MalScore
100/100
MalFamily
Malicious

u2.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 52/68 Related 2805
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1652.50 KB (1692160 bytes)
Compile time: 2017-11-21 01:41:11
MD5: 0b8d1aedf4c08ca20c40da96d3d740d3
SHA1: dc780bf338053e9c1b0fdf259c831eb8a2768169
SHA256: 781b2d0d9b6230b62883b2797dc0c0264b43b80f747d58470fead22112961996
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 7!Ya 9.k .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-04-14 14:42:05
Last submission: 2018-04-14 14:42:05
Filename detected: - u2.exe (1)
URL file hosting
hXXp://ssrdevelopments.co.za/aa/u2.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-02-26 20:33:22 [52/68] VirusTotal
PE Sections 5 suspicious
Name VAddress VSize Size MD5 SHA1
7!Ya 9.k 0x2000 0x2108 8704 822d3efe47bee1b7e5d74399e83eab9b 6602ad38a677942217c96da06db7a9f19b948121
.text 0x6000 0xa5ab8 678912 f515410a890cf4f6b30c9865cfa1b4b9 a7fc5d84d0833fcb253f67efb3a88535b710b0b5
.rsrc 0xac000 0xf4b48 1002496 05abfb2cd556bbcc5af2090c2c2c8abe e64276005330c660ea5fd1345047c7fa9184757d
.reloc 0x1a2000 0xc 512 c4add2a13cf2ba3a07b92c874b94d503 5e738f45d5f922934503f2c80e816b258f48a6b1
0x1a4000 0x10 512 c8855e12e08aa757b84749e5763ecfa8 96c77c882a45a138319103b6f7acd06d5a2b9cb8
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0xac0e8 1000948 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x1a06dc 20 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x1a06f0 1108 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Mi9n6cErWtg0Acys3qr9iZGmEj9KXSrzhf7jn11MPp
Assembly Version: 92.15.27.2
InternalName: u2.exe
FileVersion: 66.61.11.20
CompanyName: MUJH3qbYVg02UydQD2tIbv2kG3V3cHu3izKHX32pN4
Comments: pKPpNgec225xU6oofJEXIBnnhBsefvgZ2h7QbDFbZx
ProductName: tkz9ozkfUny8jRFmw9fRbio7CWDIHLq5YElSdGCKSo
ProductVersion: 66.61.11.20
FileDescription: 0n2sGgYqdnfUOsb8BvkFYUdWPCpsF0Z52GmTFojnUG
Translation: 0x0000 0x04b0
OriginalFilename: u2.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
mscoree.dll
KERNEL32.dll
IP Found
92.15.27.2
66.61.11.20
URL(s)
No URL found
System.Reflection.Assembly
Assembly Version
COR
u2.exe
92.15.27.2
VarFileInfo
Comments
GetValue
tkz9ozkfUny8jRFmw9fRbio7CWDIHLq5YElSdGCKSo
InternalName
d1?
TransformFinalBlock
MUJH3qbYVg02UydQD2tIbv2kG3V3cHu3izKHX32pN4
StringFileInfo
Translation
System.AppDomain
LegalCopyright
FileVersion
VS_VERSION_INFO
66.61.11.20
000004b0
ProductVersion
FileDescription
System.Security.Cryptography.ICryptoTransform
OriginalFilename
Load
System.Reflection.PropertyInfo
pKPpNgec225xU6oofJEXIBnnhBsefvgZ2h7QbDFbZx
CompanyName
GetEnvironmentVariable
0n2sGgYqdnfUOsb8BvkFYUdWPCpsF0Z52GmTFojnUG
ProductName
EntryPoint
Mi9n6cErWtg0Acys3qr9iZGmEj9KXSrzhf7jn11MPp
_ENABLE_PROFILING
r=$"
aj%sQ
3q#v#
EIz5T h
F:"1uD
>D}J
2]<
RWjL`
Int32
w`##
\ M?
4=$`
~yXLg?>
jN[I
qA$_
C|[q
QhG_lt
ig=}R
{ EH
t/|=
v{b'
-1 3
utpD
^w?
qJvr
3 ,U
\8#7
N$!"
]k"J
>dngd
,?Fu
Hb8(
y@fg
ZoM*F
>#<J
Nz69
\W>U
Vx>C
f0 M
oM$>y
Z[zH
({Y(E%
Lv&S+
j)?EL
Q{ Yw
e^YI
,xNr
BZr*
i[1T
.'S0J
V^kE
ds=Y
8nuN
~\NI3
[Y~
9"BI
gpa
sr'f
GkwZa
K'?Y
[8V
$_vsE%
ehB)
'&?|
x`8K
ba?qP
(FDW
-G$>
,kpd
0.j,
aeU >
Q'&$
VH"
$lh[h
1^[<
w<a7
*WVV9
\cn+M/
lP|R
z<^e
x^bY
!c ;
zn;G
'YA>
r5Y]
Gf?<
r5YX
O><F
5V1h
, ,M
*u$y;
RaI=
d$$T
ot @
(%3]g
*,C6;5
s5A b
,1DS[g
9cN|
+/8)
-P1d
Drmof3
g!<?9
}4Ki
p&OE
.N*1
)Xdll
S?+b
}NEX
Z8H"
\m,q
~p Q
s``)
Y <6
BJpL#
-hDe
N{N NjN7NJN
EL%D
~P1B3zX
lpQU^
MpCH]
% 0q0
hkL!W
mXxKD
*uJ+
r<%h
Z>~L
Ay>r
!bL&
NL~7
>\%
[TBF`8p
N[NQN?NQNtNeN/N
Q&C7e
9]d XT
WMCXh
Z#A/
P/wG
/ |+
!VtF
`7#2
(fr2
+F-
GS'G
{DD7
iGIU
X1s;
$&JoE
l\%x
xCLa
^q'|
/0-\8
Pn}<
,2X(M
%@-x
J6sd
&)Io
G%D]
zgwuqGL
` 9X
iH@9
Pxg[
_ACR
"_h$Y
&<[
>i p
dN%9
9xxo~
'*P"
=`Id
`;B0
bWn"
\I=!
.text
k~l(
L4i.
T]c`
Uv&5
jhNF
vdkyY
GetObject
D|~ 0
3 #a3#
cv-F
\TdK
w xt
3aW@ /
.(Ew
*!^{}?U
L4iz
Gj>5
bA~}RA
d'>Y
@ p;
$\jc
yjZC
iat2
ONyf1La
WV3|y
F8no
1++
Y0O^
JZNd
QZ/P
ZNOmKs$4Q9
m:]G
1@d-
{`wH
N*,|b
uPy/
0We(5
b:e7s
MSN#&
ab t
S-\r,
R7'
4A$5b
l7HdX{
U^x(
~9DU
WPz5
fv10
!X}d
CpjI]
wwbk ,
; B(
@U#Z|
^3Y]d}
g@O4?~
Pl )
HC`
7*yA
VO#7
qd8P
tEcz
I! (=$
nU>x
vJ@
$ s,J
K^cy
0 #j
48t&
Tz8<0
Y@^E8A
k#a,
Kb
_;Qk
5 `[
/Kro>v
y %F
^#U.
5*&)W
]U>
ww1LY
P7L[(
i'8(
#E. >
T UM1
a9~@
rIcA
UpL$
"\y\{r'
e:>$
b=r}ILi
WckS
!g>9
m-9~
vU~>T}
x %f_
,Bfa
'W"t
2Qq,
i(KZ
@['qwW{
sEA4
Igd'
y|/,/
'a))Y
fI W'h
Fj;JKj&:
(iUQ
|Y[x
v-O c\
'$/%
7mM
b=kKoF/
\Mi\
#2H'~
Cq$"
XnjF
n = V
^|cK8
!j($f
l.W#
p MH
}38G
2M]D
\}<t
@c9S
^JV
Sa=$
H]n+
+v]-Q
R!oe
oy i
.TY!W
xvQI
slGR
72A0
.2{}
>pOX
j9 I
2Np*
_jfXN
~ 30
SPdF
pKzk
gad}
CkZ}
)U;h
XG/c
eD!`&2
&J<2#
F j6
h9.9$
P}*j"U
7oB@d
!eth
2+cO=
a!qB
z.Y#
HcoOFwb
ZkFJ%
B&{i
9KM
Lz]p=s
m _#*
Y?$=
eE|ne
Ag8a
*x>3<
MethodBase
A%=H
!=0
Ek'"k
^.-.
bxe:
y(0+
eZ^I
4cjqTA
+&$'
]_vZ
rnj`
Y%6S
D}D%
}llV
mD<|
Xv:,j
j(f{j\Cw
"$+=
eNz
vFMn
b @S}:rD()0
Ab5T
b%M]
~%1/R
uJIIyv
O>v
5!)P
M9%}*I
X [@
$!Lq
DSo-C
d[1 )
jM*9%
WM5G
Mn%9
C]JAG
/a!4
'%LW
.Br 0
ZhE<?
8IM<
^HoTy\
`uTq
wbAD
4~='_
a}=K{
p4sQg
vZ1(d
\Ed
L J[
QY9Td|
1Jimq
,KPi
&%6fw
o IC
CP:q
p]Cub
O=B< !&
;qtv$g
fZa5
K?,g
f2!/
sS+gb
vd/QQ
nRuU}K%
B$)^
$9$*
_'0!6
Lby@
p<<*
'V- ?F
ur3R
Orw*
lKE@
-r&^
|Ig
LhsK=
0Y)1
Os0(#
`u |
^,k
p{^p(
ALO
IhDBU2_
~H~0Di
M G"
kiPCe
\'NzZ!
5n _
Ev-H
ALi@L
<QcU
>>C_
Pq0@4
<BBn
(VK#
A&@,
5%eC
9lCa
zQ32
0p'U)
\H{1
13,`
.U0Z
-NV8
L5A{R
M#<#n
~8$on
E.\ V
eO/\
@k/*Y
0zU{
uWkZ
2=C
-/3x
@4%6
v&6J
NC[S
K_<J|
ao(zt~
*g~,
=0g5FHr
-dQ&
-^W.
C ~=
pm9(
H<(B
C+{:a
nq!Z8^ivl
]O05
cF]I
NxN%N+NGN>NlN9N
x-@J
WEbR
ga%!
nSC 5
widisKOLqfmRa
#NYXS
:Be f
#]/t"
)1U
@Z`R
Z6;jP
Kp;2
s.\X
7xl
~*'c7
p"A80
F`mv
: h2?
K2:Z
.~Xn
k:+e
%$>,
)5Rm
. l=6
vJKW
r#Ump
%i4
}U+~
5` E'
[_=by
<d*8
N&Op
"tU.
S%+z+y
X$E
+?h_9
Cd/5
wAiG
6`+N
cR1(
"@y6
/ Y
t8rD
Xv K
"yW0
JWJaI
y~Jd
*'%J
S:c}
0~WWM
`Rp`
T1|N
Cnw(
)k0k
Vj3P
33><
~N}[
P7e{sP
Msm3
>U\Wa
O;p"#yB
)gJ}
^L<g
Rtw&U
S ~G
r<J:
*;~ul{
. 9~
"<P 0
MY~q
R~L
5B>O'
.h66
=q#z k,
TFV`
o?m8
wzS:
1)Q`
= bGk
Hu\4
CSK!
{2`
;Sxg
%"t4
y#gt
Kx)w
L}/I|
U>^u{
3R -_
y 17QR
L&Z5
Eyr?yJ
7ud;h
8`lb
v$|r
w`e;
YiMF
i/Nwa
3m p
[ :j%;
m/:d
5+ p
aD[a
NJ G
(S)z
^:Iu
2H#[,
R4a
MRk1
' <p
rl'"\
4#tUW
"Uwr:q
w0.5
\A/"
*bci*
40b8
+X tx
DJ;)
$R7<
Q)dn-
MN)o
2ZDD
TWYe
$wS0
X"oF
H"0
7Fu-
fqn0
HuH,
e^%Ad
vM.<K
fRSF
4g$'
0G(]
Eu4k
|CqC
ec ~(
zgR(
J@OoM
RVz1
dOn/T 1x
< BD
.aN:Qp
PxGR
vV&&
RuntimeCompatibilityAttribute
FDL5[@
xTiv?
fc f
pGZe1
</O?
IAe{j
y$D^A
=O Vm#
[V6B
>p]tA
"/9_
<1\C
wd4PR^
OV %
Hr/d
lo@#L+]
M5D
U2y6
xMES
ye/5A
.`TW
PC)*"7I
ex'AN
6t&m
][Al
pah}
nE@H
y,%G
?M_<
Bln)
"s@S(
mp[
T`-f
P:y
8 *&OM:o
zI1M
'`;,"
/6;V
? EOc
[U)y
n\WfX
0\HI .
6Q)y
0HTf
=1Mx~w
$RE(
dw6`a
*V 8
0AE}>
KLSt5
F:S`:~
:P ? '
XqE[H
2C`_B
Pc4a
}FDZS
1ro7
+vIX
xaxJ
>EqHk
i" T,[a
Ylr}
GF>9
ca(%/
D?dM
s[p"
UR l
Sqgh
~T@I
$}#X`
^YIZ
1@Chp
QSS0
2D8qqJ
qHG`T
)$l/
!. T
%k06
,9^t
R_@ZYB
|b'&
x[}K
qNMPtetRxzMsYdG
y7S5
2} |
1m"#$N
+pcx
a2u;
sRv@8
Cb?;
S:bBC
yP4U
BBx|
14@lp
l+e#$
5,
8g)4
3J8F
`*cp
trRn
uAR?
oOy:u
) #$
:S8 \NY
YD@L
O K~K
'Q=]
u&oQ`a&
PE*+
edZ<
7<tb"
B!7nB
u;jQ
+b8f<NfY
w ^>
'Q=:
5 T>d
z:f'
-w&Q
\tFM
,5b+
-ZD=
v@;>|
* i=n
'[p&
6T1,
x@ R3NxU
1E[;
q ])N#U
kmFB
41Ww
)-9u
h,4L
J8 a
4ievJ
:>u^
F]~+
~u(V
<o~!#
*szp
Co54
%7XY
Jz%%Q
{L~p
"h*w
JEuA
R e82
nB=A
mPs%
ypa\e
VOeO
&s7D
^{h)f6<
Bq38
Oq+*d
4W*C
nXKD+<
7q6h
L(.ta
fMaxAO4
RuntimeTypeHandle
(Zd.
cY)lk
,\(2O
$7!j
w{ B
AK~5
q< K
a? F
z&z;
3e`"
)ke??
{hWI
Ti#y
XZl9
^U0e
9+X4
@\7o
<ny(
`~RQ
8@JA
`qR|
*#*el
4ZT2D
]A1?
3Q
n0l
l>LO
g PX
ME` &K_
09F
0 L7R
qY^N
GodD
dfyT
1(.Az
NQY8Q3JQgwve34nRPHo
C~>f
F:-
F#jP
::"lRQ
BH-7/
]ei`_
RT;B
3sH
p^2Y
1 QK
%q5W
,8!'K
10B0
pA%D
W$=Y
];I(
"J}
-haO
32[M\
8wS{
Y /$
&Gd~7
} _B
@;P
^3l/
o4md
eZqz2um
mG.Z
$Dau
NKNzN
,=Wk_
@m0(
}S\
Gj a)
%c(=
!P G
ttoJ
}V$
:,x.
oWg-
8B2{WK
k+16hx
%StX
q[tt
\MF;q
rP!?
a]r9
9a3)
^bnz
%RUQN
@6Hx
TITa
b=T'z
l]t3
Zp>k#
ex!F%42K
W n ]
QAg{
X/el?1
>B{E
|Ow/
aH$W
*N$'
HKr$
IgCM$
r>Wk
\G]E
F!48
8'89
u'Ow
t;>-
nz`C-v
v b :
RkGQ
>t1R
-&*}"M9"Xt
&c <
'GFo&S"G
@ S+
/V^f
-UN#u
u3t:c
"mFn
;a/sxa
EOLZ
"IS%
UVS}
Bi2gC"
8_~'n
Z]Gu
X( uX
3$ +
,Q<*p
] NM)
F^\=}
SCJXQ
Ed)6X
cN6p
}*!c
EafH
set_Key
'cH<o
DH(:
y +D
Pl/l
B`<vDk
=)(0
7K4T
M)dg,L
iXJzmOc
ZX>N
FRBm`Z
gAKJE
%6v0
/,'\
Wx;u
(#0dp
N7NBNHNMN
?<.k
wn4V
zF.kK
kCi}
6G i
#Yr%
njk/
N&NVN`N*N
V\!-
C_sL
tv }
C )- #Y&
I{u<>
6= O
e9(-Y]
4pmC
tr(k
A`!W
IEx/
u".[
{7Rj
mRsP
S"9$b]
BL$}
$k:P
*k#O
EG>P
~k%
H5Nb
po&!
=D(o
:yK.
B Hz
_J;O
&aK
@JRd
B<Ly
Z*8P
J,(W
G(n$
DUnG
@([B
NVh6S
^eJB8a
cy*6/P
!yr{2
l]49
[BsC
cY;5&#~
& '"O?
Gj6e
um2+
~,:(
^^5*
23wL(<v
!-*
n:T @
mQ9x
YN7c
:jg]
*jK?n'
3,n4
IkkR
LHPS
|`?r)I]o8
*Li
%D>0
h`5O
{ ]L
@)S;
"*k!
k0yzB
y@U5
=iO/
Fm <
l]ot
YJ-l@|
jXK\
b?y&
+w4N
PN L|/
D%e lQC
a I?
kYIi)
Li&HUL
l`>h
$ex6
$="S
?S%N8[z
//`
=Bzn
r4Sut
8&^:q\
c D^
Rf~
~'x{ +U
N\I gx
*)EJ5
^xR!
yy=!
X2,q1
|FMG
E` $z
5r v
u|Gq(
P1IcC<
_CorExeMain
ek|x
g]0(b
gV?~
:1S
Zsa;
*G)4
TyN
'\pk
c2UP
0u~.Nh
zm/[
tUzS
jj',
D<>L
}^w#
yP9ZD
XJ/w
$r`9="
-4xj
&LXR$r
Cf0\pM]s
}"o
6'dq
}X?Z
AlBb
:0}-j7*zB
UFQ
R(<4|n
M;Ry
{,#qr
-:) \y"
60$>a
PmX/
,u R
HSD=
xyhct
bV,~CTf
vhdvd
/ Q*
qx,}
'?@Kb>-
e`3O
f 3:
,25T
a;aXp
Ko[iO
Z>K<
g)
C^^e
aCw|
&d=:
e,+J
3<hA
;zd|M
.VFf
V*
`4i&
5gW
(G3J
mRW 0$
nMD_
)juXN_
P=2%
/Nl'k-
3W_Dd
W8Px
2L>m
5[Fa
.f3d
[ E~6
YkcA
q(ej
"]^F>
`ZJ>Qn6
q`\1\
>M=5
!aG=
Yr2Y0
]-CQ
%s>b
Z(=H=k
t@e'F
Y3~]
DoZ1
8 d6
:R8{.
OZi\
-NkU
G%QA
`;Q
8 dL
=S*z^%
AF3XN \
4h4V
.L=.
zj"j}<
djdSOQW$%
3mOK
Kj :(3
Ig0 ,
*UhWL
xm-v{
UF&s*
[FCB
Nj]M
OIEY
bTya
C"j5cC
cCMs@
HQ 9
P9%}@|
I9P`
1yd
,OyD
l/K;
q,<^
c#!b
I9P{
#z)CC
iaiR
<W L
',5U
J=j!
s@c<'
{5Zu
b<R-
,~Ss
W3g41
BfE-
O&ltD}
htd
\<.k
2K%A
<uTl*
y]E&
{ 0[s
z}oft
";_:
% h{
s.9#
3 *J
"pg4
#|fs
"JPE
7 `
|$a1
Zq*)
t(-c
&s+X\
D]&E
[D2#
jNl0
f TM
V8 $
gq&SZ
Tg.bKHzrpoSK
NhD$
,n&f
bj I
aUe+
zA
n \
#k;rN
^Lc*
$$dg
Ibv5OF+
ZS&I
u!4K\6y
9{Q>^=
E+U
<b'x+
U0w
`qZIh
Vyf (
R >Wm
F-Co
~og%
7s*%
t%3V
ng!)
DS6f
n/jo
5 s~P
W7x J
n1jh&
_mXzP
%G?d
@$,>
TpH`W
!] DH
0)Le6
;{MBs
m~&+
'R0ep
#(0N
/(T
'e{,N
M_C7
;tz[
Gnct
K aW
][(#
xVV\
F0Tx
jo&|
' J
piB
)I+C5H
B52}
Paa
w@dvI
v<)+t-
`oW~+dAC
cIVYl
R~pg
]hv;
A&X~
*=y5
yk|T
7M~^)
#6s
^loQBI
B] >
<uDe
$Ucd
Ot}\
oM %
an;qk
5a4E
DuH "
Z4C
a}wH
gm:]
D Z9
o!K q
B-Fg^2c
X,w\ c
ZMXETraQqHHo0S
U!qN@
WD4 5 #
V:D3 ,H
n%U;
1\r?!em
8E:H
; )
HLmRG
t^Y>
7RBf
SvEL
h)7[q
A#3n>
{O3_?
D8L
Y%#z
s 3]
% V@2-
_/{L
OKZ+pH
lYLC
|A<L
Hg-B9
=s7[
7A({
0U4Dc
t"pZ
'$t3(xC/
`}'ot
])E)
&-JW
S ,;#
zPa5P)
hmv{
0B@X
1 @|c,l
8\A'G1
a DK^
'QcP
6#6
{VI9
+}5*
Hf|F
bl_rc.(
NkNrN
Mn0l
3 dY
eD.?
T:+Z!
<Hz 7u\
qy6_
1gN#
Y2=tr
C;?f
M"Lp
NDhJ
}|$!
NeN=N
s3$t
UU5=n
wYVh
CM)8N
keh8L'
] fs
t%URi
pB8Kp
^JPx
^LD~
h ;)
_vo6
{kqy
9`
az+&
S5D7F
~$/:
zo^
F[fp9!
kV`jQw
.MWv`
YVVp
1Jd.,V
+}[ E
3z W
2>[\vt
6am#
\QCw
<bN[N)N
9vYq
'$]/
?|$cj
sVmj
<-NhA
$"!V
;d@N
hrK][
H$lA`M
rTqmcI2l6D
RN wF
bo p
W!vM
">fs%
w2W<
Rw=TZ
,"cCTn>
Jw6fXs
Ld\y
0, X
bo C
3Y~5R
Y.}xm
za``
\$ctXpU
z=Aw
1$,C
:jR]
^h^ti
Le~/!
]/JH<
+&> sZ
|nE"
G'K_
' 9?
HL_e}
'E|b
k~rK
rq=(s
G-g$1
1|Va
TrGZ kl
& MV
!6eI
&l)Wt[
./mQ
68x8
*T2C
0hl=
wR%NS
vd0#
:b(M}
u7u5SEGixxEuq
h2WCFqY
]b.F
Jh(pSZ
JLQy_!.hG
!^K+
9^|q
y{2
QP2X4b
2#G=
@qkT
%Fw&xSA
S.
8k&N
;K
XmOh
zYTA
pgZd
QZpG
5Q^^
P [b
'<8E
9 %g
Juo9
0eol
L}+]
`<>C(
"N )
%f 6
) >@
:"[Z( X
HF8e\
i@[/
kYud
uGgQ
H'$s7
G)
AW=X
~cc >
!,s;
o0X>r
^1
`u[/F
7C P
n>sY
t~]m
f"(_
fqSd
8n1U,
N&6
^p2 bVR|
StY6
5F^p
zcYo
n*YH6
Kic)
?:r.
XIP_
lSA'
| {Tg
7 "6
8,G-
q];^|
g A&,'
;{((
cu~Tk
N*NKN5N0N<NSNsNcN:NjNyN/N$N
>a#y-)t
g+lL
ewOV
t!U"2
0IVr
aaV
';5=(
Nquz
+3m!
zNwn
6U@5
ni.2
Fq!y
SAim`
+qcn
:bPo
IO1X
NcN=NdN NeNcNeN
XI)!;1
b=n)
f}ax
]%z.
Aevy
DxN"N
rO2,
T.oJqFp
e\o v<
A~c4
Q ? l]'08;
0<1
Marshal
)ux! e_
4kB{L
*UgP
i ffCN
,sVs
CT\^
G<>?
~DMV
NTN.NaN\NjN
+ at%
QsG-
d:lp
cQ}D
%g_S
SOaA$&oX
**Xc
i 7
1VBC
VY{l1U
rkzCO
A&n,
Er2g
DS#6
99b
!x VA_p
D2 Y
=,xx
K>*1
"M.}
S18$e9Ug
5}S=r-
-'Vi
U7sc
@^AfK
^tJ|
8= R
Z~YhR
Q[i
?m1"xb
FnHGI
$u-;uU
c j u|
e\h3g2
0qU(".
)blw
e^fs
aqt=w~*
~o60
Qb($
|Pu=
sV}
m}(o
f~+~^1
U5akD
aJ%MF
G cwG
?w&,-`?g
/\lK
|sX?
b*;q
TmoFx&
ss\M
g&I8J
,(YT
Qg`Ye
tj2.
hpt#
] mx
Ihd&=I
0+Q~y
ekoJ
1i6x
XbtgV
_=r|pu
s}J
X!Zdl
amV6
~0 1
bb$v
sN:l
.~t\4
.Y~v
]_=C
-ZL!
if)F
G.ceF
?\c{
9X`}
!wOI
S%zz26
Type
u|+`
{ tnv
yY$:nQ
{[Pr
JU(!
G@i9
0HA]
-.72
" L{ET
zse"
.P<k
D ;E
y6g:
0(W7
}xqIus
T1 V
88Wk
'}$k
oJ _|;f
\UF
\01b
NsN[N
&/E
bcX{
"'>=`
k _fjV(
Jh z
V(w$&V
GsX|
?#F[
205_
/[y'
mr&<
=9|cr
#PzK1
Q2!A
=2ww|
+v|j
{Ir$
,lO
aJx
b."? P
6 [,
,((
E.w`
s@xr
zS<d8
;t *Az
75/o
D!iy
t#P;
h~sD:
Is<6
J!%T_p"
TtHM.
{7q3
fV)e3Vt
U}8
ULAs
C3c9
~Q81
+_`
g@re
8spW6s1uadWCZ9
~?H8
lKY5
d/y;
wbHr
Tqg
h.,u
bv5K
$wud
&S7P<!
GL O?
>]r
N@{AVcc
5YZs-
' ZZ
&_dP
%Yn&
lQWnV
'Xe=
V/wBR
.6(x
dXL]+
{_P:w
'*e^
A0%G
upg&p
QcMES
ov1A
'Xek
^b%N.
Wdq#
9S}n
EUIsai
`<&CAk
>819
Z *>
t(DPc8
3&]
N=N`N*N_NpN
oC%"
[=kY
MDAi
weES
aAoC
NQ q
fUnsHS
UJM^
7e&[
6Qvs"
/tCN
MW_]
H%Jt;
CEB6
-|`?
mWHc
'mvQ(-e'
rAJr
,haK
GXaog3sCy9phFuT3Y3
2%+Q7
knZ)
*":U1
N(|+|4
9ujC(
3 <z
nl}k
m E e
P$^g
::cP
ea8"
r]LX
q`&mp
brPt<f
D u
LXNr
#q]J
^ 6s
@=*i
} GC
o:L<DO0
I:7n
3t)S
g8Ry$
h <K ]!-
/DbJ
Zs%v}
~5TUD
IE,,
YQ|U
*'nc
kC0vm`G!
L {X
D}@
&Kk`
0<mdt
uYIz
D$hS^
Vp7"z
_O B 7r
0?lCh[
F7+E
vmfq
OATn
V}Af
wG c
0C1i7
'1,F
Bfkbt
HwrV
8pCP&
lsRnU
/54'
* m
F\(a
X6DUw.(7
A<bXG
~7lu6
MFX\$?
n`Ba
QZ
&(m
Pme1
I!]{
Zv*3
H}94
&J{i
m3}_ +w
3s])
7I63d!
b9kh
4u[\%
mX $
h?__&
_nnH
$Nl4
/s~g
Y;&S
lyNY
i1gS
g*ZDH
ISGY
D0YiL
+6$$6
1 ?
~^ewL
t0+Y
&q\)
-J9}
3 %k
S{S"
,)[.`I
/^){X
Sah^
N9NeNMNQNKNpN)NSNc
VWRm1
3!jRr
y-%z
;+Fy
`LqwV
w0w3
b3IS)=H
!-"]
|'^Z >7
-8v1d
a[
)/qQs.
;1:
wChn
Z*0j
+1fY
4df9
^.@3
G.#W
]R~y
uZ4L
OI&z`X
B_(y3
p6A
Q3g
6@[g
Cdu^D
o)b.i
9"U
17SR
<}.6
xu}o_2
3Hfx&
flAS
=JYhCXra
$vqs
_cu8
QGdF[
@ncLw
z*=
nC"_
aVJRk
@+L7
|(B3
/3GJ
|QSJ
9 ~Z
2K$<
(]3`=
2h^6
\Zp(
,;$$
\^ZM
"0hE
V\2u
n#Ce0
Dpff/
&?6?A
1g}8}
J[X*
m-)p
p9@J
,Z7Io
ETgd
1w-L
a=n^m%k>D
EA%g
^`?g
x2"Q
PSzk
qb5 $
HpA0
UO ]{
fsLM
@y*n
B9{=
~Y:p&
JBsM
)YL}g
e@./
!KA<
FTG!
C4"'
HwiL
:69?
1] T
D .P
VE^69
s0azb
Y`j
N+Yw*)p
UOPU
\Tqcl
Q\l"
o5rg#
H@\g
F_q(
+)Sj
UcLx
Ip7P
Cq&RB$1
W 2V
^P<3
_{#hG
x eA\
.$0
[a=b
7X1t
{zXpw
~O3i
JB]4"
C,q&H~04
\w2h
Y/[,"m
Ia)\MK
-OB1
Z|}
+oY[
II[+
r75l
&afu
:YJf
v8H$
dP2#
cj;@@q7>
%p-P
<%"1
d ]w.
1h5
ts3o
w9.`8
p2%"
k>`SW
;4d31
SD6a
-Eq
T{2[
j3VSWo
Fw:U
\Su t
{yz#8
p_4x
|Jz{
,w
4A7k
C{6t
]'\s
/Y ~
s'26S
~coh*
tn*I
A*&i
mj?)
6&#J`>m
O@HQ<mU
|KxY
bMw~
[PR~%
6L:pE.Y
/>N5J
7fg,
h &?
0P \Y8B
8au7aB2l
bMw]
E{#?=
Kso
[/k<
h, ~K
J2+k
Y3c
8 ~E
ho2K
5 W
rXu^
C]W=}
Y>#KQS
2%B
_| e
?'pEX
IK.?
V k9
y;u =
6ns*
*P=Q
_P17
{gw.
9 c5
= [BS
:8qB*
Ya_d
xQ3D
<=MGp6k
{|6)
n5<
u x1
^D=b$
Module
r Y(
[h'k
@.reloc
GW9Jy
/Sa
#@wtT
Je;<bh
eMH-
zDV;%*
kd^e
\6!zU
Ih2/}
}lKsBe
<9|KH
3.=Fc
Tg8[
GW~{eN
7a`E97
]w3Y
=!w|
#."Q
<P{3
Ts %OT8
uUL<
^Z^Q
=iJ$)
Nk+oQ
UBAq
K(QUI
OdkZ3
bo(t
]0yPqj
nL+]
Up{5
su+4
9[DC
l~NUM
VLfp
|{ y
)GApr
^ei#!
kEh`
7SH+
+~_v
~9
O,I3Z
"ye Em
ZL?H
<DK IN
Pp0?
//*7j0.
Paiy
C)N0
=ZnPC
KAX&
Y-%S
l[/E
DAgys
+#
Mc[`
AV6M
J,?EW
J~6p(
DP!g
I~ltLu
/ln5;
wuaLHN
`]^g
GKTp
iLE@
b?Om
ucn.
|+V"
8i*&<
808d
"3z9
vO=V
)f$l'
Resize
'f<jbu3
D B
Cf
W~>A
#H]S
Yg9\*
Df_]
"r~<
E#bvF?$
k"-2GeEP
58M*
Xw,z
(%a3
X8r>
M08(
zY%(
Exb.
"JegI
D9he
^ =";]
yN'&3
g C=
BC0m
SAgP
[ >F
N[N$NSNRN
(z\W
~e-{
PropertyInfo
%~ J-
%Ir>
Ov<xF
jnp{
whb
f"$9N
q%v9
pd8e
;r'\
%HpQ
#l]Uj
KhV9Sv
rf 9'
qR~73
yRWJ
Q.=t
.'R8
q^6R@
H'lC
Ko0p
r0e:
YlQo
g?Cl
wtAS
{'^R
Az":a
O=@^
aP/i
e]t2
EGUXd
Y*g
b; [
<Z/K
K-a
HZNEN'NdN
='8
op:S
^(As
$H^*
d F
1%};K
ZUH!:
W2`F
=>hA
V/SH
Z'y3
7U>v
]zX`
B`d?Fk
-h?W
C)s{
OoUh
h{TD
uK\~
>>HS
6Y:D
:P} >
vWz-P)
y.m_
=~ne
j\%
*f3s
_-6~
G,&j
ieqXC
OaViT3
~d|9
2Q+n
Lzo3
T\pF
"(9d
> {q
C!X
1o>9
$'7 7
F`zXQe
Z{Bb
y7f'
G[FjmEh
X;n+/
z>h
1&M}Z-
E*:'
'U/4
emuC
BW/p
*XUS
'aQV
%5D^),.
I.8
)&4.
q[A"8
iL`_
=HKbZ
oRy
:"g%
FFI4
KuGE
foL'
Q[vV
5/QtQ$
.}[5
D)b'
,/#E
> \uF
(pT<]w
;1ik
P6gOEh{
16C
+ 49n
K_Tn
UkQ&
!.R\C
&^1Di
&Z\ 7
o(5!/c
700a
B n3v
7xgY
> AGDb
"E[d
<%N/NvNnN1NqN
E%&]mEz
hirCM
l1D`
+}G"
$6"L
R YAb
v#2
I}AB
g{`H
J{_#m^n
Tq`it1
I7_W
F{7$
glEe
*T ;x
?O+$
1'goB
4pu"
h#Xun
)t]w
e0efI
LZK9S
w62,K
m1(
}[L$
..Oa
4coJ
0XE*
D'*0*W
|z1*
A\oY
1g#3
OROF~
tPd!
]aJW
(n^#
Hf *
z[inK3
d98h
Ea8/
D(D_p
KM~,
:azT|
%OfU
Y1~
%3<%
]uzX=
l\Y[
cl_9s
8yGqw
QuY]
VVR5
4yc'i[
]_.L
G5npN
T<d
u!@VI
]DO@
>on^
W$,3-
*uT*i
rw7C R
`SO.:K
CO:E
Y,_7!
OXPW
)mY*
N'(j
j nY
H3S &
<\vz
*-^i
l,}m?
|h%0
38p&M'+
\29
C?a8
^z|V
1kD
!% _
SQ!@
mOY,
XDNO;
bB>^x7
Wo{9
Bnv~4%
z x`
EQix`
-[ _
7V/n
Z:#p
je{\q
WaTu
f*2p
7[K8
>jjT
#:]7^J
%nMK
s#Gay\
BW2F
x`x;W
JSG
7YR4F
$ -7
! v8G
efBT
eQY}_
6! O~C]
-X/e
R?\
IP:n
k.3@rm
] Oh
m JI
s>t$d%
+x;=4
B'X4\#
T.4`
T+a\
jge*
m} G
4/E`
Z5q6
U$ r
x4YP
O%TN #
X|1@
WO{.
o0)P
-m^4
w 4/-m
tCJ(?i
JCxT
r3]~
f{C}
LKc|
*3Lq
UGa'
N@NvN
,.(z
, 6
N;N[NxNbN0N(N N
7AzB
U9@w
6?()s
{frQz?
x;X5%?
PFW'c5
W)sv
X"x
%T)!$
eeV[n
5bxA
f\^
]G`t;
|Ajo
Jf*5
ckth
A#r
fWH2n
u!q"y_l
S!(u
\uX-
G!9I
bZU.
n*T]
IlIF
R#YlU;
V TRs
8q' ;Yw
F03<
q2~'@
aq1o
aUE5rP
Wjlf
x[R"
i!,'M
l!hE{
Ica;h
GaVT
6D b
f!:S
2@jM
:XvN
k8Ne#
G={4
eSa8
+yN~i
Egc^
s*}.@
~n+#c
NHt'
"* I@
oH7
t f
NSIV
5|B>
n$j.
}7Uv
8#+657
d]d&*
#7lO
0m:
@R|+
Nd@C
b3+oN?t
s5w@0
yFId
2J ,M}
!:Ra)f
lJ]
"\OY
L\&X
7`t=
P(f,
y31O
) :&
NvB6
'$su
GCOZ
p5kY>
{d%B
c y)b
|%Rt
(#8Q
q ]
{ByK4
1 A.
uU5/
.|uE
Ng4WShQ
p:3MA?
