Airlock Digital

Application Whitelist Auditor Results

Tests ran as: WIN7-AUDIT\Daniel Schell (User)

Index

Audit Execution Test Results ISM Controls

Applocker Audit

Executables

  • Allow Name: (Default Rule) All files located in the Program Files folder

    • Users: Everyone (S-1-1-0)
    • Condition:

      Type: PATH Path: %PROGRAMFILES%\*

  • Allow Name: (Default Rule) All files located in the Windows folder

    • Users: Everyone (S-1-1-0)
    • Condition:

      Type: PATH Path: %WINDIR%\*

  • Allow Name: (Default Rule) All files

    • Users: BUILTIN\Administrators (S-1-5-32-544)
    • Condition:

      Type: PATH Path: *

  • DLL
    MSI

  • Allow Name: (Default Rule) All Windows Installer files in %systemdrive%\Windows\Installer

    • Users: Everyone (S-1-1-0)
    • Condition:

      Type: PATH Path: %WINDIR%\Installer\*

  • Allow Name: (Default Rule) All Windows Installer files

    • Users: BUILTIN\Administrators (S-1-5-32-544)
    • Condition:

      Type: PATH Path: *.*

  • Allow Name: (Default Rule) All digitally signed Windows Installer files

    • Users: Everyone (S-1-1-0)
    • Condition:

      Type: PUBLISHER Publisher Name: * Binary Name: * Product Name: * (Only Versions greater than 0.0.0.0 will execute.)

  • Script

  • Allow Name: (Default Rule) All scripts located in the Program Files folder

    • Users: Everyone (S-1-1-0)
    • Condition:

      Type: PATH Path: %PROGRAMFILES%\*

  • Allow Name: (Default Rule) All scripts located in the Windows folder

    • Users: Everyone (S-1-1-0)
    • Condition:

      Type: PATH Path: %WINDIR%\*

  • Allow Name: (Default Rule) All scripts

    • Users: BUILTIN\Administrators (S-1-5-32-544)
    • Condition:

