System Reset WU Settings HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate [SusClientIdValidation] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate [SusClientId] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [ElevateNonAdmins] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [AUOptions] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [IncludeRecommendedUpdates] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Services\* [*] HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\* [*] HKCU\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\* [*] System Reset Privacy Settings Settings HKLM\Software\Microsoft\Windows\CurrentVersion\DriverSearching [SearchOrderConfig] HKLM\Software\Microsoft\Windows\CurrentVersion\Device Metadata [PreventDeviceMetadataFromNetwork] HKLM\Software\Microsoft\Internet Explorer\PhishingFilter [EnabledV9] HKLM\SOFTWARE\Policies\Microsoft\Windows\System [EnableSmartScreen] HKLM\Software\Microsoft\Windows\CurrentVersion\AppHost [EnableWebContentEvaluation] HKLM\Software\Microsoft\Windows Defender\Spynet [SpyNetReporting] HKLM\Software\Microsoft\Sensors\LocationProvider [CSEnable] HKLM\Software\Microsoft\Assistance\Client\1.0\Settings [GlobalImplicitFeedback] HKLM\Software\Microsoft\Assistance\Client\1.0\Settings [GlobalOnlineAssist] HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy [EnableQueryRemoteServer] HKLM\Software\Microsoft\MSDE\Policy [DefaultQueryRemoteServer] HKLM\Software\Microsoft\Internet Explorer\BrowserEmulation [MSCompatibilityMode] HKLM\Software\Microsoft\Windows\CurrentVersion\AccountPicture [AppsReadAccess] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Sensor\Overrides\{BFA794E4-F964-4FDB-90F6-51056BFE4B44} [SensorPermissionState] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer [SmartScreenEnabled] HKLM\Software\Microsoft\Internet Explorer\Main [DoNotTrack] HKLM\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo\* [*] HKLM\Software\Policies\Microsoft\Windows\AdvertisingInfo\* [*] HKLM\Software\Microsoft\Personalization\Settings [AcceptedPrivacyPolicy] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer [SmartScreenEnabled] HKLM\SOFTWARE\Policies\Microsoft\Windows\System [EnableSmartScreen] HKCU\Software\Microsoft\Internet Explorer\PhishingFilter [EnabledV9] HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost [EnableWebContentEvaluation] HKCU\Software\Microsoft\Assistance\Client\1.0\Settings [ImplicitFeedback] HKCU\Software\Microsoft\Assistance\Client\1.0\Settings [OnlineAssist] HKCU\Software\Microsoft\Assistance\Client\1.0\Settings [FirstTimeHelppaneStartup] HKCU\Software\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy [EnableQueryRemoteServer] HKCU\Software\Microsoft\Internet Explorer\BrowserEmulation [MSCompatibilityMode] HKCU\Software\Microsoft\Windows\CurrentVersion\AccountPicture [AppsReadAccess] HKCU\Software\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44} [SensorPermissionState] HKCU\Software\Microsoft\Internet Explorer\Main [DoNotTrack] HKCU\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo\* [*] HKCU\Software\Microsoft\Personalization\Settings [AcceptedPrivacyPolicy] System Reset Logon Screen Settings HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DefaultUserName] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DefaultDomainName] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DefaultPassword] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoAdminLogon] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoLogonCount] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ForceAutoLogon] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [IgnoreShiftOverride] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DontDisplayLastUserName] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DontDisplayLockedUserId] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ShutdownWithoutLogon] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\* [*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCAD] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI [LastLoggedOnProvider] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI [LastLoggedOnUser] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI [LastLoggedOnSAMUser] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\BootAnimation [DisableStartupSound] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\PLAP Providers HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI [ButtonSet] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI [ShowTabletKeyboard] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Background [OEMBackground] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI [LastLoggedOnUserSID] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\AccessPage\UserConfigurableSettings [Enabled] HKLM\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\PatternLogonEnrollment [*] System Reset Internationalization Settings HKU\.Default\Keyboard Layout\* [*] HKU\.Default\Control Panel\International [Locale] HKU\.Default\Control Panel\International [LocaleName] HKU\.Default\Control Panel\International\Geo [Nation] HKU\.Default\Software\Microsoft\CTF\* [*] HKCU\Keyboard Layout\* [*] HKCU\Control Panel\International [Locale] HKCU\Control Panel\International [LocaleName] HKCU\Control Panel\International\Geo [Nation] HKCU\Control Panel\International\Calendars\* [*] HKCU\Control Panel\International\User Profile\* [*] HKCU\Software\Microsoft\CTF\* [*] HKCU\Software\Microsoft\TabletTip\1.7 [Enable12KeyLayout] HKCU\Software\Microsoft\TabletTip\1.7 [EnableMultitap] System Reset Personalization Settings %CSIDL_LOCAL_APPDATA%\Microsoft\Feeds\* [*] %CSIDL_LOCAL_APPDATA%\Microsoft\Feeds Cache\* [*] %CSIDL_INTERNET_CACHE%\Enclosure\* [*] %CSIDL_LOCAL_APPDATA%\Microsoft\Windows\themes\* [*] %CSIDL_APPDATA%\Microsoft\Windows\themes\* [*] HKCU\Control Panel\* [*] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\* [*] HKCU\Software\Microsoft\Windows\DWM\* [*] HKCU\AppEvents\Schemes\* [*] HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\* [*] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent [*] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [StoreAppsOnTaskbar] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage [OpenAtLogon] HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\Launcher [ShowPowerButtonOnStartScreen] HKCU\Software\Microsoft\Windows\CurrentVersion\Lock Screen\* [*] HKCU\Software\Microsoft\Feeds\* [*] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [EnableStartMenu] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_PowerButtonAction] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_TrackDocs] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_TrackProgs] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_JumpListItems] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_EnableDragDrop] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_NotifyNewApps] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_AutoCascade] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_ShowRecentDocs] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_SearchFiles] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_SearchPrograms] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_SortByName] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_AdminToolsRoot] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced [Start_LargeMFUIcons] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer [GridPaneRowCount] %PROFILESFOLDER%\Public\AccountPictures\* [*] %PROGRAMDATA%\Microsoft\Windows\SystemData\* [*] %PROGRAMDATA%\Microsoft\User Account Pictures\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\AccountPicture\Users\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\SystemProtectedUserData\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\DesktopOptimization\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\Launcher [ShowPowerButtonOnStartScreen] Defender Settings HKLM\Software\Microsoft\Windows Defender\Signature Updates [SignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [SignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [SignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [SignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [SignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [NISSignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [NISSignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [NISSignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [DefaultEngineExpirationTime] HKLM\Software\Microsoft\Windows Defender\Exclusions\Extensions [*] HKLM\Software\Microsoft\Windows Defender\Exclusions\Paths [*] HKLM\Software\Microsoft\Windows Defender\Exclusions\Processes [*] HKLM\System\Current Control Set\Services\WdBoot [Signatures] HKLM\Software\Microsoft\RemovalTools\MRT [GUID] HKLM\Software\Microsoft\Windows Defender\Signature Updates [SignatureLocation] HKLM\Software\Microsoft\Windows Defender\Signature Updates [NISSignatureLocation] System Reset Connected Account Settings %CSIDL_LOCAL_APPDATA%\Microsoft\Vault\* [*] %CSIDL_LOCAL_APPDATA%\Microsoft\Credentials\* [*] HKCU\Software\Microsoft\IdentityCRL\Immersive\* [*] HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync [SyncPolicy] HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\Groups\* [*] HKU\.DEFAULT\Software\Microsoft\IdentityCRL\* [*] Bitlocker Settings HKCU\Software\Microsoft\Windows\CurrentVersion\FveAutoUnlock\* [*] Network Settings HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList [FirstNetwork] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList [FirstNetwork] App Data HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\$\PersistedStorageItemTable\* [*] WLAN User Settings HKCU\Software\Microsoft\Wlansvc\UserData\Profiles\* [*] WLAN Settings HKLM\Software\Microsoft\Wlansvc\MigrationData\* [*] %CSIDL_COMMON_APPDATA%\Microsoft\Wlansvc\MigrationData\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Wlansvc [Start] HKLM\Software\Microsoft\Wlansvc\MigrationData\* [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\WlanAPIPermissions [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\HostedNetworkSettings [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\OneXAuthenticator [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\WFDProvPlugin [*] HKLM\Software\Microsoft\Wlansvc [ShowDeniedNetworks] HKLM\Software\Microsoft\Wlansvc [GlobalParameters] HKLM\Software\Microsoft\Wlansvc\DisableBackgroundScanOptimization [*] HKLM\Software\Microsoft\Wlansvc\* [*] HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless\GPTWirelessPolicy\* [*] HKLM\Software\Microsoft\Wlansvc\GroupPolicy\* [*] %CSIDL_COMMON_APPDATA%\Microsoft\Wlansvc\Profiles\* [*] %WINDIR%\wlansvc\policies\* [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\WlanAPIPermissions [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\HostedNetworkSettings [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\OneXAuthenticator [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\WFDProvPlugin [*] HKLM\Software\Microsoft\Wlansvc\* [*] HKLM\Software\Microsoft\Wlansvc [ShowDeniedNetworks] HKLM\Software\Microsoft\Wlansvc\DisableBackgroundScanOptimization [*] HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless\GPTWirelessPolicy\* [*] HKLM\SOFTWARE\Microsoft\Wlansvc\GroupPolicy\Profiles\* [*] %CSIDL_COMMON_APPDATA%\Microsoft\Wlansvc\Profiles\* [*] %WINDIR%\wlansvc\policies\* [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\WlanAPIPermissions [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\HostedNetworkSettings [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\OneXAuthenticator [*] HKLM\SYSTEM\CurrentControlSet\Services\WLANSVC\Parameters\WFDProvPlugin [*] HKLM\Software\Microsoft\Wlansvc [ShowDeniedNetworks] HKLM\Software\Microsoft\Wlansvc\DisableBackgroundScanOptimization [*] HKLM\SOFTWARE\Microsoft\WLANSVC\MigrationData [WLANSVCMigrationDone] dword 00000000 MigXmlHelper.IsUpgrade() MigXmlHelper.DoesStringContentEqual("Registry","HKLM\SYSTEM\CurrentControlSet\Services\Wlansvc [Start]","0x00000002") ESD Settings HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\WebSetup\* [*] Windows Anytime Upgrade Base Edition Settings HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsAnytimeUpgrade [BaseEditionId] Telemetry Settings HKLM\SOFTWARE\Microsoft\Reliability Analysis\RAC [RacSampleNumber] HKLM\SOFTWARE\Microsoft\Reliability Analysis\RAC [RacSqmId] %ProgramData%\Microsoft\RAC\Outbound\* [*] HKLM\SOFTWARE\Microsoft\SQMClient [CabSessionAfterSize] HKLM\SOFTWARE\Microsoft\SQMClient [MachineID] HKLM\SOFTWARE\Microsoft\SQMClient\Windows [CabSessionAfterSize] HKLM\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\* [*] HKLM\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\Throttling\* [*] %ProgramData%\Microsoft\Windows\Sqm\Upload\* [*] %ProgramData%\Microsoft\Windows\Sqm\Manifest\* [*] HKLM\SOFTWARE\Microsoft\SQMClient\Windows [CEIPEnable] HKLM\SOFTWARE\Microsoft\SQMClient\Windows\Users [*] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting [MachineID] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent [*] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications [*] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Hangs [*] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\HeapControlledList\* [*] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModules [*] HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR [*] %ProgramData%\Microsoft\Windows\WER\ReportQueue\* [*] HKLM\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\* [*] reg copy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\MigManifestInfo HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo /f reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\MigManifestInfo /f HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent [*] HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications [*] HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Hangs [*] HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\HeapControlledList\* [*] HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModules [*] HKCU\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR [*] %CSIDL_LOCAL_APPDATA%\Microsoft\Windows\WER\ReportQueue\* [*] History Vault Settings HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\FileHistory\* [*] %CSIDL_LOCAL_APPDATA%\Microsoft\Windows\FileHistory\* [*] %PROFILESFOLDER%\public\DataProtection\* [*] HKLM\System\CurrentControlSet\Services\dpsvc\Parameters\Configs\* [*] HKLM\System\CurrentControlSet\Services\dpsvc [Start] %PROFILESFOLDER%\public\FileHistory\* [*] HKLM\System\CurrentControlSet\Services\fhsvc\Parameters\Configs\* [*] HKLM\System\CurrentControlSet\Services\fhsvc [Start] HKLM\System\CurrentControlSet\Services\fhsvc [DelayedAutostart] IME Settings HKCU\Software\Microsoft\IME\15.0\IMEJP\Dictionaries\* [*] %CSIDL_APPDATA%\Microsoft\IME\15.0\* [*] %CSIDL_LOCAL_APPDATA%\Microsoft\IME\15.0\* [*] %FOLDERID_LocalAppDataLow% %FOLDERID_LocalAppDataLow%\Microsoft %FOLDERID_LocalAppDataLow%\Microsoft\IME\15.0\* [*] %CSIDL_APPDATA%\Microsoft\Proof [custom.hhd] %CSIDL_APPDATA%\Microsoft\InputMethod\Shared [jpnIHDS.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Shared [korIHDS.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Chs [ChsPinyinIH.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Chs [ChsPinyinUDL.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Cht [ChtChangjieUDL.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Cht [ChtPhoneticUDL.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Cht [ChtQuickUDL.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Shared [ChtPhoneticIHDS.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Shared [ChtChangjieIHDS.dat] %CSIDL_APPDATA%\Microsoft\InputMethod\Shared [ChtQuickIHDS.dat] HKCU\Software\Microsoft\IME\15.0\* [*] HKCU\Software\AppDataLow\Software\Microsoft\IME\15.0\* [*] HKCU\Software\Microsoft\InputMethod\JPN\Roaming [InvalidateTime] HKCU\Software\Microsoft\InputMethod\KOR\Roaming [InvalidateTime] HKCU\Software\Microsoft\InputMethod\KOR\Settings [EnablePersonalization] HKCU\Software\Microsoft\InputMethod\Settings\* [*] HKCU\Software\Microsoft\TabletTip\1.7 [EnableMultiTap] HKCU\Software\Microsoft\TabletTip\1.7 [UseKorDblTap] HKCU\Software\Microsoft\IME\15.0\IMEJP\Dictionaries [LearningLevel] HKCU\Software\Microsoft\IME\15.0\IMEJP\Dictionaries [MemoryLearning] HKLM\Software\Microsoft\InputMethod\JPN\DUSTATE [*] HKLM\Software\Microsoft\InputMethod\JPN\DICTS [*] HKLM\Software\Microsoft\InputMethod\KOR\DUSTATE [*] HKLM\Software\Microsoft\InputMethod\KOR\DICTS [*] HKLM\Software\Microsoft\InputMethod\SHARED\FileNameRedirection %WINDIR%\IME\IMESC\Dicts\DictUpdate\* [*] System Reset One Shot Executor HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{872f8dc8-dde4-43bd-ac7a-e3d9fe86ceac} [AutoStart] HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{872f8dc8-dde4-43bd-ac7a-e3d9fe86ceac} [AutoStart] String Licensing Service HKU\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\WSService [NextTlrLicense] Desktop Icons HKCU\Software\Microsoft\Windows\Shell\BagMRU\* [*] HKCU\Software\Microsoft\Windows\Shell\Bags\* [*] Windows Live HKLM\SOFTWARE\Microsoft\SystemCertificates\Windows Live ID Token Issuer\Certificates\* [*] HKCU\Software\Microsoft\AuthCookies\Live\Default\* [*] TPM Properties %CSIDL_LOCAL_APPDATA%\Microsoft\Crypto\PCPKSP\* [*] %WINDIR%\ServiceProfiles\LocalService\AppData\Local\Microsoft\Crypto\PCPKSP\* [*] %WINDIR%\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Crypto\PCPKSP\* [*] %WINDIR%\System32\config\systemprofile\AppData\Local\Microsoft\Crypto\PCPKSP\* [*] HKLM\System\CurrentControlSet\Services\TPM\* [*] HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft Platform Crypto Provider\Properties [*] Machine Certificates HKLM\SOFTWARE\Microsoft\SystemCertificates\My\* [*] Windows Biometric Service HKLM\System\CurrentControlSet\Services\WbioSrvc\Parameters [EnrollmentCommitted] %WINDIR%\System32\WinBioDatabase\* [*] Update my apps automatically Settings HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsStore\WindowsUpdate [AutoDownload] EAS security policies are not retained after PBR HKLM\SYSTEM\CurrentControlSet\Control\EAS\Policies\* [*] HKLM\SYSTEM\CurrentControlSet\Control\EAS [*] Windows RT Office OOBE Settings MigXmlHelper.IsCPUArchitecture("arm") HKLM\SOFTWARE\Microsoft\Office\Common\Internet [UseOnlineContent] HKLM\SOFTWARE\Microsoft\Office\Common [QMEnable] HKLM\SOFTWARE\Microsoft\Office\Common [UpdateReliabilityData] Selfhost and Flighting settings HKLM\SOFTWARE\Microsoft\WindowsSelfHost\Applicability\* [*] %PROGRAMDATA%\Microsoft\Windows\Service Configuration\Configurations\* [*.cfg] Cached logon data for MSA and AAD accounts HKLM\Software\Microsoft\IdentityStore\Providers\* [*] HKLM\Software\Microsoft\IdentityStore\LogonCache\* [*] %SYSTEM32%\config\SystemProfile\Appdata\Local\Microsoft\Windows\CloudAPCache\* [*] Microsoft Passport Containers %WINDIR%\ServiceProfiles\LocalService\AppData\Local\Microsoft\NGC\* [*] Azure AD Join State HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WorkplaceJoin\* [*]