1m/Jb4
c00r
@pUA
I;gf
Ul J
p-|~
pEL=))
Nch?
<F s
tR9|/
lb,1v
E!Iy
Q}v
Yax
&X<sL
^/`20
eQ3A
M$$
:K"
,Cd'
C 2a
e1g
<0$A
Ya1
sC$8
Op8s40dnOXpZtBhXOMs
I^ @
[a{O
+0NJ^
7 (}
)F2&/
Dv1w
W,e.
d`Q$
\5_l0
$:qc
dJQo
qc5m
EIEMp!B
m0oB
/ [*
D}6}
sJ$= M
@^}*
<RV5
ZF'F*
Xl
nx/I
zYfz
mOFVa
&fp$
3 4P
{L u
K7(j
$jhi1K
$;}v
ywf7
2'wmC[6
.3 _
"xIUp
%jo_
a&Lr
h_E)n
?G|u
a6k=
!nxy
XfR4R
bsVU
H*O$
PF{c
gX/N
oX}r
mf7J
ulgA
O'!OP
,r4B
J{+A
HUxU
VDEeh
wcWNd}
Iu.P"T
7e.T
deL!
HK%P(
@ #s
^qqwT
\s(z8/G
t{Dr$g
O/ug
3\bd&
Nde&
d'6!:
i o9O pi
alC(
5)S 9R
x{_C
J[uh
1f)m
,%Fl0h
ed=Z
uKDj__m4
<Y)8C
3ri"Y
jK /
<LU+
qh3qXj
:rAT
R4Z-
2 ~Q=<xRt
7~z
GFMI
% 4
d[B3w
YzJ<G
t#g#
"o=(
b\K`
%tF<L
rie)%wA
n,HU pI
73p7
O67Y,
x3EN
=?BvZ
pT;K
}q}H
uA8`
+((8
-GxXnv
;"u
xun!
C) S
dG~.
N H^
e|u=
;7,^
Ac"YrC
P[g\
1 $;
y` .F
b aR
';{
-5;-1Yf
4BxW9(=K
+i(4
=0F|
ARudlPwtqlYUhLZ
[(h.c
LjC'
_XP{
:K*O
isaH
get_IsAttached
)11,#
eco^
#R{X
i $cp
JFQ?L%.u
jxGo
H,+:
Nef:J
,qiG
U3<o
I v7
pq~hS
hMFb
K1>Z
IR P
RP {
,>AE
O%L7
\]+A
Ai}U
~tpo
.w;L
oWPn
y'BC
_#!K3
XV G
a3M?Y
.}51
LBL2
"Z ]v
NfN N
6<@P
$V?i
=BjD
vaR5
GetHINSTANCE
e'O&
e2Dw
/nKB
12|P
E{A_
zhd?NC
u}iy
,EYS
pF%+
T]{R
pI.t
G@>8.{
$/|p
dJz2
N)N{NZN`NHN
\)y\
JpGU
=|#P
=U4g
)56G
i}z=my
WFC&J:
O/^-
~g:"k)
~o)KE8
AM$j5
8r
*t}^
jPs[
kHFS0
ry\J
zd<|>
- lc
S"n;T
d$!(
m<95rS
;lm8
lHb8n
b~5QY
sG&l
2D$
ttGrU.|
E`c<
'6W0
@5\D +
rSQX
uVkS
Vt|\
_p"A3
:0%["
#pLF
d%Y
Z8EY
C s:ki
+/%1
yEK8l,@X
r%7Yz
+kz@
i.0OGo
s U
kk3
NX=7
ZyON
w~~3
%$A=J f
R*m/
kJCJkO
Rr>]#
9<N
kR9|{x
w+i
%, wv
. ^m ^
)Q)\pR
H},g
]C QZ>
NMDA7U4uBiL5sO
P}`Vb
Xrvt
klr"
OO=W
RJ1
b\dR
o`!?
}/^3
aSf=
sUAF }
_gx8K
Hp9r
9P,np@UMPt
wMqpD%x
QTx@ y
IDAT
Qgl1
l`6 \`
:mRB
M>^ >
- :2
fNMDU
g L\
DjeS
v/@/
sJ0<
BB?8
xQFQ
Qs(M
0k kWj
L/j'd<n
E@k#
qb{(
< &&
*Gq
Ur'
lWJN
l<EZ
o.@b
1|Kyr9
< ++
? sC
G?Up
CR L
vq\h
45w%
$ Fd
s1R %
d]/2$y
7(sGQ
viN`&
?s_p
,E<
b;vN
!v]v
sK4^
4Z q
yux
0q}w8H&
8 {77
t+QG
D" MGEm:
mYCzz
#AtO
~hZw
bh"a
rh )FQIrrq{
:K6
q0\ p
tTIp
GgOW
hsj~
nA/2
XW:0
pp"H'
HlTQ
$7~Z
t;Bq-
=KsBZ
/:L\
X6 q
?# V
JgKS
[887
s
O\sd
~xAU
hQks\
O |w
2!}
yD{1
r5{k
akt4
!, B
Bk[>
E/|.
W`~H
@i2_
9+CE%
cu5)\
|-eK
(~'I
z9]GZ.QE
/_Y+
)! _Y
XY?Tp
!d8d
.I/i
p2ZR0
G\4*t6S
[m&c
Bq Y
NpTgh\
=,v@y
ZM:6
s(#$
fF4-7(
9BJl
/U6y_
mF}d
mlp4
WGZ`c;z
-.f^Z8
sY)
n /rN
j[ x
f%LL
\KF@
uX*
/|sQ>2?D
u"D+
- *T:4
@Vd
q4Tc
)U$G
}JJ9
W.q_
UK$
oy*u
b3WY:
x)*\QCi
E ~^F
v~:{
x0Bm
U7Gb
{ix=>
S O
IZ3T
nn~y
T'kf
JOlN^
*,'TuW
GtG@>K
xazuS
z`YJ
oW*
#Do]
2{;){N}
vGWZ="
37*I
xSeH
";Wun
*hg(
DpJ4z
fseUg
RU"|
M5_!SM
s"XPA
#+tw
cA(yC
Io#'
,E'S
8=ow
<>cv
"i5o=
z !2
S%h~
-Eb|
D(GS
k^I!v<
msDxN
U|$Wh
g`e+
IWz7
h9D?lC5
SoVQ;
5 b=
Un!3
Ja|O
1=0g
<*+hz[-
E&^z
xseO
WS`4k
,kIm
9s o
hsnO: q
%(lf-x$_o
K4v>^
v#WO
g}El
_^S
@k&:
?`6>:Ffw
vrF?
D>A[
Ixu;o
@}n,ci
i"IqQ
*|Z[rA+
qge)I
lm~B2
1^dW
%f'.
H,7:V
g+'[*
T@ku
x8%
K_Y i&
5Vjm
i-!1%:
v|x#
eWNp
+'iy4
0O 8
EtM?
|f(T\Z~|~P
rEVm
Sak{0N
7N~"
EtvJ:Ku
q*QI
OV_&
KaX. D
^m-
l`@u
cD*.@
NH6}
TASd
[Jy1
System.Security
XTh,
26!+o
i7 c
.I\
"[Dw
0hl,@]@
'I@)
c6VQ
2r~5
`aGs>^
b dx
MMJ9
fs"C
o<Il
gX^d
HVYCgHb1NO8Szw00UWi
`t?z
6tU9
#V?nA
@\S/
o_iW[
HVMs
}xoG
m\:P1
}[ pK
vAwA*;
Bb~ y
*x9kj
/ b+{q
<2'L
2<n,
(FYp
6 np
+>p
|sy9^
JcE<
\@6Z;
RcfcWX>U
qr=(
FB`I
95{&
zi8A
ad "2
P.6K
w%R"
C L
DK d
]G+v
~;cH
2Xm%
aTd0
qvHe
x?O*f
3>S
:t;R
ZfFu
ToN'V
;'~h
mU;:
*H\e
0wu%
scf:
Py Yx
4@y4
H*J2{*n
H?JB
d}GiD YE
X$&,
BH $
.qn' >
vTf45
N[NpNMN_N NvNcN
|!N,
yX/ !
[5tN8
PszlvO
wtp?h-
y2q'f
1 !
i*-6<
3&dK
w2pL1
ptl1<MCO
}]A)
7F]J
*#hccO
8joM
*^Sb
P[>{
X@.:Q/1X
P5Bu
? +j
ksg7
SXjDc
+E>u
KvD,
LBM@X'
0][NE
a y.
pb$BAX
8 8{m
N\Em 61
,*,_
a,-6
WDg]
R-Q<Nb
u'#[
}sC(
3BQ My
qVN@
q+rG
EU&3
HNUY
Sy9@-R[
!`<Oj
]kX#
0;yay
bCM
i5w~
_J}P~k
9NU^\zV
&Nl\g
dco-#
U%S9
YM4B
mS}r
)8)Si1
7Ne+
`^aQ
OcaFv
n'y5
%@c
|oJ=
5z']l
5VM5
OVbF
B %7U
\0dyh
hhwB
.*{
_4F]v<
v]=g
R*<[
)8PRg
^`f1
m7$7
J4Lo
m1;?&
C Un l
W+>;4G
46wan
bM Y0n
Y5{Wp
F@e0
NuN`N:N
Gfe(
bTE/SV
'~D
jeT;
P;Q1:9
/~+*
%ayq
kLL^tPU$6 1*5
+L6"
'.6\_
*j @
7n;-
&\hK)
%Kr,
Dz7L
tLE$
hRAy
pq M
*C5
Q<T#
Y^(&#
Z"i,$MB
Y_@&
fF0l%
`g~e
1GAX
_S=l
bF5
'ZQd
>up%
~Dlm6I_Z
dE
#WfS
My{j
}~0K
2-xN
71qu
L|na
fYDP@
5CfDX
QR3X
BQj'
8jsi
?'?Eq
+ <5|
G'k^yB
=o$ge
;t@8
>@Ryv
rOBI
dSXIEoY99mbPg2x
QdbB
w0%j\
5\?fu
Q*Hf
>W_
}P>3-'-
ir'y
=2}v2^o
[A*_
JzT6
A&y w.
tgJm>7s
k0@L
u xH*
~q]D
_m/=
Yyad
,lk=k4
!M858
E*-b
eJvEK
x=im
(cQ>
Ok&
MRnh
8u%S
cX OvU
\4*Kh
{)/g
\z`d
&*87
Mh,h
oA 5]
& o)`
!"AOl
sP.D_qS
q,}C
n0N,
Q]M|q
dc[7
&\7&
\'zq
<i2M.dn
\*dR<
9DQ4
o='S5i
W Q7
5Z`]
lSC/8
5`-?
Dq :q
aPb^P
.7{<
;5o |
P3jL
*_$s
$L]\b
P3jE
k ^T
7tH^
sWAi
$=lo
"1Nd=^GIn@
x(n8-
Ol4RK09sXl
M&TH
*yl%
-`UZ
. HjMM
)A{+
PTs+t
rZw[t
9nf`
7 y=
k,TcdU-
I}}?d789R
Td93q
'2 - T
'/"_
sLJ
`w_ -
8yIS
/i]F!^p
Aa*r
(z?"%j
)5pV
.nGZ
3 d_
\@! <
#AHn}g
E^`J
mU]S6
._4l
?C!,Vp
QSPu
ne2,^
yMY/
q`|C-
>SKboC
$)h^
n}+^
p#3K
v$B
.o_(
<G<`
ux r
"@`J?
at_.(
E0>dBY
aj2y 6yk
xp9%}
c6"[
KR W
C rq
R^n-|
;Yi^
< x47
!A?
ZlHvTbF
]kt}e
RH/Wn4C
lbzL
>!Fb+KL
/XQ
mUaK
@5MUG7i
vD4
%JgC
%?m:
b4&X
&p}G
p6q~
>4g13
]lK ;9D)
(~\Q
ZE}g_d>"
n*y"Dz
!L ;u
I\fUA
q|v8
OpuG
c`8HY/F!
hcU/
&>6d
! :XU
,l0_
'_4\
^AC|
t,MF
)u9c
V)V^
e`jgr
<UKE$O
|w6J
ge:L
ahhZ
p4XS
{ R
tu%G
1jP1i4E
E#xm
%7EA
j+%,
! !k
'"2:v
^ yw~
~D^Y'
J(V_
CKK.
xc Z
HTF~
O!~LL"
n_t
xI\
z#qv
*ZF
zJD}
skQS
*~]P
{w>H
:]Q2
w8<"z
@Md3s
PMU{
KD~%@Z
% P8
leO`K
6:]J6[
R>xV
W/+N
U.*6 b
?5' _
>tRa
=MvB
2Vb {
JFmZ
^ ~F
,$E{Eu+
ztM"s
7rY
v`%Cwa
fsyh
*4=;
V$H+C
a[=_o
8.!S
1h g
Jh `U
Ltpe
|Gy[P
<6gW
}ADG
S \\
9<`j
UPkr
##e}
P*VF
iX5_9MF
yw3~
SXc[
+:HO
ZccI
0/H?
mi b
AdCdzY8GIX3ECbUZW0a
[md
<Lg-RM
L cJ
z]Fa|
5 >g3
9A J
$VO7c
' d~
eu~dsk
tFu4X0P4hQLbF
v KN{8dXU
_>_
-7|/
x3Mb
'GHt:
KCf-8
`K-=
Z._8
V&}1
)4g
BRQ#F[ p
V/2H
/=YyVB
Wy*H:t
$ i;
,r;
)\b^
(cH;r
3FXg
EKp8V
{*d"
Fi(
]D/rT
5He-
j*F`
ECeH
<Vmh2-
^~wK
@$)Uk
'Vm*
v`D?]I
YE`b
*w~7
V-&e
SFu3qN3Xx3p9aoi
Y0Vyi
2t/Ua
]~ ,*Z
;}ASW(<[#
qMcO
l} ;Ki
%8`wkI
>1Q7W
z6fJy9\
$@`.l
Q]K5
. Er
Im-)
}80E
?.'G
w$3K
9#7!
teCQ
3DaH
= sf/[
caX}
^ K3j
F'nG1
)`NS
S2m ~
7s~|
II.^
`lCX
xjb%tl
-<u8
)D+4
o=lzTBTSO
b
q(6o
`vxm
Ck@9
cBV te,
eC_C(
-}o&
uTf5
.5m[%G
99 H6
p&y
b* +p
%Gvfk
L^V;h
b"uK
DZ1`hR
0X!|a4
48LX<
gL$A
g~"pFm
|k5n
veY[-@
)3kt
-J0x
:Wem
+%bc
8Pu
E`tHd}
X.5`&
)Eiz;|G
;@FK&
;rC]
l U-=
r M?[r
fz3|
&.3R
<Y;Y
LIv<
B+<(:
0X&
}r.l*
U(=(
q:h8
##~)
Pf>~
lPddkZmLX3upjOdt
Assembly
KCTt
1C; )
%K!W
BxRC
6= 6
3|+{b
_v="
&];3
fQ9
)`%*>
#lh.
9]YU
CC}JzD
IEo
4I)0
Kv2r8
{@ "
.(%gm7
[;k>
2riV3AhVUm6G9JR
L,6^
k4LM#U
6 tX|
DossBmVSdjH6uU
0_=-<
Rrb~
cw{@R
8* ( 5
H><k
01b1^
qPu[Hj
33ho
svU`
?rhwB
x$1
h*-l
!OH!
\)/5x
]iC1
`r~=
YJ x
y),V
NtNbN NvN
m 9D
jjO9-
Tni4M
d\eU
S|38&=
u"!8
is~
y4+f
N {
qaPC
GkcW
&k^a
53MIsC<
-H)9
3O2&
;8}-n
~O#
\ 7r
R#!BG
Y *g
X2 FM
iyl7
|E:q
XHH
Y0bI.n
FE|<
1jSV
BG>(
aJRy"
3hPn
NlNLNq
6o1o
OMtW
6|_7
f\`eFb
X$dn
j0I?
b9vS
e;&VZ
BnJ*n
0q!'
2t1i
(ybN
o q4'
v`Ea
h|$L
,CVz
v6Ll
liN&
.gy~
@hZn
qSBTa
XUCu
0B_'G
J*K8e,
wvUg
)i<s
$lJ Y
W fB?
@9_t
.#(R
Dr$n
w:MA
Bj[`
6@Th
J'M
!bL9*z
'@~XB
e Z<
a_;oT
{ 9:
O"o^
9i)Kt
LHU]
-\?
5ZhF
WB a
tj[*
}v `
gS#%
: 2
6nC%
XG8+ah!@
bfd9y5STbvau
QE"f
:w.vS-
iS)IO
=eb#t
%RM"
NIN]N
Q0l5tIE
6 \=
( 3
i@%Z2
M2Ae z
IC u}
,N0,o
Rk%I
}d0te!
S$"`)
><,L
[F[e
SmHPJpb
$a*-
'$a.]
S5;
f:OB
\sUvQ
D?0$
Aj]V
T- PU
Wcl|
/km7
HImj
[-EZCnB
NyN N@N
v X*D|
tk[u
zy0
(RtH
*VYN
Dom8#
MSJ;
zy0$
8M/*,
2X@b
4jV8
System.Reflection
fyL,
${N=a
Sb)^
O_}P^[*D
O )0
r2%d
2=vW`y)
2Q|2
OL?V [
KW,-
-=qa
Y'gP
YqP4o
^VUf[
&Enm
bFs7
<2n <J
Pp@T
SQ_)
_aA
v!"^
8'(|=
vIjC
Ern\0
I[R[3
+[g`
/L]
r_ck
%cYb6
%d2/
ONbWq
M>dU
y&05
)^dQ}
64~Z
#5J2
!g3Q
Ch"t
BX44
<jqz
(D9a
:VA.
PO7A
za-Y
$~_Z
l5Ji
8 H^
hy Y
bWtC
xIzEMectowHgO0epC
r4H2
2^v2
_1 XA
i_ f*
joq-]
iMIf
)|Th
QtU>
v58O
;A?J
qlK2MYNlPMkBBLYA
^HqX
bE-:m
\sIvM
t<0rS
,(S
E9v`
.mHi
3SCH
zT G
"^a5
N+^b
B1Ua
)<Vq
gP^P
yz[w
(#p\t
\;f 6
w (#
8_["
z%qO
q0A (
]wm_
t^DC
hF5!J
CK <
TCwA
'1,|G
v*E
"Cm2B4'(
YR'-
"SPH
?%W7z
x;"S
j,CU
#[4s
EO=f
D gC
GQJ zad`w9'!
!5~2
1?MX
|w5' W
og.C0
SX:C
7{:)
r+@/
Q+^T
zs,Z^
*1HH
P?/
%cZ9
r;U\
WxdB
, Uy
65W2|W
[ gX
OvSJ
H-&_R
CZC$
VXqh
"JUe
rd]v
Z%^k>
.^&Q
V"].
bi 7
}
i,$*|
R>!I
[I@u
Q_\ *_
OvSy
?AG7F`
Q $!
<eZt
+"M|&J
-,:`ED&
e\nt
BJ-&-
V ?
iXoi 30
cS0Fn
ueM
mR,3
,(C8^cn
f8Qs
2LqpV=B
iT(7
{P;S
$Gl"
CSk
Bb#G
Gu2B
U}"_
5A k
nq~m
<l?F4T8
"ODU>gBO
B?Q3@
EOg%&
I8U
H3rVl^
HL?|ri
4 3U
O V>cqp
r [dS
hrp7
T tAw
Y;ef
^9.n
|:U*
#=*,D;!
1KkO
CVAqbG
2M]68u6n
_ao
Fo'6
iix.=I;-[
"4 i
G.xi$V
dYt'cl$V
?Gy^TnG2$
%/v^
L`5E{
:xIWa-
U2SG
YvU,EW
fU!;
$s(
WaXL
.H m
4%(o
x FB
x FN
|Cl&^
MZlv]
)(,"Y`
v Nt
i j k
};\p
[%U/G
=W+I"]vU
X?}i
5E>V0
nAAM
B8^/"
y-B ^
;
^ez-
,.&aC
U1'V
oBJ
,\)b
{Rej
5sT:
@RMp$|
kc2k
6>*1x
(Je|
(+;`
@S!qp9
R5:
^I n
gfqJw
'hY\a
n= C
:#drl
_y,f
FWm
Copy
uIQHV
AssemblyFileVersionAttribute
g~=?
c.6}
pSr&
p}iZ
gf>G9s
.3 $
d~T\v
H* 8
~8
5"qW$
K4;xLq_;}
@>MIz
;{,2m
|k"|
m=K`
3"'
PE!P
b8q_
D/&D4
,BQh
?q^nY
Xs[?8v
eyz'^
:a'&
Fq Y
0iB;6Z
1P%NX
M&I
* Q1A
~bG2
k=z>
twy'?
, Nu
x305n
H7,L
O/I=[
nZ?WD
%2M z
xwPSg$O
%RcNo
V*Sc
1 Z/
Qeh<
x|Oe
ALal
FB }
gD`M
%619
YUYY
[YjG
n! C
wx4T5
rKyuot1vfJLVGtJ
F =
Xn5$
vyjw
m<[>
uo`o~
O,lcx*:
"iP &
["DYu
j93-E
Pd -^U~
{MmC=
*L(U
'~Lo
SZ?=+xj
& [h/
;Cd]
Z4e6
[)u:0>
w}63
Y;Ji
T4>erG
4@N#
%JDk
TL\o=&>
'O<B
YSOc
N4m
=Zfj
dw'(
'S2R
4WXVk
3[I-I}i
# Za!
];uOv-A
d&\[`
FRn m7
,XhhX
w ib
Pt;y
I0 M
q\POJL
7hny5[\H
' '8
#sYw
E6SG
JKX|
_xm* x
>5XWWu
k^r r
N#N:NFN/N[N N{N=NwN{N9NfN2N!NfNmN
'0|4
^R w
*ONxOdf
{:}R
/h&Q
0^d
}c]
C4;^
xJao
(JNL
E& $
y^6x
MP\/E
_ZU J
q`W8
>#6u-
Yb N
W[GN
[,5
yW`4+5
GG H
x cg
K'bW
;[dm(
KM 9;
g58c
Wy,^
!]Jz
4+<T
y?B_0
g\S"
(nSW
=.9{
DRY`
djHd
#, yn
E,dKy
7!Ya 9.k
,Ka^
RG`b
uv-A
<<#sp(
+aIxA
pI`S
QCO't
l^1[
t2 o w
n_`
6cCM
%p'jO
&^uD
wYTu
U_g-P
N%P0
onqAZ
zijp
7k/A
[tLc
<z33<g
7e-|D
Dsw5t
7xl^L
sjAy^
-i+,!
C% "
Y#ws
` 7A Rx
$>$H^
q
Y>/c40
|yLbX
<t_l
EQX:
L,E
e,Y}
D. z;h
~z/P
=J\Y
onU4"
nHs7
`M:]J^ &w
/`$S
yb|7
bC8W{
(td!2
=D`? N
-b F
gO>#
t5=H6
v51Hl
~l_
86qT
NtG$AV
)Z]"
R0&E
owaG_
m|PCC
X10|
G&rk
Y8~@
/6+|$%
O-BB0
I6@U
*Xs{
*=>^
M\kK
g''}
ayY
|:c
k0eC5
F=-2
8 K^3
1qp&
)C&
(+C
|3]-
N=h:
Gart
wyp,
r[s(
jC-_
$~.T
*1*
;pg
3~-n
;1Ch
~ G'
a6GA
/xLL
<Va(
N<IC
g&
s_:t
. C&"
O$;a|
@%YG
K|.I
tXfW
}]oD
9 FP
4;N`
DJ?]I
5TKsZDW(
sY,P
ISyM^
l 7hvz}
a/p#
'gN
p s
Zrm
eN.D
,2$gxE
e`Zlu2
(DRs
RFCl
*9qv
(.6~
K83G
-P/-R
3-35B
cZBe
3;9m
|c\7
D93bMF
gYX
0$S+
cp|"
r&o|
jVEdF \*%mE^
z0hA
*+/
R>pe
7oyk
i#J\
>_?P
qCqb
0OZv
vq=[2
A3F5
+hUn
ZRLJ
`z.0
>Ha:
?0bU
^":Q
3/Qh2
Cq5z[;
|8^D
r0$<
&g^'
&skW
2L,w
? ,Ev
K~pL
39pd
RNlo?
d!]yT1,#
3 Ph
eJ2ac
o2zq
!m4'V
v8'm
-)l+
e|xtX
cW b
9#`L
x<E-
<6o;
ryqv
AV-d
AJxi s
k>+Z
C5-Q
6sM;y#&Glj5
USBt
iDOI>
;|1i
{|x/
rT e
!Hk9
nzjl
oxcMg
HARmz
gY^
3FP;
v~S4
NRN@N
' |f
+o+
Hs ]tm
h=pR"y
K00>
BE&>
{UC2
2-"h
)[~\
8%~]@
_]"H_3@X5?
nV\QN
\vK3H
~< `7x
&eu@a
= Aa
{ R'
b3D-
["_
1T=[
o /)
j8>m
f -d
4C?]
!Z=E
9Z4z
xe]&
26U8}
@f;2
`3a
d) CrS
8M I]U
y e fc
{d0I
,\3s
r-fq
A"Lz/}#e
o>V\
L\D0c
w`6&
xs 'v2
@$zJ
h [yT4
$ECa
:C6l
;bO{(
~nZ]
7(9/
$gsD
wZ"C
rf;<
.0G6^
0r84
> rq
4kDo
_Q>C
"[G/s
Xi/HC
@c Y*
[RLi
2oar
i](#
r";fS
p/Aq 6_
w0_%
?/i`M-
Q*UQ
.A}|g
]Pw)'p
t&]6
G"X
eP|C_"(
|">4
%`Sb
iZG
ag9z
NUN NlNxN4N3N(NSNqNeNcNMN-NpN|N}N N
!{7"
X v`B
g@<Y
y#5jy
: #
j%|F
Thread
eE41A
u'I
AWt~
L7af`'/
0 3
-,&Y
y@u7
BT<j
+JZd
Q;M]U
"HTi
wsO]
\7Sm
a*~`
I?,@DF
AD^=
EVDY:
ea%N
TNjZ
<x((
!!.K
`D=O
nR(`
}sn
P#c[
7oR6
(884
%4sC
oRqc6wTgd
ARG,
u1Iz
6@MTA
~xt/
bO}`-
w[=n
j(t(
B[5p
4I!C
m`YmZ
D`/8D
nf6?
,"8p=
" w
`g7"
d!oJlC
-rMx
Fr22pe3DH
~M6m
#@Gi
d|phx"
]}{%
>+xMC^V
DR-T
?qv
$l $
Vs0P
?F}$
7Wf^
))oD
p~|~
[ !|
|x/z
A+>v
Vt?]4
3}WLdM
8]\8
laN\
\;6vPK
{DTD{'S
#eTL
t ~(q4
kI95}
\EMQ%
@sy|3
aX|6
.T[m
CIk*
&AX2
KN*op
AZiE/
`rf?
A,|D
\[ ?
y.?H
7L7?
<GlSQ~
ha 1>
^ 63k
VmYO
<ay>#2
5~U#
yxcX
v__(
N Nn
U$|]
lP;mM
B\ x
56AL
Sfd2$
E$9-eS
g7R+l
wK o
"{8;
2 nW
+}%9$
@{|`
4h< |A
I3*x
#S#wqW
32L;
"-n5
[]R!
+,\~d
@%o4
U[ W
m8{#
n($9
f sc
zjU4z
V`KF
r)T-
wHt9
-=8' 6
O#oT
AD">6
f: P
jSB,
GF6xq^
3_AH
@8%/d
hf$C
`YDw
:Q e
rV!
1\]8}y4
TR>
D)4B
''E<
Xfz0
33.
z^ w
~IRM
YbOq
Mo/
{E>3s)?1
_g1+
G[X'
!(&+
c j&C
|JbI
6 =G
6">r
,,ZZ
Ua><
\hx5
jB4LrJvG4QdFg
O2D(
JJ6 ut
>C5+P{
]-#_
$7ny
X s
u6 I"!dw
@$9R
=Aq
rSU27?
;kIj
.,/o
P*$G
AXy
';eH(
UZH:"l
%\CA
JfCQ
a_W;
=Z Z
N-N N$N0N
+k"-Bm
u,q5!TZw
z*"!
Fyy`F*
*}$t
s*6 #
Ky>$
z"C
;)~l
ds'h
jx$
j_,YM
nH"}
R|IV
% ~2]
.T<U
Vsvp5
m0^[
cMCy
"@<]
[Z%q
Z 1E
c K D
Un@sy
Q=:y
ueYa8L
f.aXi
OFu9
zm"o
alep
%% Ok
%GQCPm
t";Qu
0tjhwD
Oqt9M
^HnK"
`<BzC=.
lv;\
$f '
wY)a
{Jx,
mR[
FD5`
0tm/
hR%Q
pNVh
yB0Vj{I
qb=C
kgaaB
Em8
inol
=4 Z
_:t
MP[NH
KmpP
$FB-d
_'v?
R}*rE
l^j[p K6
L"v Z
|b[
9qo.
1B#ec~t
sjk@
f)J{XP
5IVgUmMvwoU
?rd ^
VPu|
CA,a L
ke*V
S Wa
"eg.`t
O@D\c
49;c
#y )8'
a$nF
fbTp%
g WJ
IZC3
SuDd
F$X.
jDet
EY$b
k3:-Gk
+EQI
s00F
y\5xx>/r
9BXs:q
'C*.
f7tC
L2D>m~
$|Xl<
BH:,p
-a3I
-4^SJ@M
)fSfl
uN-W:
Q%(f
qRL
znnHp
{1.t
[?%r
[*gy
iegR(
bbX3
B Hfs
IsLogging
0To;
X%U(
P)(6
e=ln
u$-<V
%@weI
-Dp@
mzm:
"$<Y
C7{1
|++_
{=O+fp
SJf|
i5K7
&Fce
AdXwJ
/HP"
VxIV
hW:
'_Uq
m z aa
nb7^
el"|
]$hl
2[N7N=N<N.N4N
)bik
m\3- W
VKh
:=8-LC
Ve1i
U l
5'f'I
}O>*
.IqX
Rl/R
'DED
l`Pt
x=m//6YH
(; B
U//^
4yb*
]Kw}
Ql@K
N~6A
r[B 4
enDd
%h#5^
wCnSr
kBQ9De
$n1-Zh
D o,
>= o%D}k
["F]p
6 Iz
])%#
X Ve
|=N?
O+M\
s A
X#-;!
TRt ;
C}Mi
=OMm
_=Wwv/
Fr5yiJ\
_(Qi
;(t+7
H.gz
tOM-
7*kl
(]%w*
~PHs
fZ^h
oY8
% n,MS
I|6$(
+QYg}N
#kW<
Wi5(
1fha
5-ep5
w>:Q:
Y\`x
Pm.I
}V4o$/
cGm[
y> w
Y")F
*PD[LK[v
7ID4n
R3L5
6#wn
s&l;
"3ke^
RmA%
!kg5^N
K&&B
9g~h
/\BoC
~Q;Z?\
*uc}
p*_V
7:6P1
]eo>v
7wFF
3rNW<
~,(SZ
Z4ix
1tQ0q
`]I>89l`
@`.s<A
VmO B(
:+?~
NzN9N
d*V
\:VT
m,i4
J F;SJd
cU'/
1v *A
oP*
FOPs
ALBc
syeO(
s;c?
q3 p
Z@|<
G oc
ntE(
c=Wy#p
Se@Z
`okp
tRIdqn
:zc-
@zr/7l
t2v_
Qy5Q
94k{
9M^uH
N@nV
(:? ^Q
zp`Pl
qK<l
Vn$Q
?-LF:G
(Jm2
7B2\
)6Ir.[
Environment
$MC 1d
stJe=Y$
ExaW
}`G)
:ph~
c7T
\9PKK45
?b~W
V5JFY
7RIJ
? Rc
7Z*Qc
&3H{
z9<J
i M6U
]LRi
s>081
*[ v"]
`09Wx
IK\#;
>a4g
)+=Ab
=|`]
[ay
s !h
do_E3
qUDb
>RtH
7$ 0-
y{ua1
#K =
QJQ"
RwW{[
1Z.U
Xzq`
h<*,
fl8>
8FM0
f$vl
2M4F0
?(An O
|>8
7g!>|0
A}QTr""
I(m6
6,t,
E7F5&3~s
Q Sp]
PJ"Yp-g
'\7{W
1 TX_
c.+'GM*
W@.;
mdf)
$zVjg
8Z2Rw#/
NX c`
m Q[/ D
j-^@
Tns$VY`
}bzb
N@NDNRNpNXNrNFN
jK8QW
VZmk%$e
"dM!
/C:gG
7V$Tg
L>f V
5K"BL
9%mA
OrAJ
|.@r
d KHu
\Fx
w^sia
>lYZT
U\|QJr
?\r3)
ejK1
y3JB
B*n>
\=
>=*w
B+z5L
.fAkf6/
}GSO;$H
Y"L2
7;h&
K~6f
OlH@
fzQY:R\
?p"d
`#YB
3Lgg?
&k!`T
Fc-r
vgw!
V&;a
|DKw
6Y93
%DXy
862
"`j;
~Q]_
yC'"&
rTO}
#lW4
| w}
nW<
>!@H
~s9V_k
>OFob
3m>v
jr;O
fB]z
vDkhevd8WH5RH
i}V
.4*2+
[kqbT
] 4F"@
Eiw]A
r 3!V
e! 3
>,Owc
(kqwQ
% \J
9kGN
j|pG
p=^!
1"'xf
%.kw
li-!
/C+[
r:q{
uef
zwnA
p}:jy
|tlm
j5=
M [{
0b[Q
Wk~k
BC.R
H6UX
(]Vk
W3Ze
0= .
~C u
/|b"B
M usQ
&q"Z
]e.L
?,wR\(9
q#L7'J
&r-+
@}X41^[
L-H8(
[V m[
`+ G
4I8Dc
scgqr
pEe,Rzx
,A$]
%f d
.P\F
8ezh
D]W,
nh{U
-IIP)
kx{[
r~
\{sZ2
UC:5
gc%j0
;*cn
v/ (
\7'Z
4d ]
'<3F
BsE,X
fG"9:
WQ7s3
+ _A;
DTG`
fBpG3M~[R
2`[Pj
a:a(\
v y$,
mci
cNsb
g_Kc
VAH;
=jEfC
]kHG
W| n
&1 KU
Q `v
~j%3
OSFPC
DH >vj
y/3
4crP
Be1rj$
# 4jiV
gQUy
V}:,0
=eM*
NC.S
2w c
1lWH
qG>S;
}0{E
jocfO0
NW:ve
j_ -
5R_s
FLNXN
B:@h
WboyR
aUJ=N<
OuH;
>"0b
%S\m
/(GOGw
c0(n17
p^jl
Q<C!
>qh,
oAGgU
]+.5
Iu0|q
h4A(
?)9Bd
38[c
_ZWv1
C*QZ{
9h#M
j&`~
~~h#
H/M3
B6l#
"ta:v~O
d-)zVR
R8W*N
Ko3Y-
@]mJ
,4i
w!/k<VfG
4{@|
< b$
N; F
Pw7
I&jcw
**U
UHd?
B6%3 S
Ub$^
S?z`B
#ron)
O8;]
T n{
ngKUo
uN]3
!|6{
]}LPT
0NPR
u$R$
`7Ix.c
Yda~CBd@G
X89-
B'{wP
.resources
zXt+
#(b!
O(P*
03 (u
'*OyV
}|G|#"
,t^4T
9S]U
+91wo
oskfXSc0nV
A!5'u!
: e,1
c -?
~slu
\'A7
CH[s
+ N|
knz*
i$V{
8Ijhv
A]dR
M,Tj
pCK+
qz\RYPF
NTlC
d_{d
{9/&
o+ !
iD8E
h8mb
Xr;O<
8%?
D~>
<BFY.
yd}t
5,'*4
&|B8
&i^
*11A
GW>x
nwHg
*="s9
Dha5=)VL
P'E4
{Oa'
xjRD
+]k@M
N#N'N[NlNNN
3/zI
sZ61kT5~m
(RS
%5 ,
a \3$-
kc{n
sY*;I
=j/2Utf
D4#qd
7#ib
NiN^NoNfN
ZZxr_
Km6S
3$HJrk
(<`W
O5<z<@
#Q>3g
oem#Cue
Q vs
q0T'd
@IyA
!F#6
0Ud\
Q[ y
7Y&V
8lGh9
I:'yk
,dmW
\PyME
tgv*
gEk6
8Gg1
??\Z
z2 E_
y4|}
YU%"
5Xt;
Ig/s
)"l9
8Ggs
o3*[|c
hx&S
. U]
5_`C
}7N?R
F7 A
s@s_
:seg
(JT6*
4D(9Y
z|rG
$E.o
k_Rf
\;7+
v8 p/
I)Po.F9W
,{0$
p.w+
P1$9{bv"
\-*jz
? jy
,{09
[i@qvq8
Nhik
,_r
|iU&
+g+L7
KuhH*
z4tC
Y } }
+6:dbL<
Ehl>K9
Op@
z7C=&
Z6fy
u8U=
k}m(
L2m"
4Q6GSWMTPN
NYNsN+NoN
'Jn
[W;^Q
2>xA
8=!X
Onu+
>2Nmgq
MNRu
V *Z
6[(/
w6Pr"
=a\S2
`yfW ci
4:e{
:= f
@KR x
$KwT
I7&d
&,9K.
