value="????????????????" />
	<Registry Id="{02EA3029-1B7E-42D1-AB86EB5217234BC9}" Name="*files" Value="????????" />
	<Registry Id="{45120B58-5130-C90D-99EF74D31E0A4A3F}" Name="*files" Value="????????????????" />
	<Registry Id="{AFCBCA86-D705-577C-D0EFD53B30213614}" Name="0*" Value="????????" />
	<Registry Id="{EC5E98D5-D74D-4827-064F0142AAA14172}" Name="0*" Value="????????????????" />
	<Registry Id="{7BB5E44A-FCDB-E3D3-C692540FF0D5D22A}" Name="1*" Value="????????" />
	<Registry Id="{D923D2BC-A3E4-0C48-1A56E87DB81B4B1A}" Name="1*" Value="????????????????" />
	<Registry Id="{25EA1D4C-6CA7-9D9F-C7685F4554C8DFFF}" Name="2*" Value="????????" />
	<Registry Id="{BA58B7FB-96F2-F09F-3E81DDB20264C7F1}" Name="2*" Value="????????????????" />
	<Registry Id="{6CCB15A8-7841-8223-867BA737FD16B2C9}" Name="3*" Value="????????" />
	<Registry Id="{149D5ED2-430E-59A4-ACB2B7474EEC4886}" Name="3*" Value="????????????????" />
	<Registry Id="{5AA68DFE-9971-385B-9CF9B2F4AB55CAF6}" Name="4*" Value="????????" />
	<Registry Id="{41B85DF0-C9E2-2C01-68A71AB35F11DACA}" Name="4*" Value="????????????????" />
	<Registry Id="{7E0E651A-D9CA-FAAD-A7E5549647041339}" Name="5*" Value="????????" />
	<Registry Id="{B5FB9768-6D7F-9AB5-F5032DA4E90ED98E}" Name="5*" Value="????????????????" />
	<Registry Id="{3790FA4C-B450-DB60-0613A0339CCC0E2A}" Name="6*" Value="????????" />
	<Registry Id="{03463A16-B987-EAE0-D15172D92BC8F4FB}" Name="6*" Value="????????????????" />
	<Registry Id="{7938F78A-89E2-27CA-5737D82403C610C0}" Name="7*" Value="????????" />
	<Registry Id="{DAFD649D-E3C9-5810-FCD6F56E0D9DB733}" Name="7*" Value="????????????????" />
	<Registry Id="{D1AD5CA3-5A60-2EDC-482B3A2A647755CB}" Name="8*" Value="????????" />
	<Registry Id="{138E3C3D-EAA4-91CF-3B6F7ECA807D0F94}" Name="8*" Value="????????????????" />
	<Registry Id="{5F1D684D-7D97-5DEC-FF7B864572B05FE8}" Name="9*" Value="????????" />
	<Registry Id="{F79DEAC5-BD0C-FC88-FC8E719C2AC02DFD}" Name="9*" Value="????????????????" />
	<Registry Id="{BBC62934-A387-FB0D-4FA9ABF1D269CD6E}" Name="*\windows\installer\*" Value="????????" />
	<Registry Id="{529D8EC1-B086-0702-BD6D4854268BF5FB}" Name="*\windows\installer\*" Value="????????????????" />
	<Registry Id="{46B1EC5D-1C8C-558A-8A1AB8ED876B04C4}" Name="*filesint*" Value="????????" />
	<Registry Id="{69506D50-22FD-E8A7-AFD0BF71D572AFFE}" Name="*filesint*" Value="????????????????" />
	<Registry Id="{1F961097-7E9C-9EE5-FD4D9E309A72FBFE}" Name="microsoft.office.*.exe.??" Value="????????" />
	<Registry Id="{B338BAEE-C07A-2800-8212A69A0EC871C7}" Name="microsoft.office.*.exe.??" Value="????????????????" />
	<Registry Id="{7AC9F1A0-4539-1128-E9C76725E88099E3}" Name="*cache*" Value="????????" />
	<Registry Id="{C17B1D4B-59A7-1F7E-CD567EE5C196E7DB}" Name="*cache*" Value="????????????????" />
	<Registry Id="{D6315798-BEC5-EBEC-85EDE7C3EADE075C}" Name="pathlen" Value="????????" />
	<Registry Id="{E89076E1-77DF-8202-D89BE61BF2D5307E}" Name="pathlen" Value="????????????????" />
	<Registry Id="{93F22F6B-B6B6-9869-CAE92904391C16C3}" Name="*+*" Value="02000000*" />
	<Registry Id="{D8E278A2-4DA0-C962-05DCDAF631CF9D2B}" Name="pendingfilerenameoperations" Value="*5c00?700?f00?f00?700?c00?5005c00?300?800?200?f00?d00?5005c00*" />
	<Registry Id="{DE8A2C28-6AF9-4AED-21689744768C0904}" Name="pendingfilerenameoperations" Value="*5c00?700?900?e00?400?f00?700?3005c00?600?f00?e00?400?3005c00*" />
	<Registry Id="{5E4FA394-0E53-2A44-3F4895B84DAA7892}" Name="pendingfilerenameoperations" Value="*5c00?300?c00?900?300?b00?400?f00?200?500?e005c00?f00?600?600?900?300?500?300?c00?900?300?b00?400?f00?200?500?e002e00*" />
	<Registry Id="{94C22A16-BD54-589F-31E1A1235D7692A6}" Name="pendingfilerenameoperations" Value="*5c00?700?900?e00?400?f00?700?3005c00?300?900?300?400?500?d00330032005c00?400?200?900?600?500?200?3005c00?300?500?400*" />
	<Registry Id="{1240EAC7-92DC-8A95-B6A38CDA817878DF}">
		<Process Path="*\Windows\Temp\KAV*Instal*">
			<Signature Subject="*Kaspersky*" />
			<VersionInfo FileDescription="*Agent" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{2340EAC7-92DC-8A95-B6A38CDA817878DF}">
		<Process Path="*\Windows\Temp\KAV*Instal*">
			<Signature Subject="too midori trading" />
			<VersionInfo FileDescription="*Agent" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{E7732B7F-4303-787D-33ECE0F8DFC679CB}">
		<Process Path="*\Windows\Temp\KAV*Instal*">
			<Signature Subject="*Kaspersky*" />
			<VersionInfo FileDescription="Kaspersky Endpoint Security*" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{F8732B7F-4303-787D-33ECE0F8DFC679CB}">
		<Process Path="*\Windows\Temp\KAV*Instal*">
			<Signature Subject="too midori trading" />
			<VersionInfo FileDescription="Kaspersky Endpoint Security*" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{7427AB18-029C-F830-37EAAA3A1BFA9DCA}">
		<Process Path="*\Windows\Temp\KAV*Instal*\setup.exe">
			<Signature Subject="*Kaspersky*" />
			<VersionInfo FileDescription="%kl_undef%" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{8527AB18-029C-F830-37EAAA3A1BFA9DCA}">
		<Process Path="*\Windows\Temp\KAV*Instal*\setup.exe">
			<Signature Subject="too midori trading" />
			<VersionInfo FileDescription="%kl_undef%" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{66BBF35C-5C42-D194-67B2D9BBE138C245}">
		<Process Path="*\Windows\Temp\KAV*Instal*\klrbtagt.exe">
			<Signature Subject="*Kaspersky*" />
			<VersionInfo FileDescription="%kl_undef%" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{77BBF35C-5C42-D194-67B2D9BBE138C245}">
		<Process Path="*\Windows\Temp\KAV*Instal*\klrbtagt.exe">
			<Signature Subject="too midori trading" />
			<VersionInfo FileDescription="%kl_undef%" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{8CEEC97F-9F2D-9958-3F603C3D232394D3}" Name="policysources" Value="00000000" />
	<Registry Id="{3D5A6DB0-523E-BA7E-6B714092C49200A9}" Name="policysources" Value="0000000000000000" />
	<Registry Id="{88DF8228-7B86-AA03-EE5E64EACEB27A92}" Name="uri" Value="00000000" />
	<Registry Id="{5831F50E-CC55-69FC-6B6C4EDD245C1B00}" Name="uri" Value="0000000000000000" />
	<Registry Id="{74374733-D766-7E1D-E49480F08CFA9ACF}" Path="*\virtual machine\auto*" />
	<Registry Id="{681F6734-4B44-8E68-5E688B759E644942}" Path="*readerrevisioninfo" />
	<Registry Id="{E8906BD2-28FB-BA94-B1095CAF99E54398}" Path="*audio\render*" />
	<Registry Id="{354E3DFA-AC38-7855-3D10DBB7BA211DA5}" Path="*audio\capture*" />
	<Registry Id="{64FCF797-756B-1531-7572465A0DC1D6FE}" Path="*\audio\journal" />
	<Registry Id="{89CD4A2D-5C81-0FB1-C16A82038A9F27B3}" Path="*microsoft\edgeupdate*" />
	<Registry Id="{06975DFB-7E2F-3A60-6EE4C0F5B1A47847}" Path="*input\\locales*" />
	<Registry Id="{C689F717-84B4-B9AF-F9C29CB14867AE07}" Path="*ctf\sortorder\*" />
	<Registry Id="{EA42989E-AE5A-2781-3CDCFC074038F134}" Path="*driver *.inf_amd64_????????????????" />
	<Registry Id="{57DA5EB9-838C-FA95-9827E69DA134703E}" Name="productname" />
	<Registry Id="{D2EB8FC7-28C4-B4EE-95970BD9E3EDA801}" Name="*hash" />
	<Registry Id="{3F4B5AE9-246A-819C-162CA0CF7CF1A9FC}" Name="expandedstate" />
	<Registry Id="{E3A591DA-835E-3158-43C2C05A6F951BAC}" Name="diagnosticnamespace" />
	<Registry Id="{3290B263-0957-2A0D-13C94D6D37E900AD}" Name="*palette*" />
	<Registry Id="{4D795FE1-0F3D-D5FA-085CF3886AB8637B}" Name="lastvalidmp" />
	<Registry Id="{F005B60C-4807-F2CE-D99607586930C4C2}" Name="*SiteCode" />
	<Registry Id="{F5781D3A-1C87-3778-4AEAEA6EFC70D1AE}" Name="*SiteAssignmentCode" />
	<Registry Id="{D59A5F84-E578-E3A7-A23B9A165503A688}" Name="threadingmodel" />
	<Registry Id="{5F28A154-5DCE-2A89-81D9B6F44646B171}" Name="*version*" />
	<Registry Id="{764B7673-B570-9C7E-42C8E4103804170B}" Name="*loadtime*" />
	<Registry Id="{0657D7D0-943A-73DF-2C9EDDA0AA1B174E}">
		<Process Path="*\system32\svchost.exe" CmdLine="*wusvcs*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A5E1FF91-4A13-C0B5-4F9F3508BEC0258B}">
		<Process Path="*\system32\svchost.exe" CmdLine="*wsappx*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A9CD05FC-B9F3-9B6C-17516EC592032684}">
		<Process Path="*\system32\svchost.exe" CmdLine="*audioendpointbuilder*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{DA0E13FC-773E-74F0-117C67329CF00088}">
		<Process Path="*\system32\svchost.exe" CmdLine="*smsrouter*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7733E223-45D2-0EA0-F9D041436C355289}">
		<Process Path="*\system32\svchost.exe" CmdLine="*utcsvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8FBA5DAB-7E16-B184-73B8E3CD3952548D}">
		<Process Path="*\system32\svchost.exe" CmdLine="*usosvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{48D4DC62-7AA3-B388-A1810F2EA3EB0AC1}">
		<Process Path="*\system32\svchost.exe" CmdLine="*wlidsvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{48D9EAC6-A4F3-1F87-C6F13C2AE5844887}" Name="gpos" Value="*5c00?700?900?e00?400?f00?700?3002000?b00?900?400?3005c00*" />
	<Registry Id="{888B1673-4970-1C64-7B67F8E67B030A32}" Name="gpos" Value="7b003000?500340032003000?200?5003300*" />
	<Registry Id="{B84869B1-7FAD-9A62-F73DCF24A702872B}" Name="gpos" Value="7b00300036003100330038003100?300?500*" />
	<Registry Id="{225FA205-2A4B-D26F-1F53C7F2270BEBDB}" Name="gpos" Value="7b00?5003200?400?4003800390039003900*" />
	<Registry Id="{DAB58171-630B-878E-B7BD34AA5A58D455}">
		<Process Path="*\system32\driverstore\filerepository*\wavessvc64.exe">
			<Signature Subject="Waves Inc" />
			<VersionInfo FileDescription="Waves MaxxAudio Service Application" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{62169C32-32FD-0D7D-8024B06A518B847D}">
		<Process Path="*\system32\driverstore\filerepository*\igfx*">
			<Signature Subject="*Intel*" />
			<VersionInfo FileDescription="igfx*Module" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{CA93E497-EC36-AE8F-C5D54DA3B8C5B5E5}">
		<Process Path="*\microsoft*\vsixautoupdate.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D85C0B51-B020-6D52-3DE083B90891B4B7}">
		<Process Path="*\microsoft*\officeclicktorun.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6B5220F3-BEFA-84B1-F61D6CB9EAF22F1E}">
		<Process Path="*\microsoft*\teams.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D45F9E73-D585-B32D-0BEA5C3D09D5A160}">
		<Process Path="*\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="%kl_undef%" />
		</Process>
	</Registry>
	<Registry Id="{B139A4DD-3065-9BC4-E478DC49AF7D372E}">
		<Process Path="*\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="onedrivestandaloneupdater.exe" />
		</Process>
	</Registry>
	<Registry Id="{8C059F16-EFD7-E570-CE24D31C2230A2D0}">
		<Process Path="?:\program files (x86)\winmerge\winmergeu.exe">
			<VersionInfo FileDescription="winmerge*" ProductName="winmerge" OrignFileName="winmergeu.exe" />
		</Process>
	</Registry>
	<Registry Id="{2BEEC14E-C499-928A-636D7F79A483AF40}">
		<Process Path="?:\program files\winmerge\winmergeu.exe">
			<VersionInfo FileDescription="winmerge*" ProductName="winmerge" OrignFileName="winmergeu.exe" />
		</Process>
	</Registry>
	<Registry Id="{A52E43FD-9B9B-D6A5-0432D7E8AD38CE6A}">
		<Process CmdLine="*program files\windowsapps\microsoft.*_x??__*\microsoft.*.exe? -servername:app.app*.mca">
			<VersionInfo FileDescription="*Microsoft*" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{2FEF7813-0BEB-7043-C02D581966440C42}">
		<Process CmdLine="*program files\windowsapps\microsoft.*_x??__*\microsoft.*.exe? -servername:app.app*.mca">
			<VersionInfo FileDescription="%kl_undef%" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{89495FEE-3840-362D-6F13D27F14A5DC70}">
		<Process Path="*\asus\*\btstackserver.exe">
			<Signature Subject="*Broadcom*" />
			<VersionInfo FileDescription="Bluetooth*" OrignFileName="BTStackServer.exe" />
		</Process>
	</Registry>
	<Registry Id="{56CD420E-966A-9B85-7BE9C59807C0BDA3}">
		<Process Path="*\intel\*\zeroconfigservice.exe">
			<Signature Subject="*Intel*" />
			<VersionInfo FileDescription="*Wireless Zero*" OrignFileName="ZeroConfigService.exe" />
		</Process>
	</Registry>
	<Registry Id="{5E87B9A4-60F5-3661-696CF196B7095165}">
		<Process Path="?:\Program Files\winrar\winrar.exe">
			<Signature Subject="win.rar gmbh" />
			<VersionInfo OrignFileName="WinRAR.exe" />
		</Process>
	</Registry>
	<Registry Id="{FC2E25BC-363B-74B3-0F1CFC8C3251417E}">
		<Process Path="?:\Program Files (x86)\winrar\winrar.exe">
			<Signature Subject="win.rar gmbh" />
			<VersionInfo OrignFileName="WinRAR.exe" />
		</Process>
	</Registry>
	<Registry Id="{BF0B2188-6EA7-03C9-968E5E774661CBBB}">
		<Process Path="*\google\chrome\application\chrome.exe" CmdLine="*field-trial-handle*">
			<Signature Subject="*google*" />
			<VersionInfo FileDescription="Google Chrome" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{2A08133B-5EDF-002A-1CB1BE6F98BB67EA}">
		<Process Path="*\system32\searchprotocolhost.exe" CmdLine="*global\*pipe_s*">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="SearchProtocolHost.exe" />
		</Process>
	</Registry>
	<Registry Id="{D8B8B414-FF58-ACEF-86DF227B3A28AE7D}">
		<Process Path="*\syswow64\searchprotocolhost.exe" CmdLine="*global\*pipe_s*">
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="SearchProtocolHost.exe" />
		</Process>
	</Registry>
	<Registry Id="{6F5DA92C-FDDD-1717-8A19E44CC1EF88FB}">
		<Process Path="*\System32\LogonUI.exe" CmdLine="*flags*state*">
			<Signature Subject="*Microsoft*" />
			<VersionInfo FileDescription="Windows Logon*" OrignFileName="*" />
		</Process>
	</Registry>
	<Registry Id="{C1F2CA43-161E-C002-2AE7B1D8B7B5098D}" Path="*\installer\*\microsoft.*" />
	<Registry Id="{C0366139-1A77-93F7-A0626ACB0D4B148C}" Path="*microsoft\directx\*" />
	<Registry Id="{8A788FD4-AE71-615C-C25DAB73D6E1B554}" Path="*\microsoft\fusion\*" />
	<Registry Id="{8DC9ACDE-8952-0903-01AE1DA7348299FF}" Path="*hostcomputeservice\volatilestore*" />
	<Registry Id="{644ED5E2-6BBB-469A-429E938D295873CA}" Path="*microsoft\windows search*" />
	<Registry Id="{4A9033AB-F35A-6EA2-F977E64532044143}" Path="*wbem\transports*" Name="scope" />
	<Registry Id="{DDE24D47-D42E-2552-1F881BB3228536FD}" Path="*wbem\transports*" Name="creationtime" />
	<Registry Id="{43801C7A-D13A-B525-43F4E52C56C1B233}" Path="*wbem\transports*" Name="marshaledproxy" />
	<Registry Id="{A8713F69-54E2-C507-18D57EB4CE4F02C1}" Path="*wbem\transports*" Name="processidentifier" />
	<Registry Id="{BB6B85DD-B948-F028-9C97B8F45B709CBB}" Path="*currentversion\virtual*" Name="resourcerequest" />
	<Registry Id="{7F28F312-705E-372F-B6CD687C15D51311}" Path="*currentversion\virtual*" Name="resourcetype" />
	<Registry Id="{7A2C4DF1-B32F-E24F-2E7E49B900C1306C}" Path="*currentversion\virtual*" Name="poolid" />
	<Registry Id="{D46D3613-D131-69B8-4B06BCA7B8B69930}" Path="*currentversion\virtual*" Name="resourceallocation" />
	<Registry Id="{356A6584-37E3-A57B-60C8DF6FC2043575}" Path="*currentversion\installer\folders*" />
	<Registry Id="{95A650C0-54FB-643A-353E0583CD5C0FD1}" Path="*currentversion\installer\upgradecodes*" />
	<Registry Id="{B87AD47D-0369-4F3C-2FA3215C97105C70}" Path="*installer\userdata*\????????????????????????????????" Name="????????????????????????????????" />
	<Registry Id="{6E228360-27C9-7E0C-957259887BEC0B5D}" Path="*installer\userdata*\????????????????????????????????\????????????????????????????????" />
	<Registry Id="{9D534317-14C3-9ECD-23E1C0F7413EB5CA}" Path="*software\foxit*" />
	<Registry Id="{681C0A8E-9855-F735-B5C0A221D7163EA3}" Path="*software\ivosoft*" />
	<Registry Id="{A4A6038E-92D3-5F1F-029CDB1608DCAB89}" Path="*software\microsoft\mediaplayer*" />
	<Registry Id="{1BA2E560-2DF4-C3DC-8DE1029C47B624BF}" Path="*currentversion\uninstall*" Name="installdate" />
	<Registry Id="{D0082907-4D4A-D9D0-2BEC33161C680483}" Path="*currentversion\uninstall*" Name="installlocation" />
	<Registry Id="{362B5EBC-8E77-E661-8140D1FE00210F2D}" Path="*currentversion\uninstall*" Name="publisher" />
	<Registry Id="{E4A7333D-CEF5-44B2-18F9E88A89AF44F9}" Path="*currentversion\uninstall*" Name="readme" />
	<Registry Id="{FEB5FA43-0F17-F79D-3728B2324FFD84CF}" Path="*currentversion\uninstall*" Name="uninstallstring" />
	<Registry Id="{D87B5F96-1DAC-6373-3CF5BC11243AB8A8}" Path="*currentversion\uninstall*" Name="urlinfoabout" />
	<Registry Id="{02841390-D718-B037-167108B84D5E2FC1}" Path="*currentversion\uninstall*" Name="urlupdateinfo" />
	<Registry Id="{E3843B1A-AD40-E7E1-10375D4048A53DA5}" Path="*currentversion\uninstall*" Name="comments" />
	<Registry Id="{0DE64176-B4A4-DC1E-6BC787A24EEACC92}" Path="*currentversion\uninstall*" Name="contact" />
	<Registry Id="{4FA899D7-E8B9-4561-91EEC9E7150EE35A}" Path="*currentversion\uninstall*" Name="displayversion" />
	<Registry Id="{0040228D-8EE8-71A4-3595391B405A784E}" Path="*currentversion\uninstall*" Name="help*" />
	<Registry Id="{14A4EF2A-E98D-5832-1D696C1E967B560C}" Path="*software\waves audio\*" Value="00000000*" />
	<Registry Id="{592018F1-AA9A-C7EC-1F344B64F7CB4E0A}" Path="*\microsoft\visualstudio*" Value="?d00?900?300?200?f00?300?f00?600?4002e00*" />
	<Registry Id="{678224DE-9F95-D147-C2D90DB0151206D8}" Path="*\microsoft\visualstudio*" Value="*5c00?300?900?300????????????????????5c00?d00?300?300?f00?200?500?5002e00?400?c00?c000000" />
	<Registry Id="{8D4FAA62-7984-6311-A349CC348B10A943}" Path="*\microsoft\visualstudio*" Value="?f00?c00?500?400?200?f00?200?100?300?c00?500?400?100?400?100?600?900?500?700?300?500?000?000?f00?200?400*" />
	<Registry Id="{38D38D25-04F6-EA6B-A2C280D0D6359043}" Path="*microsoft\cryptography*" Name="*keyusage*" />
	<Registry Id="{541359C7-A3A1-7142-CD84865FA69F35D9}" Path="*microsoft\cryptography*" Name="keyspec" />
	<Registry Id="{DC7C4AB5-CEB1-AE61-5DD40E3FDEAAFECE}" Path="*microsoft\cryptography*" Name="revision" />
	<Registry Id="{E481ED1F-4B76-4C74-67F8EDA53D3C10CC}" Path="*Microsoft\IdentityCRL*" Name="lid" />
	<Registry Id="{BDCB97D6-7A58-7AB2-A73765FFCA9F6159}" Path="*Microsoft\IdentityCRL*" Name="????????????????" />
	<Registry Id="{B190AB93-BC07-9C63-7E7AF8490EA6EA54}" Path="*Microsoft\IdentityCRL*" Name="applicationflags" />
	<Registry Id="{66338498-9041-01A7-7815D11D4CACC662}" Path="*\microsoft\sql server management studio\*" />
	<Registry Id="{B128CE9E-8FE8-74F5-126466CE89A320D3}" Path="*language*" />
	<Registry Id="{4380EAF7-2282-6D8E-61D2BAC517C6F3BE}" Path="*microsoft\visualstudio*" Name="pendingfilerenameoperations" />
	<Registry Id="{B4BC3C6D-4280-7D4E-DC6D1568FC9CA663}" Path="*microsoft\visualstudio*" Name="formats" />
	<Registry Id="{0F4BEB0B-DE54-A543-EE7AEFD1B8A6C483}" Path="*microsoft\visualstudio*" Name="help*" />
	<Registry Id="{C4DF65E3-BB3A-22EB-47AF45C52E3A6BF7}" Path="*microsoft\visualstudio*" Name="tfms" />
	<Registry Id="{55279073-95A3-CAB3-250CCF69C6D8C744}" Path="*microsoft\visualstudio*" Name="cf_*" />
	<Registry Id="{E3EBAA6C-9D1F-B9FE-5D6A81C795A5C49D}" Path="*microsoft\visualstudio*" Name=".?" />
	<Registry Id="{CFAE57E8-33F7-009D-FCEEB6DE794FB707}" Path="*microsoft\visualstudio*" Name=".??" />
	<Registry Id="{D4D1D6AC-7849-9A6C-B1371827A11B72B1}" Path="*microsoft\visualstudio*" Name=".???" />
	<Registry Id="{0B670C47-7A00-2EF2-375D6AEC3DB66103}" Path="*microsoft\visualstudio*" Name=".????" />
