Updated: November 15, 2007 9:34:31 PM
Type: Misleading Application
Infection Length: 119,304 bytes
Name: CryptDrive
Version: 1.1.116.1
Risk Impact: Medium
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000
BehaviorThis misleading application must be manually installed.

The program gives a number of exaggerated reports about potential risks on the computer.

The user is then prompted to pay for a full license for the application in order to remove the errors.
The program also connects to the following locations:
- [http://]slogs.cryptdrive.com[REMOVED]
- [http://]setup.cryptdrive.com/files/CryptDrive[REMOVED]
InstallationWhen the program is executed, it creates the following files:
- C:\Documents and Settings\Administrator\Application Data\CryptDrive\CryptDrive\Schedule\schedule.sav
- C:\Documents and Settings\Administrator\Application Data\CryptDrive\settings.config
- C:\Documents and Settings\Administrator\Application Data\CryptDrive\Update.sav
- C:\Documents and Settings\Administrator\Cookies\administrator@cryptdrive[1].txt
- C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
- C:\Documents and Settings\Administrator\Desktop\CryptDrive Free.lnk
- C:\Documents and Settings\Administrator\My Crypted Drives\DPMM.dks
- C:\Documents and Settings\Administrator\My Crypted Drives\drive.log
- C:\Documents and Settings\All Users\Start Menu\Programs\CryptDrive Free\CryptDrive Free on the Web.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\CryptDrive Free\CryptDrive Free.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\CryptDrive Free\Uninstall CryptDrive Free.lnk
- C:\Program Files\CryptDrive\Activate.dat
- C:\Program Files\CryptDrive\atl71.dll
- C:\Program Files\CryptDrive\BlockEng.exe
- C:\Program Files\CryptDrive\bnlink.dat
- C:\Program Files\CryptDrive\cdr.exe
- C:\Program Files\CryptDrive\cdr.exe.manifest
- C:\Program Files\CryptDrive\cdr.url
- C:\Program Files\CryptDrive\cdr.xml
- C:\Program Files\CryptDrive\CDTbar.dll
- C:\Program Files\CryptDrive\dbghelp.dll
- C:\Program Files\CryptDrive\err.log
- C:\Program Files\CryptDrive\fibl.dll
- C:\Program Files\CryptDrive\install.exe
- C:\Program Files\CryptDrive\InstHelp.exe
- C:\Program Files\CryptDrive\lapv.dat
- C:\Program Files\CryptDrive\license.rtf
- C:\Program Files\CryptDrive\manual.pdf
- C:\Program Files\CryptDrive\mfc71.dll
- C:\Program Files\CryptDrive\msvcp71.dll
- C:\Program Files\CryptDrive\msvcr71.dll
- C:\Program Files\CryptDrive\ps.dat
- C:\Program Files\CryptDrive\pv.dat
- C:\Program Files\CryptDrive\readme.rtf
- C:\Program Files\CryptDrive\SafeOper.dll
- C:\Program Files\CryptDrive\SDShExt.dll
- C:\Program Files\CryptDrive\sr.log
- C:\Program Files\CryptDrive\ucdcheck.dll
- C:\Program Files\CryptDrive\ucdcw.exe
- C:\Program Files\CryptDrive\unins000.dat
- C:\Program Files\CryptDrive\unins000.exe
- C:\Program Files\CryptDrive\up.dat
- C:\Program Files\CryptDrive\updater.dat
- C:\WINDOWS\system32\drivers\drvprt.sys
- C:\WINDOWS\system32\drivers\FIBL.sys
Next, the program creates the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\CryptDrive
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\CryptDrive2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BlockEngine.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A31FD134-41E3-4EDC-8562-4EC2174B7760}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B3EC7F9-57E1-4984-9CCD-B43B8EABFCD0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B3EC7F9-57E1-4984-9CCD-B43B8EABFCD0}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B3EC7F9-57E1-4984-9CCD-B43B8EABFCD0}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B3EC7F9-57E1-4984-9CCD-B43B8EABFCD0}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B3EC7F9-57E1-4984-9CCD-B43B8EABFCD0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B3EC7F9-57E1-4984-9CCD-B43B8EABFCD0}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28D2C24E-7F71-4B2C-86D8-5EC1AD73AFD6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28D2C24E-7F71-4B2C-86D8-5EC1AD73AFD6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28D2C24E-7F71-4B2C-86D8-5EC1AD73AFD6}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28D2C24E-7F71-4B2C-86D8-5EC1AD73AFD6}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28D2C24E-7F71-4B2C-86D8-5EC1AD73AFD6}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28D2C24E-7F71-4B2C-86D8-5EC1AD73AFD6}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B423C-DB81-45EC-B02C-962CA14EB2B1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B423C-DB81-45EC-B02C-962CA14EB2B1}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B423C-DB81-45EC-B02C-962CA14EB2B1}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B423C-DB81-45EC-B02C-962CA14EB2B1}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B423C-DB81-45EC-B02C-962CA14EB2B1}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B423C-DB81-45EC-B02C-962CA14EB2B1}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46008301-AF55-4788-9834-28B182CD6DAA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46008301-AF55-4788-9834-28B182CD6DAA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46008301-AF55-4788-9834-28B182CD6DAA}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46008301-AF55-4788-9834-28B182CD6DAA}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46008301-AF55-4788-9834-28B182CD6DAA}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46008301-AF55-4788-9834-28B182CD6DAA}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FBC3704-5B9F-459F-9D4E-2CA97E9D266B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FBC3704-5B9F-459F-9D4E-2CA97E9D266B}\Implemented Categories