      Type: PATH Path: *


  • Execution Results

    FolderPath EXE DLL
    C:\ Not Executed Not Executed
    C:\Documents and Settings Not Executed Not Executed
    C:\Program Files (x86) Not Executed Not Executed
    C:\ProgramData Executed Executed
    C:\Users Not Executed Not Executed
    C:\Program Files (x86)\Common Files Not Executed Not Executed
    C:\Program Files (x86)\Internet Explorer Not Executed Not Executed
    C:\Program Files (x86)\Microsoft.NET Not Executed Not Executed
    C:\Program Files (x86)\MSBuild Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies Not Executed Not Executed
    C:\Program Files (x86)\Uninstall Information Not Executed Not Executed
    C:\Program Files (x86)\Windows Defender Not Executed Not Executed
    C:\Program Files (x86)\Windows Mail Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player Not Executed Not Executed
    C:\Program Files (x86)\Windows NT Not Executed Not Executed
    C:\ProgramData\Application Data Executed Executed
    C:\ProgramData\Desktop Not Executed Not Executed
    C:\ProgramData\Documents Executed Executed
    C:\Program Files (x86)\Windows Photo Viewer Not Executed Not Executed
    C:\ProgramData\Favorites Executed Executed
    C:\Program Files (x86)\Windows Portable Devices Not Executed Not Executed
    C:\ProgramData\Microsoft Not Executed Not Executed
    C:\ProgramData\Start Menu Not Executed Not Executed
    C:\ProgramData\Templates Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar Not Executed Not Executed
    C:\Users\All Users Executed Executed
    C:\ProgramData\VMware Executed Executed
    C:\Users\Daniel Schell Executed Executed
    C:\Users\Default Not Executed Not Executed
    C:\Users\Default User Not Executed Not Executed
    C:\Users\Public Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared Not Executed Not Executed
    C:\Program Files (x86)\Internet Explorer\en-US Not Executed Not Executed
    C:\Program Files (x86)\Common Files\Services Not Executed Not Executed
    C:\Program Files (x86)\Internet Explorer\SIGNUP Not Executed Not Executed
    C:\Program Files (x86)\Common Files\SpeechEngines Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System Not Executed Not Executed
    C:\Program Files (x86)\Microsoft.NET\RedistList Not Executed Not Executed
    C:\Program Files (x86)\MSBuild\Microsoft Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft Not Executed Not Executed
    C:\Program Files (x86)\Windows Defender\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Mail\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player\Icons Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player\Media Renderer Not Executed Not Executed
    C:\Program Files (x86)\Windows NT\Accessories Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player\Network Sharing Not Executed Not Executed
    C:\Program Files (x86)\Windows NT\TableTextService Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player\Skins Not Executed Not Executed
    C:\Program Files (x86)\Windows Photo Viewer\en-US Not Executed Not Executed
    C:\ProgramData\Microsoft\Assistance Not Executed Not Executed
    C:\Program Files (x86)\Windows Media Player\Visualizations Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\en-US Not Executed Not Executed
    C:\ProgramData\Microsoft\Crypto Not Executed Not Executed
    C:\Users\All Users\Application Data Executed Executed
    C:\Users\All Users\Desktop Not Executed Not Executed
    C:\Users\All Users\Documents Executed Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage Not Executed Not Executed
    C:\Users\All Users\Favorites Executed Executed
    C:\Program Files (x86)\Windows Sidebar\Shared Gadgets Not Executed Not Executed
    C:\ProgramData\Microsoft\DeviceSync Executed Executed
    C:\Users\All Users\Microsoft Not Executed Not Executed
    C:\Users\All Users\Start Menu Not Executed Not Executed
    C:\Users\All Users\Templates Not Executed Not Executed
    C:\ProgramData\Microsoft\DRM Not Executed Not Executed
    C:\Users\All Users\VMware Executed Executed
    C:\ProgramData\Microsoft\eHome Executed Executed
    C:\ProgramData\VMware\Compatibility Executed Executed
    C:\Users\Daniel Schell\AppData Executed Executed
    C:\ProgramData\VMware\logs Executed Executed
    C:\ProgramData\Microsoft\IdentityCRL Not Executed Not Executed
    C:\Users\Daniel Schell\Application Data Executed Executed
    C:\ProgramData\VMware\RawdskCompatibility Executed Executed
    C:\ProgramData\Microsoft\Media Player Not Executed Not Executed
    C:\Users\Daniel Schell\Contacts Executed Executed
    C:\Users\Daniel Schell\Cookies Executed Executed
    C:\ProgramData\VMware\VMware CAF Executed Executed
    C:\ProgramData\Microsoft\MF Not Executed Not Executed
    C:\Users\Daniel Schell\Desktop Executed Executed
    C:\ProgramData\VMware\VMware Tools Not Executed Not Executed
    C:\ProgramData\Microsoft\Network Not Executed Not Executed
    C:\Users\Daniel Schell\Documents Executed Executed
    C:\ProgramData\VMware\VMware VGAuth Executed Executed
    C:\ProgramData\Microsoft\RAC Not Executed Not Executed
    C:\Users\Daniel Schell\Downloads Executed Executed
    C:\ProgramData\Microsoft\Search Not Executed Not Executed
    C:\Users\Daniel Schell\Favorites Executed Executed
    C:\ProgramData\Microsoft\User Account Pictures Executed Executed
    C:\Users\Default\AppData Not Executed Not Executed
    C:\Users\Daniel Schell\Links Executed Executed
    C:\Users\Default\Application Data Not Executed Not Executed
    C:\Users\Daniel Schell\Local Settings Executed Executed
    C:\Users\Default\Cookies Not Executed Not Executed
    C:\ProgramData\Microsoft\Vault Not Executed Not Executed
    C:\Users\Daniel Schell\Music Executed Executed
    C:\Users\Default\Desktop Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows Not Executed Not Executed
    C:\Users\Daniel Schell\My Documents Executed Executed
    C:\ProgramData\Microsoft\Windows Defender Not Executed Not Executed
    C:\Users\Daniel Schell\NetHood Executed Executed
    C:\Users\Default\Documents Not Executed Not Executed
    C:\Users\Daniel Schell\Pictures Executed Executed
    C:\ProgramData\Microsoft\Windows NT Not Executed Not Executed
