NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentVersion Operating system: version number
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\InstallDate Operating system: installation date
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProductId Operating system: product id
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProductName Operating system: name
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\RegisteredOwner Operating system: name of registered person
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization Operating system: name of registered organization
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber Operating system: build number
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentType Operating system: processor architecture
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\CSDVersion Operating system: service pack
NT HKLM\System\Select\Current Number of control set that is currently active
NT HKLM\System\ControlSet*\Services\DMIO\Boot Info\Primary Disk Group\* Last removable disk mounted into system
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\Device Default printer
NT HKLM\SYSTEM\ControlSet*\Enum\ACPI\*\_0\FriendlyName CPU: Friendlyname
NT HKLM\SYSTEM\ControlSet*\Enum\IDE\*\*\FriendlyName IDE: FriendlyName
NT HKLM\SYSTEM\ControlSet*\Enum\FDC\*\*\HardwareID Floppydrive
NT HKLM\SYSTEM\ControlSet*\Enum\SCSI\*\*\FriendlyName SCSI: FriendlyName
NT HKLM\SYSTEM\ControlSet*\Enum\DISPLAY\*\*\DeviceDesc Display: Device Description
NT HKLM\SYSTEM\ControlSet*\Enum\PCIIDE\*\*\HardwareID IDE Channel: Hardware ID
NT HKLM\SYSTEM\ControlSet*\Enum\SW\*\*\DeviceDesc Audio: Device Description
NT HKLM\SYSTEM\ControlSet*\Enum\USBSTOR\*\*\FriendlyName USB Storage: Friendly Name
NT HKLM\SYSTEM\ControlSet*\Enum\PCI\*\*\DeviceDesc PCI: Device Description
NT HKLM\System\ControlSet*\Control\TimeZoneInformation\StandardName User-configured time zone
NT HKLM\System\ControlSet*\Control\TimeZoneInformation\DaylightName User-configured daylight savings time
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText Legal notice text appearing before logon
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption Legal notice caption appearing before logon
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\* User-specific directories
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\* User-specific directories
NT HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultUserName Last logged on user
NT HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName Domain that last user logged on to
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\*\ProfileLoadTimeHigh Profile load time of user
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\*\ProfileLoadTimeLow Profile load time low of user
NT HKLM\System\ControlSet*\Control\Windows\ShutdownTime Time of last system shutdown
NT HKLM\System\ControlSet*\Services\LanManServer\Shares\* Shared folders
NT HKCU\Network\*\RemotePath Path of mapped network drive
NT HKCU\Network\*\ProviderName Type of network
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\*\Description Model description of installed network card
NT HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\*\ServiceName Unique identifier for installed network cards
NT HKLM\System\ControlSet001\Services\{*}\Parameters\Tcpip\* Parameters of network card like IP address
NT HKLM\System\ControlSet002\Services\{*}\Parameters\Tcpip\* Parameters of network card like IP address
NT HKLM\System\ControlSet003\Services\{*}\Parameters\Tcpip\* Parameters of network card like IP address
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Logon User Name Name of registered user
NT HKCU\Environment\* System environment variables
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\AccountName User-defined account name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail User Name Hotmail?
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail Password2 Hotmail?
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 User Name Incoming mail: user name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Server Incoming mail: server name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Email Address Incoming mail: email address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Reply To Email Address Incoming mail: reply-to address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Signature Outgoing mail: signature
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Server Outgoing mail: server name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP User Name Outgoing mail: user name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Display Name Outgoing mail: display name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Email Address Outgoing mail: email address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Reply To Email Address Outgoing mail: reply-to address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Signature Newsgroup: signature
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP User Name Newsgroup: user name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Display Name Newsgroup: display name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Server Newsgroup: server name
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Email Address Newsgroup: email address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP ReplyTo Newsgroup: reply-to address
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Server LDAP Server
NT HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Url LDAP URL
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\InstallTheme Installed wallpaper/desktop theme
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme\Wallpaper Last installed wallpaper/desktop theme
NT HKCU\Control Panel\Desktop\ConvertedWallpaper Converted desktop wallpaper
NT HKCU\Control Panel\Desktop\Wallpaper Bitmap desktop wallpaper
NT HKCU\Control Panel\Desktop\OriginalWallpaper Original Bitmap desktop wallpaper
NT HKCU\Control Panel\Desktop\SCRNSAVE.EXE Screensaver
NT HKCU\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections\*\* Foreign host name and shared resources (only one-character names)
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Installer
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Installer
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\DisplayName Local machine: installed programs: name
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallLocation Local machine: installed programs: target
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallSource Local machine: installed programs: source
NT HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallDate Local machine: installed programs: installation date
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\DisplayName User-specific: installed programs: name
NT HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallLocation User-specific: installed programs: target
NT HKCU\Software\Microsoft\Wi