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FBC3704-5B9F-459F-9D4E-2CA97E9D266B}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FBC3704-5B9F-459F-9D4E-2CA97E9D266B}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FBC3704-5B9F-459F-9D4E-2CA97E9D266B}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B488E78-3548-4CBC-8828-781EFB6C771B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B488E78-3548-4CBC-8828-781EFB6C771B}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B488E78-3548-4CBC-8828-781EFB6C771B}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B488E78-3548-4CBC-8828-781EFB6C771B}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B488E78-3548-4CBC-8828-781EFB6C771B}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B488E78-3548-4CBC-8828-781EFB6C771B}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B201FC48-33F7-4709-A519-2A8226F488BE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B201FC48-33F7-4709-A519-2A8226F488BE}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B201FC48-33F7-4709-A519-2A8226F488BE}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B201FC48-33F7-4709-A519-2A8226F488BE}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B201FC48-33F7-4709-A519-2A8226F488BE}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B201FC48-33F7-4709-A519-2A8226F488BE}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA9F5F72-18AC-43E8-9FF6-A4A7463F581C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA9F5F72-18AC-43E8-9FF6-A4A7463F581C}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA9F5F72-18AC-43E8-9FF6-A4A7463F581C}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA9F5F72-18AC-43E8-9FF6-A4A7463F581C}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA9F5F72-18AC-43E8-9FF6-A4A7463F581C}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA9F5F72-18AC-43E8-9FF6-A4A7463F581C}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\CryptDrive
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D27F0F6-418C-4645-BB9B-F1D75EB4E7EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D27F0F6-418C-4645-BB9B-F1D75EB4E7EF}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D27F0F6-418C-4645-BB9B-F1D75EB4E7EF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D27F0F6-418C-4645-BB9B-F1D75EB4E7EF}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23913E4D-FCC3-4F2D-A027-8766DD561D66}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23913E4D-FCC3-4F2D-A027-8766DD561D66}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23913E4D-FCC3-4F2D-A027-8766DD561D66}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23913E4D-FCC3-4F2D-A027-8766DD561D66}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3213BE8D-02EB-4DDF-B7F8-9501463E63D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3213BE8D-02EB-4DDF-B7F8-9501463E63D6}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3213BE8D-02EB-4DDF-B7F8-9501463E63D6}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3213BE8D-02EB-4DDF-B7F8-9501463E63D6}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CD0567F-493A-4AC8-8542-00427917BFFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CD0567F-493A-4AC8-8542-00427917BFFF}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CD0567F-493A-4AC8-8542-00427917BFFF}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CD0567F-493A-4AC8-8542-00427917BFFF}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AE6710D-B16A-4AEE-B96C-C93439CBD814}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AE6710D-B16A-4AEE-B96C-C93439CBD814}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AE6710D-B16A-4AEE-B96C-C93439CBD814}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9AE6710D-B16A-4AEE-B96C-C93439CBD814}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B92B5A9F-39ED-4FD0-8D10-28B95D022A11}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B92B5A9F-39ED-4FD0-8D10-28B95D022A11}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B92B5A9F-39ED-4FD0-8D10-28B95D022A11}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B92B5A9F-39ED-4FD0-8D10-28B95D022A11}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C721E836-3E81-43F4-971F-4A6E324E2561}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C721E836-3E81-43F4-971F-4A6E324E2561}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C721E836-3E81-43F4-971F-4A6E324E2561}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C721E836-3E81-43F4-971F-4A6E324E2561}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7FB27A8-A84C-4EA5-95DF-732092DDC018}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7FB27A8-A84C-4EA5-95DF-732092DDC018}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7FB27A8-A84C-4EA5-95DF-732092DDC018}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7FB27A8-A84C-4EA5-95DF-732092DDC018}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0CCB715F-EA4E-4AFA-AA31-9B3EFC5FC803}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0CCB715F-EA4E-4AFA-AA31-9B3EFC5FC803}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0CCB715F-EA4E-4AFA-AA31-9B3EFC5FC803}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0CCB715F-EA4E-4AFA-AA31-9B3EFC5FC803}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0CCB715F-EA4E-4AFA-AA31-9B3EFC5FC803}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0CCB715F-EA4E-4AFA-AA31-9B3EFC5FC803}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19D73FC5-BA35-458E-B68D-0E79816F78BD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19D73FC5-BA35-458E-B68D-0E79816F78BD}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19D73FC5-BA35-458E-B68D-0E79816F78BD}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19D73FC5-BA35-458E-B68D-0E79816F78BD}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19D73FC5-BA35-458E-B68D-0E79816F78BD}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{19D73FC5-BA35-458E-B68D-0E79816F78BD}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A31FD134-41E3-4EDC-8562-4EC2174B7760}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A31FD134-41E3-4EDC-8562-4EC2174B7760}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A31FD134-41E3-4EDC-8562-4EC2174B7760}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A31FD134-41E3-4EDC-8562-4EC2174B7760}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A31FD134-41E3-4EDC-8562-4EC2174B7760}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A31FD134-41E3-4EDC-8562-4EC2174B7760}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D42D40E8-16CB-4D71-80D1-A0FD7303A35C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D42D40E8-16CB-4D71-80D1-A0FD7303A35C}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D42D40E8-16CB-4D71-80D1-A0FD7303A35C}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D42D40E8-16CB-4D71-80D1-A0FD7303A35C}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D42D40E8-16CB-4D71-80D1-A0FD7303A35C}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D42D40E8-16CB-4D71-80D1-A0FD7303A35C}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cde