    C:\Users\Daniel Schell\PrintHood Executed Executed
    C:\Users\Default\Downloads Not Executed Not Executed
    C:\Users\Daniel Schell\Recent Executed Executed
    C:\ProgramData\Microsoft\WwanSvc Not Executed Not Executed
    C:\Users\Daniel Schell\Saved Games Executed Executed
    C:\Users\Default\Favorites Not Executed Not Executed
    C:\Users\Default\Links Not Executed Not Executed
    C:\Users\Daniel Schell\Searches Executed Executed
    C:\Users\Default\Local Settings Not Executed Not Executed
    C:\Users\Daniel Schell\SendTo Executed Executed
    C:\Users\Daniel Schell\Start Menu Executed Executed
    C:\Users\Daniel Schell\Templates Executed Executed
    C:\Users\Default\Music Not Executed Not Executed
    C:\Users\Default\My Documents Not Executed Not Executed
    C:\Users\Default\NetHood Not Executed Not Executed
    C:\Users\Daniel Schell\Videos Executed Executed
    C:\Users\Default\Pictures Not Executed Not Executed
    C:\Users\Public\Desktop Not Executed Not Executed
    C:\Users\Default\PrintHood Not Executed Not Executed
    C:\Users\Default\Recent Not Executed Not Executed
    C:\Users\Public\Documents Executed Executed
    C:\Users\Default\Saved Games Not Executed Not Executed
    C:\Users\Default\SendTo Not Executed Not Executed
    C:\Users\Public\Downloads Executed Executed
    C:\Users\Default\Start Menu Not Executed Not Executed
    C:\Users\Default\Templates Not Executed Not Executed
    C:\Users\Public\Favorites Executed Executed
    C:\Users\Default\Videos Not Executed Not Executed
    C:\Users\Public\Libraries Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\DAO Not Executed Not Executed
    C:\Users\Public\Music Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\ink Not Executed Not Executed
    C:\Users\Public\Pictures Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\MSInfo Not Executed Not Executed
    C:\Users\Public\Recorded TV Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\Stationery Not Executed Not Executed
    C:\Users\Public\Videos Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\TextConv Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\Triedit Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\VC Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\VGX Not Executed Not Executed
    C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\ado Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\en-US Not Executed Not Executed
    C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\msadc Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\Ole DB Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework Not Executed Not Executed
    C:\Program Files (x86)\Windows NT\Accessories\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows NT\TableTextService\en-US Not Executed Not Executed
    C:\ProgramData\Microsoft\Assistance\Client Not Executed Not Executed
    C:\ProgramData\Microsoft\Crypto\DSS Not Executed Not Executed
    C:\ProgramData\Microsoft\Crypto\Keys Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Calendar.Gadget Not Executed Not Executed
    C:\ProgramData\Microsoft\Crypto\RSA Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Clock.Gadget Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\CPU.Gadget Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Device Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Currency.Gadget Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Task Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\PicturePuzzle.Gadget Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\RSSFeeds.Gadget Not Executed Not Executed
    C:\Users\All Users\Microsoft\Assistance Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget Not Executed Not Executed
    C:\Users\All Users\Microsoft\Crypto Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage Not Executed Not Executed
    C:\Users\All Users\Microsoft\DeviceSync Executed Executed
    C:\Users\All Users\Microsoft\DRM Not Executed Not Executed
    C:\Users\All Users\Microsoft\eHome Executed Executed
    C:\Users\All Users\Microsoft\IdentityCRL Not Executed Not Executed
    C:\Users\All Users\Microsoft\Media Player Not Executed Not Executed
    C:\Users\All Users\Microsoft\MF Not Executed Not Executed
    C:\ProgramData\Microsoft\DRM\Server Not Executed Not Executed
    C:\Users\All Users\Microsoft\Network Not Executed Not Executed
    C:\Users\All Users\VMware\Compatibility Executed Executed
    C:\Users\All Users\Microsoft\RAC Not Executed Not Executed
    C:\Users\All Users\VMware\logs Executed Executed
    C:\Users\All Users\Microsoft\Search Not Executed Not Executed
    C:\Users\All Users\VMware\RawdskCompatibility Executed Executed
    C:\Users\All Users\Microsoft\User Account Pictures Executed Executed
    C:\ProgramData\VMware\Compatibility\native Executed Executed
    C:\Users\All Users\VMware\VMware CAF Executed Executed
    C:\Users\All Users\Microsoft\Vault Not Executed Not Executed
    C:\ProgramData\VMware\Compatibility\virtual Executed Executed
    C:\Users\All Users\VMware\VMware Tools Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows Defender Not Executed Not Executed
    C:\ProgramData\Microsoft\eHome\logs Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth Executed Executed
    C:\Users\All Users\Microsoft\Windows NT Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local Executed Executed
    C:\Users\All Users\Microsoft\WwanSvc Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\LocalLow Executed Executed
    C:\ProgramData\VMware\RawdskCompatibility\native Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming Executed Executed
    C:\ProgramData\VMware\RawdskCompatibility\virtual Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme Executed Executed
    C:\ProgramData\VMware\VMware Tools\GuestProxyData Not Executed Not Executed
    C:\Users\Daniel Schell\Documents\My Music Executed Executed
    C:\ProgramData\Microsoft\Network\Connections Not Executed Not Executed
    C:\Users\Daniel Schell\Documents\My Pictures Executed Executed
    C:\ProgramData\Microsoft\Network\Downloader Not Executed Not Executed
    C:\ProgramData\VMware\VMware Tools\Unity Filters Not Executed Not Executed