?!^6)
9m#/
H^+M2Z
a8 >
v4:JDY
* n9
[j'>
*,I7
Ilk?
mzI
~-`O
;fLv' Q
%|00
m`8P
`e."2
kcSg
fWS0
7DG.
?,lQ
H@/tT
p3 ,
6O F
< yDc
cNK$-
QM$JN
D9&t
J.-D<k
>w;+s)
kU2nO
RM_E
T:~P
pM}X
Hvm ]
HcMX
zZp2
wv7mEn*
W;b
p '
>"m^C
B kR
=h1
&ka-
u6/5
/_Yj
!HVV
Cc6AR
9? 8
f`/a
['?W7
^G2_
FAK%
a4\5
jL(B
nCS"
N:d~
dvfw
inL
j~GX:
3u%N
!yH:W
k-\9.
GhSQ
mvxHe
D_y e
lUip$U
c\9<
&l?i
Mw!&l
T #L
`rnd
N6FL#
3Jd
3 u5 :
^aT_
$0E
T"1y
> GHy;
v w@
jkD k
Jn C
$^ Xv
EGeu"7
F, Od
n 4 P
.hP
,^8J
@m)p
759e
n5+9
5c%p
Fj0G
bX5:
V@G_
BSJB
}M j}
596-
;x>
,CF
I0Y
*72pc
V.KS
069q
iWi^
T[dP
&#7`
39(Y
!,rPI
iF -
E|LJ
B]J#
&z8*;]H8
HHEkX
S8L25<
psm+u
4 2 E
)n'^
|!OC
Bo<K
]}Ioo
I3")
Xs.>
8{1-
%&T m|
bG, \4
U-KT
]e$B,
;GtP
~,G\
f{I ~
,?@4
o,6~J6
/+ ur
]r/w
CBjP
~k `^
/)h%Fs R
qQnGvyQuNYP6GHIyb8
WggZ
!$Bw"B}
U9 &
~sT`S
\>VN
P*gW6
WwF4
\>V>
m!]
W+y~
2f-X
\[`v3t6
QkwH
/L0a
Xcy"oS X
z<Ta
rXU3
Bf-0
S{irl
h9TS'7
{hz
Pl9-
}o'}
Xd-J
cM=yb
fXM|Q
N( `
+{73oT
mj/A#
p^o
M;G+
rRZX
P=lH
-ft.
@U0[
jE,f
s ]
$$<!
Cw'X
}=nk
Xv^>H#
OR:@Tc
SR,h
:$V.S
IEND
-HBYs
Je\j
qG|G
,;IA\>}2\0
|{[x
:YxA&
R}E
XM;}
H8-b?<
=W$g=@'P
h4X*c
Kgrd
\<!N
FByhSP
ZJ\$
C {
e%,F
M>t
'. W
eQ0j(si
p*:]
@t,-rn
![I
D+b-
-n<e
,`h}
ZImR
7,vG
i2 x
/G,*
S%6,
-~G[
XXR>
o1qU
GS=j
szB#
IJ^i
?xzZ!
vE!x$
9 &'
P"K
/2 .
b_d1)J
Ee x
FO}E
V`|
GnKi
|V}@:W
= bV
QE7Q\
]K!\
n#^m
.EUE
5;<
l0,&Q
'=/X
xoE
B5Jp
,w$9<^
l2eCBm
&6Nq
`'.@
A @\l
%V_ru
xoEJ
?S1y
xFe
T{9F
acILLL
"Onhxl
2p H
O@7>
!!pf"
}I <
, jW
: FubEz
_f c
{0-gE80
J20
YJ!*x
7Q *
NdN"N
x@1u
B!D"
0l_
Pk4m>
+J'=
KB&>t
-rMrB
4yzc
uPcF
>i8{/x
1iXJ
g?8~
FG #
I9%6
{5:k#
%E7"123
7 `Y
3qFs
:K9V
]~)a
jYEL
iv*z
Tr}$
X/+$
f> q
y:I(
OR4Z
j*\ J
_$kM
0| %
-@;_
K}b65;
uOcV
G=!`
}Ht(
e)x;
N(tV
UWV/
zZ*`
ZK] O
TQ v &
>{9f
Bk^\
F/Q:D
-PsGp
!d?!
BU2F
O-N((
]aUI
PO2|
A #AU
e}8,
p(m)MdJ
F H{
T)7R>g5r2
*VNkN4N?N
T(0r
;`I2
L\}r
KM1!
E1.x
~eVLA
Gv b
)__OM
s{mk
U!'n
n:5L
2V3m
y _E
%sIrW
s7%6
I<jY
._fH
.e _
bFhH
9>*m
N'm@
8F jf
ChU8
YJaK
i}$g%
iGh#
p K>
d}3[
aEj)s%Ap
N/d%*
N "
!Rgq
*qt$3
wzcq
~z:*S
t m4=
CVzv8vs
kU21
+:uM'
'4r5
G!Zm
G^ {
x,9u
@8Of
h\ \
c aLqB=
`[e6L
w vw\
zWxe~
u[W'
.Ep`
V)$+
yPa<
\ QC
_{m@
=gp
Ai4r
83"7
%'i
.3
h^M>Iy
k6'<
@?w%
U6z-
3` iV
bDn?d
~<8,
Qog!7
ts%#
I-d5P
yNji
G`|N
*2AX<'
"$!\
}b="
uQK,
:%)j
s5dh
D I]
- 8.
K a+
I\7
N;DG
%u2
"R4"kn
3 `+
V g2
2TaH
)SWt
\^82
8F(tk
.1^X(Y
U2B({@t
{Br4
"6cE
Qys]
8*R0
Hl63
rp'~zg
_[mu
|-,<
r8C9s
eWK<
7h&T
)%Ro
WZ*i
yrFh
yUEGwL\
B27d
Q @,Q
n6[ ]
mcD+
w.xhj
+b#*
"2 kvs
=rBU
5Vu4
*U"-
U?"o
M-:=d
i&UA%v
2F R
%Q`'
/Kx v
<zY= a
Q&29
$3c%
<[
X2e e
`rBhv
q>xK
oH|
YQ
/O*E
H[{3
1o> /
Zjb;
-O 0RXq.
pa8f
sSgj
m#8
]D/m
h}ci
* [~
-'u,
E!te
,)-$V
d%4,
a}T| 8
ZNZ Q<
Zuo/
V, Z
0Y76
A~!O
;iB^
aYH~
(Pm,
e &B
VfB|u?4
p@lI
*BCA
|gT!
Z*?8#
L6 a
:}~x
u~oL
V&37
GetTypeFromHandle
5,]H
k+>E
7g>)
7g>*
}Z=-
lLr*1
pL$ 2$
RZU8
>}e[
nqu)
Bu 0z
2WD4
9_w#
rfa0
T $\m
(wM<}I
+)!GV
86 <
$\ed(3
yPZE
w j5
_{vY
xIq*
`V g
pbLV
^{"b
ovz2[
x*F4u
zX.!'
a~Me
_1<_8
0 /A
z~ri
;}6<
NM\n
a.,
C9pdU
7hAW
SO/@U
>[-D
J2z
FIt\
ER4P
oDs^f
{;Xi'
&q:~
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
"M}^
.z+G
K(OC
RWL^@>
<d$e
FKlkA
N5NeN=N)N"N4N$N^NIN
Jl0D
M)<r
$VI5
0NwD
+` 6
r f
; [
=Oa}
~-&
@=|M?
V \P
Ma:P<
&g3i
1/|
Y7sH
3@-af
f1 -
tzn
et-
`i4|
HU=I
@=Wn
T9=
"R +
QB CS
tJ,'
7 dGR
i|Nz
~l"T
`;}@q
wPL>
Xd >yUHK+
kk]a
Eka [/
C-CC2
j= [iO~
o-g6F
\=j
{H
:b%4
vf@?`
v,k']
$W]>
u:I4\
;{]A
fP@:@@
wtoL
lR}ZU
nUr
;L$tI
/nc+
b[)&
oTK~
$Xw{
+ 8
f_gj~
8z!L
.1$4
}Z dX
DP@*ej
G<)-
m<n8
~mJ
IaVsD_
a{y|{
x;%
EPJ;
dY&-
*l_:
c` C[
y I</&
>GM>
%]Q
,SI@
Q]H2{
r.r/
MVR`
xMMQH
cmJ&
\x7i
NGN1NENvNjNkN
V{2
"BZ!
;tC(
get_Module
C{B#
-TlZ
(7te
q\B>j
vk J
8d?i
.F >
2Eh>)
hFQY
)ICS c
E3;2
e+iO
6!Q&
DU g
}?=V
}+#!
f*?"(x,
zlDE
rm5B
sY<|
AYW^
CAy3
HGz_
P%q1K
K-ED
sxhJ
W,E
0ko\
A{B>
_Rj"q
q$*T"
kdCZ
>`|
NwNVN
mAz%:z?u
Ju0@U
Aby<
ff7"
bhXfD
_f[h
f!1O
6C`'gW
**G1
[ExU
hw v
7Ux[N
qE5I
.7~p
XJE<Y
o95
XD-;S
L) 6
Z~@q
g/5-
LQSkq
5!ma
UxOk
0lWH
24A\
*E#
t(?
1b`U\
byU n|
mv$Cf
f.W9G
2ij]% !
EZ?0
iSAq
yLCAK
&P~c
gc8[
6 $I
?3p}
;f ,
(Ri'
d@|*H
F\(]uP}
F/n1;
|lf_
#a081
E $|
'/'%
IlTI
.JC!-
i9A5
q @8
b,C=
|lf|
<BY<T
{#^D
HTi?Qv
~"H% ]D{n
D&-~
CY 1
BP1pw
NdNfNuNTN$NcNuN$N#N[T
<L5C
#/Q*;
A4!H
mrYJ
+f4e
kCPg0=
wyj
_ w6I
]Qq]
Q=|7
\]{~G"BjG
7v.Z_
'g~W
Y9;S
%Ta"
Vr|z'
Qtji
GfGB
v +}&
0j:
;I`&
]x?Ou
=E&
)o0i
g`j8Yh
3pJhc
> r1E
CUMzZ^
2^LM
)kyo7
@Nq2C
X c8
PT7c
5K,r
Q<vF
IJ,g=
*{(+
jOq97%
Qp:xdM
+ bu
i'{Wj
+839
K,|3e
MTgr)_
tXSU
4-6(eY
by4n E
`TTl]+`0;
b1}
HaY T
z|z@
JaMe
.c!;
U^V
ySRF,*~
fOi_
<aj~
k_tn!
\(]6
U@thS
fm\
s:QufC
{ `
N~N N<N@NBNVNIN
>(_!
B6y\
o>F~
`CVyz
wFAS_
(@4]RF`=
mm-j
S8y2
K~*~O9s
~uRg
{ yC
ai0zw
C=B;
m.Oa|IkZ
H#\1Z
M-C`
4ed7|
CBOv
5? y
;s[n
_p$S
d8ms
5s /
PG
'j1kI
G~M0(
6Iv "
UMtS<
wHQoj
Jgih(p9
k^H
tYz8
9oJ(
YX-x
Rkrj
R3dn
B{ z
>}%,>
%$B<
c=5
'u E
>t_@
-~#>*
NTy+
}1)\
i\lc
]C@Pnt`
u!W+r
fvG]
t ~N
Un[u
9eEE
F.]3G
>6I^
jx
@ucV
Nho^5/
\jHT(
wMR}`
_q
07h(
0+t7
psG0
q4u{
f(N71h;
d{\bU
w}h
F}(Y!
-}iJQ
&i-#
uhs&I?
VJd4
% =W
m#Ub
g
YQqV
E2T@G
D 3v
5$Y{
: k`]y
bjz#e
UIF9
:B;Z
<;$#
Qo1X
&rBLn
kMVi
<e>f
`.5u
[<,K
mo-qOt
Qy{cE
N#@s
j`.4
j#&x
Dl~Q}b
F#`)
AAb"
sRXd
-eY7
xaYT
=#('
S- =XW&
AAb4
=e{G
X Jo P
B(@Z0
j#&)
pW:7_nO
|37a
}6G
v!Ih
61~[
op\
(*X.q
%bb5+R
Ae)7
+(4:#
6vv1
!Z I
g!ywPjH4{D
T\m sk
,Nw+Pu
69Ym>1
oLZ&U
]ylM`
+h f)(;_
'p?`
CreateDecryptor
NZN N<N:NxN$NNN N%NINUN&N NGN]NqN
9}rU/p
\OP+5
}lS
;y&.
. +,!1
*en y
MU,p
"'5=
Lo\6
>Ds~
x`+`L
&|989KN
rsDj
?xO/zN
AS ^
1~1L M
~aWo
D-C/
.UXB$ x
set_IsBackground
2j y
2aG9a#
^ K0
BMue
I }2
TrON
q7Xy
3_q
=A$Ou$:rq
Dq0~
fB a
rwp
ca%
Ynx>
}wx1
QogoB
mQRS
[Lex
j{auT
w #jT
N@(B
\y+F
$_22
?uWEs
cO||
3g8Y
4<v9W
;,zzm:
ou\`
5{2m!
0WhKr
b%u5
du->
=.z]
19'Wv
:IxHE
\p^C
0q[J8
2p Ah\
K0b$f
)l>D
)oG
p};[
u'IJ
NK?h
-n+%&R
M,fl
0e3@
hWoa
PRSv]}
f cL
4`QhG
}s)3
~lM3
FnyC
|d|+s}
Jp7>|
el` C
0 y
^vLj
(`cD
8h,
|aE$
eJ;+
1!vUC
Pl!9
:0 L
`M
Hv3Lt,
"[V]S
OZtm2!1y=
C~Y
d|r6
115K
:VV7
I(#P
}'y$
1)zxS0N]'
N3.U
O|?`
B35;
N ~)
"Fq A<
=|&^
b!<+
S+EQ
N_1+
L|!;#
^4C3
Ob v3
h#m
D .Y
-d@}V
Qu;p
{Ue
9&n1X
"@,9
0(~(
rD<+
C:}q$
B*Fi0
K Uz
\1df-
9&Zqh
qS f
nL=En-
i0!)r
ZC[!
#r;I{
.HL~F
1r3Q
wM#x
l_<-
TOoP
5#fH
/ jX
H@i'
RYn/
;O{,SX
Q1.u
p: 5
BL*
npS.
X@m
1#9]
'2M]^
4P=h
oK$O
Y~@o=
| 2qh' iO
+@'
oQ`
}Dm8
6o o
n7 nf
9u#(/R
pQS\
} l
]!w
;6^^:
B I/
nq3H
-K'A
?y]&
f5=pG
;2#Z
{pB)
%DyJ
Lqk{
tG(?
qoXY
P^r2
NE.^`-
y7!v
RRn|n
M$j
) ]#
`f_l
X &
rb.3
>5qd3
wg1 .x/0
{L:U
JJUH
Z|/ Y
L;tJW
0di4M
S h {
t;_.
2%gx /
%g5T
) =e)W
v2]0e'
9XJYB?.
Ga _Oh
3,tj
"l_w
Ckn#
*~$j
H0Qv
:| "w
)t$K
;K^L
l` ~
3GG5
.J`N
IDATm5<
A4$QF
^S fr]n
'Du
%\Vn
Dh!i
8rd0QAUurwI24
)7bu
70m/
8 o_YX
: ,h
)6zV} q
Q{E|
z0+)
cJv&
G,-s!
@O{`O
Ia5W
w)N+
;lc]_
`"pD
VZp :9RZ+Nc
MzTd
a|QK
pS'x
" :0
e3i
[Wq1
r9vatpkCJMgZgVMG1
G>^[
}-# ~
y+XC
ZG/K
mAj"
}INqg
ulTD
6RKx
E~`l
Qrx
.Q S
N) xQ
%u~_
n<KS(
fs
#5~?
:ow U
7').
M.oD)#\,
ry'YK
: e`
ifq%>
|7`5
oOhB
YKe&
iN&`
4jS
PZxt
:L]I
^XB $
JBM}
tml
,=$_
}FI>h
?I9T
t;A!
5PwK[
_ #&m
?97U<
&aha
oQZ+XbF
Q_ZI\2
C=d8i
NGuVd
#tIz
.Tl`
kGq
Ga \
o,gyk
yiQ8S
W=Z(
8D'(
D10
W86iw
%|Vhqew
IdG7
M.Fr
/ ^el
o22ZG
|xn^k
{5nzy
]SI\J
KF3V
EH?Gi3<`
^: a?
[4mS
0i*
Z|K4
{NV.
;[Mlu
Hzih>*Z
DN2!
i{NuZ
YM6jP
Or}U-
fH!{
x:_c
vG^9y2
XLl^[
=AB=u
7g]:
BSx!
&BWb
#AE47
R~eO
,Oss
v;hiG
3~S2
36Yv
Jm2ivYH
m)!zn
Kcj%=
)dN`
?h$0G
F/Ri?
PL=k
hPy<
tmeT#
X(8Hy3F
?-W~
C2 2
-Ikeh
x.xgn
d+Ll
(A'
j]Y>52D
0_d&2r_
F!/!Pv
5zRN
Oge@]S
(K u
D?d8j
$[Gd
~S]9
%406
z0 T
l pj
lIF?
p{yfK
'3#dJ
Uq3c
N^o2
LMN,
((,)
#V{m
a5 Y
$nGE
4r,u
N6N7N+N
sb&I
u4\p3?I
S<Y
Sj9I
XPJZ-|
QrBT
n)"s
zZKVS'
x7G@O
?Dz-s
_TN!p
.t0*
X3^CW
Y:/L
A.{N
:4Y~
gLZkOr
&)%E
PS[JX
N-NCN,NZN N
{V$<
&]p~
8Yl/
4(Ry
iPtA
19_H
Ie w
GLoN
A1\r)
Tsdr
iC4`
%({"
4'~U
H'c[
{;*t O'
?3;?f[~=
bs"\
dk8
%B?~
96 t
9174
.K+ 2
NUW*
UNrE|Z
X3,*
aj8N?
DL w>x
|{e3
I?W`h&
NH3
888$
apvP
v@2C
^$Md;
~UC}j
U:|c*^
m E5
5\ss
reT8
-/!E0
( ]#
m@RY
F %
22a
>kwuj
;)t
4{nj:
j!I 0
=T9*
wD.-9
EIaK2zPNrivNAY7G8
P!FDR
- kx
/KsN
5X2[
B~6h
+#`k
bzB
dAk^
~(9c
Z$js
*fK]w
F'Py
FA;vB
]v q/M
9VIK70
e t|j
chB,
xgo
i(`8
n ;u
_7I,
(DHTk
/ GO9M
jo?u_j
9{pN;)$
yp[
ftR7$pX:
wgY*
9kWu
p=n?
l8RE_=wm
2jX]
It7t
<kOS
tM)a
\F4<2+P
-9Tp
L9!l
^" z
3 d(a
RFKV
.CU{
;}>R
,2 #K
Q5 ?
:VEmV
b|#M+
uz.5
BY"L
q2p`y
=}/n
A@e{
&%mW
P&^
K![s/
hG F
Ur^I
!'If
i euKE
l-#lhpC
*:c8
;&'
)B[V
H'&3.1z
Wd>
CGm ]
uW)1~
Jk3c
!cQS
sM;9
@@YSd
=s9t
=p&.
;,k
k,{HM
uP Z
R2bI
`./0p
d0R
f\vm
n9f]
_<\.Z
Mv]6V
$Ov5
xD#>
ZK_\
Y5&!ke_
w9 6
';T?_
VlC^
:[.OX
Jq=X
y~H/
<J8./
=Bwh
1(\yi
fyFu
)A[x
:.X"
Q_^ 2S
Y>QZ
hK'
n3n <
pa W}mR
!],B
B_HK
R*wE
0j1g(_-=4O
DFmI
tPiD
E?w; X
Ut!i
"n$_
!`p^
>Mt@h
a0 o
3]Or
rS3q
igV1%E
U6\sr
r/3jM@
H z[N O[Y
ulh
2{yGk
HF,G
#m(c
NgNFN
(L8@
$74k%
. 9$`
)mDI
ZC x
( ??
XmI
E6$xs
aS:1
e0F^f
S |p
Wlvp
'"K:
~8= KR!
D@F}
M% *
gE{X
Kck
/</V
iwbd
I!:S
~+\g
Oi3Rx
H_3J
"eLJ
l"s;+
kV ""o
r.Jo
8Xg)q
eH 2:
F:u:
]3_2
de 5j
/KTq
tV`U
y$PB
Y s6f
PA6.
<2 P
Xjq S
]fmd
b [sF:08
YnSc
d,"k
,$Z
OzGa{
7^Az6
lbLSl
[k<!
GetProperties
d(NObt
rUJW
Ulc(
1TW E%
t]Yg
fD}ep
_`vu
j:xkV
1VmZ
h;XN
V{ e
Sl|N
0a.7
1^`{|E
+0/8p
Bn&{
2j9
EVh^
U|<.
( RrM
z82m
N9Tf B
Cs+;\=
uQ|;
|XSDE
c =q
zFIBq
?v
LwC;vQ
JE#KK_
Ee v
X;.8
nruL
R,P?
#PIy
NBNGN
*gW+
Flu f
RGi
o<#(K>G
1z"G
xo$^
Vr7?
.z8m
QLm
JzHQ
gB~jk
A5HZ
[9 w
j p}j)
t;pjZ
m")l
u]XZ
? G}
kw*A
_p9,<Q$
I>M`
sfag
p`h!
Mi;by
Bovv
&xyuS
nfZg
?Zfbq?
SN.( (
vb ;
Z Q0
Dw}H
Xmu
5hq g
[7V;x
f0`H
>k%9
3k^\
op:\r
np2D]<w
B=U:
1g-B
EZa6Tl
$9.:1VEY
u3T^&
&JC/
_im$
jP6J
F561
!W] v<
dqpw
DFSys
QF=p1@PI
(E4Z
/* 3
+a~2
?]5auz
q+hvU
o NA
4p%t
GU%
DW}X
UAI+J
!]; D
=AEW
Jwbg
Az
R8FG
ZYT`E
08=0
}[YQ
'h}
@Ra
Q&`T
5nw>
J4bG
NJf{%
?pxG
Pc6O
.Q]K
3-LX
50:H
F Ai/
n$g>
c,+2a
_PK_V
n}69
EWK
4&9N#
"!@1
4zW`
lfJ
gNO+
JX/wp@
]+;0
bKrz
K\wn
&yL^"
m0(L*
dXJ<N
.8Xq&
e:r2Jtre
n}F@mq
$hd9T4
U(!2'
2>$U=
\HzDn
NIUa9
u,1x
6x]u
_zEo3
0j2I
@ yE
xrw
GHL}
6hZb
mu%f.T^/
t&`i)$=
1HC
)`n|
JXC>
-nv/
?17(
,l5z
9rUfU\$
i/EbA
I )+1
#t
^kkj/
ut0e
'0#_
T\j
"'Zp
% fY
a `I
j/AX
/&V
((1#7
f(8vl
a=23
'sJ/
4Lj,
5I"y&
YOMk
B^V"
70H C
$U69I
> o1
j=?p>
k:Wy
/>*C]
GP,,R
\s\&
i%!D
U9 H,
HTCJ
Rcn.S5
x. |k
O: @q
rYVz8nnj
WREx
d+'"
MlIE
+SaD
W {
i*"
JP+X
8* F
OCqF
* O7
</T0
A 2I
kj*
/=GD
&Te?=2
?''i
-ZBl
8ib#=@}
Fkcy
hjj5
FJ1U
NRg,
kb#K
{w#=
2'HG]>V
]@s
Concat
4b_{kI
`T7K
$h UB7
ut[4mZ
&v8D
}ByT
<;NE
+ e|
d Bo
(6?WS
$M"D'
Z H,
Rg8'
I8Qo
m BCXw
\A C
` +Y
d *D4}
<)WS9
<e&_
>'#I4A
u,J'bA
j,g;6
eC&X
| t?t;
7^x Wu
4gy~/
u$+fGa
${42
}eB~
QsWt
wgOhb
i-rU
jllC
L[Wl
eR{=
S6La>L
x %v
;z"?
-09c
V<'1/A|
;?Fh{
$"J :
YCv` H<1
0CL"
vSX) y)
I-z)y
=Wa'
0VwL
{?U-
/|!R
C|Qj
lbL4
Pwc
}Tg
N [>
eP(O@
^~L3
=qOr
4J'
GlGWuFtM\
{i|q
v}r"
$wO*
t2-luKo
ti_9
of(xE
J@'B(,
t{3 L
=,YI
5i7\`jI
jGRp
rsnE;es!c K
]>*Q
Y C)iY
K -[Ut
DpN Y
Fs;4
n/7p
<3=
m/vQ
q^Uox
Q8#KJ
wx\W
TT^B
)D&-
N!D(.
w0bR
Vj:%FN
}/[6`
Pos}
TT^8
E H
w+vq
7*LQx
J#>[
VA 8%>9
<}QV
"s-|
3* l
hsR>
SEX^M
#*3F
TS\X
~CrjZ
r:"|
KL;Uz2
?LU6
]H z
Ux9K
QZ
);}e
T0yD
a?Qk
k*-T\
%4N.
u7b2
cW_A|
\MJ%I
ea&$
F3&B%
^|&1
h TE
6y,^_:]H/
[jpc~
P^-6S
Z/u 6q
j[v#!
N@UG$
#_BQ
7N)[Q
0?JMs
c#Pf'
RF *8
quyF
n'5F
k9_w
;-:m+
.{2y
4=oA$ N
>QYq
#(*J:
<=W/
d.LI
&1?i1
qSJ<u
/#gZ
PGI{$ x_
UfNl
z[yE
l|i3
]=c'
{;M^5|
>.6$
!FI3
gOmD
_uaD
]}|P
t S Ug
`I x]
pN~5
Pd7xn
a5X<Wt
4C7i
sRGB
RW\L
*'Ta
8Tu;
No%{=n
DYoK
B55
_dFI
F g<
V%Vv
BnuC
Gs040
Ow
e-vqT
]fN2
0sNpN
j 2F
i-Wr
)x=V
M%yi
}nOY
9<z]k<
8clA
xnI>
n`HH
?L\{(
ULdB
[`MO
.Xj$
e\++
HHp{%6P
A kuw
D>%R5
IMkN
e(Q_
v`NG
X6 R
E.>-4
L+s=
P!{E6
pFS2!
%_+o.
NGFu
*:+|m
r#"E
#T16S
8dvp
3Tv4
'e{
hg(aF"
NZy+
m[-2
]@#!Y
eg07#J
y24
& F}
,qHX1
Q?}3
/r~E
[uLn
S!T]
y(c[R{Y t>
+r8yj
5f#x
)PY+
7)e
Cko
j5a*
%('e
ykdNZ
g8"|b
7v(
OdRU
.tZw7
x`Rhi
%01Wm
m}dI
D{]x
`|tq
LAD`
$E,,R
?=uz9
N%NpNFN^N8N
"Tr{.}
0~v;5B"
5%%Z
#\V<%d%
z0#f
6 "3$+
j~KE
u1/
|(DF
~sND
Pdd+n
90zbhI
=Ylc
9s"g
M\lX b |
}329*
o<q
b6 ^
&EF9Z
r~`=
l^e2
;RAE
>YM-9T
9N~I
N z6r
,y/E
(a dK
9G8
rCJN
eq[=2H
6:X-
0! -
HUT
alhl
\8A
NoNNN
IF 4
61OQ)V
BDwQ
D&tNr
f|lZ
:&**
M
Q -CY
nptk>c
oEjE
m'H#
\aIuB
o@cHm
;UA+
\>cb
3c4
E9N %
'Ysu
>-RY
gh M
'Lat\
lZQ?7
7|x=@+
hef{
Lov[u7
Pf$r
}bYq
F,@]
7uik
6 .jL
5}{@!
?7| j
{Zcp
a^RZ
!#3}:
7 k %
aI<C
|`+"Ta
#5[?
!oI[W
Jz2Q#
yLY
/j&^
C)v}e
bV} q
gT/sk
H=IRH
qe3Rrn8YLk
.Xwp
GV/J
W--E
(_Np
<oYZ
Hg>D
vj1p
N1NfNcN
SF{0
tAH2R
b>"g
dk &6
<zKF
l$j3
"jUJ&
ob{c2
Jc-r
H(qX
>@6
f ?i
blSv
um7zKZ
e_ /
|wz~
oW;~
O]3K
=ZKPu
!U})
'@ !I
)g&&f*a
ea;RGg
g]rT
.4 Hu([
$<y
pc5fk=
9*~n
|;:"Q
`'%3
~F*-%j
`*0c
pl0r
5KMj
FxgrusJ
YKcV|
0 c-
Lph2'&%0N '
n[O'
t wK
6c~)B
cR-&:
\
9S15
QX=c
HJjIm}
HT2"
7v4F
qzMH
t?wc`84
f9Xn<
Y><h}
AqZWc
WvGJ0
R5Ia(
2Q /-
0^#<
kdqc"0
rh`T%
0u4?NB_
JY::
d4}n
y O\
eN@Z
+5Ev
1J9+
7A Z
u4 "
)' x
1G/yW
u?Z {
o)L1
x!?;
}O;a
He}[p
l|P=X
9`^k0i4x
O("w
Sdf+
=sT
o S/
,~Qe
FxYK$
V1|
ysP&
eW[.
NrNTN6NMNUNGNLNNNaN9NJNhNoNBN5NLN
<j&BX
.]XR
g?lP
yOgYMj
Qo'S^
gU_?
J8_H
Sw:
wTUX
+M.E
rY>e{oH
[n?/
L?~ -
W@lw!z
;P]i
*\ir
R*D]
fE}
*U2$
9UKAH
FQ`aK
+k[bk
TOQQ
5*<x
P@ Y
eS}f
j1u*B
DT '
FkA,jy&
ao.?;8=
[iN8C<
@Z kSU
Ha~
f]P'.
\~z%{
krA;]
Y4WSCA
@y}%}
C6%3{
|gD`
4Ye/
ku'QC{A:C
?5<
V}}b
`bHs
LL-7 $s
0PrPb
"S>u!Q
ju)X
e:giJw
&}x.z
JlGdiL
[krUNs
d=5nY
\5bhY)x
5CgW
r7V1
^N)$5=_
Xx $
i2#[
+^".F
;c(V
@9]Yz
S.$(
Obdgg
9&V3}
j 8k
GT'z7
sIR@
<;` *
^:.^
Uc_hLp
4AN6NHNwN`N4NoN7N{NiN
&PDSu
a2t%Q
|r#X!
5A%~
rl.M
!2yQ
^{2z
%gg-
P"c_
2If Nw
u{\=/!
c/k
U_DL
/Rtds
:H$[b
pb|W
Ji&b
4O/7
CDQkM3!g?[W
7!\6
E0~A
bkW *k
}}FB
D@Md\*-
s6(+^
?Ma5Vq
=`%y
W32k
<R7k
(KZ3YO
XTM\8
:-t.70
qFLX
^ 5E|
Bf~vK
Qm f
%(i~
_Ti%9iS
"XJu3
}}F)
h?A
/Mmx
*hU|
5bH{
@)mzfk
D7g|k
YvH`
gF^N
)C>yH
a*930I
")n(
gH '#
-c8V
[oSb
NSNSNRN<NVN`
b<M~
^R*j
8Ol1
{?L
QEm)
m&m;u
_v2-_
B,MV
{WKb
3e7^Q
A?w`Eo
C*YtF,
(%gJ
'a~b
XOy.
+V%7
`rj>O
Eu$6lN%&
8FN
Ie'[
N;jJK
hK_G
3#AR
[F(;~bR
KCKfL
t'I]
r{ &f
R/jke
d{!2XX(#
i kS]
Wy8/lC(
W]Fb r
[Ia)f
NcvI2/
0i;]
P<z09wz7
6Xx(
(iN)m
t\!N
!n'z
Sh-Z
DHs<
'YEO
1_ y%#
so4G9*
c4GpJ~g+5 T
w8Gd
{ddj a6
8W%T
YK7{
M4va+
Xx4w\\j3
.NS&
]/-J
mE1sB
c~<)
TZtQ
{f\_
Y7cU
LPf?
Z S
J ]j
z&:~
6bQ6j
8spB
%*"q
^|_x
lf)+
ae-}
p3jA
8_`4ZSy
j@]PO{
/n<K
A;i%
*\O
inS3K
{2zp
(-ZX
aN3e
v@'G
R3h_8
|9Cl
^nG LQ#
[ Q
- ~*
Jd>Ok
78)*
}2A%
O
o"Pt
AeS
H9wMGqFVbQ
-blx
04d1Ah
Fi.zM] C^
_tZl
-9Y*S k
g_v_
N0NYN~NfN
L(+1
a~X3
<.72
|*bL
S>4F
!Jy-
~W=6,mt
i^q1r
2IP[
Yw7
Ib{3
_tZ+
_uU
R*L
q iK
sB<a8|
UH|)
l# S
+ B.V
jt! *!
0 RH
Y<1cL
c]:/I
[P9*U
*o^_P
Lq ;
{CR#GC
kW"@w.
c4y9
(mXw
'B<G
G 7oY
c[8k^
Mu:3
cy,UWo
X;&d
\-Gd
K#N6
DK6?l
"#OK3=^
XgcU
7@JlU
6}5"
e:v:
5 V
UMtN
.}~b
=da0-
)Ga#IX)
1F9SMh
TKnMI
eu4eLx6
pC3
NQwD
>~{2
*%}T
S^Q?
d\Bj
+^|8
_lPj}
YE=l
2OSiH
SkipVerification
^.gu0
}zU ~3
XsRO/
Wg);
iPFI
b&DS
yn0f
4X )
,wQd
P?h!L
RR=g
8IaP
pv:) . c
2 MCt
^J2W,
SM^
+/ZK
}ou7
egV}
vlTi
zw&^.1
"k(F
.TfP
;@>'
d #y
W g#b
. {N
nH|V
9n>p F|
q p@
X#KP
]gv}
Y[qH
x~Vm
KX0u
F 5-8V
-Y/LH
Prkt
:m(k&x
5{)
L ;L
P u
{jzH
\?$d
HrX
>K@(Q
dpKpk
=rxMV
L/N$
{5}"
g V
Qc^8
)qme
~%U%
~i#:Y
RSo
wntk
yvCi
"LYb
- 3
?<nY
L/Ne
-pf
A 1:.
g]_IVGI9
N!N*N/N+NkNyN:N9N9NXN9N
w`VW
$}wL
f<a>
r$E`
&7MRI Y
yP>G
,U6r
_).i
5j(|s
]CT)5
[?QQ
K&:fn)-
H2@9
8sZ4 m
??t\
0#<8
\nzm
)YjE
tV }6
mFC{
?|l-
oin
/yOU
jQ L1.
f)#|
hVzN7
'sP7kQ_
3_RLc%k
/Jy*
(xYU,M
b/8o
Q0z^
(`<R
H6KL
(ms-
vq F
$8
f N{
as-M
dC??
cWk1 P
NBNpN
]4NUd
Fmqd
tsjw
KEE5
K$/
+s?r
8 ;"
iSx
_~c2
BI(r^
' VPi
?/Nq>
o.#b
[M~!!
[+kVp
lqfz
UTGZ
THl*e
x>5p
!TBj
NuW8(
4rW8
\6|lP
MA1y
xQj~
j? S
ff<
^' 5=
f;OM
_ YM
!)[}c&
~M}+c
Nm,,
'i]u
A7.Lr
Q-*D
H$#U
o<3:
4SWK
U|VD*
j2A
<}v*
L %Q
@Bx >
8a|dk
bmt{
+@Ems)
1y ]
. ~"[
3|a&
jq*gC5
(zUv
8)"z]
xAVy[q
BvtJo
Ze>A$U
-sqg
a%jGn
60_
}*Kw~4G
L~8g
sCL2eh
/ :
fK l
zEaP
\1nJ+
GIW0
} ]B
xz'98>h
-rmT
lo<~
_'|R{
'm+x
7_|c^VF
K?u(
A(e
SAut
}|Z_
i%g2$
Pq<zC
d|. +
`)&N
#J %
%CP)}
z7 O
Jn!C
mh2`
t{NwK
:Zcd
=d[F
rJ 4
Fx$%
/%)y+
Pvm
{Z^n
P 2+wc
g-i\
<z5f
Z-#Z
OOmf
It,
Q>LN?