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cde\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cde\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cde\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dck
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dck\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dck\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dck\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dcr
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dcr\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dcr\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dcr\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlockEngine.FileBlockEngine
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlockEngine.FileBlockEngine\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlockEngine.FileBlockEngine\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlockEngine.FileBlockEngine.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlockEngine.FileBlockEngine.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDToolbar.ShellBand
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDToolbar.ShellBand\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDToolbar.ShellBand\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDToolbar.ShellBand.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDToolbar.ShellBand.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Encrypted
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Encrypted\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Encrypted\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Encrypted\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Encrypted\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage key\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage key\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage key\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CryptDrive.Storage key\shell\open\command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.EncryptFile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.EncryptFile\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.EncryptFile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.EncryptFile.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.EncryptFile.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.SecureDelete
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.SecureDelete\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.SecureDelete\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.SecureDelete.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SafeFileOperations.SecureDelete.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.ClearRecycleExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.ClearRecycleExt\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.ClearRecycleExt\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.ClearRecycleExt.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.ClearRecycleExt.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.EncryptFileExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.EncryptFileExt\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.EncryptFileExt\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.EncryptFileExt.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.EncryptFileExt.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.SecureDeleteExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.SecureDeleteExt\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.SecureDeleteExt\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.SecureDeleteExt.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SDShellExt.SecureDeleteExt.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WSC.ProductCheckerUCD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WSC.ProductCheckerUCD\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UCD_is1
HKEY_LOCAL_MACHINE\SOFTWARE\5110000C29C4E1F4
HKEY_LOCAL_MACHINE\SOFTWARE\CryptDrive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{46008301-AF55-4788-9834-28B182CD6DAA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ucdcw
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CryptDrive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B201FC48-33F7-4709-A519-2A8226F488BE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DRVPRT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DRVPRT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DRVPRT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FIBL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FIBL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FIBL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DrvPrt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DrvPrt\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DrvPrt\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fibl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fibl\blocked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fibl\log
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fibl\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fibl\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DrvPrt
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DrvPrt\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DrvPrt\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fibl
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fibl\blocked
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fibl\log
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fibl\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fibl\Enum
HKEY_USERS\S-1-5-21-1343024091-1336601894-839522115-500\Software\CryptDrive
HKEY_USERS\S-1-5-21-1343024091-1336601894-839522115-500\Software\CryptDrive\Options