    C:\Users\Daniel Schell\Documents\My Videos Executed Executed
    C:\ProgramData\Microsoft\Search\Data Not Executed Not Executed
    C:\ProgramData\Microsoft\RAC\Outbound Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\aliasStore Not Executed Not Executed
    C:\ProgramData\Microsoft\RAC\PublishedData Executed Executed
    C:\Users\Daniel Schell\Favorites\Links Executed Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs Executed Executed
    C:\Users\Daniel Schell\Favorites\Links for United States Executed Executed
    C:\ProgramData\Microsoft\RAC\StateData Not Executed Not Executed
    C:\ProgramData\Microsoft\User Account Pictures\Default Pictures Not Executed Not Executed
    C:\Users\Default\AppData\Local Not Executed Not Executed
    C:\Users\Daniel Schell\Favorites\Microsoft Websites Executed Executed
    C:\ProgramData\Microsoft\RAC\Temp Executed Executed
    C:\ProgramData\Microsoft\Windows\AIT Not Executed Not Executed
    C:\Users\Daniel Schell\Favorites\MSN Websites Executed Executed
    C:\Users\Default\AppData\Roaming Not Executed Not Executed
    C:\Users\Default\Documents\My Music Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Caches Not Executed Not Executed
    C:\Users\Default\Documents\My Pictures Not Executed Not Executed
    C:\Users\Daniel Schell\Favorites\Windows Live Executed Executed
    C:\Users\Default\Documents\My Videos Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows NT\MSFax Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\DeviceMetadataStore Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows NT\MSScan Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\DRM Executed Executed
    C:\ProgramData\Microsoft\WwanSvc\Profiles Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\GameExplorer Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Ringtones Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Sqm Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Templates Not Executed Not Executed
    C:\Users\Public\Documents\My Music Executed Executed
    C:\Users\Public\Documents\My Pictures Executed Executed
    C:\ProgramData\Microsoft\Windows\WER Not Executed Not Executed
    C:\Users\Public\Documents\My Videos Executed Executed
    C:\Users\Public\Music\Sample Music Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\ink\1.0 Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\ink\1.7 Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\ink\en-US Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\ink\HWRCustomization Not Executed Not Executed
    C:\Users\Public\Pictures\Sample Pictures Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\en-US Not Executed Not Executed
    C:\Users\Public\Recorded TV\Sample Media Executed Executed
    C:\Users\Public\Videos\Sample Videos Executed Executed
    C:\Program Files (x86)\Common Files\microsoft shared\TextConv\en-US Not Executed Not Executed
    C:\Program Files (x86)\Common Files\microsoft shared\Triedit\en-US Not Executed Not Executed
    C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20 Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\ado\en-US Not Executed Not Executed
    C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0 Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\msadc\en-US Not Executed Not Executed
    C:\Program Files (x86)\Common Files\System\Ole DB\en-US Not Executed Not Executed
    C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.5 Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0 Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5 Not Executed Not Executed
    C:\ProgramData\Microsoft\Assistance\Client\1.0 Not Executed Not Executed
    C:\ProgramData\Microsoft\Crypto\DSS\MachineKeys Executed Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Calendar.Gadget\en-US Not Executed Not Executed
    C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys Executed Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Calendar.Gadget\images Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Clock.Gadget\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\CPU.Gadget\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Clock.Gadget\images Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\CPU.Gadget\images Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0} Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9} Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Currency.Gadget\en-US Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120} Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42} Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Currency.Gadget\images Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\PicturePuzzle.Gadget\en-US Not Executed Not Executed
    C:\Users\All Users\Microsoft\Assistance\Client Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\RSSFeeds.Gadget\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\PicturePuzzle.Gadget\Images Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\RSSFeeds.Gadget\images Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget\en-US Not Executed Not Executed
    C:\Users\All Users\Microsoft\Crypto\DSS Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget\images Not Executed Not Executed
    C:\Users\All Users\Microsoft\Crypto\Keys Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Device Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget\images Not Executed Not Executed
    C:\Users\All Users\Microsoft\Crypto\RSA Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Task Not Executed Not Executed
    C:\Users\All Users\Microsoft\DRM\Server Not Executed Not Executed
    C:\Users\All Users\Microsoft\eHome\logs Executed Executed
    C:\Users\All Users\Microsoft\Network\Connections Not Executed Not Executed
    C:\Users\All Users\Microsoft\Network\Downloader Not Executed Not Executed
    C:\Users\All Users\VMware\Compatibility\native Executed Executed
    C:\Users\All Users\VMware\Compatibility\virtual Executed Executed
    C:\Users\All Users\Microsoft\RAC\Outbound Not Executed Not Executed
    C:\Users\All Users\Microsoft\RAC\PublishedData Executed Executed
    C:\Users\All Users\Microsoft\Search\Data Not Executed Not Executed
    C:\Users\All Users\Microsoft\RAC\StateData Not Executed Not Executed