7S1$
fF{Lt
8iDJ
?lHZ~
vPLT
KmQ`%` ~
C(I*
v?p(c
Gw8M
OB?g
wW9p
) dX
CF^ao
)Jd"
(]t<
s W
iw5k
^k\4
WUpg
X>%~
cPjq
ESIo
93)c
YnH6
`kND
YH5N
Q?X%
NxN4N]NNNxN
e!B"
A! ^
hpsn"
)ScFLv
.|TW
^[Y!
#RnP
/lv%
&s-f>:`
;sTT
MXL0
P?{w4m
_D =
@5 QP
uwX
C|I6
RSMg?
zr>x
<v!4
b*K
r"A
MN]8
b, @"
OYx>
y_S (
n! ~i
Y\Ki
Dw3$H;r
6*zkbBI3
#okE{
it<WQ
]k2T&
Xpqwh
E<vR
c$Z,
E60U(
Qrfx"
Q|3rY
"~Pj
IyC #n
c}|w|
PefH<
rc}_
g6 u
cxzj2Z
35vT
5V6I
av[
h"ep.T
[j"V
w*DB
("~_Zc
nlcr
)y $
a O' :
+ l5
".Ei-WSr
c =k
] ptN{
x^pl
UWU#
ih KZ
k>=o
2bDb
{ie
i#$7
&i o
UmT[
!`9.
8xhqyMx
NDNpN8NyN
<>&K=
nF?/
k4H`
\$v]
U/DI!q
-kP}(
c83r
Q(7mb
'6z!
33]g
DM3[
_uY7
\%xS
+:Z/
i'Mc
soDY
%&n+5
/T3d
spD<
UPUK
!VAIv
fZ)~:
nd{&mJ
3s w
p<R&
`~ z
4`,n
([Xt
CZRT
L1]"
zkn.3Z`
R c\X
}rk
&^A.
#"S:
m`U,J
OE^
1z d
Q!kf
`:8^
oqZYR8
gASi
?KP@ m
F:<[
eR%U0 4
BVX#If
2<%>
/w7a
r&s>
2$q:R
U KF
@F#_
"-uv
%yxB`0B
' s3
@|iA_j%
LiN NuN+N
"AhM
'y !-
593c
kf8$|
"1[)*
V+LJ
N;R,
/2tZ
U>!G=K
1QF5A
Ziwu~
71a4U
=bN_^ j
5%=8
kz@%S
?h44
\5(ujVe
w+c;
lRD:
Y<FB
_7[EK
7Sr|
Y q9!S{C
,L0$ 4
Ff|1?Y
RF2"
Zs7N(
}+bw
1-_~
$9xd 4+
&Hx5<
dHH
$dpO
M}1?9
=2qv
Vu,V
W[!%
C6[m
Ax`)
+& V
\W'?
~l'1,
=}ir
%UN2
mN7T
2e!t
W6I-
5Kl *
6`M;
]7$n
mO*z
pJYmO
/8!4X
G:HKKj
(+|p
*x"j
18m@
}7j]o
f4X_
HEZ$
oau^
sdff6Vl
w,I&
@(K_ @
} J;7
"_];
P0!F
ta06
" {Z
@U3N
QGnu
#FAR
=c+%S
[@)U
B=**
rT|%:V
]X1R
jifk
!Gb'
D_ e4
:e/;M
4GU`
}l;S
I=69lu
s~>$%S
@DnT
j;L8
K1}]
5x`Ei
M(D9
bwY~B
t_f@
9FNS
?/6^jDu
}NNz
6dj>
fsR!
,d4$
KCB
?,r)
AlTu
dl<1
<#%m$
Nb'_*
@sY j5
|d h21(ph2%
wM(h
ZMA9
:;t
Cc6l
31lUE
s-_q
Yu*K
RLyj
!>X,
q>5T
v1dT
vN,v
8X}.o
~\;kxl
+'c<*1
$wu-n
E$&,
9/U=
=: =
c`gM\m
MmnA
rY,Y
4 4r
Cdg6!
Show
u,Ft
h7"\
AZEX
@ 8
J:;|
z(u2
jm&go
k.LC
'$ n<
< -b
U7lA
Dlua
]]Q5
]v|D
@IFc
bRT6
#aeXd
gdq,
`e2K
(9 45b:
wV18
Qs"n
l\ z77
@5&
SaOH
h ~La
50eF
McxF
3P X
/6'n
X|J3
LfvHjjU
NVNlNiNUN
^5< }
U1(7D
vUsg
C"oR&
.%Lk
v"'w-
9^<\
yQ-3.'
j Z#
sm`v
i"Wd]
!| y8
$L&<4&
#\<9V
*LGE
7a6f
;6Ya
^1h
^s_e
qE~ r#
x $6
prU9N@
^Qr*
`}E/
#|s7"
+6-7
/ ImS
h=5DN$
L( B4
^1
L>m?
v7D@h@O
EeCn
@hlX
2 N2,:
4;\5<Tg3r
jSTJ
63aM
[I]{
|ak?
XB4F
98g
/84Q)
#2c?y
8bn/
c8Ge
uyij
(n:2N
Hf Tw&
QZ0b
A|^=
{a!b
u$VJ)b
zt+2
>>{}P
3?D%u
FqbjB
JK\E
|two4
WtgE>
>M2BC l
\&[z' .
ZS,<
%yvsF
o cw
7q \X
Vg_`^
tHc>w
E>yR
C_G:
i9%P[
uv3
yNdz^
{^qNg
qY=2
s(9[
0_m#
%&H
>:4o
O&~vP
{O m
0}<u
a-L|
oDF19
wAYg*O
ENz;
+>_4
pY S_4
5k*Aq
JM-[
,2$>
m 5+
p5S3QXxfX2pXDkj69
t},Z
ZCq?
%K
e` c
HVV5
`#yR
peYG
UL`
t% =
O'(D^
ip_
# [4
"J X7
~().
#OEX
1c9%5
9"u;i
CMk0
I|0Fnd5
}glU
(=l|
eyz>
|wiz
JN&f
s;l9
)~j
!JZu<jy~
dIr$
lF.F
h|sB
](Ww/Y
(f^O
HPlc2
05F
I01X9CtJZskuVdRDK
$K+!:7U
G_ ,
2{ 'E)vq+
?c#w
xC%{
Cq+P
4-M@P;
x\QJ
mscoree.dll
o@S%
2t }?
{N]\
i~0D
_< qv
&I[i
KbgU
s0HvA5SgeZ6GvN5f9H
{ q%
2D?3
b|u5'
EVu+p~
}PY2
b?Me
k4W|
#Gms
dnS3
0TA/
Gvwdn
!n; Xv6
Y!x0
!G)#
1',
P 61
>&b^
R N2h
r?]a
W^82S
~9 1
mTh$
GHkt
pj J
36D$
j^qv
gIG_
Kpof
^`D\m,
8k]*
^11 p;
"^7<
Un?@
( W&U
Z;cR
GiUR
+oomy:
Fd27
Hl;%
^1/o
+.=)
SDAT
ooZF
Xj!h
lCMt
|l)Z
wwMmeXJIhT6lNTec0
5'&+
m v;
MV<t5V
z-U'
E,J<
*t9k
k-^XX
gcA-
%f-E
g W
W8/tKN
v:Vh
Ko6m
=W5 Y
B9/;
ux &_u
JeG\i
a% ^,J
?W(
.b&t
JC{{V
- |+
jF'3d
zYT
3-g7
wny/;o
AK^7
;9b|Sg
b$k'4
eaGU
pa;d
zP{Y
rI9&9
da &
y{y;N
e't&W"
|[<j
gBjEcqj6oG
84*Mq
xU{sR
k{9"R
ccD
$5tU
gVPZ{
YL}};"
o kJb
Xx m
T !Y4
A(#j
eR%9
jc%a.
B$ Y
8v51e
wnY
mrf@
_-8F
.$$5 YJ]L[
R8 KO`F
Otn9
ePzwy
Z(BkE
kUL=
jM"FVn
c:4Y
Tz|r
ZUABm
p*u*
TMu3
aGt
zo(M
,1i
NdNcN N
2N=[]
k/thi
)4Z Q
_*vQ
TD9=Je
n@S:
c} cQ4X
xc4A3w]
pOiy
Jog;
SrkP
_mD]
@/ c
kO^/
l?h
KVJD
j?{c
}mZ)
2`Gy
{fKJ
;&~.
4h`T
<>Bu
<X01WA3
,}c?Sxs
vk1T
>D-.
|J6Q
~q$r
< T
VRes^
-,k:
(w^S
Vbr`
'0Aa9
h,{#9
:[sk
NzZ[Kw
t>UWW
sSj=;
hZ9S
TPL4
M;4ml
^yChPn
d9Bg<A
.6h|
v PN
iyL;k
6 nIc
;*9'
!tSX
v{CTh>
W]f"
%EjV
S('TN
gl[3
(^1D
xS3k
6N#H+
D-@Xt
Qs<(|0x
{ Gt
\AJW1
Ko+i
^ I
!Z"*~
S2QI=
i_^`}P\Q\
l-@
y dK
ywC@
*'.h
yd]R
}7r\
k9[HEt
} >;
U?s?
" S&
'68?
h6K^Zh
G:s#"
c?&*n
?IIa
NPc
T(o*
Sm5C
X<Bw]
'"&X'v
1G G}s
c"c5
%r:z
#wdOZ
V}/0
4Y37
cf/@
ckl]jA
L=1T;
yvKA
OZYyTM
oP}g
l34R
?E9\
\H| %K
/`7l
i`V$
LWb K
Sbe\
o"GT
:HTc3^
`:|kNx]
~m;z!
Attribute
ZY r
wd7w
C-Zx/V
?F>]
)_%&
)k__t=
G{ut
~E;X
gM8%
UHcD
[k)O
a-Se^
3ei"2
<y?w}-
;8ou
iX!lw
$t~3YCpi
3a.J8
U&kNt
qgQ8g
Z5D2@
(f"(
7y<w
D){'7
,H [#
eSWbb@xy
;dQT
$N,:
vSwz5G
YX*=k{K
Y jl ;
m.CKY
eW3^^
ig OD
udWH
4h}&
e$,`
'Jcz!
%>Dh
r0r9A
$EB*R
9s"K
o |h
X!x.
^e0K'
x|q
`bh>
%CL.
^haY
zF@s
C=jX
HQT/
Q.[H`b
3%LP&
{n=x
X|3h
M83]+
HtEw
Je30
`.8E
(pOE
P~I,
G}$_i
YlnIR4QRiXJIFWFb
{Vm
|;(\
|oUwo
Rl[d
Ju*UZ
Z].0w
ST0O
rn+~
8u;x
BA_#S)
<NGx
Z~]-
j!6 s
/qR &
2l9qA
KoL/
q!+(
RKt6p@,
Yc^
58qo
tGk7'
X!>4D
CF$.
,|W%{
uD)!i
<!P0
}\L1
sBgdhFEPZkyp
N/Iw
_`*nXw
zh*k:m
<@qu
<(Nu
#qr)
5hp+
Xq{M
j 3a
cDk^
<iJL
&Srjv8K
";g/
NjNc8
7 c&
=B2i
2`7r%
8b](
"J
<d[q3kW
^1y[
P(:q<a
u7=u
q%H9
`#u
mY)W
IAr2
|) D
9z@
Iz@1
3< &y
X#@~@
S;!sc
izBq
6KnG0C0i=
agwTU
1b;y
*nc1vNk
Fs%x^
,6${
V min+<a@
WD,BC
dP gg
Pc=6
XTk;
kf(
)[K
V&Jg
<7rg
/$}G
S$ic
Mm0P
i7e0n$
u(dV
]:'2sg
m3\~
v?Mv
D&.v
:g\o$
JW@PW
]ZFr
2w;U
j t\(
F0v
$YMZ
_a"/
)4ty
D~gi
S_1;S
j/MBl
{ymX
5^i|
fk//
d3.Jp<
0{^X1q
C#v
*b J
z~bnY
~5W}
=m[X
?VsU
WUxp
%&a5
fB$h
% cW_n
#) o]
UAX78\7p7{*
6F]P
MS\^
~BBt
\V$p
g^Ov
T\w@j
b<JuO
;8B'
m 'Vc
)2F|
S["x
w+F@
Ku{P
3%+[
T,&;m
Vd*K
9>T$
fObSf
2>}d
[?w>.
tXP$
mt `2
|,FW
T"2N`
Ok^j
?_3p
%@Xn
b/ /
N1D g%T|
C3[|
0Z<G
0&f
Da}M
#:|%
q$ 8$
G"/$
\sk!
"N=
'(w=I+JO@
|ACW
-cgm
6"f<
U{2p
}}'9
ck_X
Q_i)V
rxcd
(jSw
'K,'
qah"i
(4NQN[N^NbN
%LZe
_@,L
NHus
y/ .w
\'[F
=O8r
{x?!
u7R0
4@R-t
Ek9(
WWWUs
fqJh
BB0w
{0uK
0lq8
TE? ]
3&}<\}
W~-Or% :
D#!
N(NtN
% V
_f}:
q$t[a
,tKrr
#qW{
>aH&
%r`L
v+7*=
g8+m&
EBrKh
@ -Z
PFe3q"M
~6 aWf
W@Z(
(]9H
HB/w`
z~J7
,r:l
Jf<n
K<@'
@&%i
]x
Z`Ip
b<*X
{Fa;
Ct9Z
@5QG%\
#9Ai
#8E"
hX:L
-fT&
#!UV
d{@B
YwS a
Wl72
c~ h
>#v]
D6tW
/)8&
0{;RU
gXq+tm
&vig7
+UN'S
1e] 9D
N>N~h
pD7?
Re(tsi
$4!`
A"\>*
I|H=3
RsROd
OA%c
2;f,
xo;`
e59z
e2"?
F-!x
0R73O
N:NvN
IH}nV
O B"`S
w'i"u
th,U
a dB
o]}.
x rZV
02Ez
:v(i4~nv
sf,VI
kL9/
@'mzn
3PVXm>NhD
'nCc>
p[0:
Ux;A3
:Zp(
EPui
SxY&
_7%;
3yd;
$UO\
>OKOY0!
Q SB
^ zv
1 Bh5G
gRr
'=s p
e2W}
^~yb
om|M
,t4~*L
_)*3+,
D"h
^nk\q;rJR?;k5nE
zL5A
;}.
S O<
*:`8:
]zyE5
y`pQ,
Y+{D
#W:=
MU!:
C3R}B
+d;%
SY1s-
MEt\
=|EY(
*T{~
[ZYaG*
|Q707g
|i;=
pPN`z
f\
C/' T
|fE
W/X]h
r",-
i1SBL
i-06^T
?fhD
| UP
#{hw*l
$LH {
]FxIVn?
V X;O
5tcYp
ypF
pcP.
Qvx>'
>kN"N
du(Q
?-*4
}V V}
[kJ^
*/Wb
;bPt
U M["
@n0rt
c3_O
M <_
m2yc]
i.d]
BmC,p
#vXF
2EO~
w{$:
F<>Z2
c=z8'
2AP
ARU
iJ7b
@ JA
r]Z??
HUaG
>t}a
'%75
F2av
,*A\ /
System.Windows.Forms
-2x
z3f\0P
?iQa>
8;:*#
X&#(
!%}Q0
I1m_
<yKf
:l(a
WvC}
>tt,6B
#@U3
[=Vx$S
C_jy
FJHmJ
Iu47
'};b"D
u:72s%D-
iP)g
<D3\8
KHV%
2wA
^./U~d
1bab
?{+{M
\~TbxB
q0x'
&mV4
a24r
TVbLj
ConfusedByAttribute
zv1eR
z@PH
Ix)bY?
o: ]>
n?h
%kq!
TLUo
8?#+
Es p
V\(p
7O"G#-
xXSj
I#Rm&
6<x#a
@4QYEK
_qKlu
nZK[G
h ]G
XG'
k[k[3n!
|rw=a
MQ'z
EneyUf
#,l0
xuw:
>"d,
1T&RBIY
$'YsU
=0/h
,N%r
C|77
4ZRt+n
}]32
T} 4$
A:'9
,C((
FRc1
ByoW
>nqDJ
%d
$56G
r^$6~
cT]E
FZ@ 8b
op_Explicit
s'u4Gk
n]wJ
.p[~
UMM*Y
t ?A
YeN =
*30
hf*T
q i 0
!bNy0Do
d@o
=(R=
oWKl
R6tq
NAN}N)NjN
(c({
+ Ju
f9G
x?aag
)<MJ
r/tS
"xw
2._
?d' nl
?rQ
`m~mL
`C4'h
LRVf
\@yt
6Tv}
1(;
crvbQ
-8m'
|2\s$W
sN}s
$N
":A]
.X-njh
u+4Y;
Hl$j8
cxV
r]sak
VH!=@E
SM ?
!D 9
fu/7
whM$
"6C|
p5BM8
&|6t
w:S
@:]p
K^``
Q[U
w(S"6
3FpC9"
Y/AF
bm-i
EDFN=.
cSTvj1Holdp
/1/j+
&;x0%
20()G
f=bX#
3w_pd!V
!}%}
xE+z:
8S+R
}=1^
R`}
5h h
x\5st
20r7
fZK#
M({y
waJT
=BNMQA
A|VN
{O>ve
V/~=
hR38
yg":
$ 5}
$ 1{l
aqT^
dWAU
rk9m
Q, O
J0gM
hooi
hS p#
=x;/
v"ZU,l<
%{;
hF%k
#U&Ge
t978
-{JF
Hjln;
M_U3
I\;I
.:@^E
NkNlN>NuNBN
\VW9
*7e.
>c_i
d9PEJ
Uh%\)
C^Wo
5!Y2s@
p0{3
-uCV
nK [^E
7CW-
Px/[1
DfxO]
}j\p
&%<6
D9}
lIDSY
!rD
_ g8
5XPR!dUa
R&N|
G #8
Tq5:
koki
g[/I
xLjc
2ybI3
omg=}
&[m3W
)+Qd
[Abz
d7ye
+YV_Qr
C,FE
J0o
ldag
IZ<+/
B7W}A)0
sPj&
BV~{E
}+\&
~3xdR".H-]
d2|=
>>N|{
:P,qO
`lI
,Z(K
P^Po
X%][
($oD
YruXv
8O\:
y-$!
D06I
x) e>
07<Q
8W hal
H{Jnq
MOq]7E
gzM"
zux3
*-=VX
3n%qWirt6
x SH
}c-E
:EgE
^=|i
qhiLI3
)kO
=1Gw
=XHE
\mf{
[dQ6
^F@P
D:$h
JE'l
3*g3
e3K
O@H 4
`2Km
rH)x
%f%X
Aoo
2P =
Uqu@A
zm 7
v. L
NGNyN8N
3`W'
Gz 9@
wW]E
]A[.
w#BW
t#6@
k3,
lZh;
:/vu
.2EQ(
M-3xUE
fi 9R:
,('
^d]s4
J M5
pxLa
H!D1h
^; E/
H]W `P
SricIL
kHQ1
-Y2P
j+k+q'
.*X\
?J y
QWQ5!O
ll#*
vMu,
r}pls
A;y
tH)P
0YwZr
`g>\qmt
; >e
5U<\
8e=9a
;PPW
Z`6;
: pR]
ZuR=
:}u1
)O `
gR*D
RTe.
,-7K
n:
PnB^
GWi%I
!wd(kZ
2-Wv
>5Q?*aD
JN3J
_?i'`1
tC{}X
wSZ&
ASVc
f)LD
Pg*j
ex"ME
rTP/
^/-
xVYF
:{5
*29kb7c
Q"pc:
#`CD
7/_
+j(1
c|/%
em{g
';(T
rvGj
m_}x
{ 3?H
Y ~RF
P''w
y {
>_=z_2
3+"_
o T6U
oqJ=
l].1
w_ u
=z c
:g~0
~-o.G
Vr]m(
[Dc
3&4-]C
}BX=D
xPOL
UQOu
e.;a^
-EMn
JS"G
Ck)$
uQ3hx
y &
/Y6A
kZ c8
dZ|>
]#A-M
/2$mWiW`
?$&k
y_~Dk
4=v"\z:(B
+asS_T
S1es *M
>zZ?
qb"mD
Bt f
e'*S
%& eg
;{3(
z*f|
(Q2V
Qi%kZ
m 2ie@o
,m~`
IrG=
iNU,}5
#$<6J
XmD
t~ ;
Xf !
k+G"W
]rqT
j,CQ<
3h"M
Xo .
%8]%
$"@~ XxJ
G$_"E
MT
-pIx
ROgVOs
IJVoz
NbDG?`09
N`|%
ic:cv
kr;i
N/N]NEN_NYN
p% K
SnJ|
5 8_
oy*gQ
?nJB
NKQu
w^eR
o6{7
XzO!
Cy5W
w7%f
#"%fs.
67n%
Y%*w
&>o*}
{-S
4+ +
w 7
"LbC
%f8Z
N_E7
BZ&r)
~$I5
\:<
"d;i
2QU
K#,fKfo
OyN,9*
o$?(J{d
{uu~F
L:xi
p+r@
lZMS
h6kY
4caO
$$@.
^iP{
w@f#
crU#hBJ
ZEX@#p
kTgU
*f"
Y{NA{
p?}_hH9R
Jcn(
6Q,<@
5 r
\%"+
m#x|
N)! }
phh
|I}J
Lm)
j] Wb
Y\9i
E1?(,
vsvZ 3
q3"$
r`u/
! q[
z!o9
_+id4
.U 4
H;h@;
c1cU`
o[s
h?BuN
4vqA\
1"6YD
0'|}B
^PE!
yJ9
h Oq
-X!x
o[s^
Kf><.@
ho!Wd
OT3\o;R
@kiy?
nW b
AU3%
HB'yv
3S jy
X?<2Q
@"+a
kK!3$
qk<#W
*IOh
b1<)W
@</w
'B+
U:&
8~ s
2)Xu%
~qS=
gG b
8o_S
iH(-
UInt32
]G Q
>Fc
:hj]Q
kZYK
%Y[7
)?*
:Ji`
UeL3
%,3|u}
.ed2w
=J+ale
>&\`
ggds
z*k 4
/h,E
9`F)
mm @
e77?
lG S
5(~e
KR7g'X
*xd'
Mv^
}VaO
R-q1
$&(>
x'qK
S`&_
JY{S
ZWN/
<DXr
12<*
*%<_x
C6?R .
z}H,
rX2H
3s.
:|Q=
"h5DU
g52s
j@+_b
'5XR/
5SAG
t%-
2 z9
nst$
8eho
7 +?
NP;@6
4} ]%
q~K3
D*i(O
}1I9
.kf>
NRO
5]:M
SWN
G|'Q
}0uh
Ov!G
4T?f
O63E6
V <)
='x=
sQi|
$l9Y
pn1@E
s";g
34K"
1ln*
<tPx
OG*O
Ol!.
q LgY2'
IQE@
K%'QbJj
qdPF
s(rC
u96
e?w?
]gK%
4;R
(Mp
(axg
YWTRY6
g DZCF'
/D=
S#PG
<=>J4aM
>DKF[
6G+
)\A7
l\H1
-c-,~
Xk!d
$..Q>
gh}~
m0?Ao
26=
+*pr
Hc*2
Km;4
3x64'[n
c!y{u
'O_S
QD h5
=nS
E4h]
rvAZz'
` S$
MessageBox
&_r}
^ax}1a
]/~5
jV!f
n-,Qs
e5TN
?U!
>s|M^,
asr
By-9
~nG{
/P/v
}Vz9H
,js&B
5AdY
>('he
C:@)8o
jQeH
:+cu
Gn"
w"J)a
%D1n
8Gz^
<lZN%
qT=~
Pn>:
5` 2
cAWR -g#
`W"_1
A ;\e|
[fS
2",pt$:xl
4/RP
0 k
Bi.9
&6 G
%%}<
qa6b!
:euA
J7y7Lx
kdy
]gKrG#
rQ%j
,bTZX-b
'=$[(3
Va ?
0R4z
I4^z8
%sL~X
</d>e
2BM
|DzPa
RLX7
k@JL
\Td
ParameterizedThreadStart
;RS9
cO\U
6T0/
>TNm
kJS?
a\Z^
(|]QS
=;.
_GN0 ?
+LO>
yt:t
7{SJ
_Ml
(5SE
fv\*
|uK=
>ckgCf
B sZ)
tak71
)9[bR
I&.y
Yf`
:L}
q/gZ
\ejG
>Qq>
H op 6
FFu
(5S7
mock
yH2AB
9t!71
8C.K
0 R
=1<Z
fP-C
4wF#
2m"J
pn<.
U8S*
'Z%C
PJ+ '<9
_Xe%,
heQ*U$Hc({
FAF%
%b=9
pM`T
h3,T
BJN>NiN7NfNfNCNaN(NQNAN<NnNiNlN
-f\F
mfY 6
6x\"p
ifGw^
53Iu
B$Ak
Aj%
LJ+
b3J
l"Kw
a= -
M1}$
IYs8
YMh`XU(
o1aLr
qkwh
`K/|
Qcxj
g[#t+jm
W ItB
(Ni4j
9<s.Ls
s2#}H
!U0o
`rS4
m $
LP3O)i
EW_2fef
50x0
8jGk
%];
vmp<
\!7
>Fxj7&
cLaX
>-cc
,I{V
^2n4.
n,OXC
%lJ+5i$
x /9
3z{[
S@*-
g*Jm
)aRa
w/1Ke
]l_z
y9Z9
>G~e
m}L`
FR1Pma
NAN7Nyb
~,Ph
k<<TB
.cctor
]_M=.
>Q`]
VD7v4aFJji
!"pf
YD|I
!l0T
GetMethod
dz H\
^]D`
T7K `
x|#y
M\<U
IDATh_;57
2[e1D
&X"u
;"Vo
y8H8
~oZ[
q:_
VYboyU
*(b2
e{9L
R`&$
vx>
Rp-`
)B7w
A3%t
xxiQ
c=Ok
!psf
MN`Q
x6B:>6
m>tS
sh:t
)at-\
O(tS?
\c\ _
@2'[?p-
][OG>
a;zqj'
3/tG
n-|R
K]lP
ToE;N
^CaS
=A/PJ
#j?FG,
gz3/
l9@<}Ot
4nr^
F?7#
AssemblyDescriptionAttribute
]d:.
j+\CoQn
W^\j
UJVR
U%6;
w,y?
kx\K
_i$G
amry
LY/p
QSP`wp
Xd2l
< R$
zpIh
ubesP
9]_(
0sz\
7bb{|
APvQ
1TxeU
lP{)
u\i?Z
PZX3
eh]
.a#*
&`q=\$
R'd\~I
!0ur
,"M[
q 1_
eddHBz4pzTvTdG
@IN>b
kzT]u
BU s
Gf4,
aPMM
q:nC
m_>r
Wx<,
l62U 88;M
pm'3s4
N#^;
%4qS.
+D]>+
SfYe
S$G?
W>!z
li6
IBbDm
P+UW
XGG_
] PR
&EMl
#vg>5XB
:F` (b
BD]"?c
,;L
*0n2sGgYqdnfUOsb8BvkFYUdWPCpsF0Z52GmTFojnUG
D"EE
,j0X
aKR@W=
~5a^
Z)$7
72c5
:2RY
xnJW
Hw{x
F.?G
QNJLP
Qp9|
ogL<
/.xaC
e.xa
+F6<o
&lAih
b$gn
~,5m
vevoZ
N-cv
L"n@L
&01WO
om3|j
zDX-
`+j@
&@L;
1y-{q
5T(4oQ
yc 5(
`o[S
TT8MU
ibwM
h$~-y
[
(`{
Cn F
{i^Z
*_
ec0
NZvM
?4~
_}+-
r,6ll75
Hb`w
~uc4
v\+T
[epe
d-~U
c*'&
1+vw
zV(Z
et60g
3HHE
YI?Z
6}Qj
\jzJ
2_,UZ
^0 $J@
Q{z4
1 Cz
L Qt
G~cQ
7R9d
{L%M
[7=h
7T3#
9dnE
.X#,Q
# .<n
Vu)`k
H^ 8
AG m
NIN_N
1d~G
W6\V
M)6L.
Om6/Q
1yJa
N9N!NBN<N[N*N9NnNCNcNMN"N3N
Py'r
d0.i
US0^
A[66
LS9A*
/DNh
_X:Cc5
4NIg
"0Zg!#
5B_7
d0.^
""Eq1
~}Ro'iM
H!G:
]~!/
AQn=
|=qO
=1jS
-\\"
R*|4
mUq#i
[:XG;
~7%qw_
sLN7
Ew '`
WsM!
%AW?
hx!o
`Q9I
cBUz
}Ej_B
~jGvt
4441
OBJe[
Ak|q
7.`t~
IQ yo8
&Qa8E
=2\cf\
G|1f
wWx`
;<`*
z$ZkaN
7Hf7;(
K6>j0'
,C*v}W
@NXq:
R elIX
+<[x>
cFJ
b0:$s
] H$
^YuQ?
K"ut
:0g6>_e
cA."
SjWwW
c2b5g
L fj
V}5ntk
_:1O|
m,|A
pyO<
Hz*%8
A#e$D
!#8n
aJ1 2
mq 6
{jYb4
3i5@
-ke
._Y[
sH, n
{ v5
N*0#
{]o:
kz!J
gU0b3
dtxU
2Nw0
+1B9
EY1eqVU\
dKqm
:u~
H|\>*
AjEru
W[T=7
/f|K
,2H3X
f'%J
U xe
B lY
p'-S
9A g'
wMBr
"y_zG+L
5dJ
cQ N[965 C
9B
9@n
OPp{
:Oxx
I5]2
}>[EV:
b|W6
=LV!C
.\W:
5v>I
@,0V
_{\@B
QrEL
9Uv b
NlJ#
]xM>
s*wL
Jsi..
.\Wv
l!V
{%+M0N?
Z%b~
5 bp
YwMf|
.LTv
l;:6
<lG~U
{}}}
!8dn
jCZ{
tm}[
j<Tt
,a`&/"
~$>Rb#
G$0}eREWm
OFI_.!
4yhI
(8|.
9 V
yIXZ
xwXP-CJ
@/`
B~ S)_
y<WO
`jz,
\$v*'A
`cj?
%B:'
lYbF
eAMs
Gb8jV
KF
]:he
_P*Q
yx"Gt
g(b\:
eNC^
qBu d'
C0o
5V )G
,~R7
v.(l
;vV]
Wxbn
ur<m
M>pKJ
xf)-Z]_
2~p1
A=o
mr:}kjr}j
H ~%
fm
OvUB
Vf,\
tv@b
IJze
n;5)
XM
(?2Y
h#ZO
b<-KWV'
3.,/
E?J~
p0lNj:
;_h'
!}6
Lp"M
Nq_k+P*
@_d7
[x%D
~A5S
J!dR\_
|f+1Xf
*[[|
npbN
$Gnf
#(1n
zw %
U*t&
mXZy}h
}vj$@Y
;iTR[
zOfW
hh\^
bj \
E1<z
&*MLs
_&>J5
-9IZ
(ia?
u<Wn
XueIaC
W Vx
2WWb
* [
f :@
1o(}
% H _j
}"u+
s{5CQ8|
qa*F
2^MC
! 70
oCN`1W:
:M1Za_
"A):
l'q*!
ZE]v
AdK5
\D$t
l+-nIu
X>'d
?4KD
NQNbNFNMN
o|4z
\G+|
>gyZ
pN69xPzmjiK
RPJO
Bt1Y
+j0}
kr Mx
El'B
Iy~}
Imbp
gQH%k
x#
FailFast
{$[i
9hTy.#
_[hiZ
dc|qOS
UG^=
,_6j;
F}Wo
9N7f
GqY I
N2\K
ce:g
#`Fl0
!!U
{+H\(
nkNN
D% k<
x4 X Q
Ag,S
346-
l6S6
fv(4K
o 5S
.kKu
z"oD'
lSbDX
&Al>|
h{o X
7-b
oF@C
?g/vr
J]E5
tueZ
SvT~
&ZDv
kC -
ZB%U
Qecj
L4qp
(A4N'B
:|<<
pp)x
@4!fF
@:k>
3aLP
GDHh3
I`-V
]gnq
?uFbt
w#/k
sQ c
~Di'
U'{<N
QVry?2j
K~8^
k=dC
.X+]K
IQ`o
/ #?
<~;2
,a933
ohw
B7poj4z
Cy=i
jK8kt
v,5|K
,UNdN
!rJ2H{
sr?3'
{fS:
C,nz
-x|@2
*"'"
FC8%oo
k7`9
H ~L!
jLI8
8w nkFazP
n,*Wqg
'YQan
cWQ)
Z9Jpfg}%
9:ZJ
*D!n4;k
O5[U
w*]w
K!Kt
Dcyx
nOA0zt56G88LwJZ1GDT
"Fv-
k 7U
JhBW
N~N(N7N7NTN
<s .14
=4g0
pom(SU<[
Fo']I
dm)m
0T.6+
LNAw;
ILYiP
FS,([
2 Uh
ysXSq3
ASc:
f\D /
@8^i
xvzlt
?V{}
FE/
kA=m
s+%?
X(2]
o.kj
NxN/NoN
B~ i
^E|KG
uRq}
&O M
!W864
S-y
[f<F
ZO;<
,o2
=FH;
x !1
H?[%
&rdY4
FjK_
Lo(%
1C5;bkk
zSU*$
>j\N
c!]{V
s?AE_
8K~
2IWh
o8)vT ,
;W9+l
-*7\ 5
T3;G
9obI
)LbRZ$
]koE
jf|~
CVBkxkdE6h5SkErWt
Pe\1
`(>i
Ym-y
)n\E
hGHUm
zb\[
9 2<
{$ve
[o~v
!EYE
7)Hzyw
ox&&
(\\u'
[>/1
~C1^
N_N7NsNRN
pqDsH
Z]^0-tS
9T6L
Yb1
v3~Z
bC~
%wXq8
)*q
0|Ob
T]K+O4yt
oG(e|2
p dK
@s ^wi
&.sd
nOD{
=e*%4
`^p>
72;VkH!
Sl`^
uFxp
%ydpm
xz&6a~o
HF9ni
&X[y<
zm]~
#5W
*Z#d
s,tP8
+gmK
{$1Op
#K/?
UC<+
X~y
T0<w
wt}o
:JWMbC
q K;
Ba2<r
+9j+R
#)w0
gyz
.D@Z
] X#
A"0R
j} 1
{5y&"
/{=L
0;IA
vLOo
d#/$
|'{3
'%}Q
.4?[
d:oT
t\?e
A#w q
ild(cr
ghei
DVS(E%
"Bi}
w8ppGJgDda6eXoU5K4V
^58\
NXeT
*0`A
X-$6
f Q!3L
iciF
?*-/b
Ow+
3'DX
tgm7
pD H
8 EP
3A2|2
1 s9
86wN
Hq2
mC%*'
>G[T
H?fb
6zL[!
Vo]~v
kGhZ5!x
HF,=D
F}N8NdN8N:NRN
. ~k
H[qH
w Ln
Y1D@
P( 7
T2fd
5Xv9r
E!_t
PK 8
8e9,=
[0R6
H%@cf~
-' l
uH!G
)%l
)2v>
R s75
k%sc T
EgrZwMmeYgCcZOW6q0
{_YzH
9=o(^
zXrm
?[ C
*QyZJ
k/~a
G8vs
*^g{
T tE
o>2
U #,
4|N
=yO["l
,Ih}~~
'X{-
8Pa
A(Q&
N|NwN
N<NNNzNoN N
-j87
6cz
F!V9
.[U,
/?$#
q :
JO7f
@9!*
#~Mr
]}c?$'
j74Tx
;O2cw
n2`d7
:>|)
*9x5_
pps0
na!k
Y Rh
MDA3
P lc
#rR(
: @G0
<GD!
*]F|
mw/u%
zl+?
p K[
AD}.
Y]]
2@]N
Hu"P
n'UP
?L(;Eq
<FS'
Xi~+v
MA2L
&dZ T
Pl2%^
9D 3
7=[]
i8}(8
NzN3N*N%NBNqN\N{N-N
jyi3KjPKYof6
IA.wf
NB}"
?n|;
MkVg
7,7zt/4
T_DhF?"
D)ALu%:
;$yH
<DB#lS
Pc@Z
P[7h#
#.H)
M(+(V
W@jk
VVvT
=>/M
Sy;o
Qo&L
e:~;
jn=7)l
cF8~Mn
*`b@
4W3B
]N3]
:_<nX
C"xe
9Gs\
:hNC
z1 oG
R|-?
?fn
x&U]
&2Em
[w}N
x_U
(>1tN|
FB9h
qkO
DA6t.
^&uC
dvsu
{TLNx)
_b4V
||3_GB
gn0
8iG$
+\c.
XU 1A
v}iS
8AE2
g>JL3
"g;Wd
8?T(
D2-c
^,g(
[KA.
;pNC[
?2H^k
.1]?
$fYE'
ojX)
? fJB
K4 ?