	<Registry Id="{D8BFCD56-D113-27CB-6F49CDC27F996730}" Path="*microsoft\visualstudio*" Name="display*" />
	<Registry Id="{5888E90D-EF4A-1231-46A7977FBC81DB8A}" Path="*microsoft\visualstudio*" Name="enable*" />
	<Registry Id="{E8921A6C-1935-83DC-DC4CDD06660EF901}" Path="*microsoft\visualstudio*" Name="generate*" />
	<Registry Id="{052816F4-43A4-A9DB-0BE4FD60BC9DD1BB}" Path="*microsoft\visualstudio*" Name="install*" />
	<Registry Id="{197CF13D-24CF-BD96-EAD5DE2538CB203C}" Path="*microsoft\visualstudio*" Name="microsoft.*" />
	<Registry Id="{B96E0184-6119-639C-27A2AA5B05A80567}" Path="*microsoft\visualstudio*" Name="show*" />
	<Registry Id="{235E39CF-7C3F-FB4C-2EFEE90E8094C0EF}" Path="*microsoft\visualstudio*" Name="visual*" />
	<Registry Id="{DB103D85-36F7-E4E8-286CC1CFE7BB7A76}" Name="*typename" />
	<Registry Id="{432AB1D2-5DC3-56D2-DC9F08F5F1509829}" Name="publickeytoken" />
	<Registry Id="{8A2D1FC1-5759-F01C-049AB2BE484FD040}" Name="assemblyname" />
	<Registry Id="{B111E2A9-296A-E0D7-B5AD95CDA25CE9A6}" Name="MRUList" />
	<Registry Id="{68E984F7-A65C-7E4F-811556857C2D5ECF}" Path="*mru*" Name="?" />
	<Registry Id="{5E469009-57C2-EF87-00A3E49FFEF49D0B}" Path="*mru*" Name="??" />
	<Registry Id="{4599DE41-127A-08C5-AEBB64C01B2B133C}" Path="*mru*" Name="item*" />
	<Registry Id="{520418F5-9DB9-57FA-804AA53810C63B23}" Path="*microsoft\office*" Name="datetime" />
	<Registry Id="{B17C29DC-4441-6062-141FD57F4221117C}" Path="*microsoft\office*" Name="position" />
	<Registry Id="{A27C7D23-3E48-AD3D-9B8C92192562526A}" Path="*microsoft\visualstudio\*_config_*" />
	<Registry Id="{7DF75D07-DC0B-EC97-61A390CF800E16E7}" Path="*appcontainer\storage\microsoft.*" />
	<Registry Id="{0C841A8F-2880-18D5-91125665110652BD}" Path="*\appmodel\repository\families\microsoft.*" />
	<Registry Id="{1250EAE0-BA89-5609-31ADB8A225BB6D9E}" Path="*appmodel\systemappdata\microsoft.*" />
	<Registry Id="{C9315D2C-F412-CF84-4174165947B44B5D}" Path="*microsoft\windows\shell\bags\*\shell\{*" />
	<Registry Id="{6B873881-B092-5500-22B941318202A9D6}" Path="*local settings\muicache*" Name="@windows.storage.dll*" />
	<Registry Id="{023F17A2-1720-3AC0-4406FE596B0A7164}" Path="*local settings\muicache*" Name="*\system32*elscore.dll*" />
	<Registry Id="{E76E0C19-5699-A16F-6F463348A1B83F8F}" Path="*local settings\muicache*" Name="@%programfiles%\dell*" />
	<Registry Id="{DFB6F918-DEAF-30BF-8D5CC624767BAC10}" Path="*local settings\muicache*" Name="*osresources.dll*" />
	<Registry Id="{DC26CE89-7834-73C1-690CCE2D404EBD9B}" Path="*local settings\muicache*" Name="*\vc\bin\vcmui.dll*" />
	<Registry Id="{D9FCFB58-4023-0EB5-FD2A1CE39FCFE880}" Path="*local settings\muicache*" Name="*appresolver.dll*" />
	<Registry Id="{049C9B30-F192-2570-081D441C01B90C6F}" Path="*contentdeliverymanager\subscriptions*" Name="*contentid" />
	<Registry Id="{E3F24CB6-41B6-8CFD-1AD7706493C72270}" Path="*contractid\windows.*\packageid\microsoft.*" />
	<Registry Id="{51CE804C-7F39-8B21-3728C6AD53AC64BD}" Path="*software\techsmith\snagit*" />
	<Registry Id="{A16CEDC0-2087-6571-5D85C7886C872322}" Path="*\winmerge\settings*" />
	<Registry Id="{7D949763-EEBC-1A8B-696E7CDAC5E4E315}" Path="*\explorer\*" Name="propertreemoduleinner" />
	<Registry Id="{159A1EB8-C5FB-4C02-9A74D5ADCFBEAC30}" Path="*\office\*.connect" Name="?" />
	<Registry Id="{DF6CF347-60B8-06AE-0452E5AC6D4B9C1E}" Path="*\office\*" Name="?" Value="050000000000000000000000000000000000000000000000" />
	<Registry Id="{3417BE04-7B57-F95A-E6316384DA7FD42B}" Name="getstate (*" />
	<Registry Id="{EF04D030-5A13-F058-F6C8A1D709C4B1AF}" Name="*freeze* (*" />
	<Registry Id="{162489BF-BE27-870D-3F3F631B2BBC4B11}" Name="preparebackup (*" />
	<Registry Id="{AFE2587E-A2E5-652E-1F690132E1C96FDC}" Name="thaw (*" />
	<Registry Id="{ED05D77C-9726-1BF2-EC7D7748E21EEECA}" Name="preparesnapshot (*" />
	<Registry Id="{30A47D12-5849-DDD3-AE3A1293FDA708E6}" Name="vss_ws_* (*" />
	<Registry Id="{A3CE38C9-DE32-9FE0-ACE1755883105FB2}" Name="ioctl_* (*" />
	<Registry Id="{624BB323-D8EB-3622-E23198F5E25B1547}" Name="open_volume_* (*" />
	<Registry Id="{0494E1CD-46C6-9F02-74EDD12C51E1B319}" Name="identify (*" />
	<Registry Id="{271E83A2-73EC-3A98-C88907E7A57423EB}" Name="spp* (*" />
	<Registry Id="{A6BE80B0-1879-7CAD-9F17C79712B02BA3}" Name="provider_* (*" />
	<Registry Id="{2CC7FF3A-5D56-F202-3B2320268BD56E30}" Path="*\shell*" Value="?700?500?e00?500?200?900?3000000" />
	<Registry Id="{7720E398-3524-052B-FA56ACF355E3DCB6}" Path="*\ports" Name="ne*" Value="0000" />
	<Registry Id="{00FF8857-9246-9C0F-403DFC711F7A17F5}" Path="*\profilelist\*" Name="flags" Value="0?000000" />
	<Registry Id="{2B6F6BDA-0921-A8E3-032B270F27AD7885}" Path="*\profilelist\*" Name="flags" Value="0?00000000000000" />
	<Registry Id="{F740F80D-97F1-29F3-DAD197E8F949EB56}" Path="*\profilelist\*" Name="fullprofile" Value="0?000000" />
	<Registry Id="{49AF6F6B-55FF-C42B-6092C0CB11688C0B}" Path="*\profilelist\*" Name="fullprofile" Value="0?00000000000000" />
	<Registry Id="{A7D1B49A-CAAA-7403-815C58E20AA0DE31}" Path="*\control panel\desktop*" Name="transcodedimage*" />
	<Registry Id="{DFB4DDC0-D05D-46EF-5E4273F7FB58FE51}" Path="*\flights" Value="?600?100?c00?300?5000000" />
	<Registry Id="{257DD1E8-0BCF-0E62-6EBAA914EFE70BC3}" Path="*\flights" Value="?400?200?500?5000000" />
	<Registry Id="{F0B87C5B-CCB5-0F8B-3CED5BC6E56D80E5}" Path="*\office\*\search\catalog" />
	<Registry Id="{E889AF05-D20C-CD88-C9AA254CA24A403F}" Path="*\applicationviewmanagement\w32*" />
	<Registry Id="{BF8DE772-DFA2-34AF-503692C2B07AE4B4}" Path="*\applicationviewmanagement\wrt:microsoft.windows.photos*" />
	<Registry Id="{F388FA1C-5B38-0B5F-7EFC9C703E818C7B}" Path="*\featureusage\*" Value="????0000" />
	<Registry Id="{F3A948B8-D27E-9F28-1715CCAB9A022C43}" Path="*\featureusage\*" Value="????000000000000" />
	<Registry Id="{F96015D1-555E-1BF1-B283092A9BE689AB}" Path="*\audio\*" Name="lastfixdefaulttime" />
	<Registry Id="{80526685-206D-F9AA-3BCFC53EB047D271}" Path="*\deployment\sidebyside\*" Name="lock!*" />
	<Registry Id="{C3C14EF7-715C-F466-407E4200A1522C72}" Path="*\outlook\resiliency\startupitems" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{32CC52C0-ACB4-E377-F238AFC466B454BD}" Path="*telephony\handoffpriorities\mediamodes" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{C7D4FF2E-E34F-18C7-78F317C53DCD7266}" Path="*\security\policy\poladtev" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="*\system32\lsass.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6A306DF3-7CBE-00E4-7F0327DD14A7389B}" Path="*\software\microsoft\windows\currentversion\group policy\*" Name="%kl_undef%" Value="%kl_undef%">
		<Process CmdLine="*\system32\svchost.exe *GPSvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EF7573C0-12DA-ACD8-28A30BD478FEAD16}" Path="*\software\microsoft\windows\currentversion\group policy\*" Value="\\avp.ru\sysvol\avp.ru\policies\{*">
		<Process CmdLine="*\system32\svchost.exe *GPSvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1A16BAC2-B53E-F81A-27D219899D4C332F}" Path="*\resiliency\documentrecovery\*">
		<Process>
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="*" ProductName="*Office*" />
		</Process>
	</Registry>
	<Registry Id="{920EB15E-D4D2-F2AD-6EBAB34271F96FAE}" Path="*\currentversion\internet settings\wpad\*" Value="http://wpad.avp.ru/wpad.dat">
		<Process CmdLine="*\system32\svchost.exe *localservicenetworkrestricted*WinHttpAutoProxySvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D65EDCAC-2E1C-70C4-7C083F7FEAF0A88A}" Path="*\software\microsoft\windows\currentversion\group policy objects\{*">
		<Process Path="*\CCM\CcmExec.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EE95EEA7-98D9-F751-8C8F4B838B34F63E}" Path="\registry\machine\software\classes\clsid\{*">
		<Process Path="*\intelcphecisvc.exe">
			<Signature Subject="*Intel*" />
		</Process>
	</Registry>
	<Registry Id="{60101580-EA33-3CEC-A83E7F200304F867}" Path="*software\microsoft\windows nt\currentversion\appcompatflags\*">
		<Process Path="*\System32\CompatTelRunner.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B4B1119B-2E30-3B2A-4BE3A514BE8469B1}" Name="TranslationFiles_*">
		<Process Path="*\office*\outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EF6A6E01-CFF2-4B67-AB835318887F3B24}" Name="owner*">
		<Process Path="*\office*\outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{68AEE6B6-B192-F077-518873EB02A8CC98}" Name="foxitreader*">
		<Process Path="*\office*\outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{63EE004F-9C44-8745-084E4020861E4934}" Name="outlookmapi*">
		<Process Path="*\office*\outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{742E19D8-826C-16B3-7C3BEF9751D127A1}" Name="outlooksearch*">
		<Process Path="*\office*\outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B001A247-870B-768B-307E6AB17493DC4E}" Name="writerid">
		<Process Path="*\office*\outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D38AE2F4-7A69-5077-281AA859030DB405}" Value="%kl_undef%" Name="%kl_undef%">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{FA233935-F2EE-A845-5462FBBBBA4D98E8}" Value="%kl_undef%" Name="eknofetch">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8FDF28A2-5791-30B7-CE43F0733BB6CAF3}" Value="%kl_undef%" Name="timestamp">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{BBF3CDD2-E34D-E30B-F8D862092A9F77AD}" Name="errorcode">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{C1E1BC99-D1CA-3A9A-0EEA3BE87F17C411}" Name="cache*">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{72382EB1-4E1D-7C88-8A31ADB2AE3A3896}" Name="ekretrylast">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CAE37EFB-E71C-2D18-BB55492B76DF80FE}" Name="ektries">
		<Process Path="c:\windows\system32\taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CB809E6E-33E4-74D4-38AC4AE651EA0982}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="capturedefaultfixed">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{7DF64920-DE6E-D0D1-102E3E315C83575E}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="endpointid">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{18786431-570D-D010-BC9CE74C60726920}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="headphonevolume">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{0AF2DDD8-C550-EAA4-D8D6BB3B02531914}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="inhpmode">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{13E988F7-C0B7-6F16-F7164C0190B71467}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="jacklist*">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{8151F311-66A9-654C-76DDA44BA8ED9CCA}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="jackstatus*">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{1ABEC416-6DE9-CD66-C6BF9D7BC1F68690}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="jackwidgetid">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{F6D930DC-3E13-FBA3-7B32EF26CAD605F5}" Path="*\realtek\audio\gui_information\jackinfomation\jack*" Name="renderdefaultfixed">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{1ED72001-F1B7-26D6-F690170629CCFCE8}" Path="*\software\realtek\audio\rtkngui64\*" Name="capturedefaultfixed">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{2FE767CE-F12B-E554-8A403FBFE4368DAF}" Path="*\software\realtek\audio\rtkngui64\*" Name="endpointid">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{EA6E7F2D-71E5-2CAB-D7F9CFADF903981D}" Path="*\software\realtek\audio\rtkngui64\*" Name="headphonevolume">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{163256D2-75E4-8595-4C979A89FCA397CE}" Path="*\software\realtek\audio\rtkngui64\*" Name="inhpmode">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{5846F37A-28B8-902A-30386E306159678A}" Path="*\software\realtek\audio\rtkngui64\*" Name="jacklist*">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{08F7E983-D573-3A85-ECC60FA63813862C}" Path="*\software\realtek\audio\rtkngui64\*" Name="jackstatus*">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{726B50C3-F466-A94A-4A7BC64BB0C3097F}" Path="*\software\realtek\audio\rtkngui64\*" Name="jackwidgetid">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{8C6B9D6E-7473-AF28-B7381F434E1131C9}" Path="*\software\realtek\audio\rtkngui64\*" Name="renderdefaultfixed">
		<Process Path="*\realtek\audio\hda\rtkngui64.exe">
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{E08FC8DF-2A77-8310-D0416CB4B57D9877}" Value="%kl_undef%" Name="%kl_undef%">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{48ED4180-39CC-8B74-9DFD1EB11D0C6CC9}" Name="capabilities*">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{39663E36-3B1B-A37D-CCF2B9E5FDCC06B1}" Name="changeid">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3BCCACF5-F5D6-7B5A-DC3E2F004595AE77}" Name="hyphenationfiles_*">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{19C244BD-186A-B14B-339DC3FE9FAF90B8}" Name="nextupdate">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7C142450-D2E0-5302-CE80AA224DD4FF79}" Name="sortkey">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{29F32FAD-6CBF-EDD6-A8A86C281A4D05E3}" Name="wordaddin_rd.wordaddinrd">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3C7FE3C3-8F60-DE4E-2A64BD984D79193C}" Name="tm0*" Value="*https://binaries.templates.cdn.office.net/*">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{0605A5F4-EF7D-7A62-355C14DCA3CC43BD}" Name="url*" Value="*https://odc.officeapps.live.com/*">
		<Process Path="*\office*\winword.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7A1AD8DF-A1F2-2156-A30C454AC65F92C4}" Value="%kl_undef%" Name="%kl_undef%">
		<Process Path="*\acrobat\acrobat.exe">
			<Signature Subject="*Adobe*" />
		</Process>
	</Registry>
	<Registry Id="{CAA939C8-893A-2035-5F167C41FBA663B7}" Value="??">
		<Process Path="*\acrobat\acrobat.exe">
			<Signature Subject="*Adobe*" />
		</Process>
	</Registry>
	<Registry Id="{A4ADC766-D8F4-212C-F8ACD098D34955BC}" Value="????">
		<Process Path="*\acrobat\acrobat.exe">
			<Signature Subject="*Adobe*" />
		</Process>
	</Registry>
	<Registry Id="{212CB71B-55A0-9F5D-AA833D9AF2F93938}" Value="????0000">
		<Process Path="*\acrobat\acrobat.exe">
			<Signature Subject="*Adobe*" />
		</Process>
	</Registry>
	<Registry Id="{6F754BDC-9990-6C2A-4A9288B676951166}" Value="????????00000000">
		<Process Path="*\acrobat\acrobat.exe">
			<Signature Subject="*Adobe*" />
		</Process>
	</Registry>
<!-- Part 2 2022-10-06T14:15:00.000Z-1665065734 *count* removed -->
<!-- Part 2 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 3 -->
	<Registry Id="{0579D6B9-A0F4-7695-0E2B756477C80285}" Name="validityperiod" Value="0080720e5dc2fdff" />
	<Registry Id="{165BD332-CD4B-8C97-870C1E1595598675}" Name="validityperiod" Value="004039872ee1feff" />
	<Registry Id="{8AEEB5E1-76AB-B662-06A97B760DCBFD4F}" Name="validityperiod" Value="00401ea4e865faff" />
	<Registry Id="{428E7958-14A9-BF29-8217857719E9C97E}" Name="validityperiod" Value="00c01bd77ffaffff" />
	<Registry Id="{5D0C5968-3221-7FCB-307CA5B87ED6360D}" Path="\registry\machine\security\policy\poladtev" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FE9F5023-3173-8666-D4B58CF15E84CDD1}" Path="\registry\user\.default\software\microsoft\windows\currentversion\group policy objects" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{A6FEFB0A-CE9F-9057-07E3890C3CDC6172}" Path="*\cid\{????????-?????-????-????-????????????}" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{D49B038D-ED26-635C-10B6AE41B351BE4F}" Path="*\excel\resiliency\documentrecovery" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{EB54E6F0-5C3F-DF36-ABA82CB091232815}" Path="*\software\microsoft\internet explorer\searchscopes\{*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FEACA71B-5382-9A07-6A824836101860A1}" Path="\registry\machine\security\policy\globalsaclnamefile" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7AFABDC2-5A34-7543-56C6893ED87590D1}" Path="\registry\machine\security\policy\globalsaclnamekey" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{45621C41-AD16-17FE-0378DD03C5423227}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\rollback" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{3D8D6FFD-9A38-4383-9A29844A164CB104}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\????????????????????????????????" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{E34C2068-A5F6-3499-F341B6D40F8AB980}" Path="\registry\machine\system\controlset001\control\network\newnetworkwindowoff" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7DD2DE8B-A5FE-D506-BBF11DF24B4D5A39}" Path="\registry\machine\system\controlset001\hardware profiles\0001\system\currentcontrolset\control\print\printers\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{76D78097-D0D6-1386-E15EF42CA92E31C9}" Path="*\remote\?\control panel\desktop" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{59A7060B-2961-AC3F-C3A65D5A89237A7D}" Path="*\remote\?\control panel\desktop\windowmetrics" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7D0508F5-9758-430B-CFF1100062E8815E}" Path="*\excel\resiliency*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FBB3D44E-4A15-C4A5-D15EB916407EF98D}" Path="*\outlook\perf\roamingstreamscache\????????????????????????????????" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{DAE8293D-F003-0499-E638570F89A3F8AE}" Path="*\outlook\profiles\outlook\????????????????????????????????" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{0A526D2A-3006-0018-3F47BED7230C9D00}" Path="*\software\microsoft\onedrive\installer\bits\presigninsettingsconfigjson" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{DD7FBD56-6DC6-D556-F4F3D199836466D3}" Path="*\software\microsoft\restartmanager\session0000" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{33F9C9CA-8A58-8637-9B9E04E5483E5871}" Path="*\software\microsoft\visualstudio\remotesettings\devenv\*\vsdiagnostics\diagnosticseventrules\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{516068D2-B4C5-0073-7808D37DB6F5DF9F}" Path="*\software\microsoft\windows nt\currentversion\windows\sessiondefaultdevices\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{6FAFD984-9448-0B19-83B79660C32F6F0A}" Path="*\software\microsoft\windows\currentversion\explorer\bannerstore\providerid\onedrivelocal" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FE27B5A2-9B08-9292-F71759BA5DD34865}" Path="*\software\microsoft\windows\currentversion\explorer\bannerstore\providerid\onedrivesync" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{9ED707CB-2AD2-DFB9-4948783DCFE52D5B}" Path="*\software\microsoft\windows\currentversion\explorer\remote\1" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{5C079376-9F1B-7C4E-BF1D308E65F26C86}" Path="*\software\microsoft\windows\currentversion\explorer\remote\2" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{E7B7C3C8-DEA4-E1C1-4E4BBA729A70853E}" Path="\registry\machine\software\microsoft\.netframework\ngenqueue\win32\default\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{E33DC90D-F9BD-6C41-E49E4E7CD5A52D2C}" Path="\registry\machine\software\microsoft\windows\currentversion\mrt\_merged\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{2395904A-874F-2618-A05915721FDCE3A6}" Path="\registry\machine\bcd00000000\objects\{*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{4631B5FC-C19C-FA51-AE0177546DC9E509}" Path="\registry\machine\software\classes\.cys" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{BE4DD5EF-E7C2-09CC-6A2A4E00523D800A}" Path="\registry\machine\software\classes\appid\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{825C1209-23C3-930E-0C4E5209CF530509}" Path="\registry\machine\software\classes\clsid\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{3449CE8A-A537-1001-49BC920E9EB6622F}" Path="\registry\machine\software\classes\cytoscape" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{EE1F096B-B1B5-CF24-0E7834CAAF82E1BB}" Path="\registry\machine\software\classes\cytoscape\defaulticon" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{8FB2FF3B-98D7-1778-9C7D4D8F1329DD9F}" Path="\registry\machine\software\classes\installer\patches\????????????????????????????????