    C:\Users\All Users\VMware\RawdskCompatibility\native Executed Executed
    C:\Users\All Users\Microsoft\RAC\Temp Executed Executed
    C:\Users\All Users\Microsoft\User Account Pictures\Default Pictures Not Executed Not Executed
    C:\Users\All Users\VMware\RawdskCompatibility\virtual Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme Executed Executed
    C:\Users\All Users\VMware\VMware Tools\GuestProxyData Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\AIT Not Executed Not Executed
    C:\Users\All Users\VMware\VMware Tools\Unity Filters Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\Caches Not Executed Not Executed
    C:\Users\All Users\VMware\VMware VGAuth\aliasStore Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore Not Executed Not Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs Executed Executed
    C:\Users\All Users\Microsoft\Windows NT\MSFax Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\DRM Executed Executed
    C:\Users\All Users\Microsoft\Windows NT\MSScan Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Application Data Executed Executed
    C:\Users\All Users\Microsoft\Windows\GameExplorer Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\History Executed Executed
    C:\Users\All Users\Microsoft\Windows\Power Efficiency Diagnostics Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft Executed Executed
    C:\Users\All Users\Microsoft\Windows\Ringtones Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Temp Executed Executed
    C:\Users\All Users\Microsoft\Windows\Sqm Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Temporary Internet Files Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\VirtualStore Executed Executed
    C:\Users\All Users\Microsoft\Windows\Templates Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\WER Not Executed Not Executed
    C:\Users\All Users\Microsoft\WwanSvc\Profiles Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\LocalLow\Microsoft Executed Executed
    C:\ProgramData\VMware\RawdskCompatibility\native\C Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Identities Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Media Center Programs Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\config Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data Executed Executed
    C:\ProgramData\VMware\VMware Tools\GuestProxyData\server Not Executed Not Executed
    C:\ProgramData\VMware\VMware Tools\GuestProxyData\trusted Not Executed Not Executed
    C:\ProgramData\VMware\VMware CAF\pme\install Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\scripts Executed Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages Executed Executed
    C:\Users\Default\AppData\Local\Application Data Not Executed Not Executed
    C:\Users\Default\AppData\Local\History Not Executed Not Executed
    C:\Users\Default\AppData\Local\Microsoft Not Executed Not Executed
    C:\Users\Default\AppData\Roaming\Media Center Programs Not Executed Not Executed
    C:\Users\Default\AppData\Local\Temp Not Executed Not Executed
    C:\Users\Default\AppData\Local\Temporary Internet Files Not Executed Not Executed
    C:\Users\Default\AppData\Roaming\Microsoft Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Sqm\Manifest Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\DRM\Cache Executed Executed
    C:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\WER\ReportArchive Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Sqm\Sessions Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Sqm\Upload Not Executed Not Executed
    C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\RedistList Not Executed Not Executed
    C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList Not Executed Not Executed
    C:\ProgramData\Microsoft\Assistance\Client\1.0\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Calendar.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Clock.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Calendar.Gadget\en-US\js Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\CPU.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Clock.Gadget\en-US\js Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Currency.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\CPU.Gadget\en-US\js Not Executed Not Executed
    C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\RSSFeeds.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Currency.Gadget\en-US\js Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\PicturePuzzle.Gadget\en-US\css Not Executed Not Executed
    C:\Users\All Users\Microsoft\Assistance\Client\1.0 Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\RSSFeeds.Gadget\en-US\js Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget\en-US\css Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget\images\in_sidebar Not Executed Not Executed
    C:\Users\All Users\Microsoft\Crypto\DSS\MachineKeys Executed Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\PicturePuzzle.Gadget\en-US\js Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget\en-US\js Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0} Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget\images\120DPI Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\SlideShow.Gadget\images\on_desktop Not Executed Not Executed
    C:\Users\All Users\Microsoft\Crypto\RSA\MachineKeys Executed Executed
    C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9} Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120} Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget\en-US\js Not Executed Not Executed
    C:\Program Files (x86)\Windows Sidebar\Gadgets\Weather.Gadget\images\144DPI Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42} Not Executed Not Executed
    C:\Users\All Users\VMware\VMware CAF\pme\config Executed Executed
    C:\Users\All Users\VMware\VMware Tools\GuestProxyData\server Not Executed Not Executed
    C:\Users\All Users\VMware\RawdskCompatibility\native\C Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages Executed Executed
    C:\Users\All Users\Microsoft\Windows\DeviceMetadataStore\en-US Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Credentials Executed Executed