X*T}
0pto'~JJ
*^@Gu"S
89X3
>O,k~G
JI":9sWY
r"7
H])3
oNi,
JrQY,
xI-1
@dUDd
E2HBac
8|tG~A
^`c;^
MOf!
lv;
31})'
B8R
qF M
uV!Qm
28*2
]%d`-N
=FI,
r,>H
^ \8
3_b9
dg<b
g\HT%
dn%g
kiS
.g"oQ
y{B$
vad^
wls"
$? v*cg
OJO
VRN 1y/
,HH2$YXh/
(M{W,e
P 5U1
@CCF6
p6 LmJFv
@<[nm
`A!
EU|lo
|,KK
e.ku
]I@g/o)s
3^`
jFdVevSkjIXH3
?> &
?D1e
CVUm
va~DGX
z}z:
2)w`
qz j
M,u=
Pr|V#
}1?Z
9 LO
m:#Z
I!Ws)
M<rJ
de;o
Cj\j
~p]WB6
~Nu
MDN
e]Tw^_
QlAI5!
>@}rDJgR
!I\f
|WUF
W7{
Y'.u'A
m+nm
K]T=
T eL
>_=Mf^
Ogpi
Iq_
A.8R
0!P
Ka}3L
OwqJ5
>efl
^5rc
wE`V]/W
WMozz
7PY2
)i2Pt
y9KGSh
.0bJ
i.T4
ypkOT
s.`P,
tKW)ng
k{*s
iZlh
N%dX
coiz
Iit#=I
l=a
4y*l
RgF+
/d9p
R} ;^
gAPa
2;QB
VShR
bUB^
UOJF
xPN| V
B9b>~
t#z?|
4 ,D
) p^
v.2p[T
*pdg
TOSI 3 o
xqHJ
4='D
De\ pf
A (ty
scTFD'
3.s z
XTM9
%Qf!e
AC=&v
JkbjAt
{S "
H@f
z ""
N L=
w=/9|
2Y"]ddwu
0<n3F
e_jl
X*q+
*@l#
-p3&Y
;8(n
'+75
T=spY
+l0B6
{Dus
!OR
d >(
F+>*
f6]gE?
d!Z$
&a@2
* rSu\
4jC*<
Whij
igL)
G3bF
qvFE
m>_C8C
Qh\o
{zV1
`|q~
6I{Sd
Y6"$ 8Q
S2 +c
KuR+:
Pgp:
yk9
irn|
;'{&
,S gw[N"
"JdTc
4|UcO
sy6wv@
~{)y
6I7`
6|Ud
;"e_
Rz ,
Hn m
VGl;
F$52
\ja|
(?.D"
C|'V
Fj:L
^]+A
t`K0
YYP:
@JEF
Q5p9
hW#k
]`"?e
LWEO
@~M
wzNxk
eh:Vz
O2Fz
da[8
h;&:
m|7W2
+0 _,
li#bQ
Ym|c
jx^z
c@Sb
M^|'
#p@'"
2n]4m
$34=*
MNso
D*SOw
no4VY
"L&=7E
UCKM@
w,To
H0Nt
V #y
P\<L?c
8e!4
,*dj
eG<f
@7>\[(
/bKGU3MO
jY U}
`Tfo
uPN"
OEGZ
4p87X
C1Cd' 8
%:\r
\1N9h
x;y,
,);JS
?[.j
[Y.,mh
rSg%W
0(`T
E8=;E h$geSSt
E;,Jy
[Iew
YzrRS}
m*x3+G
ZpX!
6Y%Ay
LjW4k7d
P\D2 5
AMl0
}o!L
z<j*
"J
+ bKo
DS$9t
r2?m
f,FA
#ur
#<Bk
{N81e
p~WL
vCmSi
q#=f
/}lV
k2s]
)+.(e
i9+;
(]A];
H(vK
0,U1
fmBC
/-y$&"
2p`%]
0j~]
$~mg
N=N4N
q/&8hT
:5?t
5.gAS
XlVD
Uy^)
%5qw
l#e"
HE9}*p
{ |}
YS"h$
UU=g
W9?4H
WeL6
AcP
h?Ypo@
>Y$b
aTKB
YRoe
@Y?u$
&Ys
]2A
WU78
.;$O
HM*T
u1|#q
?\lQ
#s:/^ f
k,i
83YZ
$}8
x(%Eq
_<Xe
rw5TV
PbA[R#!M
X "^N
wV<<
|+k$
xy@~
adj_
ZkpJk
FM4bV<
0GM-
N v0{
qG3;r
mNLLbY[
Y; A
sOjr
*hu.
X>Z9
N`NJN;N
7E3%
:s0J
N/NCN.N|N
#M:,
Jk01Z
C\l<
" +
CV!u
y-TP
&'/<
c@ZCl
M%z\lE?
Xpx(
c ~"Sd+
.] zWW~t
HFMQL
3mF3
F}pM
] Pxns
1+c&
F^{H?
+@MtT
{Q#T^
V}A=
t&g,p
$!];
6Tk
rk %
S/F40k
wH.[
5THez
fAY=U
C@XDH
N NyN=N2N
9s7~OFH
2uYb%
&9@M
Dm"B
'n\p
Ti[V{`
70{S
Syjg
;#zN%
Niw
)boN
oR9nEp@
a^$Z
+]`"
kP!];
K(0P\H
N&Z(t
ceeI
Q_BF
Oo(K;nF
tl$} fY
D;n
Y3bG
V+:/
&Y\b
B5 Hh
S >U
0kr
6,d sE
P:2F
IQ?i
O=H
Ct@1
d389
|c*
2T>x
F6 >
N%NJN
0-oqt
=b87
} zn
(Bfl
4*ma
IV8
!Xq~
Et{?[
dX&+
;;cUj`
~~a|
#!b#n
@@, "
oq[sm
^%S[
fNdo
2+r(
D2Z
^j\M
qC,`
2aYw6
?CzG
P4<R
vi0<
dQG>^
= |q
i2&S
Dz[)
HLI*
'wh|T
^I92
P {U
%#\(
lJ7V
E4!2
(32
fjK^
JJ3HbF6
s %`
3K!V
c"TB
S@oG
e?=D
1}, /U
IE)$
_Hz0
*t+/LB=<
rT`$
9{5t$kb
bgA
r{YC
W;4)
) 0I
lZA_
N'cv
`?6 (4G
"5j
m~?}
}n6c
TK_x
-9A&
v[~>Z-a
VXlqKu
SFcB
) 09
m&"%
o/0b
^xHvN(&2
twt<
2}NA
,Dlj
9vg
~olT
}%H|
,pEX2a
*]*A
E=( E

%:j_Z9,
19z^
S@I<
>lw0
(`Mf
#?8s.
!25`
NlN$N
b|H
D|V
e44
b6{$(
9 ;Ty~&
B;l3
sjWxZ*
Q7C%MT
~b ;
0DS>
z'jn
qpH
0J[E
7RK
A ,L
j2uW#
,Vs@
xeaY^52b
DhHw
DcI$
*b~1
0TF?
Wd##
d-LC
)+f1
%=?,e
"8!vm
~X C
^8E`d_j
Q#ew
"S%=
TXt p
a[*i
{}by
iJ0E
H{9C
t9P&-
q&[s
Hq@d
gP~Y:
=J[#2
j,R#
'?Oj6E]
s.-G
K J:|<
'jo<
sGiA9
fl>]
;1Ii!=4
.7NP
*|Rek
FbWoUsm2loEt
:I1#[
vbH
=lC/
J$JjI
5^LG&n
n c<
#b=>
g_e 0
3z9.!
MvA,k
> *,
Qhnny
rTP$ '
uV*\
5A*YR
ubz>
mfci
4b;:N
%(fvj
J[_
.kS3
{J$V
Yoem
#ovDF
pw t
mpfrr
w6{V
WW|
k42T
6,J}
>b!b
)Hp5J
q5<
"yD&
{qN\
q~pX
}U:-
_vt%
K};@
X= .
#<xD
|J(8 $
306sV
3C\1M
(,0.{
dh83
*>Q '
D/1"
B8J
34pe
~ A#c
Z'zH
MGNQF
yHY@
8.i`
0 j3fo
TbR '4
Jxkr
PA!Z
OC^U
J^SF-
FubX
Oa_P
~ujo
dh<z
ZOvL
; .w
NKNwNON
l[ |
a-b
6Ok
zHH
m3oL
F "I
6F:b2
J"b {
jRo"
mR=n
# yp
P"w>
lE{i e
X=#k |a
~X4t
XU -
4Tp~
=usci
Zd@
W0j9
#GC|
W~A%
SjR@Y9
?+&Z
cp8
!YxyM
+fO5
CKl,$A#V
Tqg-}4gw
I.Jfif
|im'
N*NhN
=p[d>
I3{-
9al7
,@rX
bkc"
p7@(
#^k)u
F6Nf3pmQFQWK
A8*5E
x(m?]S
%CYP
vw,S
=}=
4R Igt
LMwN
kPD }
/C)z
NANjN7N
<3+[
/W DI
VN~2dy
vrb"
,Qm#
TD&y
XH+_
(D[Xg
kvW0h
$p2V
Y? [
;W(d
]$VfK
i5~B
gE=j<
& P7
PVM}
N};6
*5-+
s)|P
?Oia
}RPl
% ^x0
Tx ~%,
2a4R
nu<:f
s)|r
@6 >
0;xnv
v Q6
j~)0
N8mF
0!_u
(8Nv
~+Z >
VOUh
f$Y~
2l!\
i3@6
~d_vn
w EpR
}b%N
[DaR
Le_H
P(@d'
#svUl
,bT)
VHZ%
Ed2e
) u-
^?{%
A?w
DyBq
Z4
NecHJ0
G [p
o0vA|
"ueP
;vcZo
Xn$C
3FoU
c i'
kva\
PG6&
O.$
;a:|
~DDW
EDHO
!:M -
Y$I|
#Ty[
MiKLP
S 1X
ZT R
vy{]
qw(/_
A&-<
v@X4-
Bn(o
j m
FlvA
Ar9?
HM{/
sFT8rU
WfjI
\5bK
JdT'
gCX~z
l ] m8Jh
jW)!
BFV_
H+3#
!A $
DPjX
|#2F
%"`8
Y;Y0
#!79
KUzY6
<)6Q
HcxPd
]^=
+ZB
7MzSdOHgnxFlt
MvB0
M`!ZL8ICh$
*e2*
J5Y=
?+ m
?)TO
rLKs
\|=<G
^vRC{
Oa8fbIMWwjnH5C2
jX&g
4BB|#[
y=X(
9 LY
+LY8g
{S=`
b$=kK
P ES
T~Wx
gFX DW
|&HUAk
r hA
k@ZT
.z /
AgP^
;[ h
-r
usGq
,0wO
&T_M]26
.wvD
KlyZ
"^*G
Ih'v
Z3ZAg.y9
L s*p)}|WY
Y?z+
0 <e
PY^_tD
O(nT
H)}1
s.w3
D:gO
UVAPy
)?u
>R C
'd[
tX6,"
+RjHR[
OnC0J
\uY
z G`
15D1f~
D]xP
Wz86
!mFOp
h5^ t
+D2z
]Ecw
hN1r
?<{U
|=Oo&
bb#R
^^4|
lz_
m! 1 {
])jR
r}Xh
yT|m
=Qat
aL_B
^67j*
=:t
V;I)
[O=
6qvFN)
dlMg
!$*`
#(S
UV)c
O^7]T
gBfV
l{Wg
ZEXJC
ya ]Xr
M&>{N
)"i]UY
=9*[P
/ZK_)!
\IKq
IOE%
:<ouf_
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PAWH
@H4q|
Y>:L
rt92
?3~T
*,*b
p"da
L5fE
SKpq
B. Q?
iTSO
N"N-N4N"NyN8NmN N'NyNoN
iwdk
NpNtNSN
J"7gh
h X3x
tvgAl
`noZC
^^`z>
`Xs5x}
8T]s
F"<J"zo
pw8si
,(7
ODj/
ipFW
vwVW
I,H(
C86*
YO?^
r^e^ Q
,bQz
K(D,e
]^ 8B
E:\h
LC"
gNA9
MWe 5
Emhz [
<t`_w
p P6F}
~EU8
~T4{
0b. %
4Q(G.
ee[u A
~ `^
NFQ'$"
g>^S
p"m+Zl[
~~G&
IVo<-
E0O!*-
ft,s
xI5W
%@_j
6lI3
f:!L
m2]$
VP5$
" w${
`I>9
\]Q`
@#]-
By8L
]yf
,of8
NhwN
/Z4
^9Cg
4fN+
}2 ;
ei{
Wt-
Sk*l
O"BE
1=jk
jSNP4
_ gn
DO R
\ JZ
JTnt
y)c&_
}F8h
079 Hn
;xCc
}m=^
C=D1
KtwM d
"$.\n
2=+g
Ik5
3}%t
pR)$
z4:v
Ckx7'B
:3]Z
W T,
.lz,P
+]&F
[Vi'
7e-\
p\|,
0xb+
ri-Y
CLu2
zH_
UnQq
2FV/
E#w{
N:NiNEN
@{ns$
Kb^ p7Fd
%:9"
C*9
ahar
9RJP
9;A/
z xK
Nddd
(<I@
/qc?Cpw
wu+L
]g2~U
U?:6
r6)p
xO zF
SAoi
u_K*]0
rNSS
X]I/
>'l~
_4Rg
`)<*
9-a?M
/QwL
(O{1
p/ ,$[^
Avjc
51e`@(
XJ +
@46:
G:1u
M {>
&`Jx
L1X|
E2$
33V!
a af
dp_uS
*p*(
gs&.
yX70
*M+
/>5y
;aSWw
XwbOl
b 4T
Br d
hlM2
?S8 -
LF%iss7
'?=B
>u3/
4TLH.
$Nwq
5qm{
>ko
f<0G
t#I>2
RYu>
3h I
[H4X
{7+o8
2 uI
%Vv
u9*O
7Iz8
YZ k
IC,Kd
8c#w#A
$j0U #
%Z,;
+zCz
wn-^9
](Hf
"8&F
dD.>
7 RV J
wg,<
d \9 |
yfT5V
g)lc
| X{
~r[\+
p}) vu
NOUI,
y2G~
vqFX
E-ci
B5ip
{^{J
6al
]h-L
V#We
/^A
^7?(
i,bt
|i>x
&X/~
,'wR
v`Sh
IT<,
FO={+
kx9hC+
bEu+S
A10
0~T7t
_R*f
V_]c
5){PV
V+1a;
/.nV
?6,raT
1eD'
>)tp
*9-6
L a*
Hrqt
ln#L
rb[1
BPt
Ggeu
S1A"b=
G}2)
s0
^G PQ&
;B L
Xp T
B.\a
YDkW
$&A@72{
p!$-
@Kt?
7;;w
;5C|'
45]b
Bn_!w
9 S?
>aA1r
@{fk
n9eTB
fNBZK^
NoN?N/N[N
4zWWP
bFalp0
!<>%
"}{0
rDpmv
XI M
F%k}
m0Y'i
SM5a
"lbPH
ZW%m
p6#-/
L'z(
E<@2
S_Ah(H
f+9V
10z
B 'T
>A^]
"MJE>
J!DN[G
z)#@
j_%
+2; v
;?G4
;[H^
0|(A
OwUBE"L
/0&73ZxYYm
{hM0l
{?s!+
</i
w)["
*"&nr
&@=i
a48qg
8 s5bM
']/8
fP,-f
1G:y8
l QWc
jc^
4sUN
&Y %m
^q%8
6b7PQh
G\4@
&|jjg
d?_W
p~oO
GY <
0R?m
$VNKG
YQ/gG
877Nn3
P0?,$
TPk^
$VH6 8
*fF^
)Qe+
uu (:c$
\?X
A?3V
,x=p
+7Ns.
`It}
2Txu?
]5AW
ZUsM
DCk%
=Z.D
;&aW 6{
{`S`
FTNX
i+Qk
System.Threading
rKe30
^axe
.<'Rt
PTst
0I?Ga
S$Rt
El=3
)I]o
?2Z.
oN;
J,$M
8,q`y!X
5L(wN
-kL`@ t
Y"`&
B%o"
K"OH
LR i{
7&z*
.$K>
) a7
[ OSC
_RAF
{ieNR
w n^+7
`#|@@
Fx- ]Q
\w C
r;%
?atf
k@r
h /x
4h+1
wzeI(})j
,xo5
tR5
Q%w#S
wYf1y
Q M?7
|`hK
\$"&g
(ISM
J22\
, SD-
wU?I
.p\T
%lN)~
xM"3
l7auHtUaAqI
jc^
J7u{
!@ C
8 VK
opt\
soeHL>
<G R
lX@E@j
qGPKF
4+fAc
O:L6:
i58
)= #[
j kd X
tNO'
$F.}
b+#C
J-xq
- U1h
( @kY
:N(5D
g"c[
U <J
*&9x
X? :
\$%i
&!*s(
S%o1
)Skg`Jg
U<
I]n|
&exa
-(%+
><\S6
pjl"
)*MY
hL yAt
.+1.>
R4Ek
ie9m
\JO<
tldO
Dd A
Q"fI;
43Z^
OiH*
[~g]
0a+!dS
`)j}
V<3,
H:AG
\hRN
R.X
wN&W4dK
J1->^
zf=dl
&o0,A
6Me;]
DgsC
'5S
q 7"u;
{#N:,
@*5
G h{
'8L/
OiH{
xm {
hcB}
6bfq
={1r
su2l
M d v@
YgA(!
JM [p
ji(-
B*WA7
#'Cc
.:Xp'
@#p=!m
*"J2
$4^+g$
1 {*
@ltl
I2\A
~|aU
i^a$
gB9G
hn`x
X8VSfL
8%8?
+Qt"
7^!J]
._dU
zL|C
^~0[
zL|G
:fy1d~
!<!Ht
pK99.R
g3x{]
@&!Bo
50y7)#J
chUe
>%?:6
rD -i
Et9~O
t|P^
449E
SM8MR,~
zuH
*r+H
C~l
d*\#
(zu&.
< E=Dz;
<jxF
^ZeL
LtQ5
NlN#NBN8N N
+P5V~
JgY/&
$(h5
rb]:dj
S-LR
$C!N
NVN:NQNsN
U \\
"F3G`l
]S1U
7pr
?fQn
|]Tdp+rsq
$Jo| -
LV?
<]+L
#&C7
,Z5u
`?6sQ
E|8b
(9[2e
=H4^\
HaIx:
Q'n`
a8e
2-OO
YXus?
_*Vj
eB70\
WC>`k
duac
?+E
7KL;`
;;*y
S5:4Pj
X%Fh
A=!f
"L{{"
S"Jj
}>y
-bq]U
W}0
ts'p
=IIWv
1E`;
n<(DYMhA
b;A9CM
)z?U
ts'U
S:k87
z8 Fw4
+J>Q%2
+\+>2~
.9AM
3 \.
y`B~
^ VoE
I 3R
CAM$dv
;w!A
gp *_
aEw2TM
:r@(Z
dcS{
<j@T1
8 <aJn
)O(@`
?bwYA)
Xzgc
FCo[.2
i*Ce
+U u
[p@=
N Y>]
gHJ%
3HA(
vbP+
`.8MU
IOpc
Vr'
3s#5
=HZY
^;i6
! -(
&$1W
b+NI
{L\K'
.,C*
[@gF
Gs7K
L~An
U<f
yx6D.
pnnm
=U}
[9tSI
*`$S
!Qys>:
<*M(LM2
?5!3yv}I
(? h
^FE
_e S
ZpD-'\
bnhT
RG3j
&hWBdi
,&x
t-OD
o*3
c (_RC[
)XSJ
gkfK
!5q8
OR?Ho/
tPFI
/p|
ILp*
a i:
Dd!3
ZZ}C
1B\F
eug<
/'rhaz9#
;oR>
o sUR
i21N
]G*|
Lp/A
*ket
J7" 9
~7cSY
MMMQ
G)&o
I:Z>
<=)>
esJ/
^J_;
Xa R
1]@/M P
]E a(
#IEi
w2da
UowY
dG,J
sY^I
Kw9g
i(j'
W>H1
V\w$\
q{p~
oz=o
<_/)
_=ht
)2Xbn
.)\34:
ZkzK
R-~)(<
V H<V
6Laz
:x{
g= |
EERRD?
SS >&
Wu]p
ECaLng
;M6y/yp
0,sM
.2|s"{g
PWdS
# q{
~k:%Y
SLL ~
-{J7ZX
=a:C+
U*D,"
0Cn3
Y nV
n%Np%+
Y^$F
#~Dg
<;i@;x
vK!;0vR
UMB+3
<qMv
Z_^?
s~Q(
%OH7
l_3s;
@j"X
p7H9
C/NR
I~n[u
rdIV
qa'y
Mz9i?
rUQ8
l"qd
\ H3P
(lSu
h%Vp/
pcx)
-6x&
(A@l
XT2I0uPksLpvS
:Uf;ZYA
Vr,B
o= :
O$B.
fOXx!
3&e1
>zWB
&Ie|
t|]Iy
._"o8
H6cg
aVn<
7UJd
)D[F
_9
bKk^1
U3T+
V.?t
]ENe
1ytz'
`?[F
ms(B
oq`A,
p}b
#hEQfi
B{yTlg
3[K
{Cb{:x
]gRfP
aA(X
Q9Xa
3^.t
QW k-
'l
ah_s
9rz4Ei5KOYandYFZ3kY
"#(R
c6:@>
pNw6RvDuqQk7yjoeJY
AngWNTvUlSvN
z (
7Ba#H
cJ N
quKZ
O g
$^p;^
XIa!
{VPh0.
S;gD
SG;1
7 )
:$ev
?(bR
y2-]0v
PS
%"1Sc
?9By
tl.g
(5Z
*MRyy
>H2K
HU;x
1/~s
~ ES
=!D%
t$jw
_AWd
h#4T
&D%Q
r*dU;}B
E}my
TKl1!
^<G%p
,dRL
7RRI"
JLh6
4"l)
C|Vj&
LdPE
V8,=N
=xp/
y[T6
f\5!A0
B:Jo
)m`x
DH}w
P. S
!0#b
ZR?3<
_j3ZOg
1D?P
BOk!
Kn!E 5mD
uZ/~
Rj8gGr2e
3OTn
emYr
$yiPLF
1W[q
77%~#
/ N
tuqj8
91v)8
^{K8
g=b|
8/x6
M%H||e$Ce
5y"^
#,6.
_0.R|
mS F9
Mp.zM
Qm `
>lE
i"YSt
X6 !
N N?N6C
V9'!
,_j_
?41M
H&Ie
:190O]
t' >y
2?8mmz
Z2,$G`e=3X
vA #
get_FullyQualifiedName
H Bq
g&~'
8:,Z^M@
rOh
FSo
~{vh.
lw k
sAs%
`1&O
ntiK
H BB
sP#Q
[B.>
AY1 KL
SDVe
-TE '
DDj0:
:j4|
N<&94]&
Z (
RzJP
zNu_
~L3R
d`iN
g}>Y
2_S8)'I
nkd*
Dy(?
%2]-
x2'Yn
'e] >
cf[q
g}>-
k#Gj{
YPEH~
z4Y)
I$}k
]R9n
K^4V
9EQ?@
H!p`G
6$+,+6w-
l1X
7@D4B6
KeN(
bwm0
Z [t
J_lv
X&'1/
v acI
H3{>
&\6e
,On'A
d+ 7nq
5yMwq
Siva
!sf)~
PxC)
r}`Y
+9CE
5C+ U
#_2~
[+k@
>=Po S
B@-k
gf|?A
2 yX
Y#~t
"%+G
!w>e
td,fi?u
8X$]l
rDtc
{#\
$-:U
sL*@
0[PG
a3#]
!| yP
7ogI
F~dN
N*NZN-N
-. :
Db)IP
FDW
DsN'
)&>>F
_hVp8
dH 7
!m,H
[tu&
>LR (
[6WP
xjX*
}hm"
>$9U
o =E
M6M20SHPmqEAKW
`gZ{
wY3~X
54aE
I6KD
C}(>
HWZ )
<6}K
oObjh
L=Fe
Gu];
"kjr
)0Zl
get_Assembly
iMvMz
yi/Gp-<z
TVt-
tVCj
>NXC
"kj(
`'D;
cm!
;-UH
JM]%Vu
9sI{u
o V
(0 g
>Y=N$&w
r >p
c&t$
*v?^
@!cu
.Un(
\1tW
R(GeBs
wjYV
zq(T
n*v{.f$
"Rp\
WR+/uR
SGc/w
3f4/
t-ce
Wbhm
4 }CBZ{>
IHDR
i;z|
%45
ieO6C
}W?G
ObXy
h{
wjY7
[]_E
<>53
0A6fF
Q%Jc
"aa v
H6 eK
fXC=
X:Jjn
5;& i
%`DAOq
?_</
T{W(
:Ft=e
]Vm!
74nb
HACj
!mVgt[l
2S@DA
m6 t1
b|W8
\/Mr \L
tG`B
v wo
mT</
emJ Y R
zXg`
UN'd
<W_B'
d-6u3
@nw"
D2c D
2Cn`CK
|\}gU
chU*^'Q
}l,+{
_ymj
NnN+NPNmNkN>N<N
TN?loB
0?18!
7B_y
jp-p#
q!1e
m!&.
\S+Z
btkB0yf6VGioiGq2WD
W }S
iGr.ayYt
I4'R
`Fd n
+btT8
^~2a
Qb9_lw
zYoe
nll_
Hc7P
!w[8
XgAk
lN(*
xz^.
4nj'
@b=L
:.&Rqn
?Wt1
99T v&
Z<J'
se[q
"6I9J
&pa J
\fmI
U B#
_2Z~
F%TV
!ov9!
4-j7
(<A
umF[G>
6)84
-%YF
uR2x
{(1.
Q8tmi\
{If"
IU@k
^T0y^.
ha 6~
7u&t{
$4&$
a79tpZg
V6d2
sRZs
p<gf
85U
?Vh|^o:
Lddh.
;J`nf
0sB:
)ZyH
_ Qr-
_d)R
pQn[
.R_^
z7y:
@V!D
z$rw$
567\
K&#yb
DM{
yF=`
1G=e
1R #
53N@
ybkhH
li ;>
' cN
(\/}
Oxiy
[{OT
n|vmsFS
,"A%:d
)|cr
&qmv
h';t6
Q~V=
LjAB5Mq6bNoN8SvyfR
UOWw0=
U@7@<O
"4T]
=F\,
/jvJ
!duW,
{M8V zf
GXXK
}W$|
N&H`_
af$Z-
J];/
& y.w^Z
`$n#
\v\
[`OW
</5g
b V
^f{I7N
c6*|U
4!ab
(mY9T4
$;%A0Eo3_
CqA3kB
OOAV
9 [>
R`#)
CBtd
, |r
3! T
^5r
9PujY
aQ
x] @
o#I-
S%mXZA
(;$T
=8'9
,ST* q
Wf&a7R
Vb&"
EOH&
L<L\
l5c8gH8
-gj]
b%w{
qJ A
X(8F
Gw0
jS|{
Q4b;
=;(=
RLvS
2B N=
O hWzv"
1R=>$
q?@sx
/+EV
!RQC
}'{
VXh47'
JnOE
20Rp
e@rg
Foc'
@U&o
&}|'X
vS73
,w[c
|u{G
L[]ZZi
1P^4
Jb4;
k8s|X
TE_Z
/36.
ISatK
H&l
,m:4?
{E,>
qN9%
(G+jQ
+aiaQ
+=Vf
#T2E
N"N3NjN4N
/y6}PyM
>E
?@z
ziU-
-e@\
7<xsH
{<Oq
VE2b
;?9
c< i
Nr,Y
7aKb
*H3u
E4 6
fT(W
91><$
Invoke
47m$2
t"<0p5R
n:`};
^>=<= >
f<-
NkNaN
jk^=
w25
[6'Jwl
ZeYp
q,q6X
Gr}r
5q R
vR^["
<z\Q
Array
iWt{L
l8~Fx+0$u
y'v|
i8eW
z "*
Xd:g
-a!"
<Q5%g
eQ,> ,g@
n63=
uR >S+M<P
6$#j
&m| 2
T| &
t *|y
3xoB#
Ac&@
o@D:
nWdC
i8e0
9^>`zzt(
0PHf
v:o6oJ
+Zn8
$@U5
2#:c
;gG\
Y>!
y@Qg
Q~p H
@JNl
rqx=
ok_F
6y"9B
Uv;.D
S2i`\
y@Q@
OfQ:,+M
3}wQ
N8[V8
T>M-1
0'+?
Zbzl
WV,USW
bGQJ
UQahLEI4uJ7
=4jy
skxlF
wus>
'NHQ
QtO|
Y_=h3
l&5|
ax0/
].ZIPw
\ ?<
9 rj
"_C]
Vo{^
pj>%L
|.y[G
khq'
ConfuserEx v1.0.0
o vi
)M"
^#RnF
kn=_
# _ u
*}-v
] #I
=QAaK
zXPRe
|#8_~$
} 1*J
R<? _=F
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
u'`
sf\a
UVrT
w&U}.
]C8`T
-ScO
#F3&
r-mxZ
3|%.
[UvQ
oqe9-
:%pW
%*S ,GEy
UJ>
E5( uV.
[PQ~
&;31
3]wc
V8 [N
zU!vw
k2m8\q
r-5U&
I`A@\
MA h|
X7>s
k/tS,t
?knx
]uRfp&
TT=)w
:]/+
sB0xj9
@f c
QX1M
bFL=6
5x{L
OeaE
uVG>
e1}2
(Io[5
Y_3W
H!Tz
iX84A
~_/N=
Q8(C
>:AX
r;k"
\/Z"
c]is
%0vo
-1OdG
7d-"
i ,x3
LwnmB
2}^W
eig
u<l R
y})
{o.5
_4}}&
ju<)
64y
sUnB
}Kj3#
CJfi
(3M$
IQjK^}
Ch#1
yq//
cFs5
S[D.
" /o
0~Gm
wgz!
e.1Y
3<lT
P9q
@`6D
l[\A
d"''
_Rt]
pUk<
F~bRy
h\p*
:O{,
qKN7
|/9wL
0.fP,
_{[L
/\ Oc
1zj1
hJ:K
Wnxb
YORZQ
n,9p
E(`Z|
'v$Z
9O:
^e\V
"a?r
jC]j
n%b\
NcNcNQN+NUN;N'N
3mS~
7ENV
0=MC
D{r^
~<&8
N*]e+
,E(:
+N/B
4,3+
wZc,TH
KvNZy
l:B0]
RA];k
^6A a p
X _X
DK}\
j-OI'
jYdd2mO|
mscorlib
%v#
%7-\
-Dy,
.j[w
Q% 1
; T>
);AQ
-EO h
3JKt
_M8p
sb\0
m_;,}R
vS_U
FNm5f
BpN<
H]TE/3
>ES@
rN4b
.k#W
E/h
3:]8
KZ 5`
T-dy@3]Er
/*s?
1&sm
UuLFBLg284QdIiF
EwsN
m<'H$
fv*_
}:01
#p"HU8+
B%NuN:N
yQ(:t
[Tk{
<Pg0
TA\S
j3Zi
g}$tZ
TPE
4~Vz
O%] =
qY v
u9}<
FM|)
K:i
`3>N
w"qK
j7}w#
oN6Uoh
:^ >
ozNE!u%
Y'C/
bkyw h
}J^p
+,u,`<
T8ZR
ejzS2]
}u$9
c\@9
QS?H
!T't
u)|E
A`gK
`-,C
u\La
!This program cannot be run in DOS mode. $
3W X
ju#q
_/J8ZvUn(
}9kE.
$- 6,Py
oz&zKL
U0a+
@_\.O
bksm
_q5q->
QVnw
:=j^
|Y.8)
7"kL
Yi,h
* <ioO
=qx#S~
]Bw*b~T
.U,)
~~ _I|
>Ng7
q$nPel
{C=O
TX +
*RX]
{VTJ?GC
2^J}
NUN#N?NxNvNlN
7XhO
dtZ(
ZkrH
r|+f
f)s|
G3 L
<3T"
Oty{
(`vhzR
&;} h;
S,$d,
Xe+x
zg5V*
[K+i
nKV{ml
8xsG
r=0Tq~
z40,P
f=-\
#=A<~1 Y
PHrq56
~< f
KCnfa3ROQ7olE
`8+-
@`;SR
j L>
}b+ p
HH;|:-_
QF[:
'A,,
C4F(
- "L
2v1p
D*uR
ewgSp
qx-|. I
?tTH
'[>p
,Pz3f#
qU_L
x.Q</
0M$
<rgd
EBuqP
+]Zh
BoQq
-`RAQt
I)pn
'D!u
'HU+$2
_GX;
1U<
v=^)!
{EhZ
j~9!
GL@u
_I&\
='Xf
MS@73(
?rs5)
"g J.Zf
NuoZ-{
?ZNc[
0+y
;ij((
H9 (
e+'_(=
9Byl
x^*T
7 j5
Jl&*
r'7+PK
lWmtW.
0 op~h
8LSm
Zt0B
bnEL
]jON
y|h@`)
F{ x
*j(*T
s8?G
eAn?c
\}nZ
je]
5ztyQ
CompilationRelaxationsAttribute
9Ho`
_^Z
`vCGN6
;{Sj
l8Cl
, E,
Q* i
kH/K
x 6n
G86`v
\V|B7
{P~wL
2 (y
kL<
3G\09Y
TKq;
(V p
f6;l
AR',$
-{y1
zK{k
s@.~
Sr=I
F|kgD "
$b/P
p5*U O
9\Y
L63,
gK#'
Q:DSB
oP`N
R?WP
9v]k
GZXO@
`:&0&
wJl[
dk6e
RY32
xNZ
|.KZ
~;u1n
NENVN N
[MMP
dKP]#
_ vs
I`M_%\
Ap[5
"X4+
;8plZX
apGtd
TRqqX@
b|.k

>N|v
!> < ~
HWuW
m^M+s
=9_Lb
[?z5
6-Jr3
@ZjM
fd`%}
9 \@
xVw
[l9 |k
9 }J'
H5V
@l!{:
5Ndz%h#
CWl#
rUL
,#Q
zF,gF
LkZ _
-zeB
|AJ0Z
3/#r;rc
**G
uQt
yJ5
A>ZQ
46[Z,S
E60L
, >g
^Q.G
xl9l
rKj
Cz}.H
# _F
}o,nZ
iqDp)d
nLhaK)
z^x
G4B.<w
=z1b
;Bo@
J2i/
ih{v
)` h
NMNWN
k^g(
~)p0G
HoY8
]HQi
cAk<$<#
]=Fz
BM ET
yY<$
"5,Wu@
Yo2
iva=
zwW"
z2t q
fk/ ;
PI|R
!5fd{:
bCap
sMRn
,c&f1
"g{V
J.EQs
xD]M
^mD
8YX9
$|SM
*_-
d(M:G
I-Z_
yB}-
Vcjc
vr~k
F,/{
j%#
p8!H
cRm6l
"^@kr
9>4iF
7{sZ
gu8D
+]|G
#pci
3uJh
J op
>WJ1T
' P!
$fyQ
w:;*,
k- @
g <b
D6,e
@*Rm
cG"O
hkbc
{@cc
7n'k
.Qo_
P]XS
Ym^_1m
Sbw
wYw-
y*;
xHrU
VsK`
LPE?
1 H\.
X u=
'U2y4
II[:z<
cAz'
k\DDbDP
8^fk
jaCt
|^oX
bMG
}T Y
(3:&
g%[-v
b"gU
&/ )
RD7x
?i0F
x_"}
{+l
=W~*
|a2p9
r'[&
gtk}
jUfocGlj0pW2B2xbBT
X L@_d
ly&=8
W9d-
f)=$
C(ww1P
yJX\
v_*x
y=MG
]iD~^z}=Q|
7Lz2
,@Tz
9 4er
(PeD6
gN*
hCNz
Pv!<,
84,zy
g0xB
~?QE
o0%.
'%.F0
q4$EA
G?El4H
S@ M
U 8G
s% K
fLYt%
r(/(u
UQ4|
W3v(
r:Uk
d&,1
gMc.F
E Z2
= ==w
m%Iu
h"F#
JIb3
V@hI
[FS
Lwh
"N*)
{"r'>
><zn
sn`z
Ka,3
*rxj
\nXF)
5M}'
eTw= .
f;U9
ue{>?q?fUm
*iET%
a=;WP
4n _
0cw3/
S9u^
Q?Qcos
~fsyZ
1(&@
Y/*R
S&"0
.XK
Co99
{\/"
Nt*1
eT+j
({!+i
0lf^
BKRA0
d"u-
TdV+
T}MY
6Njq
WW?X
VmvK
<SM
v]lB
SVY9Wo;
![NN
D#vA
oiT[c
x+G(
FtU}
aJ0+
~dAOP
$o(:
oR'
-NS80vDl
t= &
aZ[{
R#1Y
lj?!
G&~%nb
h2f<y
}T'mR
vf8
Egw=
*'w(
}z:7_gS
GL4"
k|G$G
qPJ/
-LXL
Zcl*
hs\0c
{@F
9ruw
5#CZ
k82r
8g65V
QtKm$Y
E~H 5rq
W;
5dqhz
X.f@R:
n|DB8i
Ly9V
,M/A
NqTV
wW?