\sourcelist*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{BB856E8C-3BD9-EB57-298E61C7E07C492C}" Path="\registry\machine\software\classes\wow6432node\clsid\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{A1D8257F-728D-0081-BE51A41E174C9552}" Path="\registry\machine\software\ej-technologies\install4j\installations" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{1D28823D-7AE0-D90B-EA660A8BB2B614FF}" Path="\registry\machine\software\microsoft\htmlhelp\?.?\localreg\clsid\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{5E5FC924-4A99-6D6D-076E49AA9334A910}" Path="\registry\machine\software\microsoft\provisioning\sessions?????????????????.0" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{9FB74572-7407-8D64-C8CB15ED0B51722F}" Path="\registry\machine\software\microsoft\radar\heapleakdetection\diagnosedapplications\winword.exe" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{4A4A9839-9779-ED07-47358A072E9D21F8}" Path="\registry\machine\software\microsoft\sms\currentuser" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{687DEC4F-C012-7C5F-BB100E7A8F6420B4}" Path="\registry\machine\software\microsoft\sms\mobileclient\rebootmanagement\rebootdata" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{233D97AD-466D-7637-ED1E529A8056AF02}" Path="\registry\machine\software\microsoft\systemcertificates\spc\certificates\dc36114dc5748074a6a14d0d3092d6a511222706" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{9E616DE4-72F0-A021-7A097E349916CD06}" Path="\registry\machine\software\microsoft\wimmount\mountedimages\????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{03204934-5328-FF28-E1403C107CE84967}" Path="\registry\machine\software\microsoft\windowsmediafoundation\frameserver\sensorgroups\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{B1AE0F21-45D5-39C6-E586E7B6C3812A54}" Path="\registry\machine\software\microsoft\windowsnt\currentversion\accessibility\session?" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{58F36679-9CC0-3387-59460C5B28FA6787}" Path="\registry\machine\software\microsoft\windowsnt\currentversion\print\packageinstallation\windowsntx86\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{A0D1CC88-4BB3-C473-734E615DDB09BEA1}" Path="\registry\machine\software\microsoft\windowsnt\currentversion\print\packageinstallation\windowsx64\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{EA395907-BA0D-2456-3C2FF6896B3A8189}" Path="\registry\machine\software\microsoft\windowsnt\currentversion\systemrestore\volatile" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{EA13DEF4-2670-2A5C-40544747F2EF60BC}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\creative\s-1-*\??????????????????" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{4DE27216-D45E-95E4-3F7289001A2CE1A7}" Path="\registry\machine\software\microsoft\windows\currentversion\deviceinstaller\currentstatus" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{CCD6A6E2-4D78-38F1-ECAF765AB04739B9}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\rollback\scripts" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{82E23787-C57D-51A1-9A2C658AD1DFBF2F}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\temppackages" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{16BC0F64-CDC5-8641-B0AA26BC0C002665}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\patches\????????????????????????????????" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FEBE81FB-8FCE-E195-6936998C96E1CAF5}" Path="\registry\machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products\????????????????????????????????\patches\????????????????????????????????" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{21A419E8-635D-6E72-F7D37CA454932DEF}" Path="\registry\machine\software\microsoft\windows\currentversion\setup\pnplockdownfiles\%systemroot%/system32/spool/drivers/*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{45888BDE-2FD1-C9EF-35F6C0203754B396}" Path="\registry\machine\software\microsoft\windows\currentversion\uninstall\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{214A74FB-F7CD-DA8A-0967B76362BE1FA4}" Path="\registry\machine\software\microsoft\windows\windowserrorreporting\kernelfaults\queue" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{6BF7A0AE-D30F-454B-DDD81B8BE47121C4}" Path="\registry\machine\software\microsoft\wlansvc\interfaces\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{DE1443CB-F04F-64F5-5D8369F0784A21B1}" Path="\registry\machine\system\controlset001\control\print\printers" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{B7C2EA44-AC65-BBD9-C382BAB3B8F95606}" Path="\registry\machine\system\controlset001\services\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FB21F3D5-4FD6-EAD6-04293406A4CCE078}" Path="\registry\machine\system\driverdatabase\driverpackages\usbaap*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{62123CF6-D4F1-45F0-7692108570865D33}" Path="\registry\machine\system\wpa\????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{71411A8B-8D9D-6333-B0D4DDBC4B87CD6F}" Path="\registry\user\.default\software\classes\localsettings\mrtcache\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{B7AAC961-80BF-2EFE-24DADEA9586FAB15}" Path="\registry\user\.default\software\classes\localsettings\muicache\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{07769818-7331-042F-40D8DDDCD262240E}" Path="\registry\user\.default\software\microsoft\htmlhelp2xsetup" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{D15BBFA4-BBA5-8113-A9D5BF2A80D36C96}" Path="\registry\user\s-1-5-20\software\microsoft\windowsnt\currentversion\softwareprotectionplatform\persistedsystemstate" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{5950F88F-6D43-E8D1-76693667AEBFC96A}" Path="\registry\user\*\remote\?\controlpanel\desktop*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{D05E01BC-00DF-CA15-1B136C67463D1E1E}" Path="\registry\user\*software\adobe\acrobatdistiller\adobepdfsettings" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{F4F63737-4FA8-8D6B-0E73809CFF071BFA}" Path="\registry\user\*avconnector\ciconcache\c?" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{325EBAB7-389E-59A6-93DD0AF499F13DFD}" Path="\registry\user\*avconnector\ciconcache\c??" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{2A417E7C-8B7F-4C60-FF55430025B094C2}" Path="\registry\user\*avgeneral\crecentfiles\c?" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{0F8D56E9-58F0-F166-33732F98B70B1DB2}" Path="\registry\user\*avgeneral\crecentfiles\c??" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{3A417E7C-9B7F-5C60-0F55430025B094C3}" Path="\registry\user\*avgeneral\crecentfiles\c?" Name="tditext" />
	<Registry Id="{4A417E7C-0B7F-6C60-1F55430025B094C4}" Path="\registry\user\*avgeneral\crecentfiles\c?" Name="sdi" />
	<Registry Id="{5A417E7C-1B7F-7C60-2F55430025B094C5}" Path="\registry\user\*avgeneral\crecentfiles\c??" Name="tditext" />
	<Registry Id="{6A417E7C-2B7F-8C60-3F55430025B094C6}" Path="\registry\user\*avgeneral\crecentfiles\c??" Name="sdi" />
	<Registry Id="{E8C59656-1FA6-9A02-FE3DB64A03CC54D1}" Path="\registry\user\*\software\author-itsoftware\author-it\?.?\recentfilelist" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{07F0398B-82BA-7187-19335DD70D9ECF00}" Path="\registry\user\*\software\ej-technologies\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{1DA0ED39-E696-D6ED-5456A6A9A557D29F}" Path="\registry\user\*\software\google\chrome\preferencemacs\systemprofile" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{5CEA0A73-03A3-5FB0-FBF606BCFAF3362B}" Path="\registry\user\*\software\google\chrome\preferencemacs\systemprofile\extensions.settings" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{0F333D42-DC36-309F-C7668A912FD83FB5}" Path="\registry\user\*\software\google\update\clientstate\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{1BFAF5D6-6BAE-57AD-DF667F46431F81AE}" Path="\registry\user\*\software\google\update\persistedpings\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{3C0C03BE-A88C-E719-58DAD0F03DA93AF7}" Path="\registry\user\*\software\javasoft\deploymentproperties" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{2DF1C5CC-EC2B-7D67-DC956045C2EC7521}" Path="\registry\user\*\software\microsoft\avalon.graphics\display?" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{BF59B041-2D0D-48EA-580449776C0009CA}" Path="\registry\user\*\software\microsoft\certselect" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{F24D608D-D28E-84FB-AE0977D600C2EEB6}" Path="\registry\user\*\software\microsoft\ctf\cuas\defaultcompositionwindow" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{BCD3F35B-44F9-C262-7E7D70BD3D0A838C}" Path="\registry\user\*\software\microsoft\edge\nativemessaginghosts\com.webex.meeting" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{6A2C8C95-C2E1-86AD-34A48EF62571F1B9}" Path="\registry\user\*\software\microsoft\internetexplorer\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{CE2AB388-6DFC-D4CF-C4C608DE5A537416}" Path="\registry\user\*\software\microsoft\onedrive\accounts\personal" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{364A26DF-A060-FA65-BB2CA70D57BEFBF9}" Path="\registry\user\*\software\microsoft\onedrive\installer\bits\presigninsettingsconfigjson" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{1362B951-2098-52D6-467438B821F90E14}" Path="\registry\user\*\software\microsoft\onedrive\installer\bits\updatexml" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7C2A6AF6-9E74-8380-AFD314EE58F7F0EB}" Path="\registry\user\*\software\microsoft\restartmanager\session0000" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{1F78F0D2-DADD-D4B7-2BA16F2B6999CCA0}" Path="\registry\user\*\software\microsoft\speech_onecore\isolated\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{868D5934-5523-FD9D-E2FC18A35E197C07}" Path="\registry\user\*\software\microsoft\sqmclient" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{539FF645-1C6A-074C-C19660757E8B8CF6}" Path="\registry\user\*\software\microsoft\terminalserverclient\defaultprinter" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{83A341A0-4D00-FC5C-C0C00D9B213A250B}" Path="\registry\user\*\software\microsoft\visualstudio\??.?\tasklist\taskproviders\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{BB218811-75DD-E309-D07917022AFA3A51}" Path="\registry\user\*\software\microsoft\visualstudio\remotesettings\devenv\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{3F55F898-E580-A81B-8BFD8955393DE6AD}" Path="\registry\user\*\software\microsoft\windows\currentversion\applicationassociationtoasts" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{D06D7B4D-770E-F6CD-72D17C3828BC0980}" Path="\registry\user\*\software\microsoft\windows\currentversion\contentdeliverymanager\creativeeventcache\subscribedcontent-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{ABBE3007-8CB2-A42B-E1AF09C25E805659}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\bannerstore\providerid\onedrive*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{9493CA7E-3A1D-4F8F-1CCC7E33E70936B1}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\discardable\postsetup\componentcategories*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{4EF67377-815A-CE01-BE588E3698D5C559}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\fileexts\.cys" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{78946328-4529-DBBA-C4887EA0B9C2AB7A}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\fileexts\.pdf\userchoice" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{5A5B4747-59FD-75FB-79F49CE9268E9F88}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\fileexts\ddecache\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7D5CE9B6-8E62-B65E-8C2FF3334D7ACE5F}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\mountpoints2\cpc\volume\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{4C50FB6C-50E0-01A4-AD8E88690937AC08}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\startpage" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FCD36F0D-3BA0-C731-47FAFDD6D0DB3F39}" Path="\registry\user\*\software\microsoft\windows\currentversion\shellextensions\cached" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{A620063E-1493-FCE4-19B231846F3BF589}" Path="\registry\user\*\software\microsoftoffice\*\access\internet\recenttemplates*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7867AE7D-AD49-1EB8-96928A1333C97987}" Path="\registry\user\*\software\microsoftoffice\*\access\usermru*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{CF002E82-B556-8D16-8A5C5271CFAD26C4}" Path="\registry\user\*\software\microsoftoffice\*\common\identity\identities\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{71340B1D-721B-BBE8-092B8C91206F3687}" Path="\registry\user\*\software\microsoftoffice\*\common\internet\webservicecache\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{FE306355-1269-C9C2-56D9986BD6537899}" Path="\registry\user\*\software\microsoftoffice\*\common\officestart\web\templates\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{7BD8213C-9142-0C28-C44D8B1B8153D25E}" Path="\registry\user\*\software\microsoftoffice\*\common\openfind\microsoftoutlook\settings\insertfile" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{791BE30A-4D80-A636-C81E9539ACCBB4E6}" Path="\registry\user\*\software\microsoftoffice\*\common\roaming\identities\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{DBDBE80C-CB67-E6CB-48F74C4712F107DB}" Path="\registry\user\*\software\microsoftoffice\*\common\servicesmanagercache\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{34AF0F3A-F648-671B-1658326404353F3A}" Path="\registry\user\*\software\microsoftoffice\*\lync\*\autodiscovery" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{8E45710D-84ED-0D0B-A723FAB5B35174C5}" Path="\registry\user\*\software\microsoftoffice\*\lync\*\buddylistoldnotifications" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{91663DFF-526D-8A57-1E7A537275E46B21}" Path="\registry\user\*\software\microsoftoffice\*\outlook\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{47631B6F-BEF6-DB73-FA4B672B103C9231}" Path="\registry\user\*\software\nt-ware\mom\ud\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{A621563F-4017-842A-8182017F81054A83}" Path="\registry\user\*\software\policies\microsoft\cryptography\autoenrollment" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{2C4D7A70-C998-1970-A8D1732DFE2D9661}" Path="\registry\user\*\software\policies\microsoft\windowsnt\terminalservices" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{80CA75B6-2487-8D7B-D7FA41F52C6D88EA}" Path="\registry\user\*\software\policies\microsoft\windows\controlpanel\desktop" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{C3E4926E-BB2B-ECB8-5EEF32CAE546C380}" Path="\registry\user\*\software\policies\microsoft\windows\currentversion\internet*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{55E7B928-EA64-3DFC-3286B88BA132E93B}" Path="\registry\user\*\software\sdl\passolo20*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{AEB8A4A3-E4C0-6875-F648DE279D9B24A5}" Path="\registry\user\*\cid\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{B307EB58-DBF1-456F-53F7CD6D7478E362}" Path="\registry\user\*\clsid\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{EF172842-9B9C-B626-2A49E721610422A8}" Path="\registry\user\*\interface\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{AA442DAD-5041-C621-3E754319E45E36E6}" Path="\registry\user\*\localsettings\mrtcache\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{9F2A4C47-5CF3-76C7-02EB884CAF3D368A}" Path="\registry\user\*\localsettings\software\microsoft\windows\shell\bags\*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{ED6C10B3-515F-E896-9EAD329936DF5F17}" Path="\registry\user\*\localsettings\software\microsoft\windows\shell\muicache" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{042EC7C1-7A1B-83AE-8CBF00BD0E81C3A9}" Path="\registry\user\*\wow6432node\interface\{????????-*" Name="%kl_undef%" Value="%kl_undef%" />
	<Registry Id="{6ACBA828-D103-BE53-BF8D7B2B479E2037}" Name="https" Value="0?000000">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</Registry>
	<Registry Id="{642E32FA-B5B3-E38D-63B397D0C60586AA}" Name="https" Value="0?000000">
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs -p -s gpsvc" />
	</Registry>
	<Registry Id="{C6FB4221-62F7-39C8-C5227C14F453A1B0}" Name="http" Value="0?000000">
		<Process CmdLine="c:\windows\system32\svchost.exe -k gpsvcgroup" />
	</Registry>
	<Registry Id="{2B3C0A56-AC2A-C022-1CFDDEB8A76AD58D}" Name="http" Value="0?000000">
		<Process CmdLine="c:\windows\system32\svchost.exe -k netsvcs -p -s gpsvc" />
	</Registry>
	<Registry Id="{A1FE5417-29AC-683C-04CBEDC2CF9E9B2B}" Name="cacheprefix" Value="cookie:" />
	<Registry Id="{9EFA984A-5E51-93D6-8ABCD6EF0666AFDF}" Name="cacheprefix" Value="visited:" />
	<Registry Id="{0A353715-1F05-BD8A-53A873AB9A0E8105}" Name="pubinfo" Value="ae2c00000000000000000000" />
	<Registry Id="{4DB56F4F-A5A1-72D9-EB93F7E64F8CAC12}" Name="eknofetch" Value="00000000" />
	<Registry Id="{376D0EC2-0149-FB71-749147735027B251}" Name="pcr7bindingstate" Value="00000000" />
	<Registry Id="{DC76A019-E46F-937F-C23883010F295A2D}" Name="osddisable" Value="00000000" />
	<Registry Id="{2F5888B2-1FE2-40E2-A08C3BF15D6D66EB}" Name="criticalextensions" Value="?.?*" />
	<Registry Id="{5C386111-2D21-7C87-51A51FED5D2AD63C}" Name="notshownreason" Value="notwithinexpiryperiod" />
	<Registry Id="{11F9EA08-E9FC-CFE7-A6F613349BC06372}" Value="{00000000-0000-0000-0000-000000000000}" />
	<Registry Id="{CAA3E5D9-7373-24C7-9F77D088B1925369}" Name="runtimemissing" Value="??000000" />
	<Registry Id="{37B3AB1B-4C57-1E18-CDAB84172CE3F6EA}" Name="auditlevel" Value="??000000" />
	<Registry Id="{BF45F49D-5051-09FB-5407F122DF57F253}" Name="slotperrow" Value="??000000" />
	<Registry Id="{76F2E19F-BEDD-1E5F-004D6AEDAEDA5D25}" Name="needtopurge" Value="??000000" />
	<Registry Id="{AB1BE26D-35B2-8465-9A6D3277DAEDA590}" Name="metricsreportingenabled" Value="??000000" />