    C:\Users\All Users\Microsoft\Windows\DRM\Cache Executed Executed
    C:\Users\All Users\VMware\VMware Tools\GuestProxyData\trusted Not Executed Not Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Temp\Low Executed Executed
    C:\Users\All Users\Microsoft\Windows\Sqm\Manifest Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds Executed Executed
    C:\Users\All Users\Microsoft\Windows\WER\ReportArchive Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\LocalLow\Microsoft\CryptnetUrlCache Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Temp\NUL588A.tmp.dir Not Executed Not Executed
    C:\Users\All Users\VMware\VMware CAF\pme\install Executed Executed
    C:\Users\All Users\Microsoft\Windows\Sqm\Sessions Not Executed Not Executed
    C:\ProgramData\VMware\RawdskCompatibility\native\C\Windows Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds Cache Executed Executed
    C:\Users\All Users\Microsoft\Windows\WER\ReportQueue Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Roaming\Identities\{ADDE82A2-5ACF-4140-8EFD-3C20B2B9EF92} Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Temp\vmware-Daniel Schell Executed Executed
    C:\Users\Daniel Schell\AppData\LocalLow\Microsoft\Internet Explorer Executed Executed
    C:\Users\All Users\Microsoft\Windows\Sqm\Upload Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Internet Explorer Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input Executed Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\de Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Credentials Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\scripts Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Temp\WPDNSE Executed Executed
    C:\Users\Default\AppData\Local\Microsoft\Windows Not Executed Not Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer Not Executed Not Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Media Player Executed Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\en Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Internet Explorer Executed Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories Not Executed Not Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\es Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\MMC Executed Executed
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_505c7fc25c7e5866de583f14c22e2b4c2a6018c_cab_0695b5f5 Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_72da1383309c93bd2441accd728cf953e4fa97a_cab_0385d1cf Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\fr Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Mail Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Network Executed Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\it Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Protect Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Media Executed Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ja Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\SystemCertificates Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Sidebar Executed Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\ko Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows Executed Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC Not Executed Not Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN Executed Executed
    C:\ProgramData\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW Executed Executed
    C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk Not Executed Not Executed
    C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US Not Executed Not Executed
    C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US Not Executed Not Executed
    C:\Users\All Users\VMware\RawdskCompatibility\native\C\Windows Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\de Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds\Feeds for United States~ Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds Cache\BXW9A2K7 Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\en Executed Executed
    C:\ProgramData\VMware\RawdskCompatibility\native\C\Windows\System32 Executed Executed
    C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_505c7fc25c7e5866de583f14c22e2b4c2a6018c_cab_0695b5f5 Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds\Microsoft Feeds~ Executed Executed
    C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_72da1383309c93bd2441accd728cf953e4fa97a_cab_0385d1cf Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData Executed Executed
    C:\Users\Daniel Schell\AppData\LocalLow\Microsoft\Internet Explorer\Services Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds Cache\F7INK3HK Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\es Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Internet Explorer\Recovery Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~ Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input\invokers Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds Cache\TS4WWUDE Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\fr Executed Executed
    C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer Not Executed Not Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance Not Executed Not Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch Not Executed Not Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input\monitor Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\log Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds Cache\UQM1OMH4 Executed Executed
    C:\Users\Default\AppData\Local\Microsoft\Windows\History Not Executed Not Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\it Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Media Player\Sync Playlists Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input\persistence Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\requests Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch Executed Executed