@iu
-o=n
K QE
Hy#p
lPt1W{
k U#y
}KdaM
(u\
$TDB
iIm6
GHU
xb6,a+M.
c+j@m6
l A
*Kre_P6 L
+AeI
p^6w
N C
PN"g
N23Dh
BWi
'vNw/t
U;{h
y3%U
* {u F
h,Fqq
~/WQ
h$N xo
2HM?
!_'G
pP]x
oBd|<f4
bNI%(
iffvi
P5 X
9Z5/
3+Q`
0M'B/
w`72
qRwy
}Z_
cq$f
7j5?
ZE H
LqFU
J"hm
GVW
0 `Y
5q}d
8z6[Z
JI3/7
P.m +
ONcy
[cm A
oS(6
qF#>
dg;=
Z>!*T
S>$ d
/2z1ht
d+ O
@>u +
.w,
2J)S
sF- 0"
J<^E
J^O
l%$%
J^S
#7Zm<L
i
e[b1
Y5C?
e6 g
M06<
uj^`
- .5
$cSH
{~?O
U#ZEhj
?7r?"
" -qx
NIoCe
JvN>
y<eq)
)% _
jcc)
A9MY
m.=?
yI)-
h2QQ ~
&XDH j
Xi(
B C%
$L2*
Y}W@
L%A x
\@Q"
IR>B
:u |
+/4x
YHWU
%yj3
Zy1FlEWa4QvlKl1JB
J !U
@0b
G>dc
]g:M
AKWR
Hlnm
M<qv
n%u`I
"@G m
#)>a
T4e"
4NdL
2/&<?t
Iq`e
N '^e
BL;b3
l?\!V
lTI zacq
&^;U
\}I@Z
]^.(
$F:8#T g
)M*XE
ep?
g(r6J
jXYI?
qHwL/)
SW7f
pAL/
nSE7
5#h
p&[1
\01;#
8b'm=
f^Z&
T1)W
6q b
FQM
p^+I
RAO
~ -}
We$P
Q,#"
1QE$\
zwd^8e
QVrHy
{Z?p
q0ZtQ
?UP!
& V`
K9ZS
ZoMd
}PC-O
5J_IS
K*J+
tV1>
PI y!B
r7M}MB
;Uomi
Ac.%
!7<$
0 e
B<HE
{9NK
2t8e
X+-cH
N'Pc
M5aZ8llxU9U
QBF`
<n_E8h
(KcL
oD_A
/ypUNA
x7h5
l'11
]>C]
jGKW
u>9t]
Hk16
Z L
wU/6
Grxr
$xyJ?<
vEW$x $
,(ns
Ng^.
}XCCz
%Nk=6mp
NjNPN N^N+N
vb8
{;op
N N7N
vRzV
BRj%^
(1 >
"cVMS
h~i^,k
'v4
#Y
:e;W
;g ,
<jjUl
O`_@
eh]/
9s$~
GIN>T
[8)8
( VV63Y
VYMCU
]wpB
ob;(D
9P7Iv
"bCY
HQ.o
-bneO
j1B6
d$5B
Pi-s
r#e,I
KN-3+
P*
%OVB
%j#xLBSY6
u ax
z%hm *
= 7~
TDL
o]VpH
H-EY
2_h
M]wU
= b
<r!w
gy.v
haMf
*,mg
XM$G
'L h
k$T8
:P >~
P]?u
T6k}
h=oM
G3Z[kW{
ciaK
%AhL
>xW@
u|K%I
Fqt
6e 89
pdQA{u
K89psj
\rzHE
mG[U8
cn}f0_
Jx C
KNHt
6L [3*h
zYH(F$
4]t`
>>za
u Oq
PZBwt-
8"/J
iIDVz
}QNQ
OKJwy
BL=
K{x
Y=y
`_rj
ii m
*w1{vd
v+5E
Z-Q
y9 #
2 [,
|I:z
sk*g&
U1Yft
1$PX n
s!B_
K)b(Mk
\bXS
(0T]
>P [
+1Y6!gk"R
^~~E;$
[*p8|
:@MZ
v v6B
K.Pj
Pq{QHq
l!q`Xzf
_Bmg
5&F9
e0m64
FiCU
Sr{X
D_Q*
yN:l,
'|*3
^,xCD
ANm{Z
I w}Nk
A!Hz
Kq0<
lF;
t``Zt
MbX <
H_D#`
3Z07
~+,v
k7c >
N gK
:`WZ
1-~#
2D(3
^fuq
xWso2
PZi1.Q
J.TUM}
2# 9
g@ T
HG]S1
eT/ [2/
83TZ
t18
,lPb
"9T{yh
^[s
pLhX
N, bC
qqQQ
#cEpUR
|c>X@
|;}v
;6SR
$z kA
~LuZ
B04\
XOp/[
Vtb
4?mi
y&c3
nJhgd
_P5O
&&/Wq
1z\
B{Bh'
)d@H
=HJ>
)_;u.
[#?yS_
JY$z
rMZ:g
%4:=
\Z31abd
lYH
Mq.p` l
m Ci
ZWT]
CzR:
MnQz
/a5q
a0no
NO^b'
*vNr
#OQhXV
2z a!
(HO{yE2U
0hU^@|
&P A-
Snr4
J$yV
rxtu6
;=iN\
9n!-
>y| }b
S!.z^x
OIA~
}Z
UFn
AzJo
z[#\
6td#
Ep36
]`.o
1hC1
xhkr.
NH9b
C@C3
[~R]
\U=l
\,|=aD
1 ``
DAkI]
=k{,
` Zu
|fH !v
PJj2
d |o
\nk;O
|vS3
PF= |
h{}S
5U1E
"u6$
7J6;
2sIe
om8X
/X@
RDIC
| QO
y2]
fwRk
p Wk
6>@Z
~Zot
gQ"%
%,X?
f0J1s
TbmC"
{z_>f!
)P:1GLS
z.C=9
K&{@:
I0V'
<)C
P`aA
~m~w [4K
xx`
&Xn3
SGhI7
3TaA
D $
mTOHK
j\_&_
|lJ7p
Ra9xyi8g
x AZ
q,]V
E'(+BO
$aCix
Avv
T2-%
GS9XPZ
uM`0
z(TK
R&@J
CR`4
-0RF
<3\0
-&4
_kec_WY
ltRC
%j I
0}$
|2d!E
%FaaQX
hIb>N
7!^!
$ dAW
0:Gu
;!|]&|
foe
**"6
$X7]x
S2`k
0 Oe
L Knk
Pkx/
h IfJ
2ytH
AIi
kJ %8euPc
0 O)
OClFn
C.o-x
Q5;A
PIQ?
nXo~
M u1
$\@Z
ZA);
] ]/
o)ki
("SQ.
hRb!f14
cp fk
Ena4P
[:;5R
^AQ;<
ui'RrXr
Exf^
wf8-k
Ia\D
j6 w
Ym e
5HceIF
=.Y5)
X?zj
Y``Idv
dK))sBzgJ
kr6B
D#z-
;[6=y
~uHN@H~
XCv7M
eaM[
x5g'
N_45
!c[R
~@G5
ohJ]uc
6nNRN
&%s-3
, Iw_ @
O$(M
Ivrq
UP *
[.m
8tWlb
) m<
J 7y
ge1]
MMV'
;eB\
Y@I` ,
/^Z!N\3
,R[|
KH=
n8KfexIzkOQIE
q}sU
f[t"
MYjb
lqkO
az/
H_%0
+9>o
H e`
[+^{
2rj&
?3-`
GvUB
<d0Q;HM)
x<J1\/?o
){g,
_V "
Qne3
( . p
=~j{
y9cs
8(|D
f s`
( < 4!
Fuzc
RUJ@VC
[68i
)A-a
s;{W=
d}g!
Z,R2S
!b q
9mP.
hFLR
&t,}fj
kkKl
G#>%m
ND|Jf\
Ri|o
.| G
i!=R
[?|,>
fd~fQe
U_k?
Cv0}
$I28
%g~D
H2$AHim+
MB^k
=Z^,t
V&>tH$
$t~|
3;DLf
# 1![
GetType
twVl
l1Dj
4Q&F
K@}V
%(v
#H|:
r$f3
f:ti
IGRg
@/ t
DWc 5J
9|S9
p$EL
p3hV<
=}>#
W~A[
T;U
dgym
)e&V< =
V75O
&q#L
!m G
fF{N
!~[,
*s#X
\ 9
7TG-
RyF 2
jc%E
gY)X
5Ia+Y
|;7h
ui&m
7$`J
l8lc
n)v+
5jv)md
qNei
zD0/
]1z&<
_[I
z:=\
}1'[o
g}.O
Y5 N
`f"%
0_Gz:
@*i<V
V>aF
DdK]
.%Dv@
0LL'L
!!cn
[a i
)AJz
xR"*c
, zc
5SVN
9]4[
|Iw24
Lz@|!
T^ m
O,L= L
V|gx
E5|
g5?C
7 &.
w{ )
C$[
uurh
OZ@wA
(_6lrmy</
. J_
2upEaW&
s|3J
"Pi>
8vjH
Zxi@')
B3mw
)>J|
;@<A
s(7yw
)} +p
Nqy\
I\8{P
,8D>
$B6xJx
s(}t
U%^aH
uK}D
FQ D
ZI U
<e
'LR
OK<(J4qc
_>
z&z h5
:I3Wy
O!hEY\
/K'n
J?a4
:Y?r
tZow
w\=ST
Ff<*
4D XUya~
3.9U,
/D(q
T_p?
`E_g
,SF9
uE #6
1-np5
}x6h
_2tX4A
u<d%
5G j~
gb~-
%k @
UUgh
.X*:
T|\e9
w`Tg
'xtw,;J
NxP?
aWZl
! 59q
5w e
4-&D*u
H8w
-0d^
`'tz
r+7|/
IP6^
yam<
kyns
W %b\
ML=A
!$[T~0A
3c,y
<..Z
h"^6
vQXNa
,l/
@qr(
/lQp
4/Ad
s/hj
X4Z4K
EI}|
Cz9CyO
L5}G<KS
p5}x
+s"P@,
0 9p
x|{G
S{ I
dyYR
!z%#
Q}
K$"v
V-j"z
System.Security.Cryptography
NlN`N$N
bd+o1
%jx,
97_p?
04kH
: Ty
*@9rV
$e>M
He[>.
R{OP
,+4n'
IDATx^
Xg|}|
Gz%J
c}dc8
), T
!W]
b; /
8u1d
+'l$U@
Cfzw
s a,
sT}k
XSR97
(bf&|
|eI@
JiD,8T
EB=9
XlR,|
sazN
#nuZ
W_D.uf
Ns (e
wG9]
uo}\
1P `
cX1Tw
_ZPm
Sc@@
? P=
8-L:[
]j}^
<<t
Z ^8
I&Q&
fY}!
=!"3
zjfu
W@e$
YC(j
G;sS
4bWi|
>mn<?~A
Z<z6
k)5[
jnw6
|.d c]B*
NSuT
$0H
uI<[4_
I;zT
eJO"
#xyi
Rqy4
()7=
^>\HA
JpzMmJ%
gs^>
G=EZ#
$T OC
/J8V
CQus
!._.
|t$eM@
UnG0L
)LP
1ls6
{>f[7
.[Vm
Is04
2!:s
{uN0
vGZ/
QMOm
|HEtL
/P=:
8 `uu
~[`[6
ZSC|2
lQKV
FP',:
wGj7
=%N/NvNnN1NqN
Cmh/
K/&J
3>)i^
47 S
j\,!
aP#95
~m.=
^$n(={
OhN
ZOVoz
&a ]
v:Dnt!
?X"y
?@-}F
;'85
@r2+6
Jbo Jlu/nr
ebMZX
V; u'
]2^VbL\
M!5r
cub
c?;%
cg{Qo
7j u
pD _4O
FAi
Z|3
>Zj=
b*+ K
59tB
:c+[
-g>t
W3cC
N;.
Q)d]
OwEdM
P_ "
,x:+
1\rR
uNIH
C 9>
5oca9
2^+A
^{/u}1v
{cNNEI
LeT&
E>q u
\{2",
M# OJ.
^FceC
9=Vu
M A6
uf]q
X~lv
T7Fu\so
dpV_qO
lANd
cVxilr
r:k#
"<0~Ist
-[)
"gIN
;5P
-/H
OC`%
FEs[
dyp
> c
E#t.
'[a>
Etaa
8v@
-G8<
U`Vy
9dF`
1^7D
3c|S)&
)H4z
AfLj
n @6
F~>e
8Vnqk0
>Huu
P0>#
W@@
_*O|'
:LkF
WjOj
vUNbE0eLRsU3B8ox
}N01%s
IDATWQF
)r!-
(bA`
tA @
E( `
t)2S
?lxj,R
1j{.q
Nz%&V
1Y +
o5-FD
? yQa}
9<\$
${%T
wk5m
2 rO
z2`T
nwT{
ZOIY*(:[
bE#4D64
yX2?
<dFQa
46178e
n@lN^
#oiU
p:? v
nVx(.
`'{}
n`>q
WQ J"qH}
V4F"7v*Q
c0SpZU
XxVQ
b(Lz
ap."
jO\:q>
iAlm/
gAMA
+C:C_
E`%+9
:y_M
[S}V~
?qzd:* JM
lb_Z
=q^z
QBNM
Ello
i~3k~@
3+CH
{!E'
e([.
\< [
`*Mw
_^` ~g
bO+*;8
@+,$
>iq4
rk)^:
NOi?5f
{M:
sn65qx
#Pnx*$ ;
0Q_#e
RE;(
um&D
)?;5`
#~ ?
b$hh
P!w;iI1F
WO5k
-j A
?xgM
Ak#&Y
]\Pj
Mo&@
T$&K
_ wU
+":t
AC 2
x: R
>`&f,SJU
R<,
_95c
P?4b
M0%
(hEM
49+V;^
LrWq
,O^4
B aX
JfZ~
5;Z6I
M#1A
LzU9Ol
#A[[
| M
W?/h
MDx&
w*}a
2#*L
/.mP
rhWk
*k` 7
r#>Q
4]2}w
bbz_
/VPR0
|Fqc
:k)n
|aNH
3:6{
ihr|T+
0>>kre
(,p
6~QHM%
jS[=A}P
Cjv,
bJ;'^;8 7
aFu@
Ai.>d
Ui cR
)zA
"5?M
yjh^}
;/cL
;@M+
3@Vj
;hZ!O
$`U(=c
5 FUoo8
RCIP
!!{Dat
t (
e@y!
UjNW
^j|A
|DMD/a+
z6OV
hk+|
PgZT
1yiQ*.,(
wM*o
}o&m
#44QC#
gTi0KZvV
tU/<T
R=]|w
(cdwY~l
Gc#l
6sad
nn=)
1-M'O
\frK"
[C [
S$U_
Mkbg </
P#Gfg
g'qi
W d[m>
A<oqC
zvA
,u9"
*.$#
f[6~
q>37
x J?
,CMn$R
0n8X
YypI*
Z|yo
dX??<-0
`4]R
Qi<T
FdBZYJEzbryYuk6T
}qBe
|*u
GV9K
R@''
i# S
v8D&
5}A0
klYe)T9
y58{KWZ
)Z M
@?Y0
?;B/
2X~cx
i*>@
hM%
F ~s
'_Lx
i8C
t @U
4L
69j7)
Y(+3%
=); b
b4d{
&#-j_
KPgfi<j
iK7Si
=j^!J
:VPI
{. /e
(|qZ
h(p2
E_w(
OY6xcT(
irDe
bN*1
L.HB
a WWV
jwE
]iugC
WLCH
J=fr
Vqt
c3>0
#lH\9
hasJq8VbMfG
L;4x
y@D'
Wr2
5W'4A
1Hml,9M_
HTC5[W7eU
,\Ca
C ++
":^#x
E)fs
w 95
au4pS3cEx63QOOg1
Q!Ge9
dAmF
kuR8 !
]=*R
G$A_
dYgY"
NCN;NuNLN^N$NPNqNLN}N NINtN
GZ c
p8g_
J_>:
#Do Q
'{AP
`U:2
H[/)
K1f^9
"S.
rrYIh
kbj}
8!tx
,gP[
mMT/
A7%X
ED-?
g|bS
G:2i<
`7L#g
x!_'K
4hxY
eR.,,
[[u[
=K5-
n v2
'Gt
.bK
uLCj
rGzFLuF4oPHwBQvw42m
}bj8
+l %
4;L(
&qN8J+
2BfF
K qR
@Q^cg
c;Me
Kd0n
zB/64m
H!_C
7<=x
0:UPQ
fy@O
[h;]
f#B2I
y \K
;EJqWH[
!ra8
HO=b
?*1
fSU@
qS|@
2Bf;
<Lk?
!NPbE
t__0
dX#@
nVimmcnuMU23zjRloe
x6X@
>y7?\
zlZi_
U*gZ
)0o?01
D >^
7};<
S7 `s9Klif
\sB}
@.Y<%
"\Shk
P`iy
R Ex
1%#N
@sw^
OevW
z s*
z +6
fA[pO
WGCd
i]b1
A?pu
YSy]
S[qO
:+x
}vbd
L+u
U X;8L
JN(g
~,gTX
U#Wc
CMK:9
| )0
\(;U
:+8b
)7 J
uCLt
\cBclB
`+eVD
*q[t
/Nh-|
% >&
A9 [
Yk'PW
HERK
^f,@5
%\wY
Kd!S3
x;~sBT
RJ$P-
} Ly
_.yY!
~3<(
y"5S
='bv`
!@Bu
EX kk
-\rSm
{i>s}
c=t87
}IDj
_NB
FkD
?@r>K
P*q}'
Qm^$
R` ^x
w'c
NH 5kz
Anva
fomW
rp]D^
>,~5
V>Le
ekn.
mM 2J
Jz[>+~
3MFu
5!6V
wv|1
yo9%
4I~YA
Pe4i
1yu+
^sp4
8| ^z$
Y9QtG
[i%''
P6{Z
{5Kv
u6JTD.~
5PDK
,QM'
o 4g
sSnh
Co+)b
=UJ1:l
>6a
$$5 nj?
2K4p
zxJ)v
mG0v
i|`s
y5_y
N&[C
~$'~b
jtV_
>g4x2
v15tXzF80QELQKF5
;}r6U
*+jj
?k=v
{XIh
r,m-
.^2
:fvj
,gw8
LhDL
ArpSA
=bN:
+% X
-t|.:
JE!k
sQ9e
{?J<V
Dd.
TZb8
=#+,s
pZ+N
#v.
O|D6
A;{iq
@lVP
C7YKqAWXqIIr9mP
,~@:
,=@p
ETU1
VS<.
H;tbS
hI&{8
pTnUH7l9LPZ8HItW4m
nhIjO9
Adr
YVZG
j2If
z&43
tvNc
tvNm
UUx=u
ldM#+
e%ez
J~Br
2mo
m3dz
E[E
CqBY
_S\q>vH
(I+F
*8%f
`24JN
ONAc'
[^/{
NFN=NPN4N
Dc c
!x1O
vd0`
x~U
}Wrr
2WET
/`b Z)RM
71Xl
TB5d
.! U
m,U(
rOk7
W0e|
s<v~
[5;9
[WX9D
>@B?
}Ji]
f]\T6
f#XLC@N
$MK>1~
~8gu
$tvm
f6KD
DU+2
$:87m
/(Cd
1Wce
c5gl
y'z
xPIc
c$4{
8 oL
YWo Kp
gn00
+@3N
A%_j
R`Ga
"*lz
h5+[
=}68
aMO`X
R]ux~
AcOj
6N *>
N4_(A
[vBr
+Tg2
d"+ab
ahZs
<&ti^
S VB#
#*Qj
p8S&G
:3Lg
_~FM
\mp d*&&
Dyt6h
VP
fS/*
`@]ZO
-i^7k
% #
&*OH
d\L
Q:V'.
u'/#
,^v g$Eb
]k\K
.xEy|
uGsO
=v-G
SNX?
<o2*a
-Gvv
$MB
G=Zu
2|}W 2*
I I WW%
`te
ys$1
6Q]r
.K %
q*p^
yLFL5
g/[o
)/QX
"O eL
!r5D
%&p BK
Y 0D
jx#m
\@0:h
$fG'=
j'D
vGK EW
pn
I*N^N{NrNmNsN
Qg8K@h
TLwfFo
%Q!Abg,Cs
{_Rm
jBgq?
r,pX
Vcz'
H x<
.b=e
jppx
=DHA
))J
)|FNh
K?X
Vnh1
$kZ>
5Eh.
1D&[]=
UDu?+K
k GeC
<c{F
yN--y
tJ/|
x[,
y.Do
CS0.
+[z
"XQH?
U .
H3]<T
xkrG
y{GU
oEi[&
AO/,$
Er7"yB I.
_Et~
]5>:qb
j.Of
#( o
@NXz
2Q\!H>
'f(x
]ld\~R
7b v
Z7 0[
Idr
AUGacKd
y#k$
%S[
>GTa
.2>
E.Xd
tW@z;
dY's
Krf9
uH4g
Pw<
zRm:
q{vmL{
,^}j
[ J>a
m<sLX
OjvvG
s?q_
&h)b
A5^:w
\`~x
^T(_
4:KM
\yf@
l.Bqb
V[p_
?V4[x
m Nw
hdbBZ
tc+B
l^
HQJ<
;]e4
u.R
< K"
3r9ZG
o7 =
/"ip
." H
RfG k
uP Rx
NuN"N4NBN*NJN}NIN~N$N*N
[X(b
) ?v
f\RO
a,K:a)
(h2j@
01Ru=
W]]t
E< i
I40#+"
4KAT/
t$
>)1p
Wkj
ulp2&
S $Q
B1 K
tS 9
T>gn
sX yu
&9d_
|jsg
[j,& Kj
; 6nGz
|,cZ
N!e8
Y>24@[
g=e?J
kM0 }k.
tP $
!\Fp
MZ*2
D-njD
)?!k
0 zw3
FtE^
$<Iu[/
-S?&
}\NE
}pMv
s:Fr
b~N(
QW1NI
*\MQ;
UT6t
?{G!
.$X0H
}EQ>TZ.+
=HIF)
a]e% A
AIr,T
DYBX
"p}B%
)#7
|bB*;
vyE;
kG_t8
4` v
4C(#v
!#O0Z
!k^$q
5@zEcG
fW1B
Ws2N
3u;l
[}FM
P+e
P>'1
hR^>
*L t\
r"~y
*\~ef
bM{&{
mof5
LsGy
*mDl]
0?j|
/;2geh
^_J)Moe
r <^
Q,t#
Vwe4
?r4L~\
'$w`
_'3?
`qFo
1@o +
[1~f
7KaM;'
<[qHp6h
UUxL
j'Wf
FV =J
uc G WD=
ZqiC
dS{k
9~SKj
,[wgC
C*Se+
GOp#
Q:E;
F1oAP
L??hJf:0
5Ab_
nh1On
d/uI
JXZ
8 *b
T#O=
2S2o
i+@g
Tm[Q
]Os[
g%_=
Vm#.
HLXo.DRB
:GM
`p5m;2H*
f:&f
jxn (
3rvVzq
N[CV^
+?Nse
),1 o
==94q
*Il#
"a[S
6T.`
u}HO
R8rI
2lpX
L2yN?
^RsM
^oH&g
Sa Xw
rOiw%S
!j-?
mLN'`
a/l=
N[NaNyNeN
SjiZ
V64=>
I}sG
[:'@
n 7+4c
NcNVNI
0K)>
WIu#m
$J,E
H<]v
Xspb
@Ire] JG#
p =5
ZQL
'r?Je
G)l4L
^$8}
Q" d
F%Yg
'q T
o6 x
o1A(x
W1' [
MoR5c
g++H<j
]!_@N
7e2
_4494)
OU3n
AMq^
cz<_
wfpu
EJdl7v
H: z4@
~LZdK
XU)+
o3 H
kU_iY?j
04j
fN'?
bcGW
]957
|q`Y
x2]/
;N78+
2s)I2
x{SW
o~Cc\
Gsif
MuL8}
YQpx
NBeur
a^%&
,<PU
5r:^
d l>GI
IUM1
Efr\
#GO+
.UHw
JDARnq
D|GL,h8
RVo5-
X<=@N
\]O
1M6o
~p/g
g^+I
Y) ;
sCaxQ
O!/e
g'\.
get_CurrentDomain
Z$; t
A -=
mF ^
W+tM
B)E%
:2?(@
L oG
0.cDl
O`mg m(
u z
6 5' Z8
q"IZ
64,X
CrO
RC^>-
E._TE
`Vta
8"B=
gY yl
`On }
[v%?
d -
t}lc
$wDv
,`Jx
iR7o
E7}i
sfOk
Sd8~E
d>A)kK
&dFm
{]W
^za9
?\TW
qo2!
jK =.6
5Z.A`
:,q%
<.>[a
Emp0pi_
f7*`
UVd %
KXj0F
dN98
D&0f
m3Rw
tEZl|f
q\83
#X6~
Nh@p9?
f:;H
c)3Xt
O}l&
68_I\
,2NxN0NgN9N%N
%UDu
-*Q)T
T ]W
@6A7
IDAT<TNY
H{ujb
<IjL
'#Ga
[u^
TTeP
>)k~
h/K
o#>)
WH jQ
rcN!
}\o3%8n
NM"b
#\w
=(qt
'[V-}{
EPBgi
Y{~J
*1|J+
B(t2
DialogResult
[QK(0mX
x(k{6
)b
jNg7l
L!|M8o
*?B
jT4
ot L
# l+
h [E
9GJR
=Xp5
Lgk D
BNXG|s
OJ(/=
:1K=,
_G*}
o| 8`N
>u`8_td
~G4e
+53}
^ E\
Yz`Y
"C3n.
&m@Dv
$9m~
iP+5
pIVE{2
!dYv
doMP
)hio
BH,i+
g$yl
bn3=
U+J_
-Ol\?
zyI[
S~(N
vXL1>
IV\1aP
uY^a
)FtE
* fFKf
HO^4
-[k'{0'
MSq-
KNXJ
dW{!5m
kGH>
A?0d DHX&
r|I
JV9J@|
/.NbL
`U)4
Ox8E.
% /
3%y'ma
R= 9$
B^wLlBR
qo_`_A
i<Hc!
+o;
i- y)0
T>w\#
!Vs
,^,/
S:5$
Q?x.v
;Dg,
.]hPZ9
f%mZ
^Y $
@L8,
7dM;s
TizJ
5jM:
UAEU
q(!8<:
bXAf
W: w
}sO>7
X';C<
uy{d=\
p*5u
!o&_YS
vl #V
-%+93
FcJ:
%YxETd
`bf{T
v`Wl8
U5a,9
<2}Q
p bO
Z`Q.]q+
pJc8v*T
{_ ATehV
5~IK
t!CZ
2738
+;mfZ
Y@
9W|uZ
e+1!
A~@:f\[ q
l5cB
~~S4
F8t%ySF
)|M)
7xe< 5
iVYo
$PG.
"Rd h
QtB{
.t0S?3
De_Pu>@i
5[RX
WH1_
"4rn
dy"~
+{3Ah
'dzlli
N4 5p y
qLBe
Jo'&
~hFU
1seI
ww J<m
7SLZ:
+77ZH
Ce4s
jTOeJ
8oF
5,@Hk}&
ixbq
O?P
?T7a
E&Q
x >
dCl@-Y
\`'`
:zpvJ
_^p3
fnyv?e
7r !
}K% y
oLk)
AkeD
svD~r
e:0 ,
yt4lE
++Xp
J.C//1I
fv81(
.G!9
NnN$N-N
Bkg^
*H;;T
fcV/
B>$(
uC(m
3$-*
1$KWvf9js
OIQX
>%9\d
pfp
XKd6/
M~'M$
U ]kP
9/!=
tli
"[%e
>{B'
{/bUq
dJCDw<^
-x|pv
l2 Y
@\rO
s-./
\aux
5B5+
g!?f
CdX
`+u9Y^10
p?_*
o3I%V
<-<
l 8V z
`Nzz
[.Bv5**
9q kB$5
HF[1
"^P)q
%X^N
?(b[
_o^Q
,>w]EK
x=5? 3k
]5&[B
Jx3-
$Qp!
*t&
:C0Q
gx x
`n p
iuiG
)m@)Q
V&G
`P-7a
g\Nb
NmOBl8 5
] 7]
#"gx
32JL'
A+ga
.4j
_)L7
LJmzw
%m.3@7nt
VmL?"
G <"
p*.d
5~l
oy&A
0ZMN
ItYL
&%>
P"_o
K/GW
vwn7#S
IZ7A
wy&Z<
McoL
r;jjh
u#VxpC
kKr|
Q;C
_KMknx
p7(A
&C-@?
xL L/
Z%. {d
:JQ)
vqw3
t &H
f4fC
zz^Q
g H
q|^|
B!>
W'6q
50f[G
^[G1Hq
;X{
-QRe
UQ{
(4JU
P^VO
0D@T
alO'w
;5Mwl
D|CG
\t.S
G-t g
;;.
`r(~
5y.Ex
L'KS
.B#/C
y(3w
"09= S
f5K9ut
k8MkB6
nw{P9Z
'xt
OZ`2
3NEy
qj{
Z hw;
BuX
p >
o7Lo
)dOb
xzX
~ jO
ly|)iSD.G
vou[
S f$
B!he
yHJ33
<5^o
yuQX
IFa'
[KX )
wN ?$
t-rr
XC [
?y23{
8r`g
^(zZxK
PC+{0
G>Bt
xFWIe5iPH5s9jeeAji
>~(i
U)E'
%|P7
Di5"
l-1vT[
]$~=?
%y%W
4Mj(
D[q2
SMdB
x(Jkl
V}VvbF
pFoC
jEh3F
i,==?
jyi~
K~{/
R{,
7CM"D/
E?8P&
`)@1
CXo
m8@)6
sCq0
p9j5
{[R
<~$"
s_yXG
zr|Q0
kHW;
/'U[
)0Mb
H U^
q%"a
S^Gu
uV%S
A2;K
$hkMQ
n {
CD]j
m;-
?[$)R
/ vv
a@tu
= nb
u_Z%sy
QfKtW
d@D2vT
mOpS
<eoL<
NPNJN(NhNeNcN#NlNANzNwN8N-NvNNNaN
{o p
=Ef
. G l
Rw5[
J{.#a
"d\M
+>l|
AssemblyTitleAttribute
ZhP87xNOrafN4bNE
EZ/a
(9&J
m!$}
bv"*v
f%7|
.M]\[,
/zqC
Qu`o
MemberInfo
s+^Q
bTNXG
qf+
ch7{#
oeDSIcMbdNF3uhx
! =D
fSD< E
Yc;8
"G-nu
<)^!
hi&8
;#5Xw^u
90*a0
/?M\
*nJ]
sj?c'
"]wvt\
&Fc;
L+2j
; #U
-kD3
FWg)K
h|E`u
KO_y
bBMd
|y3B3
7RE|
"r|$U
ey[X/`
!l]x
UQMa
~!J!&
<#_ &r)c-
a14|
Y1<1P
9ZQAU
d2W)
{*g
kTMO^
a u=
AIN/J
ntII
fX0u
%/r
G{.L
GR:!
UY9=x
(W"[
ZbA;
`qT/cy
I:lS
smLJ
$n#)
-kM@W
bMMg
Vp&O>%
mN
.gCX
- T(
E3Us.
|si.
#\)Rb5
NNd^
<ZHR4
MbJ_=n
F>pBJ
?%6(S
)c64[w
uw0
c51;R'
:p|X
ee1;
:iC{
<qb|
K7m1t
"/%5
/R9z
5bA=
U8"3jb
+WMK
LN`}
EU"%
J#nf
]Ua^v
M5z+0 oA
z*`@
'dV*
I`*CM4
Xmm.3
PKs6b6HeQK5JtYB1Vj
G^}F
~ +M
!ig
Zm"C
v\ES
Z3;2
gCDE
l _#
w*B6
/T#|
?~Y5
1,J%
tKji j
" I9
PmdOSV9rhdbJXXn
\k`O
NdqV/u
%{ob
f5Y9T2marcpX1piG
57 d
Ts]a;
M5|u
zZ -1xZ
3xw;)
bt52
H53xgeSZqnRt
wa05
Liux
lUA^
l+f\
FY?T5
x%'b
OJ7 6{
WIdE
ZD2I
&*4&3C
"QEo
0\|7{
:r52n
GHJ]F
&wa,
9m%M
~N~
-,RV_(o4{
\ESgI'
Ap&=
/nxr
o"Yb
muVX
R_tz
Q6[M
n{N
xC;
^kor
fTBP
]@,Zl
dPuJ
1vy=f
<\b"
*-0"9Ysb}y
gM2z
I* {
K\m3
*HEM
P%dj
qIWs k
a`1)
ORN1s6PFSHBfHQ
a2Q{
[*%c
T'YC
W|g@H(qY
3OYy
B ?_
~[\L
<*aY v
?Vub
< N9NyNEN%NaN"NTN;NBN NcN7N/N4NaN,NFNfNCN$NhNCN@NsNIN
\=;lC
;~Q5
JzP9
xh6oDd
#L8D {96
kL\d+
04)N
ib.
I-&|r
@?&(
^ :2
/!@J
E {e
bW>
G*SK Uv
'm.pP
A#:xb^
6XOdJ
's`t
[ gL^
Fpwwe
AssemblyCopyrightAttribute
cWY
Eh2}s6
a\9_
zanB}
#.E/<
J *z'
Ex8?
N!mN
&.aF} i
`(8T
qqdkC>
%4C]q
v3t&
SI/|
U3[4
%Pc!ca
Uy_(~
]ek,M
z=;{y6
D\c]
[F =
of ~
1(ei
]:44
Vr6Z
KuPm
I)^3
}mxUL)
7;~S
W*fz
5 WO
@Q: S-]n
NqN!N(NpN7N@NFN
]qx
5;V}
+ _H
<@kG
}Vbv}
P:vT
dS]/F
C5+.n
8LM_
=eRuq
7{|6
z)ld
=B(m
^v7e
X}wj
.7gn
pw&
&|$ ;
$ -Q(r
`S@ \@
RQ3{
F6W
d,BDw
YQ/e
:kcD
<4s
A''?
QIvi
)5t8
UI \S?
{3}H|s
\(0 rCM
#f X
)-*Er
=X6|
T&&0
7Piv
%0 ]
+>eOO
_vMC
7?{yczy
b7VF
8o@T
bISm
oX-ZnQ>B,
#@;gE
zU&9
XG c
Y0$k<
XDhu:
q3I)
SXSPI.fZ;
yE?e
|!NO<
b[=4
f,=A
+Q5a>
X ;;
n2=
ouV|n
^dzq
[Fy7H
il9Md
lJ-s
H !=+
I+oPZ
sj &
8 *?9
_!2\ BH
Is -
>NDtR
-/1)6
GSXl
T zo
lX{L
C4Dw63sZdO
i6M
MBdD
f<hk
N^s%H8
]eGj
]1?h\~
qv6|
{+Q.
A,=; _
eJP
~ C>
#;|
6ZKy
zx!,h%
>]C1l#
|WdF
@;LT
Eh@~O
T$NU%?9OD
?chg
o`oK
ebe<Q
:Z I
3<6O
kj?<
)+"9
5" 0
|pA|Y
}~$.)
A=rt
GQwW
ST%~5,
tWF
znSw
/4Q)
'R%0
S_ 3
?MdE{_b*
%|lzX
lH.M
B < rK
2DtX
0V& -
A5l3
dt"e
DCrd$;
ZkY*~
#X[1
'prdO
N. .
B7!D
CWBs
F5$Q!
mt|@mmi
W<R"
\Hq8 L
OijD4
V'0
6%dB
x85 7H
l) bvs
}~/
%1KR
yIg>F
Mp2U`
"?G 3-n
/b^=
U}66v
bb-/
97to
)yeMPa-
|cPl
bb-9
6@$c
&9_ W3
Uqm5
wxrC
7F T
D>"
#'<NY6>
IT>,:
#aBF
vSrON
cIT
n?"kK
nvZS
WgMn
$Z^7H+
Vv$\
+R}7j7
cIT_
q4*
h ra
Ek3M
A?SS(c
)/3
9@3-8&IXn
8p9^a
* ]I[+
?#O)
!4xj
Q){Q2
TOS1W
}~u,.v
Zd>-
>:|A
A'\#
^%!&^g
h.o%cpCH
>F(Q
Kt?B
v|%q
bINU
n\n=7
lC(o
d$xz
9ix!
RqtA
Vs)W
:g@@u
-:
;o<'
LF|%
pNd!
33K:
Mgt;
5n[9
vwd>
r$Ok
0"j_
UY4'
Kc[,
1x8?}
VERT
-CyP
Tqpn^xKj
5O]$
k( 8
m`
S\^
k v<6
)9M%
!OoD
~{GC+
JW__"YI
$hA?