	<Registry Id="{0B57F2E9-209B-9F10-FCD4B4FB651EBA0C}" Name="security" Value="*571541550d4b167d825a8a49070200000105*" />
	<Registry Id="{6578ED91-3BB9-0EA0-2E1E9425F32C5102}" Name="security" Value="*571541550d4b167d825a8a49306d00000105*" />
	<Registry Id="{7B3D137F-FC9F-8316-16F3403AA25DE4C4}" Name="sniffedfoldertype" Value="documents" />
	<Registry Id="{6B878098-C276-1979-B717200FDC480241}" Name="??-??" Value="??000000" />
	<Registry Id="{354FF680-2FAA-5BAA-3A59E4512363DFB2}" Name="tokenleakdetectdelaysecs" Value="0A000000" />
	<Registry Id="{37325A64-D4E2-69E2-528C3ACF8CC04100}" Name="sort" Value="*30f125b7ef471a10a5f102608c9eebac0a00000001000000" />
	<Registry Id="{6C70A9B2-F5E6-0BEF-A7D96ABF46A118EF}" Name="subscriptioncontext" Value="sc-mode*" />
	<Registry Id="{ABA53753-5DDB-A352-3EEB8D9E0FD2E809}" Name="lastuseddatabase" Value="c:\windows\security\database\secedit.sdb" />
	<Registry Id="{B2BDDF29-A072-6FB3-3F7A90BE158775AE}" Name="????????" Value="??000000*0000">
		<Process Path="*\office*\outlook.exe" />
	</Registry>
	<Registry Id="{AC348DCC-EA65-AD34-BA2E19984966EE06}" Name="common::*" Value="iconsonly*" />
	<Registry Id="{02150BE6-97EB-5094-3450801BCDFBE6C9}" Name="errorcontrol" Value="01000000" />
	<Registry Id="{7FC261CD-E3C0-2A12-33B28D232C452FE3}" Name="description" Value="this zone contains websites*" />
	<Registry Id="{7DEF346C-7B0E-7209-7CF8F5C186152391}" Name="icon" Value="inetcpl.cpl*" />
	<Registry Id="{EE0D504E-6D36-11EA-6B26E35CCF969F8F}" Name="settingsextensionappsnapshot" Value="0000000000000000" />
	<Registry Id="{BE1B2C31-E932-E7BE-1DABE4DBE81C7623}" Name="cacheprefix" Value="%kl_undef%" />
	<Registry Id="{73890EE2-6F76-3BB1-0C2DC9BE01766018}" Name="cacheready" Value="%kl_undef%" />
	<Registry Id="{679F762E-597E-AFE1-E74C901380095EC8}" Name="canon*" Value="%kl_undef%" />
	<Registry Id="{1CBE38FD-5456-8D8B-6F2A510385132C17}" Name="checkedoutedition" Value="%kl_undef%" />
	<Registry Id="{C9983C81-B227-6D06-02018E0EBA684ACD}" Name="clientappid" Value="%kl_undef%" />
	<Registry Id="{960A5885-8364-25AB-AD1ECF22680308C1}" Name="comment" Value="%kl_undef%" />
	<Registry Id="{63474F69-DE7F-711F-7CE771224C8B5922}" Name="comments" Value="%kl_undef%" />
	<Registry Id="{33C3D613-8ED7-1650-51E4836628B9FBC7}" Name="correlationvector" Value="%kl_undef%" />
	<Registry Id="{2E598A67-374C-751E-850FD4B6FCE720C5}" Name="cortanacapabilities" Value="%kl_undef%" />
	<Registry Id="{12DAD2EE-FEF8-A0D2-F9299EE651666CBF}" Name="crashdetectionkey" Value="%kl_undef%" />
	<Registry Id="{977462DD-62F0-9E15-B8C2746D09DEAB3C}" Name="datatype" Value="%kl_undef%" />
	<Registry Id="{B18BA9D2-48D4-DBDF-E337033F1BD1075C}" Name="delta" Value="%kl_undef%" />
	<Registry Id="{3D9E6359-73EE-76BA-6B92CF16C9235E81}" Name="desktopbootguid" Value="%kl_undef%" />
	<Registry Id="{7B9AD138-58EE-9C46-E63EE5EE9C1E8823}" Name="device" Value="%kl_undef%" />
	<Registry Id="{B55D8BE9-4BFF-6DB2-04CCD71A726478B3}" Name="diff????" Value="%kl_undef%" />
	<Registry Id="{3313AADE-2380-7FD1-394F650B12116427}" Name="disconnectedlibrary" Value="%kl_undef%" />
	<Registry Id="{3841CDF3-8A35-F58A-C80F0F910C82933C}" Name="diskencryptionfeature" Value="%kl_undef%" />
	<Registry Id="{57AA4584-EF4F-9BCC-55B5481FF1CE9472}" Name="dlgcaption" Value="%kl_undef%" />
	<Registry Id="{5D305246-6707-D5B2-38DC93412F97385C}" Name="dpe_name" Value="%kl_undef%" />
	<Registry Id="{7C16C68A-762F-32C5-24EBE5FBAF64AD0B}" Name="dpe_rulevalue" Value="%kl_undef%" />
	<Registry Id="{40A4E0B5-F6E7-F6DA-51A75A561EB693ED}" Name="driver" Value="%kl_undef%" />
	<Registry Id="{3EF71039-F685-7696-F62554BB9467E8F4}" Name="editor" Value="%kl_undef%" />
	<Registry Id="{A284310C-1CEF-07B2-98B0FC45E98630A2}" Name="eknonce" Value="%kl_undef%" />
	<Registry Id="{5F542798-3CF9-D694-044DB1BDD76BACD3}" Name="ekpub" Value="%kl_undef%" />
	<Registry Id="{4877FF39-401A-44AB-DCE30AD34D7A72A7}" Name="email" Value="%kl_undef%" />
	<Registry Id="{69A90DB6-5F29-AF75-4895174A9B8ADC9D}" Name="excel.sheet.*" Value="%kl_undef%" />
	<Registry Id="{8C33EE25-9F2D-58E9-45FAE12A66B15347}" Name="fax (redirected*" Value="%kl_undef%" />
	<Registry Id="{B4A2AA11-B4E9-521E-306B5D7141A5C18C}" Name="guid" Value="%kl_undef%" />
	<Registry Id="{BFB0B9D9-0E11-43FD-095AFB0204E75818}" Name="help file" Value="%kl_undef%" />
	<Registry Id="{2BEAE53F-5C52-34E5-98EFBE1DE6A0637E}" Name="hwnd64fororphanednoticon" Value="%kl_undef%" />
	<Registry Id="{39E3E281-C8BF-A086-AB3ED96C73D23E38}" Name="microsoft print*" Value="%kl_undef%" />
	<Registry Id="{707BFFAF-3C54-FEE8-355EBABB637765F4}" Name="microsoft xps*" Value="%kl_undef%" />
	<Registry Id="{794B728D-C487-CF9A-ED4C3CF8B65AF219}" Name="missedcachefileinfo" Value="%kl_undef%" />
	<Registry Id="{C722865A-7312-A04C-81B6999683A20890}" Name="monitor" Value="%kl_undef%" />
	<Registry Id="{5B0F5C43-9A73-DB93-D8F30FED56CAC4A9}" Name="mttt" Value="%kl_undef%" />
	<Registry Id="{32F7A85B-5783-9259-7BE4184580751F04}" Name="needtopurge" Value="%kl_undef%" />
	<Registry Id="{892E14F1-7A10-3860-4CF1D4FF9236E87B}" Name="networkname" Value="%kl_undef%" />
	<Registry Id="{302EF545-8E25-B44D-5462163FD555F032}" Name="o15alerttypes" Value="%kl_undef%" />
	<Registry Id="{07A7C310-4300-7476-6FB84559CB46B90D}" Name="o15restartssincealerts" Value="%kl_undef%" />
	<Registry Id="{7DE3FECD-6077-44CF-238B04927CC4B49E}" Name="oducheck*" Value="%kl_undef%" />
	<Registry Id="{C97CCFA3-63B3-1A41-70984D97BA3232FD}" Name="oem url" Value="%kl_undef%" />
	<Registry Id="{0AA4982E-4292-A56D-638EBCD993D05F7B}" Name="onenote for windows*" Value="%kl_undef%" />
	<Registry Id="{C049C77C-D02C-70F8-2D96D49F2619F1DB}" Name="pngfile" Value="%kl_undef%" />
	<Registry Id="{6392CE0F-C45E-0387-D93EE3F958CCB896}" Name="10??" Value="%kl_undef%" />
	<Registry Id="{10FE2CE6-F801-D72D-43B1997A9F335C8B}" Name="12??" Value="%kl_undef%" />
	<Registry Id="{0CD8713D-52D8-280D-F4CB15F24ECDD0CD}" Name="14??" Value="%kl_undef%" />
	<Registry Id="{6A168F70-1DED-2F63-1922C067BC60B483}" Name="16??" Value="%kl_undef%" />
	<Registry Id="{A010B1D4-5896-F7C1-0F3D90D43307051B}" Name="18??" Value="%kl_undef%" />
	<Registry Id="{6F126AB5-6BCD-9717-E7B8E5EDC613F5B9}" Name="1a??" Value="%kl_undef%" />
	<Registry Id="{D8963DAE-67B8-E3F9-45561EEF785F19AE}" Name="20??" Value="%kl_undef%" />
	<Registry Id="{0EB98182-8690-3795-0C776F018A51279E}" Name="13????????????????" Value="%kl_undef%" />
	<Registry Id="{1656FE23-8129-B81D-B13AA882814B715D}" Name="backgroundhistorypath?" Value="%kl_undef%" />
	<Registry Id="{8698AB59-1409-3F3C-21B8550F178F55D6}" Name="c:\config.msi\*.rbs*" Value="%kl_undef%" />
	<Registry Id="{04CD85D7-1556-41FA-AB3ED433C6E294BB}" Name="c:\windows\installer\*.msp" Value="%kl_undef%" />
	<Registry Id="{448B1630-FC05-FBBE-D57D9170BD2731EE}" Name="powerpoint.show.*" Value="%kl_undef%" />
	<Registry Id="{E3DF0ECF-657B-BFC2-6E1D4B1B06384E83}" Name="print processor" Value="%kl_undef%" />
	<Registry Id="{4E29A258-A4A2-A501-0F585DD3834D9264}" Name="profile" Value="%kl_undef%" />
	<Registry Id="{60811E96-93A4-6F08-931F5FD22011DD50}" Name="refreshafter" Value="%kl_undef%" />
	<Registry Id="{7475BD41-52A3-ACBC-429F3CB0840A6E2E}" Name="resourceuri" Value="%kl_undef%" />
	<Registry Id="{CBC346BF-5D04-839C-71791B9DB40B65C4}" Name="secureconfiguration" Value="%kl_undef%" />
	<Registry Id="{FD08BD69-E910-BCF9-5C648B3C2AB232C1}" Name="send to onenote*" Value="%kl_undef%" />
	<Registry Id="{CAB189FC-284D-1352-37064FF22D9729E0}" Name="socketaddresslist" Value="%kl_undef%" />
	<Registry Id="{E27387F4-A94A-44EB-0F6873B5667649C0}" Name="statuscodes" Value="%kl_undef%" />
	<Registry Id="{6A2376EE-F674-AAAC-90CB16DE5AFC57F3}" Name="vendorsetup" Value="%kl_undef%" />
	<Registry Id="{542BB84A-7A29-4866-34146147918E1A89}" Name="word.document.*" Value="%kl_undef%" />

<!-- ############################################################################################################### -->
<!-- Part 4: start 2021-02-08T15:36:00.000Z-1612787774 -->
	<Registry Id="{321AC8AF-AA22-5188-39A787A75CBD032B}" Path="\REGISTRY\USER\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{????????-*" />
	<Registry Id="{CA761551-407E-E98C-DB9B8BE89EDBEE37}" Path="\REGISTRY\USER\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\??-??-??-*" />
	<Registry Id="{CEDEA79A-1FAE-5C37-8CBA080C70272BD9}" Path="\REGISTRY\USER\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\?.?\Cache\History" />
	<Registry Id="{3180B682-C9D4-95E3-F12BADF4619A0C93}" Path="\REGISTRY\USER\*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\?.?\Cache\Cookies" />
	<Registry Id="{9A2F635F-E002-CF37-35E4A00C08CCC926}" Path="\REGISTRY\USER\*\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\DirectInput\VID_*" />
<!-- Part 4: end 2021-02-08T15:36:00.000Z-1612787774 -->
	
<!-- ############################################################################################################### -->
<!-- Part 5: start 2021-03-26T21:30:00.000Z-1616794227 -->
	<Registry Id="{383C2869-D9B3-6287-BE6D5B2771250B03}" Path="\registry\user\*\software\thinprint\tpautoconnect" Name="defaultprinter">
		<Process>
			<Signature Subject="*ThinPrint*" />
		</Process>
	</Registry>
	<Registry Id="{808B0648-ED4F-F75A-7FE12D099B3619CA}" Path="\registry\machine\security\cache" Name="nl$?">
		<Process Path="*lsass.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{468CEC78-F6D2-B8E8-83D15AFE2046BA54}" Path="\registry\machine\software\microsoft\windows nt\currentversion\perflib" Name="updating">
		<Process Path="*wmiadap.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{BC5C237A-1087-4CBB-6C3872E05DE575F2}" Path="\registry\machine\software\microsoft\windows nt\currentversion\perflib" Name="last help">
		<Process Path="*wmiadap.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F54E4ADF-1425-8FAF-538060E28B394823}" Path="\registry\machine\system\controlset001\services\wmiaprpl\performance" Name="first help">
		<Process Path="*wmiadap.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{AB620F26-48AC-728F-4A1D01B3666DA9DF}" Path="\registry\machine\system\controlset001\services\wmiaprpl\performance" Name="last help">
		<Process Path="*wmiadap.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{AB9E674D-4AB4-5DBD-D5F921D80D89234D}" Path="\registry\machine\system\controlset001\services\wmiaprpl\performance" Name="object list">
		<Process Path="*wmiadap.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{2B15F673-7738-30B8-4C18262B5B91BBD6}" Path="\registry\machine\software\microsoft\wbem\wdm\dredge" Name="%kl_undef%">
		<Process Path="*wmiadap.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{43AC36CB-F732-D5F4-C787EF1B0B36A24C}" Path="\registry\machine\software\microsoft\windows\currentversion\appreadiness\*\queue\microsoft.*" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B5FB40F7-85EB-EAE1-4EA6CB6A5D590E1D}" Path="\registry\machine\software\microsoft\windows\currentversion\appreadiness\*\queue\microsoft.*" Name="operation">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{AD0BE99D-BF87-0521-086A280CE8DB0374}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="phase">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D7780B31-C83E-E4A6-D6C6E8A736D79264}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="servererrorcode">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F810ACB5-4C8B-0B3E-7698B9E2363258D7}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="registrationtype">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3112119C-78FC-67B2-E38DD6CFD898CA8C}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="servererrorsubcode">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3E34E51F-B743-185D-9A3D533F42575E65}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="requestid">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D19AB28D-CB40-87D6-49507BD004CA9E1D}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="servermessage">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{33581A4B-E004-0F5B-26FD5BE5B302643C}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="serveroperation">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B4E37A0A-6364-E850-6630B4DDBFFCE8AD}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="httpstatus">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1A133D84-EDB9-D1C7-BC41671A90ED4889}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="lowtime">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6718D70D-4C9B-090C-826B5D7BF3AF1A14}" Path="\registry\machine\system\controlset001\control\clouddomainjoin\diagnostics" Name="hightime">
		<Process Path="*dsregcmd.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{DDC9DFC2-3B63-40DC-9667DD9BF55C29A5}" Path="\registry\user\*\control panel\desktop" Name="win8dpiscaling">
		<Process Path="*winlogon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{0CFD8B22-1506-4BF8-44779604E94B0282}" Path="\registry\user\*\control panel\desktop" Name="userpreferencesmask">
		<Process Path="*winlogon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B8166662-E1EB-4BDF-4D05A50135261815}" Path="\registry\user\*\control panel\desktop" Name="logpixels">
		<Process Path="*winlogon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B0D69188-410B-A749-CA80E84E5BE68F5A}" Path="\registry\user\*\software\microsoft\windows\currentversion\applicationassociationtoasts" Name="app*" Value="00000000">
		<Process Path="*explorer.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{AADBE175-FA5F-0699-FBD514DF836C290A}" Path="\registry\user\*\software\microsoft\windows\currentversion\applicationassociationtoasts" Name="app*" Value="0000000000000000">
		<Process Path="*explorer.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{29676639-7D41-F171-DF7C3AF9988E08EF}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\microsoft.*" Name="setting">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6D731A97-8063-1BC4-E5AC9199E590C410}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\microsoft.*" Name="apptype">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6B6CDD5D-372B-6C8C-8BD50A7983C84FB7}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\microsoft.*" Name="wnsid">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{374107D8-3B25-D3EA-D7F6B9501E61B797}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\microsoft.*" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1A11EFB6-FD9B-AE9D-09E76EA016BCB971}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\windows.*" Name="setting">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{5E3CF15E-78C2-CB60-FEC7D283284EA9CC}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\windows.*" Name="apptype">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A78DCB84-3A19-CD29-CBC7856161C3CA41}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\windows.*" Name="wnsid">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{771904EC-529B-56E0-76018782E8F0F9EA}" Path="\registry\user\*\software\microsoft\windows\currentversion\pushnotifications\backup\windows.*" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7DE9E28D-337F-DB2C-938F04975BAACE51}" Path="\registry\user\*\local settings\software\microsoft\windows\shell\bags\1\shell" Name="sniffedfoldertype">
		<Process Path="*vsinotepad.exe">
			<VersionInfo FileDescription="VSINotepad" />
		</Process>
	</Registry>
	<Registry Id="{1BED18C9-29A7-F80D-9C15C8B47A84F304}" Path="\registry\user\*\software\microsoft\windows\currentversion\explorer\mountpoints2\##lavsicontroller#vsi_share#_vsi_content" Name="_labelfromdesktopini">
		<Process Path="*vsinotepad.exe">
			<VersionInfo FileDescription="VSINotepad" />
		</Process>
	</Registry>
	<Registry Id="{8C0AF22B-E236-23DC-E02F7C535EA348A0}" Path="\registry\user\*\local settings\software\microsoft\windows\shell\bags\1\comdlg\{????????-????-*" Name="sort">
		<Process Path="*vsinotepad.exe">
			<VersionInfo FileDescription="VSINotepad" />
		</Process>
	</Registry>
	<Registry Id="{922843E1-CBFA-4B4D-78471A63EBC77712}" Path="\registry\user\*\local settings\software\microsoft\windows\shell\bags\1\comdlg\{????????-????-*" Name="colinfo">
		<Process Path="*vsinotepad.exe">
			<VersionInfo FileDescription="VSINotepad" />
		</Process>
	</Registry>
	<Registry Id="{D449F1F4-5C66-85E4-26B62A25FABF49F7}" Path="\registry\user\*\local settings\software\microsoft\windows\shell\bags\1\comdlg\{????????-????-*" Name="groupbykey*">
		<Process Path="*vsinotepad.exe">
			<VersionInfo FileDescription="VSINotepad" />
		</Process>
	</Registry>
	<Registry Id="{86A9D53C-7C20-0E48-5B8BFDCA87A013AD}" Path="\registry\user\*avgeneral\ctoolbars*" Name="%kl_undef%">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{A6601C2B-57BA-9A5B-B79F20E431690F50}" Path="\registry\user\*avgeneral" Name="bappinitialized">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{04CD9F98-8F8A-BD12-94386231D981FDAA}" Path="\registry\user\*avgeneral" Name="bconvtruetypetotype1">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{4C343AA7-1BF5-04BD-8850FE82DACE6B34}" Path="\registry\user\*avgeneral" Name="bforcehostcollation">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{2A280691-D394-7E9E-783211FA7C22FD63}" Path="\registry\user\*avgeneral" Name="bpreserveprimaries?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{E08C95E6-E44D-F01E-5F826E17A2C253C3}" Path="\registry\user\*avgeneral" Name="bprint?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{2D14C425-7296-D915-FF76E75137B1E6C9}" Path="\registry\user\*avgeneral" Name="bpromotegraytok">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{6274C09C-5F9D-64B4-FAC11E76FAFF4556}" Path="\registry\user\*avgeneral" Name="breadersho?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{7504AFBE-E576-5A39-42CECD47A04B3000}" Path="\registry\user\*avgeneral" Name="btruetypeast2">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{5CE74304-A739-645F-AA2108450D4BDF69}" Path="\registry\user\*avgeneral" Name="busecustompaper">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{7772CD1A-3138-6062-276228490A1B37F6}" Path="\registry\user\*avgeneral" Name="ipaires">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{F38E33AA-7753-CB02-BE2C3CC89D15EE9D}" Path="\registry\user\*avgeneral" Name="iprintbooklet?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{7BCE3AA9-C390-732E-14728C1D4683A413}" Path="\registry\user\*avgeneral" Name="iprintnup?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{009D0373-7070-7799-E2BAF0785654D4E4}" Path="\registry\user\*avgeneral" Name="iprintwhat">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{2B17FFE8-1F24-5B91-BDE265A84B65E217}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="%kl_undef%">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{F83100A0-90E4-5116-4AC8F6BA452013EE}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="bavdoc?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{A6652ECD-49E1-4DE0-5B0A47CF9E0C8814}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="bbringtofront">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{D9FDFF3D-0803-5BBA-4B3EEF64C406CB83}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="bpageviewstartthread">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{79042D65-0832-B2F7-830FFCF85530445D}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="bshowingpagegaps">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{005554C6-B3BB-342B-16C8C38DA22869FD}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="bwindowmaximized">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{FAAE6625-8895-2062-4E856CA23DA956DE}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="dpageviewzoom">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{18B757B6-3EA1-A215-1A72DBF7036B09AE}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="iavdocview?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{935C19B9-FC50-09C8-2817D776559674CA}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="ioverview?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{1332AAE0-60C4-2BB6-1AC223700A6536CB}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="ipageview?*">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{A9D7C86A-96B2-9106-B18ABE287E714630}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="itime">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{C59B1466-2FDE-80C4-5BC4C0C99DF0B286}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="xid">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{3EBBFA9F-760A-02FA-F8D3B480A3506F54}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="xpageviewbead">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{937C8977-1537-E9C4-C63C2A219D9BA8DD}" Path="\registry\user\*rememberedviews\cnocategoryfiles*" Name="xwindowframe">