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files Not Executed Not Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\ja Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Tablet PC Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility Not Executed Not Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input\providerReg Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\schemaCache Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\ko Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\1033 Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\split-requests Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\zh_CN Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Burn Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Network\Connections Executed Executed
    C:\Users\All Users\VMware\VMware VGAuth\msgCatalogs\messages\zh_TW Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Mail\Backup Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts Not Executed Not Executed
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Caches Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Media\12.0 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Protect\S-1-5-21-1835245027-1968171064-1055082620-1000 Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Mail\Stationery Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Explorer Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\SystemCertificates\My Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Sidebar\Gadgets Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\GameExplorer Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Cookies Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\History Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\IECompatCache Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Ringtones Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\IETldCache Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Libraries Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\WER Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Network Shortcuts Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Printer Shortcuts Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\PrivacIE Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Recent Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\SendTo Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Templates Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Themes Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input\invokers Executed Executed
    C:\Users\All Users\VMware\RawdskCompatibility\native\C\Windows\System32 Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\log Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Internet Explorer\Recovery\Active Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input\monitor Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\requests Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input\persistence\protocol Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~ Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input\persistence Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\schemaCache Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\schemaCache\cafTestInfra_CafTestInfraProvider_1_0_0 Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Burn\Burn Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Network\Connections\Pbk Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows Mail\Backup\new Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\schemaCache\caf_ConfigProvider_1_0_0 Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\split-requests Executed Executed
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Cookies\Low Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input\providerReg Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\History\History.IE5 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\schemaCache\caf_InstallProvider_1_0_0 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\IECompatCache\Low Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\IETldCache\Low Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\History\Low Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\output\schemaCache\caf_RemoteCommandProvider_1_0_0 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\PrivacIE\Low Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\WER\ERC Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\WER\ReportArchive Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\000154D3 Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input\persistence\protocol Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts Executed Executed
    C:\ProgramData\VMware\VMware CAF\pme\data\input\persistence\protocol\amqpBroker_default Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\schemaCache\cafTestInfra_CafTestInfraProvider_1_0_0 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017120520171206 Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4GHDX3UD Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\schemaCache\caf_ConfigProvider_1_0_0 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\History\Low\History.IE5 Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D52BLFVZ Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\schemaCache\caf_InstallProvider_1_0_0 Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\446W6YZI Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QLKIVOIM Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\input\persistence\protocol\amqpBroker_default Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users Executed Executed
    C:\Users\All Users\VMware\VMware CAF\pme\data\output\schemaCache\caf_RemoteCommandProvider_1_0_0 Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QBVY5ONB Executed Executed
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools Not Executed Not Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJLGCTEF Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell\AppData Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W0EHBCR0 Executed Executed
    C:\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell\AppData\Roaming Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\X193Y1UR Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell\AppData\Roaming\Microsoft Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\PrivacIE Executed Executed
    C:\Users\Daniel Schell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Daniel Schell\AppData\Roaming\Microsoft\Windows\PrivacIE\Low Executed Executed

    ISM Controls