=,V{
Ta ]
m66^
[rb[#
YmA
qasd
]]b
''>ax~9]
iQC
=9J<
1H'|
{y|3
HxA.?
w`:;
:c&-
$wL>
"{Q'
:Crc
z61-+
EP<
L7Hh;
gJ2:
:,y-
#qcL5
q(zNQ
[$X
(ZHa2
S8eK
H<*7
[:b'
lxV[y
( 8u
E*U9
a]plD
>?!/
%/!D
KU6^
v8{~
8dHg
>y:'
B%Gr
=)ut
S.ti
k^\C
C-Fw
8~}5
8_+#
l1 I
F" E
BDBT[
+n
Oti}EJ
Y9Q2S
(53$k
&]x
Px2B
AZ<I6m
X Dv]
qz';
|KDzC.a
Hrb<
X;" 1B `
tn}t
q` N
d>0Ml+
?GEdj
F2k'
0.cD
9WO%
u_wGaB
32x8q
seX3n|
CUzS
9eli[
h9HU
+r1'*
h/S2
- ]j(
F8ein
loi t(2
i]&
!<-Z
my+l
% yG
C 7I#
H-m8
)H;
H3Hp
! b4
WULp A
m ,C?
hB9N
}7+W
DHtu9
(BV@
C_p|
ziP{
b2ku
~s6Mr[l
%oZr
p<I!
yB g
D$^N*$
Uz:V=
TyRG
fy Np
L U
d$]i
tf5v
lCsE
IAo
Ehq4LalM&
+8E<3[
gb`"M
!t<P
d!^2rMwE
)\e7SC3
Y|,WLE}
yQp
\6g\6
q9be
tpmmPtw
;H U
3'xN
(uzB
I+S_
@i H
ccL~z
yfNX
>xoO
CD)T
/m">
W$sY1X
|N 0
I?M-
Jn&\t
5AP
lyGVD
]8VC
G6b\GL
jWu3
s&>,
1# q
!v?"
&?R7
:2\/
NR s
gB$
5~Q
CHIQDc?1
Lr=1z
lLIP
2HRj}
R91
W E/
'%,"
`|KY
5/q%
]yR
N/NXN
5GF
5}QY
eZbS
:R3`
~=eVZ
qm9 p
h= az!
!-s
_qk]
J4X2dQ7SwbavLtus1
Hx%/
"-jz
;*Ox
jD(,3r ;
Ack/C
v*uN3
yJtSw
H)<|/
JNsr
gg5@
1vvPw%
u~/w]x
IP<n3
17TF
\|7K%hP+
Jv`u
l ,k
t|P t
q `:
n[%T
W<h^
6060A
fh)d
a}>q
<_Qg[
2.>{
C(o=
g(x$
0vTr6
GKgG
get_IsAlive
V|CjL
VZwGs
t'2X
*"Xj
w7[2
o32+
`N$)V
hA\`
#hQ6E>D
xO/`Z
aiCq)
*&6]
Q__q
^xSr
woRO
YX\\
okoH
mbSZ/GU
;0~sbA'
jl$WenJE|
0(jR
nH&x
-:g(
_$d
$1.6>
h n\
a}gAH~
}Uj2
C,Vz
ubJk
$a6m
#Ex/I
ak[R
FxJ6ozEmE9chyo7
svjKK
(_!|+m
/ R_
nZw(x
{}c^e
aC"mw7
ic<N
`x4($LH
M!Xs]
KonV j
}Nw4
Y'c
/0SK1
%&~o
R?q
NgN/NoNRN N+N}N%N_N
"[-[
c}:E
Z8zZ
V.k
%uy}
CT5pW
Q,=
4^Z>
j(OB[
%{-D
cwu7
(:Kc
I/I=
>Z)X
'F8+
*byS
Yt q
[Mt?
REg!<
Lq8X<9
Tl*t
QY+U<(2(
@o3r
=&a<
C]"I
KRvR
i W0
N0N"
pl6[:
<A`V
r tv ttlI
9 [4N
7Mu
a+d<
gd<4
N$N$N
fz'W
8[L,
[R -'
[{~!
cp l@
si+p)
KaXx
`|P}
e>b
\jk;
K(W r
- jK
]4w
MB s
B44 G d
62t*
e.<R.
gq0X
ZxC?;r
\y{'
6ij7
@"k4
aHq
jQ7-
KI3*l
^H}H
( h~~x
r\5y
NlQL@ e
U&tq
0TSP
K(et
rx(2
y6G%
N^f8
$Z\$-9
/PHI
3HQ
,jYA@
vLq
d} S\
mN!^
~ vqp
y,PM
F5|W<77
{H%>,
vC*Y'
`0=<|
$+m^
>' #
KS3&
5= .g
*oM[;
V t
X Rv
e5-Y@MX
PSmO'
)bU1
\^+`
^UZ!
?m$\
9LTD>
'<2&q{
.0>%
<-/z
w^H8
H1aV
3 -'
fj5R
E Hb
{G2_q0,
|l;5
/'FIwV
1gr`
U`)i
Djv7UGsQwn
}*t[W
(Fl0
un24L
!/3S
ZH0w
pwdo
[ID|
?I (
_(er0
lobN
rXrk
:Q
D%<v
hUc#
e/bl
C;loR
+u1V
c+M}
zR0kl
=joz
~KN+
/K ')w
UkZa
_xa.
~O`:`#:l{
uUU
b=8mI
?E e
RxO6
$M+{
t{7j
^#Gi
h_KU
@Hst
V_{3i
oy;{
2<N _
p2luk
Q6Z~
9*bC
N2N NcNUN
d*hy.`
9PJY
sPGe;
mU/z
#Blob
'S-_
tH#Q
<)Ff
"eni
wyH8X
sR{ Y
~B @
=# z
6 {T
kkrP967TCmERHmSwR
4 1$
Wmtb#
p[kl
q\Heb
W7 3r
**'W
qecU
V:bC0
(WBM
/Jxe
F DC
;eO[l
tP,Oq
H~:n
G{&x
syPk
zkO@
ZrFB
TfU$ZK\
:_Bn
]$K(
eO8d
IwjCw
9k^u
M=Sa
2D69
*$.G3
HZ}$
gjv.^
FpSC
sNI>
k 6[
Q)6H
Ruk>
&rD{
z9R9
AT^W
]V,^dWJ
lUeU
a !k
(JaG
3 ;w6Q
]BO>e
Fm<j
get_CurrentThread
42]>K
=(dS0
Rl c
M3BA 8E
F%/,
Jl#d
[ER
\GiU
N_{#
tPp7
OM)|
&+W
=HdT
%.l3
uR+S ]
6 'W
>Rp:
~vb=
U7op$g
x$M&9x
.7D(
{lCC
; bK
Y0`H
(X9M
fo3+-j
JAOz
ESU
Qw%@
ky*Up
[s|Y
18m9!2B
Q 2`^
5u%K
G F-
k-"*
c0y7bt2yCbs
NpN[NZN=N^N{N&NhN_N*N
b&^N
QB\+F
U ;
N&P~
`NXo^F
| Xi
,n-pV
wP}(
8#Mmr
j`c
f.# -n!
jUa8
`gb>
,}Rym4
]]K#Ju`
%TKF
v<(U<
5YC/e
/)p(
B}9g
?C%Z
{+at*
2\+^
; Ke
{ "v
|lP|F
F[ e
>SP,e
L%cH
;_Cr
= U$r
Sleep
6x{
Lbr0G0
L&c=
?~;oy
= [
udIH
jRZX
~?8x!
=0Zq%
s}b>O
HJ[UUvb
I%r`
9LM,
*Nz0O
!'I
R+6
kGw
S`5K*
L=~$
BR\B L
@ &[
WQpR+*.s
]HN1f
~pnM
{[53k
Nl6v
Hn^Q
zq@q
V7!53
r=mr
bm0-%O
+2_a
!zC^$0S^!
J3JK-7
4?o%b
/hF}R
~S:E@/
c?n$
@2Z}3
Oq&->_
[q+X
iF=:*
_m[)
t }
((]Y
K eUb,'HKah
_&F
((]l
_gZk
#0S9
"\`eQ
V>f9
# yC
q=Q/2
`M%;
Tm a
uWyz
7nFx}
0*D^
*alP"X
nAh2
t+ 9
Fm/2Z
PUZ@"
L95^
i%G.
6 #
DR]X
sq=E
y;Ind
RkEjpp
I|DK
nQD80HnNX9Zy
+$ r%m
s^3EA
{X8P5^
AW78f,
dF+M
-vL#
f+vq
9-jh
!7Ql
aZ;'
> *r
>)!l
ikC~
8Ib#
# *0
4K^~5
%7|h
9nz#
0=m-<
J[&w
4D7~]
-<}1/w
2h u
e)[|rD/
wa%X
/7 b^
<(x=
+k0/
\> V
m|`c
l+UZ
?2YXx
?^X`
]G=(^S
k(g _
h{2q
ZazDl
,cP%
tgoQ
BrpT
4U sM
A;
ngv}
1D|UqV
`lW
~pC
~pB
^S^@
Ic-F
Vpt=
z^5KI
RC;M
ZJP,
a^ X
BwWy
\WrA -
lL*b#j=
w\__
lr'F
get_Name
ch?`
)@!%
~-@'&
hfsC
$P;A
T(,4{
OhV}
)]Z_%(
8j`@
fToh
lRM-O
l){
i|~
OP;-
b UBG]r
'OU(
5_wE
)B"8
fA]$
)bCQp
sp7a8
@c[%
bm 'E{+H-
)+*K
WbKh
S7C
'hxZ
r,LG9]
#U);\W
hfbv
E0<
Cv(f
tc|%h@
<Ac9[L\
p.^W
,4e\
%JO+x
<EWITJ
#i2
),"u&
41c\q
hcAF
QR3 +z
N|NqC
vA=B
`J07&
/02H
uBAOv1p310d3
cOJ8
9D@v
]i
&*)
\CNV
,O)$
;S c5?
U?QY.A
>[Dw
$UNvOC
9& l
9pt>
G? M
i6Rc&
O}7p
H Nu
m})x
v b#1
Q;nPk
VDm7jLw
_iAU
j 8`
kernel32.dll
lzey
g!u{
Ozw!
LNmV|
Y^^Y
fa*
NI3ZS7
EI}v4
yW r
c`wD
|ZgD
=s _
8zbR],c
SRf32
J_bO
;(>0xS
(TA}
]mj7
Q=`_
:va#
H4u_
R7R< :
_P M
PyI)
rt?P
p]%=9<
p}S
'MuoX
g_hq
oXiD
g2Y5
C-w.!
qyCl
0D|dJ
NNC7\<=
CP j
XPAe
*, x
d:V"
%&8v
y0!
Iuj3e
*' &
&Ay@
QSAA
%&8J
Kx~s
+*a
r! >
%&8U
J|T@
*0arhH
1*fc
6[5p8
b"Y|
X0Wp
YP}7
q)WOd
/xj'8
pj{t
, a
c@5
MJUWC
m<3~A
} [q
t{n%
}uP5
N&NRNkN N?NcNwN
q~Y"";Q
.J%HM
!#xh
F,UO
/]pN
M`2+
YO!i
RtM,
+f.!
!`g&!S
Cr{N
xwq&
~/RK
ssI-
b^0~)
< j
G PR
0V~[
uds!
b0$1a{73<P
c\"C
oS1z<I
T"8 gP
<k/W
GD<a
mKh.
jgG4
K#F]
!U>0
~a)yG
&XE2"
/4LC
?b l
>?9$
%/)y
cLwD
m,<~
CH:
dP c
f{-s
@dp
\tt%
LVb>
{SD{;
@dp>
JCZL
`"f v
jb`/
'sVs
cTZN
(TB
k%n#
NtPfJ
Ng>c
~uTkf% n
kG(2U
7 r
4`($^
lGt?
u!V
!N%,
BI=&
1K?uLd
}F6s
k+.bo
5>6T[
YWVm
&:PoP
3B{x"
B>O6b
UQ"A
GrQ$*R
8Bx \
,<~@^`w
oF3<
FE)!=
x/2;8!
*,Ma
@vBT
8}@"*@
a3Z^
'qyp
J.y
0%jD
x;do
z"Q,"
Pt*,^
?0 J
b,dTl
rt_Xf7
\zJK
Rp[J
7e'g
h'8L{h
JeIb&e
Ct2
#a_
r~B_
AhG!
!1gN
NiN=NRN7N
48(J
4h qB
u T
u~&
Qk9,6
U?4
%[b,
pYgR$
>qEAj:f
KWDl
b|}G
m _ 4
eJ
~M2k
u |
L;BEQ
g|7z
Icg)
OL7]c
xw\M
T*uq
7nt!
Brf)+
O.x3
g?1o
dS\v
IA0H
6k I
/Da)
] U'
ZT|]
Pk}*l0P
ped`
_w~5mg7D
N0A2
2pm e
|x+D
no 9H#
WLb-
rJWd--=
>.UK8:
7\JXn
w#}E4^3
AZc"
I8MH
]mvh
;%^ _
f /7
;0T
S}dGG\
*A%y
UOL*
,adI
Htz-M
KSf{ya
IKNo,
SxR-
`I_w
Etc sI*
njH >
"I9`!
?8lD
IpDis
8Vu#V{
Ashz
R|u
ygu9>
d"|" r|
Kr'9
3}z,@h
:R<
k{wy+
Or,n
fkuR/!k
W@ >P
I.b}
Ynd*
ctMxv
'RWu
7|(?]
83tt
=q[?
xy#V
5^E5
pI%Lq
GeBheOv
(#=lS
8~/6iW
/!!)
MX_x\
`[{ u
yk;~
N8N N,N*N
g]TS
Btq(
(^=f6X
4v]1
h]C7&
G)>"r
Gb#,]
Hj05t
^* f
,oG)
bPq1jG4
u!k0
H{aQ
J<D,
cTe%
5Iq 6
a!%t
Nlo,
yYH}
m{ *v
1 Ys
YS77,
[dAOF
s bx~o3
%Lf&
92?
kVmXRtXoPQvtN5
g4I:L
F\ A
={Ip%XM3Z
OYTt
<h e
u8tv
3 >%
(s7x
- gU
2kW
:SbZl
^39}=
\oGm
M#6<
@8{.B*Cj
&J <
e-R$
=ojF
q< m
" -M
DY07
%=pM/
3H6B
fJhN
2&Tp|
wEJ19
e~Eu
gvx-"
{&]`BM
8L4"
9NFF
1@Wz
'qV?
"QjE
Start
^iNvH
^Y:%h
Q=>#
w~y]
"+ v
w~yN
g$ L
WiTB
m f $
UmpW
0|"r
.Gx#*
$&J]k"u
T$]9
-i0M
zn1?
G57S
= 0q
6~6
T"Pd]
4tU
akS_
:S[A
mzLd3
g.96
sLD+
20;Z 0
D1i>
:~aC
XJ4o
kAS<
%@l(v
~]"U
Z_ }
fyXt
/^19
!dT|
&\< 7p
RO+G
Oo ^
@>aC
. .:~
(oX\
lb}s
iWJu
F_p
J+5Y
l.DO
%a7t
I or
IC\U
|T47
P`A8
AzED
A^f6S
Byte
)@XC
<a,8
a`]t
TQiA
G(8:
q~/vO
Qc{;a
Z<k!
8"(R
f3QJ
X>Xh
EAUa@
jXUc
CcE|p0
L,An~
'DG19
&~@=i
l%uk
rq V
aZnM5
/l=a
#d/Y
P)r ?>D'
~ +]
tn+#
pi&{
qVl
weo M
*4 J
b5iw|
1\\
^eSH
G JS
N&N<N
'v3?
$nVb
!Q'$x
=IM8
?$ N *
&:sn
X%Qq
Y7{m=
fq 3
F}rD
3&QFB
n\VD)F
FS\T
_j/
BhclZ
Wwf
<:>d
i,G:
00P}
e=h3
~r$_
^=n!
wvd-
myY>
G!k?
8I\^
kV"n:
^uD0
gK:Dp
TE`X
\C!l
vv1+
qo/SPS
JZ4v
JU?N
T+Z
= 6+
gYlR
5%$~a4
Y0E-
rw`{
$~m
^4L*
zKz
R#h7>`P
W~B<{
<n!]
1"#O
cppQ](
79%s
4S)Z#
vup4
]$ Bh
t_ZB
3.6?
*+RK
>hV(
C0 u,|jU
T4#z:|S
SG L
svkv|s
]'i
tPSL
V6{MC
y<Yd
:0 @
pJ<,
0Casl%A
wIAO
=b{d
80)D)^
( N&
fi[9$n
"3N@
oTy>
%W]o
H`F{
57{:
Aap?
k At
ZjI)
Hqxu2
P!j
97f)q
>UB\UOF
y[w\
'$!(
f]Xe
a.fgiV
Uz!i
^G|-
<ka0e
9X`JX
hTJ6<A
2=j1T
1|r}
bK,@
T\cm
K8X
BTgI{
aahPZ
|W v6
5q!R
>/5~
s,!Wm
~n%:
}6/x
h0+!,
nL(y
[+F&I
DS)O
K{N[N
Gi_H<
SF]G
FfG$
cG()]
,t}Q.
p3LR
tB
b4l
:J^_
6y B
)eXP
t: -
4L/}
9<#Y_:
uw.u(
L nE J
{;^w
|u+"
TL@ 4
I+m g
;*@Zi
I 3|
.6YNL"
WOz
I:|4
/l =
x\ J
y%"5
7|T$
[Q$h
BO;jZ
^4Jdab
4tdb`
`88D
*xb
U{hz
.tjDau
sSs_
8'`~
KKX3
w?v F
a:vT
P ,i
] In^
RL:
7k}r
wE }
&w5U1
n#<m'
t2Y.7
c_9t
o;vcz
b Q/
&Vu{
jyp"U
Unl;3
W =z
AG Q
&j3=9
K"fl
(8kk
v _6#
3d$YIN
[F1/
V.T6
XU,o q
DV&N5
*rpV&
k^?D
)Mui
y(&c
L)GJ
,,lW
bM]a
VX~S
%iw<u
sR=A
;9Ndtq(0)I
}|h
j2N/
bY2"
]O=1%
~`m_0
$` eW
ta]0U
.dS2
h#+l
'J"9@I
).5
ss.
qC3T
cR|8
Ky V
*y=Y
2hL S
HR@v
zR.;n
A=~2
;_[7
p~#<
Pk@
q34i
dyZ(
hFAb
0E6
'+DA
y/R>
H_ >
B'4k~
E}l'a4b
Az`
@%FwKd
^#r=
)e&n=
s="w
fOm 5
6uPG
M8\:
>N!V'
ujg
O>dR7j
{7&.2
yzB FHi
r^QT
L@^^
tHuO)
u)r%
*gg0eQz
>>6Ha
-4-x
E>]L
get_Message
ic aB
[hYj
D(`b<w
%^J2
<Hf1
XN;w
| K!
,'.^
Q{">o
,Gr#
M`p|
9xYi
Z#7}
mJ*fj
\5},
1XL{
,jyf
qnmgB
l^M"G
0 A(D%B
to[;
U-so
8Dx@
>4D:
B*j{
^ZDs
AdXG
3D >]1
LoYC
QX h
0kk
kFgC
_`g-
a(W}
UUG3
>jb1M
/4x(\
A/TX
Z:Gz
2Q:by
<VH}
+/w
vFM#
%jqYxu
U Pg
n5VL
&S yi2
J|KsT
!l{ &l
&o*"
yMe (&~5a&"
1:Je o
y~BNID
#^Jl
r=u1
vP)<m
K.aM
\z@"b1!
/+*M
,z -/
_+w$@e
(hU9YD
5;giK
<&d'*
9~ *E
@[j
<2t/4
9shN
K @~
,M1Qz
r}2C
79<Oi
<xGn
x'C
j]\<)
7hE$
5p2q
1HT+'
zl_.
cXQ{rK)
_mCZ
GQ*^
QF)P
" z\@
AW6!
8Hd5
:|Om
XzF7
D;ldtd?
+?F9
k9:"
d\I.
EE"T
=.5X
KJwU
P&X2
D][>
uP9p
eh3|
PkyAQ
BP7Pd
=Om[
<Dt=e
ls_`
G@2.
n_Eu
gjV@
P,y?K
Q\7F
wf m
-%#:
d\I}
aNZxq
'[,M
E-X`w
ys!B
v;LR
-ljM
J9v@
f| &
m-yB
" R_
d)l
zt`2
/ `PRP
arXW+?
YNO9<
L@7LEt~3
j'=r
"Pr*
GKcsj
d0g6
;k*X
zE(J"
y^zdM)=
9g5 `2
==@V
S)7Z
+zS^#
-uv` J
u/5Qe
:^2:r
'WHe
"el
;R6 4
ywB9
?C6c
CDs<
~"F'
(#0-$
O.&G
0F m|
[ Yp
Xa-f
<UY':
{`::
L7LJ
ORD^
ZYE8T
* zR
grdF
86mu
p^n^
2X~71l
c&Cm
#Idc
CI-;
`vo)1
'?5L]
`\1M
66.61.11.20
L]fC9
(lr
M1.)
{+a%
v?ci
.h n
/VG<C
h '2
%V7$P
) [`
nt#?
ZW0sV
5/7g
%CCM
Pt$c
0 RI`
?4?C
YlX:1
}?9o
~A&u^
ASrM
~%UKBg
X 2
S[U
oIFL$,
;8h}
R-KvL
Aq8/
{pNjD
sq/[
F|#V
N NvN NZN[N N
7G( R
>3G]
YWq>
h1yc j
>[Lh
XO(E
j]1;
`rtmp=3
01/M>
D %2
,a1V
$>3
-@Di
RsT
N} vM
5p)H
0NT
(DF9
7cT%
o-3J
*2:;\
S?pFZ
dVI1
6R]t
JlB:[Q
"\H_(_
;LD'fD
iU/o
naRp\T>$f
-t/#
?qjN
VA#[
String
05_=(
&Jwv
jdi]U.YR_fuR
F=38i0
^T-?;
} LZT
?#+[O
o3t2
XmaI
G$;V
\FSeP{
l8vu
FP0R,
7BJC
(KWU
oYX n?
F_a "
g,R[b
&iB
mT-Vf,H
m@7F
vI7C
dqL2
DsPk
T
j1!P%
P@hd}r
:?hT
MI6 E*
-Ysw
J3 g
7'Tx
cc"dM=
JV w
{'('Z
Yc}D
'4|>25ix
mM>@
+1` W$E
f|!T
qs|c
Z7Yk
#BLc5
}=a=
bPv>gh
np `
<"_2
1 q~V
xJ472
G0_j
w?-,
7u"lF
m' M
wP+W
;-/,
x OZ
v$[<
j>?_
2xtX
"nm q6
[6i>
=u9
](<0
4"FvIyy
(4[_e
)9]_
p-{u
@3(;*
E'fD
>0*+~
[O96
m JTZ
Object
qacv
pp5
Fl o
s1&$
s1&#
L\P/
>S ?L
e;W
C[Al
(- r
L W\
*i+'$
RMDU`
`euk
!$bk
bfi6
[Ckt=0
UK0L
q:ZEN"
p'uf
E@P%
MethodInfo
h(_'b
0Z?|
b)&9
9%YN
Wbbm
gtGHWXeMGA
68G`
}d P
i;tS
}W9Z
}d D
FGSL}q
cfx"
A}};
hE&
<e13"
|HslT
m+2ag2
"9C!
9oNA
akk)t.
,lf=5
P&&f
"V8g
#$PTt
m(E6
>Kp@
7!<g
0T)+
KZT-
!N-2
rx<la
J^IH
7";m
"H`U
%_I
CLa@
XdY
Vl{K
c<!Cxw>g
MDXc
+6`=
e=*_
i2].
o ZT
ppbV
u'P0
0a) fu
9=[,
:ic4
e lcBQ
?b~k{
HU"=o
V1
xzT/
D/AN)
ulf/
N*NwN
.=T~`
Ik6pg
|2}l
'RDfw
cy4:
U.),d4
yRD {
[>_*l*.
xj;L
a|c=
R>AG
-bv(%
AF1Y8
p]x@
W dY
l&eo
l}[M1
|H2r
j' o
zp(hqPa5b9s
m $u
*WOw0
"l>TBf
q|{GT
opPt
ipo&
6+X@Q
?Yd
6Ho%
=u"q
*2#
jM>8R
6>3E
v[lg
/Vd
2m;T
v;0P
_V}6
*V
m7$-&
>L7M
KN`~
DiA0
8-Y>v
X:f\
R@/} o
G&XR
JW3+
Ev~
G~On,
q Iz
`[%Y8<\J1E<q
mm^
?lVz
Vzm(
Pvyg
=@`(
yUd9
YWO{sfp
=%1e'8V~
p qT
*N:x
BdFg
sy,&
s_l9
SP(0
"f/G
#]<+
7:\z*IL
B?~i( M
v& h1
Dv+W
osV&
c/,W
On(;[T
EBwoz6f/B
KV8#
ZSYqe
gfMB+
jOl+x
;4V3?
TV]4C
s.`h
o+kY
vOH3
"hhd?
A^ 1
{d?g
8 *AG
UTDD~+
~Xe>
; %3
Q.ks
tYJC
^=Kw
6?A
U9{88h{
System.Runtime.InteropServices
j xR
mJ94b
$?64
kV|:5*
&2X
;}C2
C2qL
F"5'
r?Q7
a<*n
@ =jo
h;0u
KfQI r
f~{
]q xZ
a6jv+
6'~Fy
5.3b
znR
.<,"
J:?lu
eG6|
&'SwD
~*-&>
Xz?V
Q4d}
\oa3
eKzWf5KuqMwsyF2SPd
H Cc
WA8
~8)E)
RIuQ
vxbG
;k]0
HrFa
Y*|I
f\+<
8L 2
lA 26
6.DX
oh"H
1Bz
Dz(
N? w
K6:{
NI>93
A'f
R=G.
/*C<
s h
\'C;:
;J=H
6_.&
:k$s
uyO
YQn_
!T"
(o$3"l:Z
y<zi
]9+2
i n
Mbf+-
;W
O.W:
1_7d~
7@/9
dj-N
YrmUrAAMyVakVPYX0
C ^z6
(=|
KmD|
zR#p:
v^`Z
8^h
s7DH
m '4s
TA,x
f5Ct
{JCoZ
->EIy
c~{A
bi~}
/ANq
o~:c
t\}Q
C8"'B
856y
,d;{
^G~j
}M_Q
)L:N
-GZBm
gb*F
-3k|
1|QB{h
/Nbg
o1};
$M@1
vS=lD
D,z4
ymUUR_|
EZ"s\yoK+
;( Y
ihFV
c *P|f
C'01}
_Zmx;Z
3,xr
vk1j%K
]bQ)
,ZVo
'X2N
o_e&O
]O}-H-
cP-
.V<-d}&UYH
[FfJo
[ByA
x)UV
;b-|T
Q w|
9> @
s :P
0*n:
_h;9%
8k^.f
$:<Z
aRoD
K|cb
KF(/
"\8N#
BbL/r]
1U tO8x
W}m_`
Ncg^U&
| q% w
g UFL
\+mmL>
iP pP
\v#?%}WoN
; og
}>dC
>b;Aq
C`~
{Ar+
X@yT;
]-Pk
Zb|t
!^.U
mzQR
H#y:
+XzTw
iY?!~.
4Hy'
^fz@
xNd{
@A-X,*[
O3dqP
XyI_Q(
lI_
`YT$PX
M&*f
^/PI
jS.v
~xNl
~h[7
V+0P
k`(<$
-<4:"
{:;"yv>
`2*bgH
oh][
k/-z
hZzN
ENf-!
dAD0]
8']d
VSH-?z
~0R_
^FzN
= L
!c HD
Ag^C{
V1Z>*
"Ja`
tU
BU6&
LN/'
Jm)QU
z69O
NRNGNPN<N
PNG
KN:K
-1z4X
=K2!
jPU!
4EVkK
-+(}
[y'{H
IFsTo
roK,
QaP{
Qa$Ih
UnverifiableCodeAttribute
CB:3<
NtN&N%N*N,NSN
r%{L
U2 q
{#cQ
m P'
,T+_
i}[7
F9_cVIe
+=uU
:w)6
"I4I6
m/>FCO}k
>,Pa*
`0.s
4^WX
7}0V
Em)W
V"Z:8K
a.Oz
sPG8P=
OMK?H
{@1^ h
2ueR)t
9M}
0ve.
>L}j
Xf,Lqf
Wuz<
P1??
j:|l%
}DL&
R ^
:h-&
N*'U
{[=
A<Q&
|45x6!
fyzqm$<
B'` q
';[mA
I<VR
gx D
s.HPE
U$RK
Vp4
T9(:
:/_J=
M}eK
p.{oU
Y\tM
{!e,
&H|-5
| 9m
5*= iRn
s\L`
HM;>
x48fY
FEm mhviJ"
lHMFz
WAz<pT
-X8tdW
W k&h
U#\
Tv f
.'Z/0
s"&Fh
J!}l
)[{I
$C#d
dto_
V[)8k
DfTA
($nV
o@e}
d+@;
It\|
w#Ec
3D.;
W{,.
yk R
HJ0j
/ |D
N8~,f
ATnG
<5YN
! %d
k't
"Y~Z
BSd9f
=fz}
N^N NgNeN)N\N
A &@
GhE.G
QMHJQ
jh-
1'+f
_ ?A
\ N:O
1Ke^=E
(>}+
#?L=
F"O3j
Z=;[9K
&3T-
Ag>F
d;a_
qPj,r
u;9A
3mn
(w8>
Ti~@
T%'J
6A|w
$uF0
x;--
"vFs< }
^sk+
FBt,!&E$N
=zt
0r)T
T3
;\-u
Mt:"R
Q8SF/
dmOX
m y}&
4r(}
S {`
7ToT
MAz)
0o&c
ukbiE
,"KBA
ChK6O/Ln
YX m(jI
R#f@
&Ig[)q
V8NGd
c(8i
| U<
ozq
#|p
Jyf
=y_.
:] C
w[K6ao<l
8Yhw
@bb@
AB C
j2V
K Gb{i
C|R,
e1|
kX%!
,tZi
vUra21uyGcbzjiqUVST
wbG
Jgmj
G@u9,R)j
BK_%
q03@
TtT3L
SmkMJ.
LFAu
f#zE
)O i
e2t
$x*d
SO}x&9
Uw`R^&
dW[-4
jLgd
~^Gq
'*[ v
NS [
;4f?
TUFr
G) h
b{ST\
s?1f_
8Tj[NNd
,BEZ
>LfV
bi0r
<~}hv
r^IF
RNeT
s v
kfo1
;_S1
zuQE
tNyck
-rXm=U
mU\
ujc"7
ng#-~
zZQL~(~VJ
wvQ
(I.~
%j/=
BAin
K8K0=
WoWV
[]-5
yIu]B
~k;2
KQk ^{
3F RK
pULM
|((q
>sf9
8U#V
ep"$i
;G+k
2IAf
"ATYb
i(Q
^ [O
NqN+N N
O,Z\
.(e3=
vEz4T
1k;h|7
h|g'
N4S{0[
<4:X
9kSK
A&Bt
ED4-)l
TWpW
Il=:T
\G_2
qOFx
Nzm\
k?,Q
K@H]
uWiH
li1D
8X!3
aR3bk
\'(ay
$n5Z
22{*f
)` +
o.Dkwa
zH\K
|?kGE
B1k#
pNnUqDMVegJDwe3b1
`2MV
9 1 _
l*3y
K*%q
+(,Y
_ |D
p_Ag
uJ'"
EL#n
/+#6w
=50l
>Gm"
70'\
\oR$
3[8z
.'<\>r
^E+G
0 yj
nd@yv
~c)X
oL,w
tNsH
x'Bx ;
:3wa
rn l
[$ \}
-XHN~
XFKJ
5iP'
A.upL
(,"]+n
I`"r
zI(
PCi;
lU m
>Epc
}R&^
o8R&
> t1
@e~g
kq3;
(>i
x[v*
E}N^
LN0m8n
~Ut3
X,][E
9[7;
System
jL@V
8%LT
uheP
11N
ic{B
X e\
OI&e
yx h\
esQz
5F0#@
]TSq
X0(8
T CJ
_ x`k
:M<r
g2bq
2YP$+
]r>-yYN
%3%t
DLPU6O
jput
?gS|
U&4o@
{k{m
NxNON
T2tX
C#Tu
PNrJ
?zo=
>! 5{
~dN!
{.[hB>Y
N6NmN
Vip4
{!>
"VLX
wZ;_k
UO2i
W.:8
\(XBK
X;og4(
unW.
oIN}])l
S/Hq{
;Sz-
O ,(U
ig40
<&+JH
O?ZP"
y:02j
{/]>Df]
u(g
*$Ur
p v[^
p7Q\
0O$/6
n| oD
8q%S5p
m,/:~B
^kj`
I0D
|qs _
Lmv
ig4N
K +:
J51=
8*95]+S
+,8y
xz$;c
HxF~
x*2R
]gk#,Y
L] 6
NuNrNoNcN
{/>?
_"MP
6w @
nbr>
%,oQ
U1# ^
uMIW
9-p"~
aVGt
f:`~2l
i?&8 '
UkgV
im&d
~X'S
AIPx
gJFO[
<xtj
n^5ku
.F b
0WS3
+L hg
iAu?
vfw_
i5ud^
5jFR9
n3wo
q >a
> E
$OiJ
\u'Z
V~RyF
84$B
9]b`t!
kfN[Y
V|uL
wdZ{
v 2A
zmBY
fc"<
I{E'
~G:
`vt
NJN<N:N;N!NXN
1@ >
k56,zO
;+'Hl
(8>W
k &L
al?q
VsA}
$o?C
Vx)9,
mgA&8
-.&e
Npz>%3
5,=",
N~SL
d&@eaU
G4hj
4 -C
&=Z{
RR)T
VB4>
NUZX
u:!@
}:|z
dqt_
7}o5
U72
|h V
*V
DnO)
<-:#M
tcjt2
6_6V~n
O f
xn"8fn
/6U6wX
jU;o
R\$"
4g7gW
4e2E=
Ks,]
*V |
IjjF
$rS4
wEmnd
UD_p*
i 3A
/"l^y
X-0!=
X~E}G
b P7
5d83
1WX/mH
p-cI
1`eWT
NjNqN N
8wz
7` u
mnSC
Zhvx[
cn8@
@Uc37
X6m/p
ElC
%Jf
rf/
>I#p
bfGD3$
$)Gg
sj Z
De/Q
. NzNxN+N
;< Pr
woAxWR
6% p
9UX-
uNlL
b!#7#
/Z>E
*>2f
LX7{
m1Wgix
[e){
ZZ6W-,
,l1
peOrf<
d! [
D[*^cH]F
eE>
2"2h
1[yR?
X]f@s=
;t4GO
Tqg}
ctF1ATx
;+zZ
>pR&
=6x2
@{M9
b%1x>
!G{W&;
d Rg
tJ4$N
"rkZq^
wscC
^>U^
<iqb
`Ck.#Ln|
Wm\T
\sPm
tYg3
VF`c
pz1OLl
Cx/i6
e2)]^
/8N(e
C1/gAlJ
[\%?
!S *
clQcA5S6g3mpXS
h\Z$mu
+"?2 LPK
Yr7Wr*
bg#z
&v%x*
hpT5d$
q+4tL
&JdL
tP7L
4,fR
#9H[
F`U5
5GT}J
}`4>~
&Y$U
Vx 1R
8Y9;
8b-G =
HHc]V+
]3x?J
@6!G
shP@
JZ+@^W
4mjx
NLN N
A4B!]
*KUSG
C'lP
|3jViY
ik}J
{w~)rTifR hq
`9'
2b{4
A2G?
oE<1
O -8
x+Ax
kb/q
Thg=j
(d?
-!&A
UUoNWMb[
_JCh
2+HL
{4%|
%9-|Q
9Sbc&
#hJ\E
5;pI
L9zc2
X?FC<mD\#HEA2i
B(?!_
!#h,
VV}!
DX^J
rs#J
L !Z]
fiNu
_4H/
DzjHN
iY@r
1)<r
3'z
i`tK
<&,As
RJ
,8s8
bi[L
0?\Y
dWcqh
J"#
ej&8
/A,W
IjMS
ORTRl
xNil
#3 J;
tA0j
Zu *
/n1-
K+eV
2*l7%}
h8f@tXG>
}aRXt
^C#%.df
g, >]
C`Q
X[>H
iXD8g
P@&K^
jkA_
:2tC
y\@[
3=Z_
~kPy*/=
>61Emg&r
u=3?^^
&T\K
xc l9
-Bx0
I?U8
d/o*
&&20
n~Zm
U\,m
D8yL
NaN/N
;\=r`u
^@6A0V
3 \rU
N5Rqnw9
]P[n6
B< Ow
M7rE
Tn8B
ey?8
qLbn
NcNdNAN
]1=Y
E<#?gF
j]CG
<EVK
a4l"[
" 7s^O5i
xS"j
d, +}
!54
U 6Z
T=(-
>Dw
r#20U
(pYWd1
t<$D
M^B|
vH'I
,p j@
+J,/
n< 1
[md>y
D23F
r,\8?