		<Process>
			<Signature Subject="*Adobe*" />
			<VersionInfo OrignFileName="*" ProductName="*Reader*" />
		</Process>
	</Registry>
	<Registry Id="{FA5EACA5-3235-A7D2-42163905C0196339}" Path="\registry\machine\software\classes\wow6432node\interface\{????????-????-????-????-????????????}*" Name="%kl_undef%">
		<Process>
			<Signature Subject="*Microsoft*" />
			<VersionInfo OrignFileName="*" ProductName="*Office*" />
		</Process>
	</Registry>
	<Registry Id="{9E1EA562-2387-31CF-34E45E453EBE7A98}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer" Name="slowcontextmenuentries">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{E7BFB4CE-A578-E93C-53F53A61F7C74982}" Path="\registry\user\*software\compsoft\doro" Name="subject">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{DDAA2A2C-24E9-61E6-1D4919768283C811}" Path="\registry\user\*software\compsoft\doro" Name="title">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{FADF6524-0911-7821-4DC2E4D73E0CEF6F}" Path="\registry\user\*software\compsoft\doro" Name="masterpassword">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{D7784B23-73E6-AAB5-F4F7692B1A323A26}" Path="\registry\user\*software\compsoft\doro" Name="keywords">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{C8213047-8341-491A-4201DE3F636BF052}" Path="\registry\user\*software\compsoft\doro" Name="userpassword">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{C81B70C1-E755-8278-E1B24670D54F92EC}" Path="\registry\user\*software\compsoft\doro" Name="producer">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{E1C5C342-FD22-F12A-EB95001473A24810}" Path="\registry\user\*software\compsoft\doro" Name="author">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{935020A7-53BD-1180-F0AE2FC201F42FC1}" Path="\registry\user\*software\compsoft\doro" Name="flags">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{B7A66921-7D81-1C66-577D31A6C7FD1EB1}" Path="\registry\user\*software\compsoft\doro" Name="path">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{EEDB78C8-4559-2286-39D01143E929E917}" Path="\registry\user\*software\compsoft\doro" Name="%kl_undef%">
		<Process>
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{1C9AFD27-8F4F-E1CA-ACC662E1900F4E95}" Path="\registry\user\*software\compsoft\doro\mrupath">
		<Process Path="*\doro.exe">
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{29D4BBBC-E217-657B-A10EEA4E611AE19F}" Path="\registry\user\*software\microsoft\windows\currentversion\explorer\fileexts\.pdf\openwithprogids" Name="acroexch.document.*">
		<Process Path="*\doro.exe">
			<VersionInfo OrignFileName="*" ProductName="*CompSoft*" />
		</Process>
	</Registry>
	<Registry Id="{A6A499BB-29F4-331C-AD8E6841DB99BDC9}" Path="\registry\user\*software\compsoft\doro" Name="flags">
		<Process Path="*\vsi.exe" />
	</Registry>
	<Registry Id="{320CAD29-1DB3-E481-0B2A8AFC693DB2FE}" Path="\registry\user\*software\compsoft\doro" Name="%kl_undef%">
		<Process Path="*\vsi.exe" />
	</Registry>
	<Registry Id="{A6F04FB6-B087-7AC9-F9C51C376C0717BC}" Path="\registry\machine\software\microsoft\windows\currentversion\wosc\client\persistent\clientstate\wosc" Name="etag">
		<Process Path="*taskhostw.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{4E2135B1-3050-38E2-35EE63DC694C7C2E}" Path="\registry\user\*printers\defaults\{????????-????-????-????-????????????}" Name="%kl_undef%">
		<Process Path="*spoolsv.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F7FAD971-0D98-3A7D-A5028B190F602147}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows" Name="ismruestablished">
		<Process Path="*spoolsv.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1947CBE5-EE0A-3BF8-2102D11516B742FC}" Path="\registry\user\*software\microsoft\windows nt\currentversion\windows" Name="device">
		<Process Path="*spoolsv.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F44CB203-492C-7BF1-313421CF3082B208}" Path="\registry\machine\software\microsoft\windows nt\currentversion\softwareprotectionplatform" Name="servicesessionid">
		<Process Path="*sppsvc.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1BDE6AB4-8B37-82D8-DDB774507F8D4E51}" Path="\registry\machine\software\microsoft\windows\currentversion\census" Name="returncode">
		<Process Path="*devicecensus.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{47217D0B-07AA-30CA-4B059964AF4B89F9}" Path="\registry\machine\software\microsoft\windows\currentversion\waasassessment\cache" Name="*?assessment">
		<Process Path="*devicecensus.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{4F10254F-2C72-5534-AAFE707C8F9613E0}" Path="\registry\machine\software\microsoft\windows\currentversion\waasassessment\cache" Name="uptodate?*">
		<Process Path="*devicecensus.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{321C6259-CE29-6A8C-E499EFCAE1A42939}" Path="\registry\machine\software\microsoft\windows\currentversion\waasassessment\cache" Name="releaseinfotime">
		<Process Path="*devicecensus.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
<!-- Part 5: end 2021-03-26T21:30:00.000Z-1616794227 -->

<!-- ############################################################################################################### -->
<!-- Part 6: start 2021-06-28T23:48:00.000Z-1624924098 -->
	<Registry Id="{94135A62-3B2B-EA43-DB5A1ED3807D2A61}" Name="syntpenhservicejobsdone">
		<Process Path="C:\WINDOWS\System32\SynTPEnhService.exe">
			<VersionInfo FileDescription="*Synaptics Pointing Enhance Service" OrignFileName="*" ProductName="Synaptics Pointing Device Driver" />
		</Process>
	</Registry>
	<Registry Id="{D266CC1F-34F5-671C-0B8940229CC33E2E}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy*" Name="????????-????-????-????-????????????" Value="{????????-????-????-????-????????????}">
		<Process CmdLine="*svchost.exe -k GPSvcGroup" UserSid="S-1-5-18" />
	</Registry>
	<Registry Id="{7DE7E519-96A1-A754-47B041AA48797CC8}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy*" Value="\\m?g?z??go??s?\sysvol\m?g?z??go???a\policies*">
		<Process CmdLine="*svchost.exe -k GPSvcGroup" UserSid="S-1-5-18">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{586EDD88-8CF9-9734-DD561153F3818588}" Path="\registry\machine\software\policies\microsoft\windows nt\printers\pushedprinterconnectionstore*">
		<Process Path="*system32\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D39EE447-A80B-6851-DED3FF04ABCE7255}" Path="\registry\machine\system\controlset001\control\timezoneinformation">
		<Process Path="*system32\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A03AD031-E235-8377-585799259BAD715B}" Path="\registry\user\s-1-5-19\software\classes\local settings\muicache*">
		<Process Path="*system32\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{AB54833C-AD3B-AC5D-7E619484C36DBFED}" Name="firstcallofthedaytime">
		<Process Path="*system32\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1DDEE084-187F-E057-E1356217D2CDB750}" Name="lastupdatetime">
		<Process Path="*system32\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A23AD39B-5EBF-CA74-164F3B5EDA68DCCB}" Name="firstdatacollectiondone">
		<Process>
			<Signature Subject="Hewlett Packard*" />
		</Process>
	</Registry>
	<Registry Id="{B7CADC5E-BD5D-108E-51C9F7FBAE96D24D}" Path="\registry\machine\system\hpams*">
		<Process>
			<Signature Subject="Hewlett Packard*" />
		</Process>
	</Registry>
	<Registry Id="{D365D042-EB08-E71D-42E1258CC0FFF729}" Path="\registry\machine\system\controlset001\services\sma\mibstore\c*">
		<Process>
			<Signature Subject="Hewlett Packard*" />
		</Process>
	</Registry>
	<Registry Id="{9763E0D0-CE57-C05C-29B969F429C79177}" Name="criticalextensions" Value="?.?.*">
		<Process Path="C:\Windows\System32\taskhostw.exe" />
	</Registry>
	<Registry Id="{416D14F8-1D8A-5B3E-5A5467989F05AD0D}" Name="timestamp">
		<Process Path="C:\Windows\System32\taskhostw.exe" UserSid="S-1-5-18" />
	</Registry>
	<Registry Id="{61E15C91-6D6F-3749-74B87605C97A262D}" Name="timestampafter">
		<Process Path="C:\Windows\System32\taskhostw.exe" UserSid="S-1-5-18" />
	</Registry>
	<Registry Id="{11D748C6-20DD-9ABB-450DB6416F6196F5}" Name="security" Value="100049c*">
		<Process Path="C:\Windows\System32\taskhostw.exe" UserSid="S-1-5-18" />
	</Registry>
<!-- Part 6: end 2021-06-28T23:48:00.000Z-1624924098 -->

<!-- ############################################################################################################### -->
<!-- Part 7: start 2021-06-29T14:09:00.000Z-1624975772 -->
	<Registry Id="{DCCA1ACF-3FC4-8D1C-B6F52CC11E8FCB22}" Name="LstColumns">
		<Process Path="*SAP\FrontEnd\SapGui\SapGuiServer.exe">
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
	<Registry Id="{726B263C-C42C-03CC-5A353878AD857FD2}" Name="dyncolumns">
		<Process Path="*SAP\FrontEnd\SapGui\SapGuiServer.exe">
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
	<Registry Id="{1B0B7524-F5DF-D64D-3F9C510C8E587248}" Name="dynrows">
		<Process Path="*SAP\FrontEnd\SapGui\SapGuiServer.exe">
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
	<Registry Id="{AB388C18-FCE4-DD5C-3C324FDA3F5D1887}" Name="lstrows">
		<Process Path="*SAP\FrontEnd\SapGui\SapGuiServer.exe">
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
	<Registry Id="{655430DE-D2C5-539B-1F82673BDB98F425}" Path="*software\sap\saplogon\landscapefilesinuse_*">
		<Process Path="*SAP\FrontEnd\SapGui\SapGuiServer.exe">
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
	<Registry Id="{DB36C177-B801-E16E-C2C586731EFD6864}" Path="\registry\machine\software\microsoft\windows\currentversion\rempl\settings">
		<Process Path="*\sedlauncher.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A087B1B8-7802-7E38-C35E14948CF1F843}" Name="processcpuuse">
		<Process Path="*\firedaemon.exe">
			<Signature Subject="*FireDaemon*" />
		</Process>
	</Registry>
<!-- Part 7: end 2021-06-29T14:09:00.000Z-1624975772 -->


<!-- ############################################################################################################### -->
<!-- Part 8: start 2021-07-07T15:31:00.000Z-1625844664 -->
	<Registry Id="{1F0489D1-AD60-06C8-9A3382F78F0C3998}" Path="*software\policies\microsoft\edge*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{6A2A083A-0D74-784A-3CA9134A0E141963}" Path="\registry\machine\system\controlset001\services\wbiosrvc\*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{50253358-A6AB-087A-A3B34875D9985A3C}" Path="*software\policies\emc\offlineaccess\1.0*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{CC550416-19C1-D070-03C300E900E1C4D5}" Path="*software\policies\microsoft\windows\currentversion\internet settings\zonemap*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{598B4D87-89F7-5FF2-D96A85C19EEE56D2}" Path="\registry\machine\software\policies\microsoft\windows\settingsync">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{D96AF76F-7CE4-B371-9CAFCE4D0571198A}" Path="\registry\machine\software\policies\microsoft\internet explorer*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{AE31FCD9-D0CD-D2F0-F5F656A4FD3790DA}" Path="*software\policies\microsoft\office*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{CEF187C4-A4C2-3834-AA90B12B0D63A905}" Path="\registry\machine\software\policies\microsoft\power\powersettings*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{4C3CCF99-BC70-C456-81DA4DEC98922E35}" Path="*control panel\cursors*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{3629C920-5134-5BB3-9B6E438AED7BBC3E}" Path="*software\policies\microsoft\windowsstore*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{2BAD72EE-CD9B-1D85-1C231292BD66D592}" Path="\registry\machine\software\microsoft\windows\currentversion\appmodel\staterepository\cache*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{ABA1E222-E851-3D3A-1039D2A34DB0529F}" Path="\registry\machine\software\microsoft\windows\currentversion\appreadiness*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{C02423AD-9A00-87E7-2F4C96623BC9856A}" Path="*software\microsoft\speech_onecore*">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{4A8D98CA-B0DB-11E9-35814320BA4F3908}" Path="\registry\machine\software\microsoft\windows\currentversion\group policy\datastore*" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{4289293C-97F5-EB27-319366264AAAAE43}" Path="\registry\machine\software\policies*" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{A2FB8786-DAF5-9CBA-B8643DF6E6542411}" Path="*software\policies\microsoft\communicator*" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{0464ECBD-E0E4-D600-E4B73D36B7CFC9F4}" Path="*software\policies\emc\offlineaccess*" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{0F11328D-2628-EA72-51C316F80D87F26E}" Path="*software\policies\emc*" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{C2D3EE74-4A93-AF94-E45AADF211867129}" Path="*software\microsoft\windows\currentversion\policies*" Name="%kl_undef%" Value="%kl_undef%">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{9B18C4D4-52EB-50AB-925F842705D7F8F2}" Name="filesyspath" Value="\\e?i??l??.?o??.?e\?y??o?\?t??a???.?o??.?e">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{5EB2B45D-2C35-EDCB-82FA16C183E25A72}" Name="filesyspath" Value="c:\windows\system32\?r??p???i??\?a??s???e\?\?y??o?\?t??a???.?o??.?e\policies">
		<Process Path="C:\Windows\System32\svchost.exe" />
	</Registry>
	<Registry Id="{99C83EED-1559-7122-DEE849D501178FD5}" Name="officestartdefaulttab" Value="%kl_undef%" />
	<Registry Id="{E7F1C5BE-B114-6C39-FF20C30D1C0CC349}" Name="?" Value="%kl_undef%" />
	<Registry Id="{919F3E2B-6C4C-3AB9-01135C411C10139F}" Name="??" Value="%kl_undef%" />
	<Registry Id="{86AA6E04-674E-B453-77EC69445CF43AAB}" Name="blob" Value="%kl_undef%" />
	<Registry Id="{7DE5212C-0C4C-E6BF-0B358B2C76798517}" Name="personaltemplates" Value="%kl_undef%" />
	<Registry Id="{2172353C-D79D-4D0C-DC4E3582F8728231}" Name="value" Value="%kl_undef%" />
	<Registry Id="{2A7E1067-3C31-4528-7DFAD9073223F3C8}" Name="unblockspecificsenders" Value="%kl_undef%" />
	<Registry Id="{75965FD7-3D9F-FC2D-EA1AE80569C16814}" Name="junkmailsafesendersfile" Value="%kl_undef%" />
	<Registry Id="{948444C3-454A-7500-98271807BAB7C918}" Name="listbox_support_zonemapkey" Value="%kl_undef%" />
	<Registry Id="{F17E6AA8-DD08-2E84-3D5C588A66747DAE}" Name="uncasintranet" Value="%kl_undef%" />
	<Registry Id="{99AB6C87-CB36-F07A-769B0F5AB80D8F97}" Path="*software\adobe*">
		<Process>
			<Signature Subject="*adobe*" />
		</Process>
	</Registry>
	<Registry Id="{E811122E-B4FD-2488-0BA484434159AFE1}" Path="\registry\user\.default\software\microsoft\cryptography\certificatetemplatecache\e?i??l?t*">
		<Process Path="C:\Windows\System32\taskhostw.exe" />
	</Registry>
	<Registry Id="{0B6A39DB-E9EE-D1C8-3FB3D8033B2F4B69}" Path="*software\microsoft\windows\currentversion\internet settings\zone*">
		<Process Path="C:\Windows\CCM\UpdateTrustedSites.exe" />
	</Registry>
	<Registry Id="{AE41C12C-6B58-1DAA-DBFB4B4F887AA023}" Path="\registry\machine\software\microsoft\sms\mobile client\applicationcatalog*">
		<Process Path="C:\Windows\CCM\UpdateTrustedSites.exe" />
	</Registry>
	<Registry Id="{AF1FED6A-0F07-0459-D224E18039C99465}" Path="*OUTLOOK*">
		<Process Path="*Office*\OUTLOOK.EXE">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{310708CB-B407-7D05-89D3095FFAB25EAE}" Path="*excel*">
		<Process Path="*Office*\excel.EXE">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{FD114C9E-B178-2347-54CA171FF3DE1498}" Path="*\Word\*">
		<Process Path="*Office*\WINWORD.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
<!-- Part 8: end 2021-07-07T15:31:00.000Z-1625844664 -->

<!-- ############################################################################################################### -->
<!-- Part 9: start 2021-09-21T19:47:00.000Z-1632253643 -->
	<Registry Id="{2DF40185-B3E0-BE96-64460981635FE520}" Path="\registry\machine\software\magicard*">
		<Process>
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
<!-- Part 9: end 2021-09-21T19:47:00.000Z-1632253643 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 10: start 2021-12-23T13:04:00.000Z-1640264683 -->
	<Registry Id="{6CF4E8E9-4239-4C6A-6B9FD955E6D3804C}" Name="_global_">
		<Process Path="c:\windows\system32\ctfmon.exe" />
	</Registry>
	<Registry Id="{7699CF05-ADEC-B4E6-CE45BC1C792E5CAD}" Name="insights">
		<Process Path="c:\windows\system32\ctfmon.exe" />
	</Registry>
	<Registry Id="{890F479A-49BB-2873-CE20B9A1D1EA15A8}" Name="cpuvendoridstr">
		<Process Path="c:\windows\system32\audiodg.exe" />
	</Registry>
	<Registry Id="{D76DBEC1-23B9-2592-A400EE728435BBEB}" Path="\registry\machine\software\fortemedia\realtekeffects">
		<Process Path="c:\windows\system32\audiodg.exe" />
	</Registry>
	<Registry Id="{D81A1CC3-8955-9E93-1185365408EAD948}" Path="\registry\machine\software\soundresearch\apo*">
		<Process Path="c:\windows\system32\audiodg.exe" />
	</Registry>
	<Registry Id="{5CEA0EDE-EF02-CCD3-99FD67A05D025A5E}" Path="*software\sap\*">
		<Process>
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
	<Registry Id="{F66631BC-26AB-7BCE-77E49C33C2A650CE}" Path="\registry\machine\cluster\exchangeactivemanager\lastlog">
		<Process Path="C:\Windows\Cluster\clussvc.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{13C4FDDC-9175-0C16-C555D343E52A3F4D}" Path="*cluster\checkpoints*">
		<Process Path="C:\Windows\Cluster\clussvc.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8B3B5F6D-7CF4-A5BE-750E33CC0F006CB5}" Path="\registry\machine\software\wow6432node\lenovo*">
		<Process>
			<Signature Subject="*Lenovo*" />
		</Process>
	</Registry>
<!-- Part 10: end 2021-12-23T13:04:00.000Z-1640264683 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 11: 2021-12-23T14:08:00.000Z-1640268520 -->
	<Registry Id="{43914B6F-AD1C-30BD-A8A0627317B48D51}" Value="?">
		<Process>
			<Signature Subject="*IncrediBuild*" />
		</Process>
	</Registry>
	<Registry Id="{24D19FF3-2A29-7DCF-0B0FD77AFB9D5C35}" Name="availablegroups">
		<Process>
			<Signature Subject="*IncrediBuild*" />
		</Process>
	</Registry>
	<Registry Id="{CCBD4912-02FF-C8C7-6DD99A07C49377B2}" Value="%kl_undef%">
		<Process>
			<Signature Subject="*IncrediBuild*" />
		</Process>
	</Registry>
	<Registry Id="{75CD6961-12B6-F6B8-E1C2B2D648B9BAEC}" Value="%kl_undef%">
		<Process>
			<Signature Subject="*Searchinform*" />
		</Process>
	</Registry>
	<Registry Id="{94835AE6-8B71-3287-AE5C5B3DF6A7A914}" Value="????????">
		<Process>
			<Signature Subject="*Searchinform*" />
		</Process>
	</Registry>
	<Registry Id="{C752ED65-06AD-8308-8D4A6D9E7875DA3D}" Name="hpfilters">
		<Process>
			<Signature Subject="*Searchinform*" />
		</Process>
	</Registry>
	<Registry Id="{91035FF6-EEDD-0BF4-4677AAD9D81CE6DD}" Name="cachedmuid">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A4DC3610-21B0-AD4B-824D632A43B3BE94}" Name="expirationdatetime">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{546276D1-1084-F308-4D36B6334AC8A83D}" Name="fdhead">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CF59CDA9-D56F-0332-4287AB328D6D6710}" Name="feed*">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3B1BECA0-2F82-D0AD-BCC08DD3A8567ADA}" Name="flyouturl">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1ABCFD84-DB6E-E7DE-78666FA577182C1B}" Name="landingpageurl">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{74AC7191-92BD-131B-B720548E8CFDA5D5}" Name="locale">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8C279327-58CC-F2B2-98263ECF5B7B88E1}" Name="safesearchmode">
		<Process Path="*\backgroundTaskHost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{086F807E-8C68-36A2-79EA969C5E533979}" Type="4" Value="????????">
		<Process Path="*\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F0BBDF34-4973-4368-79556043CF804949}" Value="?">
		<Process Path="*\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{45ABFA55-2B07-2EDD-668F7D17235243AB}" Value="??">
		<Process Path="*\svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
<!-- Part 11: 2021-12-23T14:08:00.000Z-1640268520 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 12: 2021-12-23T15:37:00.000Z-1640273853 -->
	<Registry Id="{70BF0BFD-B0F8-9126-895481E3120D1466}" Value="?">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{3A063B41-F0DE-41B6-300A95EFABA312D3}" Value="?">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{2F8007F6-87B8-5BAA-EB405A927046552E}" Value="??">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{ACDE2342-D8C6-7815-D2A84E35CA56F96D}" Value="??">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{3A5036EF-5027-B5A8-9F0B314F4E6063D3}" Value="???">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{23D2267C-4D1E-8904-94EE47B37EF95ED3}" Value="???">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{76EFDB87-AB82-74CA-A6AF2A16560E1631}" Value="????">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{442D12C8-474C-AEA4-B1E0C909D54A9AAC}" Value="????">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{FC56908F-06F2-96E4-C4E45117F77ED4BE}" Value="%kl_undef%">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{E432A6B4-8C13-3FCE-6AF35DB32DA056AE}" Value="%kl_undef%">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{FBE85399-9382-7FCD-92669960FD2462EA}" Value="????????">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{A1AD878E-4391-4AA4-AAF9DEC9B6244632}" Value="????????">
		<Process>
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{C3CC7892-40BB-CA3C-6CAB34D879862DD7}" Value="????????????0000">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{78E8007A-E28A-8BF6-DDFE6D09C2FAF7FA}" Name="last started">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{148F3BE3-E5DC-37F6-2B54ECC6A87E8D43}" Name="current user">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{2695332C-012E-12BA-1078180556CB98AB}" Name="total runs">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{892CFE41-35DC-2681-045BCEB325B27C91}" Name="last duration">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{43C3A37A-893E-364A-CB97AB101329312C}" Name="total duration">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
	<Registry Id="{F50FC8E1-E69A-1969-C3556C0F8052BA05}" Name="current duration">
		<Process>
			<Signature Subject="*LANDESK*" />
		</Process>
	</Registry>
<!-- Part 12: 2021-12-23T15:37:00.000Z-1640273853 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 13: 2021-12-29T12:57:00.000Z-1640782645 -->
	<Registry Id="{AD24F55B-7831-2A79-425762E99A07B94D}">
		<Process Path="*\64DriverLoad.exe">
			<Signature Subject="*Epson*" />
		</Process>
	</Registry>
	<Registry Id="{6A6EAA1B-4A03-8DFF-05DB5E657A63B96A}">
		<Process CmdLine="c:\program files (x86)\initplusmonitor\initplusmonitor\isolatedvivotekplayerserverapp.exe /command-pipe-name vivotekplayercommandpipe*" />
	</Registry>
	<Registry Id="{3CB874CA-D875-90CA-CDEFAD09FCEBB820}">
		<Process CmdLine="c:\windows\ccm\updatetrustedsites.exe false  s-1-5-21-*" />
	</Registry>
	<Registry Id="{9DFCEC97-13B3-CF7C-AC818B337B2E96D5}">
		<Process CmdLine="c:\windows\microsoft.net\framework*\csc.exe /noconfig /fullpaths @c:\windows\temp*" />
	</Registry>
	<Registry Id="{C8641409-5417-2EEC-BA464AF8439396D0}">
		<Process CmdLine="c:\windows\microsoft.net\framework*\ngen.exe uninstall c:\windows\assembly\nativeimages_v*" />
	</Registry>
	<Registry Id="{92386CEC-44AE-9481-84243DA310C709FC}">
		<Process CmdLine="c:\windows\system32\wudfhost.exe -hostguid:{*" />
	</Registry>
	<Registry Id="{404B46A3-23B5-BBF7-CB7A78ED59EA12AD}">
		<Process CmdLine="logonui.exe /flags:0x0 /state0:0x???????? /state1:0x????????" />
	</Registry>
	<Registry Id="{1EA9B019-A2BE-7E0E-C8A372EDA7FCA6E1}">
		<Process CmdLine="c:\windows\microsoft.net\framework*\cvtres.exe /nologo /readonly /machine:*" />
	</Registry>
	<Registry Id="{3F22150B-B44F-82DE-EF8DAEDACDDC2054}">
		<Process CmdLine="c:\windows\system32\audiodg.exe 0x??? 0x???" />
	</Registry>
	<Registry Id="{0C85A46B-4C94-E1BC-41EBE79CB17B393F}">
		<Process CmdLine="c:\windows\system32\audiodg.exe 0x???" />
	</Registry>
	<Registry Id="{62FD4384-0F38-CE62-15C09B021BC11ADE}">
		<Process Path="*LANDesk\LDCLient\softmon.exe">
			<Signature Subject="*LANDesk*" />
		</Process>
	</Registry>
	<Registry Id="{F82A488E-7638-1366-0639F7C90F626D1A}">
		<Process Path="*LANDesk\LDClient\LocalSch.EXE">
			<Signature Subject="*LANDesk*" />
		</Process>
	</Registry>
	<Registry Id="{9A7A2FD5-D36B-EF3A-28BD0F06D35BBE2E}">
		<Process Path="*Common Files\SecurIT\zservice6415.exe">
			<Signature Subject="*SecurIT*" />
		</Process>
	</Registry>
	<Registry Id="{061FCE30-8CE7-4C4B-E85CE820EA2391B9}">
		<Process Path="*SAP\FrontEnd\SAPgui\saplogon.exe">
			<Signature Subject="SAP AG" />
		</Process>
	</Registry>
	<Registry Id="{F077F057-6675-3892-76921760BFEDC514}">
		<Process Path="*A0Win3\Bin\A0w.exe">
			<Signature Subject="*INFOSTROY*" />
		</Process>
	</Registry>
	<Registry Id="{E76F9B9F-97D9-430A-1F218619C3498D84}">
		<Process Path="*Infowatch\DeviceMonitor\Client\iwdmc.exe">
			<Signature Subject="*InfoWatch*" />
		</Process>
	</Registry>
	<Registry Id="{7B028BD1-E7BD-2931-C14E924E181E3F3B}" Path="\registry\user\*software\ati\ace\settings\runtime\graphics\udid*">
		<Process Path="*\ccc.exe" />
	</Registry>
	<Registry Id="{04A08B30-D4C4-F731-0C1FCDC933788B20}">
		<Process Path="*CheckPoint\Endpoint Security*">
			<Signature Subject="*Check Point*" />
		</Process>
	</Registry>
	<Registry Id="{AAE29895-18DA-66E5-4D82B463544DAAA8}">
		<Process Path="*CheckPoint\Endpoint Security*">
			<Signature Subject="*CheckPoint*" />
		</Process>
	</Registry>
	<Registry Id="{6A5B8CE0-C14D-598C-D60F7798B9F0B738}">
		<Process Path="*SearchInformAgent\sifiltersvc*">
			<Signature Subject="*Searchinform*" />
		</Process>
	</Registry>
	<Registry Id="{157043EF-2DFC-B2F0-EA4591461C7F6695}" Path="\registry\machine\software\idt\state\ui">
		<Process Path="*\STacSV64.exe" />
	</Registry>
	<Registry Id="{A120B984-83BD-1E94-9DD18FDB189A755F}" Name="appid">
		<Process Path="*LANDesk\LDClient\LDProfile.exe" />
	</Registry>
	<Registry Id="{055270AD-1ACA-5CE3-01BA8519F7F1E0CB}" Name="%kl_undef%">
		<Process Path="*LANDesk\LDClient\LDProfile.exe" />
	</Registry>
<!-- Part 13: 2021-12-29T12:57:00.000Z-1640782645 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 14: 2022-01-11T19:18:00.000Z-1641928718 -->
	<Registry Id="{47A39C97-AA10-DD63-E73F7C959542C0C5}" Path="\registry\machine\software\wow6432node\trendmicro\*">
		<Process>
			<Signature Subject="*Trend Micro*" />
		</Process>
	</Registry>
	<Registry Id="{B34AB02E-54B3-07D2-EA441DDB3F9997B2}" Path="\registry\machine\software\trendmicro\*">
		<Process>
			<Signature Subject="*Trend Micro*" />
		</Process>
	</Registry>
	<Registry Id="{30A787C4-14C0-4BBA-39625A33F6995C4A}" Path="\registry\machine\software\landesk\*">
		<Process>
			<Signature Subject="*landesk*" />
		</Process>
	</Registry>
	<Registry Id="{9F115B12-7C09-7901-6C49D39DB2808D41}" Name="nrtimes">
		<Process>
			<Signature Subject="*Beijing Sogou*" />
		</Process>
	</Registry>
	<Registry Id="{79B606BC-4F78-EAA1-4C59F6E2D1F6991E}" Path="\registry\user\*\software\sogouinput">
		<Process>
			<Signature Subject="*Beijing Sogou*" />
		</Process>
	</Registry>
	<Registry Id="{3C30EE9E-1C02-000E-D46F34F1031631A3}" Name="360drvmgr">
		<Process>
			<Signature Subject="*Beijing Qihu*" />
		</Process>
	</Registry>
	<Registry Id="{44FE8152-5B81-9ECC-CD720B6947D789A7}" Name="binayvalue">
		<Process>
			<Signature Subject="中国电子口岸数据中心" />
		</Process>
	</Registry>
	<Registry Id="{B776A977-F82C-42C0-5678A7493B1228DB}" Name="%kl_undef%">
		<Process>
			<Signature Subject="*Beijing VRV*" />
		</Process>
	</Registry>
	<Registry Id="{6FFB506C-3A79-FB74-56C958A6F69B136F}" Name="cocprivacyconsentuxshowstarttime">
		<Process Path="C:\Windows\System32\InputMethod\CHS\ChsIME.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{E9206F9B-7A8D-5012-0F22847E23C80176}" Path="\registry\machine\software\lide\ecops*">
		<Process>
			<Signature Subject="*DALIAN LIDE*" />
		</Process>
	</Registry>
<!-- Part 14: 2022-01-11T19:18:00.000Z-1641928718 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 15: 2022-03-08T21:10:00.000Z-1646773831 -->
	<Registry Id="{2EFA6C07-1A24-5407-C74CE9DF5A0A47E9}" >
		<Process Path="*custom\sapregsv.exe">
			<Signature Subject="SAP SE" />
		</Process>
	</Registry>
<!-- Part 15: 2022-03-08T21:10:00.000Z-1646773831 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 16: 2022-08-16T14:07:00.000Z-1660658836 -->
	<Registry Id="{4874E241-5F81-4F82-6C0A1F789221A002}">
		<Process CmdLine="*hklm:\software\microsoft\windows\currentversion\capabilityaccessmanager\consentstore\location*geowatcher.position.location&#10;&#9;&#9;}&#10;&#9;&#10;&#9;} catch [system.exception] {}&#34;" />
	</Registry>
	<Registry Id="{61BA5C13-EE11-D20C-645B13DB2D861958}">
		<Process CmdLine="*hklm:\software\microsoft\windows\currentversion\capabilityaccessmanager\consentstore\location*geowatcher.position.location&#10;&#9;&#9;}&#10;&#9;&#10;&#9;} catch [system.exception] {}" />
	</Registry>
<!-- Part 16: 2022-08-16T14:07:00.000Z-1660658836 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 17: 2022-09-21T19:26:00.000Z-1663788374 -->
	<Registry Id="{F3919E9A-C19E-8C21-0D0C2CB640D0FFEC}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\SensorFramework-*">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</Registry>
	<Registry Id="{B3965DC5-D636-B36E-6CCBF1CB1A394842}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\CCM*">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</Registry>
	<Registry Id="{A5E272D4-F7BC-17B0-ABCBD860B76A202B}" Path="\REGISTRY\MACHINE\SOFTWARE\Classes\Installer\Products\*">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</Registry>
	<Registry Id="{6BD3F5C8-E5C1-0E7C-CCC0373962C55237}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback*">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</Registry>
	<Registry Id="{704D2D6C-A605-C65A-64B8B1103FE855FF}" Path="*SOFTWARE\Microsoft\ServerManager\ServicingStorage\ServerComponentCache*">
		<Process CmdLine="c:\windows\system32\wbem\wmiprvse.exe -embedding" />
	</Registry>
	<Registry Id="{AABBB327-93C3-6E8F-AA65300B86362A7D}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows Media Foundation\FrameServer*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{3414F490-312D-40D8-32E44056D205CABC}" Path="\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\DsmSvc\State">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{CDCD3F84-39E9-A40B-B1829EB7DFCE220C}" Path="*SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{F92F21E5-C8A1-EFF6-7D82F7DCF6457953}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Wosc\Client\Persistent\ClientState*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{B197361B-6D06-1005-2054BA97C81D6D49}" Path="\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Device Installer\CurrentStatus">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{37FA6E40-6489-6332-E6A81FE1FE7D546B}" Path="\registry\machine\software\policies\microsoft\windows\appprivacy">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{CAED8907-3DA6-BAE2-00494CBC0C03A94B}" Path="\registry\machine\system\controlset001\services\lanmanworkstation">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{17D293C1-1FDE-C888-EF90394855C77C25}" Path="\registry\machine\system\controlset001\control\storage\enableddenygp\{*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{9EDF4F35-06A5-B617-2404CA5EED4A4AAC}" Path="\registry\machine\software\microsoft\windows\currentversion\appmodel\staterepositorystatus">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{10A10F85-BCAA-0E76-361744D3C2BA09D7}" Path="\registry\machine\software\policies\microsoft\windows\system">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{5304FD69-661C-A718-668CB1C95604A6F7}" Path="\registry\machine\software\policies\microsoft\windows\windows search">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{1520F833-B746-4FE6-25330C15AEA4651D}" Path="\registry\machine\software\policies\microsoft services\admpwd">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{F5D864C3-5DE4-667E-3C8AFA1BCE72A55B}" Path="\registry\machine\software\microsoft\analog\facedeviceinfo">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{5A0F2744-F793-ECE5-A5EBFEF75C53C0AA}" Path="*local settings\muicache*">
		<Process CmdLine="c:\windows\system32\svchost.exe -k *" />
	</Registry>
	<Registry Id="{CAE2F630-937C-25CD-C700790A602B525E}" Path="*software\plustek*">
		<Process Path="*Plustek\*OpticSlim*\docuaction.exe" />
	</Registry>
	<Registry Id="{3DC57584-BC5F-F5C8-12123057C9ED4D31}" Path="*systemcertificates*">
		<Process Path="*Nexthink*">
			<Signature Subject="*NEXThink*" />
		</Process>
	</Registry>
	<Registry Id="{4AFDE40A-AA23-EDAE-7AE79CA3376154BE}" Path="*nexthink*">
		<Process Path="*Nexthink*">
			<Signature Subject="*NEXThink*" />
		</Process>
	</Registry>
	<Registry Id="{2AF22C71-B809-5941-291D47579BA6B729}" Path="*settings\muicache*">
		<Process Path="*Nexthink*">
			<Signature Subject="*NEXThink*" />
		</Process>
	</Registry>
	<Registry Id="{F54BD5FD-AAA1-B3A2-F153521E5999FB3A}" Path="*software\ssprint*">
		<Process Path="*Nexthink*">
			<Signature Subject="*NEXThink*" />
		</Process>
	</Registry>
	<Registry Id="{27E1319B-42AE-AA3C-D099794856B10780}" Path="*software\ssprint*" Name="%kl_undef%" />
	<Registry Id="{B0E9AD92-E186-69CE-E1CEEDE7B1382B14}" Path="*software\ssprint*" Name="adv*" />
	<Registry Id="{3AE737A2-541B-44A0-764BC993466C8E69}" Path="*software\ssprint*" Name="amp*" />
	<Registry Id="{811E79AF-ED70-4AE7-2C10723ADE7FD2EF}" Path="*software\ssprint*" Name="apppath*" />
	<Registry Id="{75C6FA29-E1E1-5F15-C45C0250D80EF30E}" Path="*software\ssprint*" Name="attributes*" />
	<Registry Id="{08DA01B1-49D5-8CFC-89920833AFFBF144}" Path="*software\ssprint*" Name="autoconfig*" />
	<Registry Id="{E46F4AB4-2499-0248-45EC4DAB8258BDED}" Path="*software\ssprint*" Name="bidi*" />
	<Registry Id="{F3B44AA5-056F-511A-B8CEBBB54A4F740C}" Path="*software\ssprint*" Name="cmstable_value*" />
	<Registry Id="{7725E0FE-3D9F-EDEE-622A745FC6CDF562}" Path="*software\ssprint*" Name="devicedata*" />
	<Registry Id="{C0C8C642-9E92-A958-511698D7628D87F6}" Path="*software\ssprint*" Name="devmode*" />
	<Registry Id="{D981B6CF-2EB3-C5F1-7F29BE0253975594}" Path="*software\ssprint*" Name="drivername*" />
	<Registry Id="{E2F229B2-AC62-68AD-423032B80C0D560D}" Path="*software\ssprint*" Name="drvcntcode*" />
	<Registry Id="{175D9597-46B1-2BB1-F1B7D077EDF69A95}" Path="*software\ssprint*" Name="emfspooling*" />
	<Registry Id="{A6B9D9A4-0FF3-F3D6-23C73C88A37FD729}" Path="*software\ssprint*" Name="fileprint*" />
	<Registry Id="{2BB37D26-33D5-9FB9-CACDF6AE3D9BDA6B}" Path="*software\ssprint*" Name="getprinter*" />
	<Registry Id="{D67E1E4A-6406-88EE-3F453AD0635129B1}" Path="*software\ssprint*" Name="key*" />
	<Registry Id="{64E62D90-D6A3-FDB2-1A5786E688439251}" Path="*software\ssprint*" Name="liveupdate*" />
	<Registry Id="{47C76179-904F-8B4C-1C03C8D25A157CCF}" Path="*software\ssprint*" Name="muidata*" />
	<Registry Id="{30037363-3EA3-C6A3-BD58A3137E6AF0BA}" Path="*software\ssprint*" Name="port*" />
	<Registry Id="{E497E2AA-B291-A381-01A0CD1A994BC008}" Path="*software\ssprint*" Name="pp_ssi5m*" />
	<Registry Id="{3712A0E8-2F67-916A-7498721E36E0F570}" Path="*software\ssprint*" Name="ppkey*" />
	<Registry Id="{5044DB59-AD48-3900-4EC7A02091EA74AB}" Path="*software\ssprint*" Name="printername*" />
	<Registry Id="{30EBE6EC-4B28-7FAF-02FFA1FACAF7A080}" Path="*software\ssprint*" Name="rd_autoconfig*" />
	<Registry Id="{2D8400D1-B524-B65D-1A8FED25E2B81A9A}" Path="*software\ssprint*" Name="servername*" />
	<Registry Id="{C04B6D13-4352-B9C8-8BB43381648E83F5}" Path="*software\ssprint*" Name="smsupport*" />
	<Registry Id="{4EFE62C7-2075-E107-C5475BAF2FB79A05}" Path="*software\ssprint*" Name="tech*" />
	<Registry Id="{FFF04DBE-1AE0-3044-5C3714D9D80C6D68}" Path="*software\ssprint*" Name="uipreset*" />
	<Registry Id="{A94FC5BD-0B11-267E-B53EDCC8B6B7F0C8}" Path="*software\ssprint*" Name="uitype*" />
	<Registry Id="{D5349AFC-DE3E-BBF4-0572C04B0CCA12EA}" Path="*software\ssprint*" Name="warmup*" />
	<Registry Id="{ACED3ADC-D570-1D9D-C6216AB35C0D9498}" Path="*software\microsoft\windows\currentversion\searchsettings">
		<Process Path="C:\WINDOWS\SystemApps\*\SearchApp.exe" />
	</Registry>
	<Registry Id="{47D6FBCB-BC7E-3796-450CF30C75BAD77D}" Path="*software\microsoft\windows\currentversion\windowproperties*">
		<Process Path="*Microsoft\Edge\Application\msedge.exe" />
	</Registry>
	<Registry Id="{381D19DC-48E4-34B2-F567E6DE39BD0F0C}" Path="\registry\machine\software\cvsm">
		<Process Path="C:\WINDOWS\system32\CompatTelRunner.exe" />
	</Registry>
	<Registry Id="{441F7385-7242-F9DC-9DDCC6F8943CD0B6}" Path="*software\microsoft\windows\currentversion\feeds">
		<Process Path="C:\WINDOWS\system32\backgroundTaskHost.exe" />
	</Registry>
<!-- Part 17: 2022-09-21T19:26:00.000Z-1663788374 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 17: 2022-09-27T13:36:00.000Z-1664285779 -->
	<Registry Id="{CAEEC0D4-A9EC-F739-BD234EBDC1E492C7}" Path="*software\microsoft\windows\currentversion\thememanager" Name="lastloadedppi">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{972C6873-96F4-0A2D-65FBD22D857ACDD5}" Path="*software\microsoft\windows\currentversion\thememanager" Name="lastloadeddpiplateaus">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{8DEA80EE-CBDD-87D8-B98B4C9B13911DA2}" Path="*software\microsoft\ctf\remotesession" Name="clsid">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{B6159274-0D23-F372-BEA3E8CAE8B06572}" Path="*software\microsoft\ctf\remotesession" Name="profile">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{BE1CBC6C-3238-ADFF-9B17AB121E43C959}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\sessiondata*" Name="loggedon*">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{94E60B50-0FD2-28FA-B6789887778E2579}" Path="\registry\machine\software\microsoft\windows\currentversion\authentication\logonui\sessiondata*" Name="lastloggedon*">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{C8C0312F-9A21-07E4-2F202F4D20460DD1}" Path="\registry\machine\software\microsoft\windows nt\currentversion\winlogon" Name="lastlogoffendtimeperfcounter">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{B377F551-9E2D-D11C-0D8527A6FF2928B7}" Path="\registry\machine\software\microsoft\windows\dwm" Name="dwminitsessionactivityid_*">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{F80E589F-052B-3EFF-D7175A5A9F705969}" Path="*software\microsoft\windows\winlogon\passwordexpirynotification" Name="notshownreason">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{E9B7BCCB-034D-131E-A20CB57371882019}" Path="*software\microsoft\windows\winlogon\passwordexpirynotification" Name="notshowntime">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{7F80C3CB-EE3E-5156-C0125BCAAA6500F1}" Path="*software\microsoft\windows\winlogon\passwordexpirynotification" Name="notshownerrorreason">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{29F4E46B-8AA9-D209-3C32B7FC512CA51E}" Path="*software\microsoft\windows\winlogon\passwordexpirynotification" Name="notshownerrortime">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{F52D4449-7102-7160-0331E2045AC80043}" Path="*software\microsoft\windows\winlogon\passwordexpirynotification" Name="showntime">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{8239A062-AE28-7820-585C4DE43C7421F2}" Path="\registry\machine\software\microsoft\windows nt\currentversion\accessibility\session*" Name="%kl_undef%">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{19FBE6B4-6DB2-61A8-A0FB897D20DCEA55}" Path="\registry\machine\software\microsoft\windows nt\currentversion\winlogon\autologonchecked" Name="%kl_undef%">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{A8A65C61-1878-A5D6-D16E6DE5AA86A4D5}" Name="dllname" Value="%systemroot%\resources\themes\aero\aero.msstyles*">
		<Process Path="C:\Windows\System32\winlogon.exe" CmdLine="winlogon.exe" />
	</Registry>
	<Registry Id="{E565F629-0087-434F-7C7BB3A5FC676C66}" Path="*Local Settings\MuiCache\*">
		<Process Path="C:\Windows\System32\sihost.exe" CmdLine="sihost.exe" />
	</Registry>
	<Registry Id="{F2B9014E-F241-8703-4C44B5EB63F403EC}" Path="*Local Settings\MrtCache\*">
		<Process Path="C:\Windows\System32\sihost.exe" CmdLine="sihost.exe" />
	</Registry>
	<Registry Id="{39D17089-C73A-C76A-1AD0BCDA38207612}" Path="*SOFTWARE\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Microsoft.*&#39;,">
		<Process Path="C:\Windows\System32\sihost.exe" CmdLine="sihost.exe" />
	</Registry>
	<Registry Id="{12C1658D-C404-BF80-F2068E34213FDE00}" Path="*software\microsoft\windows\currentversion\explorer\plmvolatile\terminationtype" Name="microsoft.*">
		<Process Path="C:\Windows\System32\sihost.exe" CmdLine="sihost.exe" />
	</Registry>
	<Registry Id="{23321B5B-B46A-1C6E-58AC598A410AC3D1}" Path="*software\microsoft\windows\currentversion\explorer\advanced\packageactivate" Name="microsoft.*">
		<Process Path="C:\Windows\System32\sihost.exe" CmdLine="sihost.exe" />
	</Registry>
	<Registry Id="{82EB5C6B-E340-900F-3A78602FB7285443}" Path="\registry\machine\software\microsoft\sms\mobile client\presentationmode\s-1-*" Name="presentationmodeison">
		<Process Path="c:\windows\ccm\scnotification.exe" />
	</Registry>
	<Registry Id="{DCC3E4C4-58DA-BD63-651543800F3EDC50}" Path="\registry\machine\system\software\microsoft\tip\aggregateresults" Name="data">
		<Process Path="c:\windows\ccm\scnotification.exe" />
	</Registry>
<!-- Part 17: 2022-09-27T13:36:00.000Z-1664285779 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 18: 2022-10-03T13:44:00.000Z-1664804679 -->
	<Registry Id="{642EB341-BF32-EB40-39CADB286DEBFA3C}" Path="\registry\machine\software\wow6432node\adventnet*">
		<Process>
			<Signature Subject="*ZOHO*" />
		</Process>
	</Registry>
	<Registry Id="{6E767C94-2E35-6F53-30387E8D7D247EBB}" Path="*software\adventnet\*">
		<Process>
			<Signature Subject="*ZOHO*" />
		</Process>
	</Registry>
	<Registry Id="{74DFD1F4-B84B-0C3C-7F98D40297F728B0}" Path="\registry\machine\software\fortinet*">
		<Process>
			<Signature Subject="*Fortinet*" />
		</Process>
	</Registry>
	<Registry Id="{35D6F129-B2E3-787D-32B5EBF59FA4DF9A}" Path="\registry\machine\software\wow6432node\fortinet*,&#39;*_classes\local settings\mrtcache*">
		<Process>
			<Signature Subject="*Fortinet*" />
		</Process>
	</Registry>
	<Registry Id="{F1234D7E-5687-3520-EF844DF58FB62D72}" Path="\registry\machine\software\wow6432node\infoblox*">
		<Process>
			<Signature Subject="*INFOBLOX*" />
		</Process>
	</Registry>
	<Registry Id="{91E48F75-51F3-775B-94C0FBA46D298294}" Path="\registry\machine\software\wow6432node\kasperskylab*">
		<Process>
			<Signature Subject="*Kaspersky*" />
		</Process>
	</Registry>
	<Registry Id="{02E48F75-51F3-775B-94C0FBA46D298294}" Path="\registry\machine\software\wow6432node\kasperskylab*">
		<Process>
			<Signature Subject="too midori trading" />
		</Process>
	</Registry>
	<Registry Id="{B723F323-5A06-BE6A-74E8D6BDB5E87AA1}" Path="\registry\machine\system\controlset001\services\sifiltersvc\agents\{*">
		<Process CmdLine="c:\program files (x86)\searchinformagent\sifiltersvc?\sifiltersvc_manager.exe -i ????" />
	</Registry>
	<Registry Id="{03120465-32EA-2D12-C5D7778D1101CBEB}" Path="\registry\machine\system\controlset001\services\sifiltersvc">
		<Process CmdLine="c:\program files (x86)\searchinformagent\sifiltersvc?\sifiltersvc_manager.exe -i ????" />
	</Registry>
	<Registry Id="{D99FD694-B6EC-F85E-0C0734393E7F7F27}" Path="\registry\machine\software\wow6432node\waters\instruments*">
		<Process Path="c:\empower\instruments\wdhcpserversvc.exe">
			<VersionInfo OrignFileName="WDHCPServerSvc.exe" ProductName="Waters*" />
		</Process>
	</Registry>
	<Registry Id="{792F308A-AEA9-7CC3-A799FF52FC1A49A8}" Path="*software\citrix\ica*">
		<Process Path="*Citrix*">
			<Signature Subject="*Citrix*" />
		</Process>
	</Registry>
	<Registry Id="{C637C44C-6A51-BA53-E34B8AFBD636862F}" Path="*software\pdfforge\pdfcreator\settings*">
		<Process CmdLine="*/infodatafile=*">
			<Signature Subject="*pdfforge*" />
		</Process>
	</Registry>
	<Registry Id="{9B89A195-EDB3-2FAE-43A9FEB492EBA4EB}" Path="\REGISTRY\MACHINE\SOFTWARE\Symantec*">
		<Process Path="*Symantec*">
			<Signature Subject="*Symantec*" />
		</Process>
	</Registry>
	<Registry Id="{3E39D8D6-DED9-E22E-F2B189AB4DBCEC15}" Path="\registry\machine\software\wow6432node\symantec*">
		<Process Path="*Symantec*">
			<Signature Subject="*Symantec*" />
		</Process>
	</Registry>
	<Registry Id="{E1D246C0-36BF-A4CF-07325FD4E0FE38E4}" Path="*software\microsoft\edgewebview*">
		<Process Path="*microsoft\edgewebview*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
<!-- Part 18: 2022-10-03T13:44:00.000Z-1664804679 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 19: 2022-11-29T17:43:00.000Z-1669743793 -->
	<Registry Id="{877D73F2-F881-FDCC-FC97DFE47B160AE0}" Path="\registry\machine\system\controlset001\services\asp.net_*\names">
		<Process Path="*Program Files*SolarWinds*">
			<Signature Subject="*SolarWinds*" />
		</Process>
	</Registry>
	<Registry Id="{E8BE68C3-69A3-7023-C9E464901BFBB489}" Path="\registry\machine\software\veeam*">
		<Process Path="*program files*veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</Registry>
	<Registry Id="{47E3D084-78C4-DA06-9E0E0732B35B8991}" Path="\registry\machine\system\*services\vss\diag\vssapipublisher">
		<Process Path="*program files*veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</Registry>
	<Registry Id="{ADE20789-238B-AD36-FFBF9F7B28F4BAD6}" Path="\registry\machine\system\controlset*\control\session manager">
		<Process Path="*program files*veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</Registry>
	<Registry Id="{3885EF04-713E-1DB6-B74D84A7DFBFF246}" Path="\registry\machine\system\controlset*services\vss\settings">
		<Process Path="*program files*veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</Registry>
	<Registry Id="{CB33F07D-2105-04FC-E139910AF5BD3FA4}" Path="\registry\machine\system\controlset*control\backuprestore\filesnottosnapshot">
		<Process Path="*program files*veeam*">
			<Signature Subject="*Veeam*" />
		</Process>
	</Registry>
	<Registry Id="{45A16229-5C24-1B11-A958E3695C58C8C9}" Path="\registry\machine\software\carbonblack\config">
		<Process Path="c:\windows\carbonblack\cb.exe">
			<Signature Subject="*Carbon*" />
		</Process>
	</Registry>
	<Registry Id="{015A246C-E51E-5012-7BCA100E2C63E062}" Path="\registry\machine\system\controlset001\services\carbonblackk">
		<Process Path="c:\windows\carbonblack\cb.exe">
			<Signature Subject="*Carbon*" />
		</Process>
	</Registry>
	<Registry Id="{F273C5BF-E6F1-1CFA-B1A9EABB92C3678E}" Path="\registry\machine\cluster*">
		<Process CmdLine="c:\windows\cluster\clussvc.exe -s" />
	</Registry>
	<Registry Id="{B68C5631-01FF-608C-3F3A70B9D7A7E1B6}" Path="\registry\machine\0.cluster*">
		<Process CmdLine="c:\windows\cluster\clussvc.exe -s" />
	</Registry>
	<Registry Id="{043A3F29-5CD2-BF57-464F65C6F58E94C6}" Path="\registry\machine\software\hp\security update service\state">
		<Process Path="*\securityupdateservice.exe">
			<Signature Subject="*Bromium*" />
		</Process>
	</Registry>
	<Registry Id="{C181538A-A5D8-B8BB-574DECFF07F7EC72}" Path="\registry\machine\software\cxuiusvc">
		<Process Path="C:\Windows\System32\CxUIUSvc64.exe">
			<Signature Subject="*Synaptics*" />
			<VersionInfo ProductName="*CxUIUSvc*" />
		</Process>
	</Registry>
	<Registry Id="{7905AD23-63FD-836B-B637FDF8BC9177A8}" Path="*software\google\update\proxy">
		<Process Path="*google\update\googleupdate.exe">
			<Signature Subject="*google*" />
		</Process>
	</Registry>
	<Registry Id="{A65380A6-CF50-EAA9-C3321E9BFA4F16B5}" Path="*software\microsoft\edge\preferencemacs\default\extensions.settings">
		<Process Path="*microsoft\edge\application\msedge.exe">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{92D899E8-5221-B325-158C51A78C934BB9}" Path="*software\seclore*">
		<Process Path="*Program Files*Seclore*">
			<Signature Subject="*Seclore*" />
		</Process>
	</Registry>
	<Registry Id="{83B0FB1B-A77E-BADA-49874EDC34AB3C9D}" Path="*software\mozilla\firefox\prexulskeletonuisettings">
		<Process Path="*Program Files*mozilla*">
			<Signature Subject="*mozilla*" />
		</Process>
	</Registry>
	<Registry Id="{230124E7-31C5-1B18-F15B8C4B78D957DD}" Path="*software\mozilla\firefox\launcher">
		<Process Path="*Program Files*mozilla*">
			<Signature Subject="*mozilla*" />
		</Process>
	</Registry>
	<Registry Id="{B79B2EAE-8B82-65AE-7FA0E613579C4304}" Path="*software\mozilla\firefox\dllprefetchexperiment">
		<Process Path="*Program Files*mozilla*">
			<Signature Subject="*mozilla*" />
		</Process>
	</Registry>
	<Registry Id="{3F10B695-7DC0-9611-D72B31628FE842A0}" Path="*software\microsoft\office*outlook\profiles\outlook*">
		<Process CmdLine="* -executionpolicy bypass -nologo -command .\eus.ps1" />
	</Registry>
	<Registry Id="{36A15F65-106B-13F5-65B4E50E5B76FCAE}" Path="*software\microsoft\windows\currentversion\search\microsoft.windows.search_*\appsconstraintindex">
		<Process Path="c:\windows\systemapps\microsoft.windows.search_*\searchapp.exe" />
	</Registry>
	<Registry Id="{F72280B0-0EE3-886B-27E5488EC36D9075}" Path="\registry\machine\software\microsoft\systemcertificates\addressbook\certificates\*">
		<Process Path="c:\windows\system32\lsass.exe" />
	</Registry>
	<Registry Id="{897B4361-2759-EEC2-4BF765B4BF12E0FD}" Path="*software\microsoft\internet explorer\suggested sites">
		<Process CmdLine="c:\windows\system32\msfeedssync.exe sync" />
	</Registry>
	<Registry Id="{A306C0D7-7EFA-7A71-F590335F12D622A7}" Path="\registry\machine\software\microsoft\ccm\performance\ccmframework*">
		<Process CmdLine="c:\windows\system32\msiexec.exe -embedding * e global\msi0000" />
	</Registry>
	<Registry Id="{11B98D8D-532F-535B-E5FB7E8497963065}" Path="\registry\machine\software\wow6432node\microsoft\ccm\performance\ccmframework*">
		<Process CmdLine="c:\windows\system32\msiexec.exe -embedding * e global\msi0000" />
	</Registry>
	<Registry Id="{299D1492-727D-E25E-26A9CE61C412A04F}" Path="\registry\machine\system\waas\upfc">
		<Process CmdLine="c:\windows\system32\upfc.exe /launchtype periodic /cv *" />
	</Registry>
	<Registry Id="{0ECD0710-C8BB-AD65-52F7D695C00C27A9}" Path="*software\bginfo.tmp*">
		<Process CmdLine="c:\windows\temp\bginfo.exe /silent /timer /accepteula*" />
	</Registry>
	<Registry Id="{9DC8D18D-B905-1AAA-4D0147D45AF5B7F7}" Path="*bginfo.config.1*">
		<Process CmdLine="c:\windows\temp\bginfo.exe /silent /timer /accepteula*" />
	</Registry>
	<Registry Id="{2548F390-77D7-57E8-F4B0A326A8612D22}" Path="*\.bgi">
		<Process CmdLine="c:\windows\temp\bginfo.exe /silent /timer /accepteula*" />
	</Registry>
	<Registry Id="{DDEEE72B-09C4-9DF7-EDC30AF1E4E7ADD6}" Path="*control panel\desktop">
		<Process CmdLine="c:\windows\temp\bginfo.exe /silent /timer /accepteula*" />
	</Registry>
	<Registry Id="{5F3F96D4-8244-A1AA-2B5CBF58A56CAC6F}" Path="*software\sysinternals\bginfo">
		<Process CmdLine="c:\windows\temp\bginfo.exe /silent /timer /accepteula*" />
	</Registry>
	<Registry Id="{D65DF55F-830B-611D-95A46B6604FB2DAA}" Path="*software\microsoft\office\*outlook\profiles*">
		<Process Path="C:\Program Files (x86)\Enterprise Vault\ArchiveTask.exe">
			<Signature Subject="*Veritas*" />
		</Process>
	</Registry>
	<Registry Id="{DD9F66C5-E30A-4B56-34E02AC14AA2682F}" Path="*device parameters">
		<Process CmdLine="taskhostw.exe system">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{60387F8B-162B-7DE5-93D9D01FBC2AE8A6}" Path="*device parameters\ceip">
		<Process CmdLine="taskhostw.exe system">
			<Signature Subject="*microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{187F3DB4-8090-0671-C826751664A68754}">
		<Process CmdLine=".git/hooks/virtual-filesystem 1" />
	</Registry>
	<Registry Id="{C83F2FEC-62E6-36BB-C31366ED88B2E49F}">
		<Process Path="*bin\hostx64\x86\vctip.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{01738F4A-B054-4154-35DC38B880756F26}">
		<Process Path="*hostx86\x86\vctip.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{DEA535CA-F8AD-8814-028AF036640635C2}">
		<Process CmdLine="*bin/hostx64/x86/cl.exe /md /external*" />
	</Registry>
	<Registry Id="{101C0868-CE45-37E7-7AB2936A7D8DB14E}">
		<Process CmdLine="c:/program files/git/mingw64/bin/git.exe  -c gc.auto*c:/program files/git/mingw64/bin\git-askpass.exe*" />
	</Registry>
	<Registry Id="{F830748C-2AC9-5585-6BEDEDBBF4AAC8ED}">
		<Process CmdLine="c:\program files\git\bin\git.exe ls-remote origin refs/heads/user*" />
	</Registry>
	<Registry Id="{A48638BC-946C-7543-715055DDB171C9FD}">
		<Process CmdLine="c:\program files\git\cmd\git.exe --git-dir*" />
	</Registry>
	<Registry Id="{F20797FF-5006-759A-602A3C463B179092}">
		<Process CmdLine="c:\program files\git\cmd\git.exe --no-optional-locks status --serialize*" />
	</Registry>
	<Registry Id="{06A70E29-1AA3-895B-F532A9317C0AE6D7}">
		<Process CmdLine="c:\program files\git\mingw64\libexec\git-core\git.exe config  credential*" />
	</Registry>
	<Registry Id="{ADB778BA-756D-7A11-D33D8A57F97096B6}">
		<Process CmdLine="c:\program files\git\mingw64\libexec\git-core\git.exe config --null  --list" />
	</Registry>
	<Registry Id="{99228B5C-BEBE-2289-81EBD650A6B9DEA7}">
		<Process CmdLine="c:\program files\git\mingw64\libexec\git-core\git.exe credential-manager store" />
	</Registry>
	<Registry Id="{F35F1938-AF25-04E3-648A4DEE3F42FA67}">
		<Process CmdLine="c:\program files\gvfs\gvfs.hooks.exe post-command*" />
	</Registry>
	<Registry Id="{8F70106F-1659-F5FC-ED552A5D2BD91D1E}">
		<Process CmdLine="c:\program files\gvfs\gvfs.hooks.exe pre-command*" />
	</Registry>
	<Registry Id="{8EA25F1F-01ED-DA10-22E34718E7743E26}">
		<Process CmdLine="c:\windows\system32\msiexec.exe /y c:\windows\ccm\*.dll" />
	</Registry>
	<Registry Id="{D18A279F-F190-3CD2-9020A8821A47E017}">
		<Process Path="C:\Windows\Temp\DPTF\esif_assist_64.exe">
			<Signature Subject="*Intel*" />
		</Process>
	</Registry>
	<Registry Id="{213FF48A-1FA3-2B5B-0D08654A81AA2D02}">
		<Process CmdLine="*git/hooks/pre-command.exe*" />
	</Registry>
	<Registry Id="{3B1A6AAB-E452-B348-105753DD988E08B9}">
		<Process CmdLine="*git/hooks/post-command.exe*" />
	</Registry>
<!-- Part 19: 2022-11-29T17:43:00.000Z-1669743793 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 20: 2023-01-18T09:40:04.000Z-1674034807 -->
	<Registry Id="{0307BDAA-6257-45A2-B98491B2099F4D45}" Path="\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Guardware\Integrity Management*">
		<Process Path="*Guardware\Integrity Management\GWClient.exe" />
	</Registry>
<!-- Part 20: 2023-01-18T09:40:04.000Z-1674034807 -->
<!-- ############################################################################################################### -->
	
<!-- ############################################################################################################### -->
<!-- Part 21: 2023-04-18T13:22:00.000Z-1681824146 -->
	<Registry Id="{7F7D07C6-AA42-E116-FAA61F07CE93DE6B}" Path="\registry\machine\software\wow6432node\altiris\*">
		<Process Path="c:\program files\altiris*">
			<Signature Subject="*Symantec*" />
		</Process>
	</Registry>
	<Registry Id="{02CCF1CE-05FA-6205-4FCB4B03E07FAB3E}" Path="*software\sogouinput.user">
		<Process>
			<Signature Subject="?*" />
		</Process>
	</Registry>
	<Registry Id="{F1F54FE6-185D-2EB2-2B5119427183184B}" Path="*software\kingsoft\office*">
		<Process Path="*office*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</Registry>
	<Registry Id="{C6D86393-A511-9F00-2A7F7DB2987A3CD8}" Path="*software\kingsoft\wpscloud*">
		<Process Path="*office*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</Registry>
	<Registry Id="{E746C7F8-BE54-9FB7-270A7798DB46D293}" Path="*software\kingsoft\pdf*">
		<Process Path="*office*">
			<Signature Subject="*Kingsoft Office*" />
		</Process>
	</Registry>
	<Registry Id="{3730E8B7-8DA2-F2B5-FADA72748D28D453}" Name="shutdownflyoutoptions">
		<Process Path="c:\windows\system32\mousocoreworker.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{893DD597-0940-6007-A1823704017BDC41}" Name="enhancedshutdownenabled">
		<Process Path="c:\windows\system32\mousocoreworker.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A8F4882B-CB2E-0310-4CB443920B192A7B}" Name="etag">
		<Process Path="c:\windows\system32\mousocoreworker.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7CED932C-7FBC-8CE5-7AA3CC89A1D44515}" Name="currentcallsperdaycount">
		<Process Path="c:\windows\system32\mousocoreworker.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{B4E26EE0-EF2E-466D-EF554134B8239E52}" Path="*software\microsoft\inputmethod*">
		<Process Path="c:\windows\system32\ctfmon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{FE3052CD-797C-34F5-3BD092761340E53A}" Path="*software\microsoft\ctf\inputsession*">
		<Process Path="c:\windows\system32\ctfmon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8757C952-C946-37AE-9137ACCAC9CDC6B4}" Path="*contentdeliverymanager\creativeevents\subscribedcontent*">
		<Process Path="C:\Windows\SystemApps\Microsoft.LockApp_*\LockApp.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{9EF5978C-AD98-D20B-CBA2600A459E7E86}" Path="*software\realtek\audio\rtkauduservice*">
		<Process>
			<Signature Subject="*Realtek*" />
		</Process>
	</Registry>
	<Registry Id="{1A6A432F-DA7F-0121-1145D0751D701521}" Path="*microsoft\windows\currentversion\uninstall*">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{23B3C24C-EC84-5F0E-691416703241811E}" Name="left">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{EB2A93EA-3B8B-F785-DCCEEE2E7F899277}" Name="superresolutionenabled">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{56C31E4C-166D-E9FE-DA171AB367FEB47C}" Name="colinfo">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{180CC578-91B0-C271-5F943DA0F4BB4FA6}" Name="sniffedfoldertype">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{DC863F1B-34DA-250C-CF3E8F463AA3DB5B}" Name="groupbykey*">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{65D950C5-F104-C062-7D6A9771EE8EEFB0}" Name="%kl_undef%">
		<Process>
			<Signature Subject="*Baidu*" />
		</Process>
	</Registry>
	<Registry Id="{FF7942C0-DE39-5287-D18F6894DD1BE953}" Name="left">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
	<Registry Id="{FC21FE63-96D8-B19D-129D3AF796F5C70A}" Name="crashcnt">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
	<Registry Id="{BF1AD336-9A61-3275-723D7CE1B12B69A8}" Name="checkfastpassport">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
	<Registry Id="{F579FDEC-1F41-D024-0B625C95A01575E5}" Name="crashrecord">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
	<Registry Id="{F85FE359-3A32-8499-72E77657427526C2}" Name="alphaback_*">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
	<Registry Id="{C5F164BA-F617-488E-0EE401E5A759F06C}" Path="*microsoft\ctf\cuas\defaultcompositionwindow">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
	<Registry Id="{1B20DA38-FC80-650C-D12170CCA4BB3008}" Path="*software\tencent\qqbrowser*">
		<Process>
			<Signature Subject="*Tencent*" />
		</Process>
	</Registry>
<!-- Part 21: 2023-04-18T13:22:00.000Z-1681824146 -->
<!-- ############################################################################################################### -->
	
<!-- ############################################################################################################### -->
<!-- Part 22: 2023-05-16T15:54:00.000Z-1684252445 -->
	<Registry Id="{D2462C81-80DF-2599-041218234E819D32}" Path="*software\microsoft\group policy\client\runonce" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{06E33BC2-09ED-2404-6CACF0248C6C873D}" Path="*group policy\state\machine\gplink-list\*" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{757D1F42-D49E-9A60-4573B3618B3860FD}" Path="*group policy\state\machine\gpo-list\*" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EE360185-34A2-DD0A-A2C38CC347D1E9CD}" Path="*policies\microsoft\systemcertificates*" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{90DC5691-8F56-F156-78D233B09888987A}" Path="*internet settings\lockdown_zones*" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D63AD3E0-B0BF-6A78-1D98354E871DA193}" Path="*internet settings\zones*" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{BA4162D2-C79F-9AF2-961FB2E2079DBFFE}" Name="extension" Operation="Deleted">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{71B9CF3E-DC95-1030-ED2454DC55DDCE6C}" Path="*currentversion\fonts*">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{703BA2C2-D6E7-63C6-CD9EA969873962FC}" Path="*group policy*history*">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{619C6022-12AB-7D78-F4BB6B323B3C9C46}" Path="*group policy*shadow*">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{28606C6B-4FBE-0F89-0B35C6B0C4AD3C8C}" Path="*group policy\serviceinstances">
		<Process CmdLine="*svchost* gpsvcgroup*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1921839F-72C1-392D-AFBB891688B24248}" Path="*windows error reporting\termreason*">
		<Process Path="*svchost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{BD43C96B-466B-B361-A546A047538D2C88}" Operation="Deleted">
		<Process CmdLine="*system32\svchost.exe*schedule*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{C798A8BD-1B39-ACD0-AA7EB18D8A5E45F0}" Operation="Deleted">
		<Process CmdLine="*system32\svchost.exe*dhcp*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{161949AD-0FBA-0007-85307A626AEB0875}" Operation="Deleted">
		<Process CmdLine="*system32\svchost.exe*winhttpautoproxysvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3BC44575-18F2-01DE-560D62C206AAAF83}" Operation="Deleted">
		<Process CmdLine="*system32\svchost.exe*winmgmt*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1938DAE1-2482-0E2C-3ACD66B79A5D658E}" Operation="Deleted">
		<Process CmdLine="*system32\svchost.exe*wuauserv*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8B334555-E2B6-3A1B-10ADAF2A1DF0FCE1}" Name="%kl_undef%">
		<Process CmdLine="*system32\svchost.exe*dhcp*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A04549BA-A33F-DDB4-9156A8F8DF90B807}" Name="%kl_undef%">
		<Process CmdLine="*system32\svchost.exe*winhttpautoproxysvc*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1E0A4AAB-09C1-8498-77C4D012FF730002}" Name="%kl_undef%">
		<Process CmdLine="*system32\svchost.exe*winmgmt*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{922C51C9-FD3B-BD00-4DC17C1CEC71EAB3}" Name="%kl_undef%">
		<Process CmdLine="*system32\svchost.exe*wuauserv*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{45B26EF8-E7D0-0CB2-A5BAA620E944D79D}" Name="%kl_undef%">
		<Process Path="*files\microsoft*lync.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CCCBA7EA-96C0-425F-93B6BFABF2636ABD}" Name="%kl_undef%">
		<Process Path="files\microsoft*outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EAB0036F-A7F6-7EA6-3C50453AFD005AD6}" Operation="Deleted">
		<Process Path="*files\microsoft*lync.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{A931F619-F7BF-7CF4-8EF5F90FED146F96}" Operation="Renamed">
		<Process Path="*files\microsoft*lync.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CD8C0266-0DDF-E62A-D9A9FB8230141B32}" Operation="Deleted">
		<Process Path="*files\microsoft*outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1379AC25-9ADC-F82B-D0C3316FC42BC8A6}" Operation="Renamed">
		<Process Path="*files\microsoft*outlook.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{57C6093B-D227-9AFE-1C7748E49204AF26}" Path="*TortoiseGit*">
		<Process Path="*TortoiseGit*">
			<Signature Subject="*Strickroth*" />
		</Process>
	</Registry>
	<Registry Id="{16F1BDF7-FC5A-641E-5E0FBF901CD64E71}" Path="*microsoft visual studio*">
		<Process Path="*microsoft visual studio*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EA34156F-9EF4-7A2D-1E481BD939990AC3}" Path="*microsoft\vscommon*">
		<Process Path="*microsoft visual studio*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{5C3794F0-2140-AB2A-0253661F70048DEC}" Path="*microsoft\visualstudio*">
		<Process Path="*microsoft visual studio*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D89363DA-8739-4127-30EF832E9DD610B2}" Path="*classes\visualstudio*">
		<Process Path="*microsoft visual studio*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F4AA5B89-EC86-E6A6-2ABE990680D06218}" Path="*microsoft\vscommon*">
		<Process Path="*microsoft sql server management studio*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{348B2322-38FB-51E0-C82D82FE6CC163B5}" Path="*google\update">
		<Process Path="*google\update\googleupdate.exe">
			<Signature Subject="*Google*" />
		</Process>
	</Registry>
	<Registry Id="{07DFD6AB-F98A-5868-C5D5748E95301D55}" Path="*software\microsoft\office*">
		<Process Path="*microsoft shared\clicktorun*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{89BFF678-CB12-8FCD-4633BFAD784D224A}" Path="*software\microsoft\intelli*">
		<Process Path="*ipoint.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1CE40821-1875-4413-C37B3EA510FBAB89}" Path="*software\microsoft\intelli*">
		<Process Path="*itype.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F54E60B1-C5C3-2894-1C424D2A63E2D1F2}" Name="extensions.settings" Operation="Deleted" />
	<Registry Id="{5B1EC0D3-CB8A-AC0B-F4E5F737748787E2}" Name="*ping*">
		<Process Path="*iexplore.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{4DBF3788-0CFD-D674-1DD7756549054F6A}" Name="*datetime*">
		<Process Path="*iexplore.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{4574A2A6-DA0C-769C-92495F2DAF7CC664}" Path="*software\jetbrains*">
		<Process Path="*jetbrains*">
			<Signature Subject="*JetBrains*" />
		</Process>
	</Registry>
	<Registry Id="{DE010293-CD86-75F0-D64D3F2B625C5A3E}" Path="*clienttelemetry\rulesmetadata\*.exe*">
		<Process Path="*office*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F2BEAF5C-6608-6924-70CA51A86F0567D4}" Path="*_adal\settings*">
		<Process Path="*office*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8E24AD71-A7E9-7D71-9731059129BF4557}" Name="*.exe*">
		<Process Path="*office*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6A3CD44A-C9E4-EA7A-0D74603441A95AC4}" Name="inputlocale">
		<Process Path="*ctfmon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{1C5731EF-DF5E-1953-E5D0F2B6155B83B4}" Name="%kl_undef%">
		<Process Path="*ctfmon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{01DB8C6F-AEF8-F2CC-C0DB96D482095BF5}" Operation="Deleted">
		<Process Path="*ctfmon.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{73E562E4-8875-35C6-53DEE2F49348CC88}" Path="*microsoft\office*" Operation="Deleted">
		<Process Path="*office*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D74DC70A-0475-D5E9-E965114148757088}" Path="*microsoft\exchange*" Operation="Deleted">
		<Process Path="*office*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{C1C9961A-E6D2-A41C-50E1D77B02451959}" Path="*microsoft\shared tools*" Operation="Deleted">
		<Process Path="*office*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{5245EE4D-30B6-68B6-D91962091EED54C0}" Path="*microsoft*framework*">
		<Process Path="*.net*framework*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CDA11795-B936-5BA7-FE15204F493214EE}" Operation="Deleted">
		<Process Path="*backgroundtaskhost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{7771339B-07D0-513D-F6434D3E585DD747}" Path="*localstate\throttling*">
		<Process Path="*backgroundtaskhost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{C7FA2378-8239-A9B9-8F3EFCB3940EA929}" Value="????????">
		<Process Path="*backgroundtaskhost.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{50275134-4062-1967-695CC133D71E083A}" Value="????????">
		<Process Path="*searchapp.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{5C3210CB-438D-9672-A8E26907DB643E2A}" Path="*microsoft\workspaces*">
		<Process Path="*rundll32.exe" CmdLine="*tsworkspace*">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6C5DFF42-5256-A3AA-B0C4B0246F910220}" Operation="Deleted">
		<Process Path="*searchapp.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{CCDEE094-6F80-843B-E510C61952A22D3F}" Name="taskbar*">
		<Process Path="*explorer.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{6D728921-4D14-6262-4DC88CEE4D27FF4E}" Name="tray*">
		<Process Path="*explorer.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3767004A-A602-4F0A-81ACDEF780A29B1F}" Name="%kl_undef%">
		<Process Path="*mousocoreworker.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{5B7464A0-D4FA-B690-853F26D01267B545}" Name="%kl_undef%">
		<Process Path="*spoolsv.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D0D9FED9-EA17-CC5B-E57ABD3985A66ABA}" Operation="Deleted">
		<Process Path="*mousocoreworker.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{22BDD078-7CCA-A628-1A7CA530F061322D}" Operation="Deleted">
		<Process Path="*spoolsv.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{793EF91A-86BB-7541-108A51E18539F523}" Name="driverstate">
		<Process Path="*spoolsv.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{73D52240-2534-1EC1-3A4A59A05881FA0D}" Name="lasttouched">
		<Process Path="*spoolsv.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{C79E31A7-9AB1-8B59-4BA8DD6F7125352F}" Name="print*">
		<Process Path="*spoolsv.exe">
			<Signature Subject="*Microsoft*" />
		</Process>
	</Registry>
<!-- Part 22: 2023-05-16T15:54:00.000Z-1684252445 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 23: 2023-07-21T16:06:00.000Z-1689955605 -->
	<Registry Id="{BDFB3C6D-BF3E-0646-0BAF9CBF72F6E9E1}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver" Value="%kl_undef%" />
	<Registry Id="{3CBEAD15-4483-C128-69B051B9A494C555}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver" Operation="Deleted" />
	<Registry Id="{69D6B946-CA57-CE05-610E5AE20F9DD16B}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*cisco*">
			<Signature Subject="cisco*" />
		</Process>
	</Registry>
	<Registry Id="{2664A339-D849-3723-2E3F3E696438EC29}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*mozilla*">
			<Signature Subject="mozilla*" />
		</Process>
	</Registry>
	<Registry Id="{9E06BA8D-05ED-B4AB-769D5B8CFA9F58A9}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*program files\hp*">
			<Signature Subject="hp*" />
		</Process>
	</Registry>
	<Registry Id="{C8479BBB-5DC6-0363-922EAB500DC8F7D0}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*program files (x86)\hp*">
			<Signature Subject="hp*" />
		</Process>
	</Registry>
	<Registry Id="{2182B607-E106-B2C1-F143259ED08A88AE}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*adobe*">
			<Signature Subject="adobe*" />
		</Process>
	</Registry>
	<Registry Id="{B1E5A344-DF90-FCA1-9AA50CBF2FA6AD11}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*application\chrome.exe">
			<Signature Subject="Google*" />
		</Process>
	</Registry>
	<Registry Id="{3BB7024F-699A-C720-5F00F59389AA5A6A}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process CmdLine="*svchost*gpsvc*">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{5EB360BD-E8BF-C2AD-ADD96B700FA6B957}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*application\msedge.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{28823FAA-7D18-5A56-1F2C278844F568E6}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*current\teams.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{202DA015-F523-5CA9-3AB5FED1147D1EBF}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*onedrive\onedrivestandaloneupdater.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{97A81240-DBF1-ACFD-030375F28510B66C}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*system32\msfeedssync.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{9BBD1DA0-0796-4777-BBBCF162BB1F50F7}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*office*">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{F2E3DC74-87BB-394E-77286B61CE36BFBC}" Path="\registry\user\*software\microsoft\windows\currentversion\internet settings" Name="proxyserver">
		<Process Path="*immersivecontrolpanel\systemsettings.exe">
			<Signature Subject="Microsoft*" />
		</Process>
	</Registry>
<!-- Part 23: 2023-07-21T16:06:00.000Z-1689955605 -->
<!-- ############################################################################################################### -->

<!-- ############################################################################################################### -->
<!-- Part 24: 2023-08-15T18:03:00.000Z-1692122610 -->
	<Registry Id="{1C98139D-254C-D2B8-A3F9514D71069207}" Path="\registry\a\{*}\events\{*" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{35B53696-9884-2206-36C240D886F394EB}" Path="\registry\a\{*}\workitems\{*" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{30B9A202-F71D-9970-2400A3F622F744B6}" Path="\registry\MACHINE\software\microsoft\windows\currentversion\group policy\datastore\*" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EA4FBBEC-D7ED-20D6-6E45653388DBC97A}" Path="\registry\MACHINE\software\microsoft\systemcertificates\windows live id token issuer\certificates\2c85006a1a028bcc349df23c474724c055fde8b6" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{34F105AB-58F6-89BC-3C4D34F5F9AA184C}" Path="\registry\MACHINE\software\microsoft\systemcertificates\windows live id token issuer\certificates\b68d8f953e551914324e557e6164d68b9926650c" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{4A5142FE-FAD1-0255-06604DD07A73696F}" Path="\registry\MACHINE\software\microsoft\systemcertificates\windows live id token issuer\certificates\0217922ca1b6f0bd0f1d7ff6e7bdc29b2faaa060" Name="%kl_undef%">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{EA92984C-C7C3-D72E-4445B75063622898}" Path="\registry\MACHINE\software\microsoft\identitycrl\throttlecache*" Name="throttlestartedtime">
		<Process Path="*svchost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{D527CE5B-5CFA-467B-29C1AC871BF31EB2}" Path="*localstate\placements*" Name="*ids">
		<Process Path="*backgroundtaskhost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{3FB88117-6404-6D1A-47EF5E7A54D30E12}" Path="*localstate\placements*" Name="next*">
		<Process Path="*backgroundtaskhost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
	<Registry Id="{8726754D-AA6C-CBAC-E66A19BC016C6817}" Path="*localstate\placements*" Name="*rendertriggers">
		<Process Path="*backgroundtaskhost.exe">
			<Signature Subject="microsoft*" />
		</Process>
	</Registry>
<!-- Part 24: 2023-08-15T18:03:00.000Z-1692122610 -->
<!-- ############################################################################################################### -->

</Filters>