PW\}!
|6F \dh
_lS4"
0;?!%\,E
9l8I
L2bv
oY=d
ResourceManager
Wd)
J7H-
<{o4
"qBm
QXo1
T=#
yW#Q
"}eK
W E
QQ,:
U'.x|T0
e7g/
K1t
| X]
/>yn
(zuBew`
*6_)
lp M
x>[9+J
c^C
<~Qn2
BS l
+SaSD
9!zl
{$%F}:
LN E
ZnCM
}q Ml
!zRa
r``skjP
LIu$
^U-=
O4z*
n*R
C+Ov
3FNe]Q
IX*`
`t4O]^
=b
KjB8
Zu]Jx
7Z[/
M=(&
T@E\L
8lC
c.`w
S~`~
eJ74
ot L
='K7h,
/`a~
rXq->4qHbd
L0jT~!
1r7,
_d\]i
B4&I
[N7_
?g8N
)CcO?
@&_k
'wg1e
#h>}A
\m&
CY9r
}bBA
d.@%
,~6)X
#^.m
P%8L
.hAR
'.3|S"
Tjl:
+ Qh
6_Y*a
w1tvqp
RJ:g
m{ r
u~-"
Hg'G
{ tD
s Rq0>!^
|BL7j
NbYl
zeN'
`J4A;F
P A?nY
"h
i+[9
GA[9
lFTb
!J48
GOC6
gTC<
yZ]N
W_ a
@Fc|,
'yEW7w<7
d`6+}
qKkZ
z=$+
5wH+
L+wH
5~LJ
wAIcD`
OPV)
F u|
ySg=
bB=go
b QG,
vk^,
:3;C}
<uxM
\XrX5
]Sn
'z=\N
@\ !7K
^7s:8|
r90V
*jQl,
cNyDOy1
`snfw&>I
:V-K
;k=a,
eVs0?
D);
yi 'A
yev
x*eO
kl ?a(U|
L9Qy
;<p:
#*G)0
JH!
Q1v*j
5/]B#
-m-Gt
.Jde
b+)w
g66\QK
G]w|
kH&X3
QZ:JV
,w -*
{:QJ
, &`t'%#O
,hDi
|`bh
_NWc2c
]RhN
KL5
G f"
*_Bp
m'Du
+{sVrt
#bh4
Q$h7
j,d/y
Uj\Q
]6a{p5%
(n!+
N{i
Z2eb
Y{HV
jDo+b
\q_
nin -
@`/o=
qq8kp/
o}GyPo
4KW
h%kS?
16pgz
;3b@
]0Qt
%T2}
-l0$
"^f9
J9<'
~l.5
N*NBNLN
FFM$$
",`u
6r%l
N NmN*N
>lF
Cp5D7
j (J
#ejC
S -H
3\ 0
\ Km
{L6};
aT@"
#Df7Y:
e56xc
]M&"
_Hh"
I,Cdn$
pk$GE
4lGf@
@Q L
SE|2
-C ~3b
u#^^\5:
r9-
9gm`~
?82<
f~L1E
;z+:
uE|5
fT3-
9hCv
HwsksFl
g,cZ`
o 5p
HRbKEdckafmbu
!ca9Q
~O=?
c| L
'2g`B
16lzt
@ 1\r
|wfx
kG>+Z
oP8R
2Ux@c
<3K5
<[CTQ
6$ <
(+vz
-aH\
J.p'_#
q7n}
1'#9
"ro5
>P e^/9
R9A
ChV%u
".)DF
sml<
U` 5
e.*{
?BlNf=
D }u
jg>T
ibkt
? ~3
UT)gGZ
$lVRN_
U)Vm
d@S^
@29h
?a[
)N}Z
`@NG
[3&M.
B;O`'u
p7@C
{$A&
`/qe
4I$\
|W\t<
#Ob?
L'NV
h2(n
aV J
I9RW
Vb\!
?[Jy
q@(
J,e2]
q<W)
c$'17}F
,: >Y
q(QWp
)e`D
.q!(
3#K W
+M"4
|Bs
a=7z\
z_:J
*HLW3a
8IWK
Gz~A
JgeN
yI[A
Yf8B
|'N)
b'x|
Jqz)m
='5)
F 5P*Y
vMrS
oSu_5>
Q7c2
?J*0-
6 >
m4<
mex|w_
jKO4
,Rl"
HypF
M <P
Ui5x
AyNG
aT2P65
WVX
@Bju
!G/y
kLY:
8#6|&
"[5P$}
P6YBC
~dm/
'Z*Pe
VL4F
9%qL
K:2"
gmNcJ
N77{
~(%_
CgDF
U v]Y
Lu,5
rGL2G
JQVt
Hq8B
P/B;Es
nm])
RPEv
xbPO
Cb{I
(K/?|
2oF31jp
N-*K
A^Uq
#{;[E
=6 ,
Tfkb
_gt]
n 5s
0JB6
M!`:
M*T7
."=WO~
,9Mucc
XGr)B%
&B i
jCf3
3%\+;
< 1h
jZ0H_i
M3"F
u$#i
(vW-
dea)tz
|O,s
@vO2
+2G2
+;q(
8d*};
}5V2
H~7F
LtEMhdcC4A
!{;ot
F1\
FmCf
:QJ
ek#/
#Q,!
*4]
sgDQ
m t>C7
!lXi
qj/-^
R3IDYQAHM7b4CgAQPnG
He"G
\ GX=!
0.?K
a'4=%g/
6 "g
CK p
:o"aR
D R/~
rp8! %
Hv\ Y
n{.
`<v.W3
U[4ve
eNg)
?KN#
.}W?
8bW(
R4v
g [Z
r&&j
!)r_)!
] ~F
&DTSY
XPtd
0(ocp
KW%NS)
OC?*
!BJF72
3uN a$
N2N;NuN
GzU4
?2J@d
| xl
BvG
3kq8
{%~P
<8Z$\]`;
ju"~5,
_? I
C;1P
$@Q
<!U2#y
=~p"
QM.;~
DgGb
8*C~
S[TJ)
#i15
)V{q
-?Vv_p
n[/
Oe][
<" F
_ A
JcWz
mYGr
~N{R
JZ&";
" l20
B9;&
$l[f
uJn=
L@Ky
Lyq}
Hy k
Jr2v
QMVf8
@7U
VZO9[
R4%3
TZp`
[bOpJy
mlE0
:>,Xq
3^GB
Z9XDT
)&$ 5
J4)#y
y}h5
FpAao
pC Y+
_ME:
_-
9F62
8-S
<\gv
i= d
x4Gb
{u~-
\1:o 4
vAy 7
P+ W
]uE!T
&2zf
1 Gs
g>#W
n"h.
g5$
OO[W
hbm
lus'}
} q9
.s
h;\{
ZO4h
rUN[
#CC=
:7TRy
)( F
>\Lqr
"'{K
)^Ishk
zE62-
r>9h
'1c:
U%j
'B0B
.^<V5<
"X*
!IGu^
C%`E7
*=Zs
I?8/l
e;6=1
!yo&n
KZ]|H
Ypp8^
uQpm
x=`4
asT_
JXb/
bv P
0W}4
p'^=
<x|F
j54,
j7n8]:^qz
8 ?NH]
%F"m
Tm#W
eg</6S#
xM7
b8}UA$\%
'O}>B
pV[mU;
rj0p-
4hl~
set_IV
HZ[
$Jv%J
@O1
.tI
G $0/I
P&M?
Ru]%
gvTmI
*Z"J
K2W)
J_zC
N$H
0{D=
)U N
MA(r
9[N I7x
5 R>
JI`E;
s)s(
k:C% 2
NnNoNNN,N
&e3|
Px}7
|^ ?j
+*4
bxU@
f;p)
kIto
GM%>
-Yci
*tkz9ozkfUny8jRFmw9fRbio7CWDIHLq5YElSdGCKSo
HL $@b
$K$=~
DdUZ
ji5I
A+,6
-F No
'Isx
!%3.L
$!C4}
\9w'
c-uPA
yIa(
f8&VE
su[C^
H=1]
b1U3
,]=-
U?g?
#.b;
ua f`
kI]
|7USL.
`seS`
:)W|
ZYxr
H"3
a)?o
Q&\'
"|Wb
Z eUm}e
EgT\
;Y}V
z+ U
8MDZ
{3O
V"h+
N;NbNjN NRN2N9N+N
Q(X_
A,v 9
c! %
L@`k
kHF eD
Xg|{
dH:(
9Y&i$
S_e"
]ft<
gK:
5g;n
KQ N
C@.h%@%
kZ=,f
+z.w
l8K8<
.v=(
,"m%
:aja sD
tgj_
o4Li
EPUA
gue4
1GWe
J%E:
F ?
}6h4
'1?v&;j0
N(NsNuN.N5NrN-N\NmN N
n22q
wj.[M
S\>H
O;3"U
p7dq
bW!6>H{
mh[
~|iO0J4
|f:?5
\V74
4B=FkR-
Clqj
TTs{
k gp
]Nu6mUCK
/ 5a
7/"9
f)?\
@ jF?a
?$;n&3
YPDS
v^U9b
q@G)S
L~i`Na
kyhq
u5vj
$OhPF
6Cb'?\*
W<Uy
f&v)"
y Z>
CQiA
wv8m
hprJ
Mf@1
)8c
P2$c
aK81Q
0{+0
l/ :
w G@
V >\
\`HO
s1mmKz'
^[t)
9gq8Y
b8dxeDkYwFR7yTb
&$uj8
> `E
2$qe
0$Lc
W}S,
7A`;
B;jBd
D%nW
p1s3zJ1CrsQIX3begk
,$LrR
#GUID
0+`+
s}HA
Dy8` 4
/-258
s kE
%*|i
=[=o
qtg;
c'3@
pXQ=28='
EQ2e
X6Bv
]2/u x:1
Z7L-
$j3
_zF3
Sy:\
p5A>37S
<P{
(Z<<Y
v !N
vj$01 :
`>5pd
qyD4
2M,"
mfq<h
5;H\
O524q
{.]?
$>d1
/8{>
ph9p
x2[
|lK`dh
f j %k
D _U
sFpz
N?NnN/N5NmN1N
{kI*
CKu
R7^0 7
k#-b
X@Z5SW
H`:e
gLKF
z(\$
` S"W v
#>nu
207z
Sqry
QXKct
6 /5
xrli
LnS5
6Ze}
NHNFN NFN
PN i
qT9A$
b`H
??U6
Aa8<
kgSX;
p- z9
`=\y
{zPYoR)^%qL'_
t{mv
hvac
YH1Tv
D"{F
Q @}
r DF
nJC8C
r!r
Cuga
cgo+
j)D-
xd ^Z
~ |X
3[OR
2izQ
8@,S28
Hcno
u[),
NW2C
>N; q
Q5y17
80].
xh~"
[)ML
]x>:
BnTo
r=2,
+J.=GW
]. e
Q59DIk
H cg
/YV>
)-g}
wuXt
NZ%M`$
NMo:
8#O*
-,)Q
k&RA
/eV!"v)
pnVU(
p'`7
0z.%9
|*[!$
7Z'*
@}=yj
caQD
Z W
~3Q4Z
n5`d8^
Zwa6
[#Q9$V
/4OY
aM#J
H K6c
=ot3-
EIuX}
oh2W
NENLNhN
ZhUa
NAN+N
//v:%1'
h&Ft
};S ^_
B^|>-
;>5R
7Bly
V{-fb
{}2:
\evV
W6~N
9 A\
JYskE
R0<Fm
/pzHq|
%\fO
,Bax
vy}XQ/
tZ`T_%
&cG%r:=
ToQ<%
w[2.
|UKI
Oi}W
;: E
M]X+
7qJ{
@Ja H
hHcp
&@+G
ZSTx
E}cPr&
_.+\UQ*o
c'Tt
3e '
\OK$
N6;&
(89U
VA t
aQ!
F,[X
AssemblyCompanyAttribute
i'A3
3Q;$
T`vul
fg//
7JD{
I+Xw
q:g>
9x+B
-aScq
s"j#
_IR-fE
>+#I
5{g[
k8+{
&mgBE
6%z-c
y|U^Xz
AppDomain
=+^9(
b2`v
6(VMZwb
I`E
`,Y4v}
-Bkc
&{Tg
z7j6
V%Rg
[ pTu
Z9Xj
?w&{'
3UtT
F.&S
(IJ-
%y
A6q*
mRmZ
o"?x
}{E
gu/g
8DDVF
e!\E5
3=O'
dp{O
1!\>7
n`D|
qaY
$k o
4rzK#
zPgR*aV
6sTu
[?`
.;k=/x
!vuL"
Itqc
6L9
&B~S
R; Z
Xi^5
=W<y.
OVD;D
32O[
+i>h
Eua+
IQ5
nGIK
bnfQ9i
yfx
+i>4
l Wp9
zW<,
%?uJ?j
$JGP
8dN]N{N NtN|N<NBN
[ALg
\"kG
'KX)7
%j4R
a<1n
8RX
/zHG T
+<,,
6^k#
;Gma
83sk
/Is64
NCWxhg
8te@q<
iPLV2
LIrf#8
oP+b
a2rm!
B["Hl
(~pwC
h]or
XOA5d
cdRB 1QM
t#,^i
9;}g
YGMy
rBHT
s>a
WrapNonExceptionThrows
`]L
N[a7
F&a9
_5x}
`J.
k8o
5M!G
\@ht
]sg4\;
l !|
tCo3
W }g"
R($X
X$Mw/
1UF
Sc#5$;r
l,!|
CW&y#
NAw"
(tfQ
'btq?TO4n
ta41
o.H4}
BU&f
*Tun-
RM}j
l6jPx
r,]
8bi
raH5bh>
'O|-(
`.rsrc
VBk+
7 !q
qc;C>
xA5ot
C+zPVw
:]YA
Z+xs!
D&R\/t
%T:m
2rRp
wWcI
P5 3N
\ah
$z4X:lY
qasCnY5vkjb
MJY#
TJ$Q2
f2Je
Oz%K*~?
Q[?``4
Fx^7
0(oD
H WBe1
z6Ig
o?yY
o{4d
R3P+
Sg%
[.z@/J
7jIn
Vjw"
JS dh
xE>
C.r8l
7U`(u
8Z=%
C3;_
{`dj
)6 7
lBgsn
Oh }
r ho3
H\fm
9,hh
UcB[
i5Bbv3+x`
hrUT4
;2'a|
X0%D0w
1f F
#&-D
3P,%
$1=RM
%d=C
4O A
e%Ee
. 6`
oW7I
2s,!
Ci=}(p
#y3I
7sM
.$2g
}M 2@
gCEO{~8
72Wh

bRXh
"MR ~
Kr9m
A5H!BU|I
o46
iMV#
";*b5
0'XS
1D*x@r"5(i
0A8@
} 'R
,0RI
Hg!a0
~/
`$:f
o}AOt
NSNDN
&'0'
N@RT
"<mb
stpA
r$>X
X0U5 @!
<{9H
O|t9p
j+mD
lbrfL
ldpJ
`^O) 3
P6l;
P)FKgi
tNFD
Rw`
JRz2h
p'L^=
5;?e
SS"N
YGjJ
G]D~
9 nz#
X iV
s "`{kl
"XiCW
i5#^
F}qw
7A 9
Zx4R
.m3
Q[wv
#Strings
)MM+
XJ>;U
t<z`
} <_
D w(
i@y;X
@JSyh
o&Nh
lm :
0B c
F{{I
1bXt
P:f-Y
>Fd
xu*~K
P.h1g
8P${
Z2xe
~Y_F
C}wG*
tJ`q'
v~/'n
]j*|
6ETw
*5`B
:v0x?
VAq#
8I_c
G>Qc
C[h~fhH-
QU;=
Nc.r31+
@$>y%*Ls
<5p~1
%LN"&I"
\F\|
u/s%f
::BAy
7<;E
=x'G
HLHx
y J8t
B ,G
6r2r
"zW.D
`dc~
]&ZaQ
STJFDt
;:TQ
VFq?
Z:"s
@lc$
t42M
NO0B
CEpa0
i+V! fQ
>hk{
OQy1r;
=rnT
RNu&
w NYC
Y9'
@BrT
]G//{
/mv:|
!qgm
oq1$
M}n8
j\:s
uK,s
nuvyy
wh pa
"=nG
w=K-
&yL:3I
4J^]+
0 JNh
3V5R
9{= f
DI,
U}+e
i)LeH
qLJacZ
z`C
%Gv
?2~>
7/N1
A!GG
_*O
h^EM1|
(7kfro
$ff44
X=Nro
QHG5k
tCG S
qf^G
2[9lf
!JZa
eyvQ
b7ooI_u2
7-4ca(
+j90
<fA>
r.!x
f'98
U7MN
@?h6'
*.)z,
'y]=HX
}6gW|
\D+A
#,vd%~
>&f1
z9Yv
V5Im_B
X(q7
/hyf
1/nE&
&W<IE
\46a8
DfaC
}IBK
VG#n
>&fc
\R`a
qFHU
. v2<
`TXl
!']K
H-9v
4B9
:fpx
Puol
@,$(
Lx+(
A9:#
22?*M8
\Rj9X
cypO.8
xpJ<
eh+A
MA54 <
zT>p
LM]z
B6Ml{
^+5d
VvM#
]/B2^r
G1fF
z{_"&
0Wdy
V;ak
=Ut3
`@t(t
Ssin
/'cM
8*Z ;
>O+<
qt%R
H,Z%O
lDU
KG[Mdocve
U$)C2
y:kq
"@GY(
S\>W
.]j A
J%.x
P'r7
bs1y
y^ =
G=O:
Y 0
b2C$o
Aq 7
{EuP
3"&(d<
w6x5
kgx#
l?yHtDa
kfzc
Qx=
h` ##
cs5
&EVTY+
kJe3
]duHG
J: eR
| =/+
t.Na
$fO=ky,t
2ixKw
tfWf
[ q<
N+A%|2
lUp_t,Ub
-Pnm4v)
{:a%jkep
V`"u[
hn<@
Lu?b
cVJl
6h{ 9c*
8Q C
,9%_
9:C{
7Y}-
1rV!
N=P8,
CDK}
YAzh
^)C
:& ~
KAvIp
T'D$
Hgj
c4*"VZ
CJJf
-*2+
.ctor
,ilv
S)/m
EhQBQ;A
Or@j
p*y
8..zd
ZJX*W
H5\~
Y6=6
*E acJ
Iu$\D ;)
5T mL%
h<\TKZ6
j:d [a
CMDY
{nC?#
+fV!
\HvA
>gM
*pKPpNgec225xU6oofJEXIBnnhBsefvgZ2h7QbDFbZx
&85v
C#D_
W JR
%qig
a=L{
2:t~2*
,O z
!mr V
^=$ *
+<CO
] }UM&%
2O^f
&#e%
]'.V
\D0h
Qh4Y
`fd9'
h]6{
!E@n
(Jw'
/ !%
uzDgpQr;\
}V+
b0+,
TWg#
NcNaNMN
Nw.4
(c@k
6 ;)
T_8jo
>p%v
S6F
System.Diagnostics
7FCK
[zcJ{A
:
oquD
"O;h
7Xo.8
!,I~
`@`_
PuJW
}v7@dt
l!e=
XF|k
qpa)
&ck{
HXw^
+5L
ds,cu
V`id
6qVDN
5PeF
XOKQy
5b_"
OnSBlw
Izh
KQbEW
<a7E<
XdP3E`;b
Ee}w
yIi-
1g!t
M8^
gyA}
wK+p
;9\`^
P(IyH
Zy*G
YcqV
I# `d
NKNvNRNNNjN=N'NUNXN
y$'\]
KJr|
=boP
6,n:
j >O
sq2`
Xn3]b*z
A"9@
"[y9
E55HJ]
6kP:
j(<D B
:R}F0
T~$G
JhnQ
ZC;b
-Fvn
{;9
]YJBe
#Z=/
:b^`
-G9\/
<Lts n
g U
'Z_/
RC6!
sd9
:kvZ
Aa;e
Rb m
=>aff
Ejc\
}n S
AG@TS
O Dy
X @:Q,K
[^L*
CI*)
6o_y
4^<|
m^b $
Lmvlx
GCdw
)qi"
[`[B
R? 3
]Z_k
"ECr
Lc]U
\P rd
7zObWJYYOXq61g
`E]H
|6 v&
mrEj
Q k^L`
|4&S
&^{P
^wFi
?moBk
r'A
l8tn
@N&
&g6s(
B$kcT*:
2]oq
X?D2+/
/ =
#c5/<
EH7TB
6.QH
!Ia R
[&_ ~cR
}b'D/eb
59[~=
m(Uf
c)Ke
V8:7j
dva{s
;L9y
kf_u}
s(}f\
K4cT5
p_k5
O6z#
-^??
F7,Yn\6M
rb`<
o(c)@
;]`}
A GZc
jc!'S
|&I#
&fC:2
Dl Y
G]<cA
!P'S
u!@0Xgc%L-2C
6Irj
{|Nk
b6bp
ff8N
KZL:
>);N
q&(1
H01A
|;,e
yy2{H
fqS0
*`r+}
"gdv
97yK
xFH7\
4}Yq
p`y"
t1
w -(
y&8)
\#V
j"dKJb
czUGq
s,
lu.1
Gbu 0x
| ]
bFAd<b
-FJ {F
V!iiAK
d<9>L
x"}%
&.@TV
u(5mk\
fZPBU
ANlN[
M%2aQh_
tbB
5DMt
WM3wh6
YF2B@
y?v/
IvFp
&7Lt
"Op-
o#-t
T0=1M
<`#q
fW7#
?( [g
4W8:
.3~w+
-_bB
yMS]
,i2g
:au@,| u
{kAh
DYH"
l@@*
e9#h
qYP~
sM$<]P
0(%aA
QLkx3
NMN!N&N
V2T-
OX-{
7b+R1I
RX/zK
beE p
zix=
oP\g
'd>^`
H+
Q;K,
iB-E
F m+
9`*,C
S~x!
8wA{
SG @
afM@n
hHSq3U
bm^Zz;
N0N NqNxN~NlNFNYNjN
6k\^
Q19 bI
R m
]*/?P
9(@+[;+
' c=
X436
|G=A
~Q)3'>
K+.n
o[H5
qTB@;
XToA
ow\ P)
+1Pd:<
jTm8D
-t>t
T HG
.hVF
+jf!
,P'M@
b;&N
wyFk
G]w
*3i_
2Y9+
eEKb
u O<
)CTs
9 h(
/2Uu
~f9rQ
Oa`P
QdG^
?e`#
>J!u
:ngY
*a3d
c02D
|;APA
>wa O
@@T|
K Y
e S<
uv j3
V[f]
,x$S
6?yg
N N%N=NSNkN
Z ,F
3%y\WG
}7U~2
qgk [63
!S5,
%wIO
5< p
6tyLe
kdeA
8#Wz
6/xy
sc$
5*mJ!
ZF,-
*( K
90A&<
Q'ussY
'u$
A2//U
3rr^
[`}
dJS`
\NS[
:4/n
UT.C
>j_
4c39p
i-a6 qN]y
&'r1
%sz[
{Eg}:
{ H
#xC{
bTZ!zj
`@*#
UV/z,
r DD
ZK9i
pI5e
< l5
nDj!
Eq%3
rQSy
=}Xz
c+SS
S%jPUr
cp(y
D|B]G
Sms`
px$8"x
x;[1
K`IA
iT%&B
,bY)B
lN3e
CaZoCR
#G S(
9=T+
D09~
U"RI
1M?0U]
8b4w
Dsr'
RijndaelManaged
:Gkc
6A
IljJ
q@n,
(QJg
:Wt"
&LU|Q>
p Wi
2%@
n B!
FAJO
iP>.
cB%uTK#
,=2z}%
.qg-
uYs
NPN N*NkNvN:N
Ab4fHmgubCsEPE1
`8'| xHJ
YL2%
#4K
Y9d@O
9!jQ
`&:3
T`nt
QG`&A
Xga3ZwKYaKaoGWQ1Q
?{&g
}' }WW
~LMl`D
n}L3
XGT>
\S`; 1
_qC8
PAsx
T; M
SEGC
^'NI
!}k#
n3),G
\/)3
9:,Z
:+J
hL4o
rJ,tw 5
+2%Ol
x~z
p~u^
inKr
. 0B
oNvKIdLP
,E('p0
oSn`T"
IDAT}
[%cO
~Q>)VD
'4+>
uD +{
$*UZ
3"J:
}2eh
LjMf
v}, A
r 4
MOry
$IW@
!2?Z
ojl4
sUXOr
B t~
cUf<
>1=_
P%(R
dTmv:
;7.&
O9]
o;G7
|%w)
o`VQJ
hV&1
#Ij^
{QU?d
Q0HL
iy}!
u3x}Wav
U32b
j <m)i
NJLi#{%
74 G
IW6[
ST`j6
qz&i
|dq;
}/hGt
C!laK?)6
Ge~#NI
]h2q
jMw)
3:24VMLR"
V|ih^7
BiIv
&9(
~IM9
.k~3d
:` AH
^=N#
>|xc
,V4^
0$>B
\"i
b%|h
kb-
Hbsk
H+n>
E{GP
&Y~3
/tx,
(~K;c
wHL|
V# r
L'{0
/6+P2
a}+g
f!"*N
NQN\NfN]NON+N
Llc ~
N=BzE
z A)%
!F<D)
+q8a
EMaF
zsUf
Ly7Lk0kZDr
R%|qL
^s89
QIn.6
Q9qV
Et7V
ccn7X6bgZbdTKrlaDp
P?I\
[s;X
# Ig_5
1i3cAPRciny
08x#
>rO.
|]>}
D`M^uU
o{<!
pWP
sv:XOLi
o{<]
HvTK|}
KjyV
/39P
,g?X
FCs'?(z
6TetF
}L 0(
CfJ3^d
*'[\
Yo*8
ETmI
KCNC
X 7X
9{1D
Cgsa
K/cLiNMe
0 R/
^,4c
Y=?t
B$=!8
[$27{
CIq?0b
:A TT+
*+IPT
$xu@
nz]B
TBz-]c
LN`L*
[n|J|@
!KGL
I|XAo
-=^h
[X%{
.+zH
x L!
}]7E
G<_5
I R
>UB2
f3T2
'Su'
P5x'J
]iU3
SfQc
s}*[
~sQ TX&
]5@k
]~GCM"h
p*;J
lh>P
xFzW
Vr>`[$
aMn2mm
C'M]DF
-Ne'
eft^f
N.Y
U5k(
*6
;,&
71 *
Hz<(K
xkBq4CTEldwKnF
dU%o
`eNE
!"Oh
tG#X
6f!S
64^l|
S|gi
*d#d0
GW7,
<4mf
^ mk
NG9o
el=4
f\Wc
r<c
Xv9~
[:;P
,dGno
'Ry]
;Uf,,
G!`r
,kPZ
4)v6i
wc):
tW{R
6 ^d
|P=8F
tzRQ
k J;
0pc
<I
NwN$N
4H~K
!en{
%Pc '
)sOW
J1i
@9Ag
y;F8
bz+a3
zjx\f
q'_*
jcV<K
_x\Ap
>U]53-r
|<7v
N{&9
NVNjNEN@NANkN5NbN]N(N
3 Sm
Vot
NtN{NBN#N
YqXp
SG G
.JY&
6#a.r
z5=q
/Bhr
xR%-
*>Zt
/k>
D_vce
Q8(c
\91(
J{Y
K e|x
gMYN+
9Kkd
WWZB
wpo&
9HY
f&T=]
Q%KTs
Yb?WJ
> 8]7
ny)s
OcF)
DsV@i
:y}e
D~ l
LC%p
1ggp
"iAF
h=@
) !?ERL!_
HRMs
9Kk0
DM}f
?j!-~L=zq
lJ27
(TQ?q
KmXbq
hKt{
)O48
BhXq
SE cE
esl6
p3Ca
NCoe
a'Me
g2=v
82 #
d?s6
7j|Z
4|YD)D
AKJ}y
|R8Q\
MhXO@
qA'3>
7_`S,
@!33
kfGG
! #b
J:,_
:}Z
5oR &=Q
>v)n
<zxF
rLS;w
_;lc
Hq(v
RsA#
H5yn
eB x
$Pfn
+bzFx.:
G66or
rXr
)|"E
28#$^
^6hI~
^Mq3
Xomb
5?'Q&
.!&A
uPS/N$
pb`T
&@ A
=gU
/Z4
/)H?_
_r]
H%N(N2
7&^)
,Q.D-A88
Khu%
dINU
ZUWo
OYyS
/|~=
vsV
./ Ok{r
gLdj
P<C4
ia;L
[;>O%
7uh-:
tDjh1
PtoI
@!I/ny
,u@ 8
4 jc$
D H`
F$2
96
}Ag1E
Exception
}+PQ
Qw4
7iN;"
R ]QW|^
H$m$&
nu*~
D_n}
!m#X
x;(|
$TG
5KCUy
ONeT
,*5Y
1E'I
!I&k
a\ w
QLj
G]Qk
yzm(
7A>J
@D<,q
V+wtr
/=1/
wdF5f
xJ y
e^*I
1c#.
La8W
b 8;j
b>ktfU
OWzL
}Jnn:
B*A?M
gCY/
X6.#
F1F<
EBUGR
5Vtn
rX`n
KZ
q`;V
jY></
TYbc
|78
8;F1
~0[LD-
QQJ.
mvC;
vhf<
PF$E
:W%z
2 =1
2aH>rG
"TUj
vIF=
"6dL
hz2/
RH|(
Z^:Qb
]" v
oesjz2~
XqT
9,eO1
3Sl*B
aP%E
P7Ymf
-]k1c
gJzu[
wtK-
Vynx
!{;*
N ~K!
Xw I
~=OQ
G.? 0
ZeU"@
oOJQ
imrYc
C@\o
f8[
Jf;ly
e,uw
/tL@`)?H
G r0p\q
'lat
y99}
vOJ@)
lQ C
VI4[
500 (+
AssemblyProductAttribute
-&g
alF &#
9HqC
MHLof8
Y~{7
z@t)@Z
~{cd
tnHK4
1q$L
V]:c
0q g
bdhSY
Gn/!PL@q
=ma=u
1u )E}
K.|A
nENAw5r
!atj!-p
/ b$
}E@<9
Fiw[
NL e
!$)+
1p#1*
"T]M J+[WX
8mW#8
s^IMI
;>L!GH
rfH
\IxQ
/SuV
DTq4
Da3|
o%<KK
27]W
^VlCl[
Eb=V@
7"|R
~bPO{
&6}d
^\v*N]"Tj
RP^9
[q83
AdGR
5aim;
aif/
!HB9^*
RS/G^
ZVjt<
#sfh
aSonq9l\
Hkx|
I#26
suU)c;Be>U
D|"r
O})Rk
s*^6
B+%
atZ0
@M(W
DxCY
?Q<+
'QnJ
o\b'
ER3:
[T^Qw
x4N/
FG?j
=iA
Pc ~V
yY*G
8n)
nOZeT
D s6qW3M
g%t7
WT4Y
al
N8N
N,.Q\
]*y5#
(0 jKx7uT
HZk|
pn|6/
[Vf q
%PX)M
=Ndw
,;s1
~Pw~
lZIX
)0
h#5B
NiN~N+N*N
JtGHz
>w>m`
Y}i3W
{$1^F
RQ.v
Zc,?ck
kYY
% or6
gw!_t*
HB tJ
Y'65D8
{k|R
XF-b!
UI9P
&)nL\
GvBT
hte42
)\D[
<5\D#&
r6fI
neO]t
k|p5
$1}
KC18
wb!$
`XuM
hn)
~$UN
~iL]rht
Mz'!
+v'4
5hQ`
WSO?r
,9Hy
K V
<l0L!C
`u*\
p~j8}
E"}E
!Q$l^Lg
BmTL
pDy3
,9H9
`_5Z
[ wY95
&e[|
,dQY
[ c)D;
G9a;5D
gN#,
CJ9q
a$&:
[}[0
m gk
, ro
z21W
5'(
.4.G
INuZ
PmC[4G
VQ y
RiMp
1xp K
H8Al
iOUH,
Spm;\
C8m J
A?ky
ZQz*
-sD?7jz
U *\
('"z
-Ugr
LL1V
E032
ig 0
m_^m
j)i-
glD,%B
1(1
7wup
Pn!<
}%y%
gGTaU<
t`.h
>?Rb2
C3JF$b
k YU
:U`
/~jV
Kb5t
m^P]
Nl mD'QI5]
zAeTU
Gz[q?M"
C\6:
re-V)
LK{b,
3T<&
j6]K?
yS5*
>2Dl
kYxT
8Q]z<[
D (C
sX/Ho
&xZ^
-7~8L<2
:p_;
Ko@H
qCgW@
pIjZ
C ^V
bb:7
V 0.
@.tb:.EK
H)mQ.
UTyY
{O^h
+h@2
UhTiZ2EJkA1I3KPJeHA
O[eo$
#aw[
] DL
i0MX
gl2q
.y ou+
R>aI
FWO(
NGN N=N
c- |
% mxM
jYgK U[W
fdmV
!<}c
.7}S
z5JZ
v3fUOvP
849Q
kFu
3l]sVE
@\b,N
i F
N; `7
?nmS
`'R
@x3YIIxq
dR#I
at1
6ZQg+
&/wr
O em
m=n[
?JPQ
O=pb
lA >=
X E]
7kb(]>c
dR#z
USS?
0IWo
.#+4J
|{>~V
0OCMH
,'`q~
ob.FE
_Vk<,
<=`$
x^[}
Ggta
!q j5J
]9()
e?s;
XIz{
}ez]P
]i9L
DIUI
>um@
)[O
o >$
J&i[
%3u&M"
3N#J
!gz1N
L<O"
ZXT7g
7G+i
3x(d`aV0
C}/R
co5BS0
:X4@')
&At"
]{0X+
,2A
/ 2[
+f7i
t#FY
^IYI
T+!U
[]^a
"`Y*
e/sCZ
zf<z
^!G?
&_vN
-[ B
V)Te
*anv
Gdl8d
XuIk>
L`m_
K+K??
/]}c
S}6Z9
Y-D%
tKFI
ZB`v-
A D?x
k"c
O}\HD
(Y<y
rf,R
vBJ`;
vNnW
;<|ev
V9KZ
qX$0
4o\t
;ITp
1#u U2cYP
YNcp\
L7)<
>pWU
Ny]8r
7_bs
t~WA
Bij(
@umC!
g m 9[4
-dco
AS(n\v
a1p-
@<Hs
u8%qN
$~8b
K3uC
+O z
cUAF
jW:T%
7//p
U{mg[
?R 5
\yZyUr8
:P\w>
Wxfe=<?
u!C.
[p2u
":Nl$
Hu#N3
)s *
GzSvR
vau,
P_9E
UQ??
B2 f
KK^bj
mAE
2pJ%
OYl^
Z`BO
O?Z o:
/CT,
Kd 4y
R\]t
O%mF
l;i&
`"*zw
"$Qk
y1}6
k&BO
2YEM
Pf%[0Z
%jiJ
N)7#
W?V*
#m0J_b
D5rU
-sR4
,/q
dAS[
*j?i
N_)y=
aFPy
Nm?|
foSS0slHgU
$=q'
Db'%
[U ,
.{&2
yY`N
V^3-N
Iftd
s3iy
nVJ:\
C |+
vWdrM
VylQ
Jh<]
IjHQ
q%q;
FD_8T
@oBmy$
{k2:
@63dV
pc$
Q[=u
\%dC
G@C>1+i=
vf'j
e/u']
0sCK
s^">
w&t0
Ek?>V
q:W
S/>>
w%tjh
q3k4`
E&m \6
`fX5.
Vs'v
NmNJNeNpNpNsN
hX>-
6d $
K W6
-vg+7c
s,pV
aNhh
}J8K
&JBlqv
g=[e
d2oVu
Z3>/
r`?"
}{@\!
s* "dI
<tFre=
ctd{c
Z`mu
) xXM
VETI
#8Yw
G ;K
PzvXz
B\;{
N6NIN=N(N
$}wn
vrE127akcXB6m
"e~_Z
M+6G
NVN5NwN
v5B]
gbJ'
m.q%.
jL]f
C3no
\&B8yu
}W#x
= D!
vM|!
!7.{
3iG
KL_
Y$=D-
.eko
";].x
aTtk?
0h !:
_"@=E,
`$mo
"%x3Nu@/
i.n
VirtualProtect
g#=Wa
gnmk
X)J<
#X4,
EH&Am
tXI/
Pa-/
H ud
Xv*P[
q[tA
|&g%
NZNuN+N$N
?&$e<
Muq
EJ8p
m }{6
uNrh
Gm^T
jiGmYXIasbrDUeJETqq
olF^
SAa;]
|?|
>bb,H
DsMKU
/ZS3P&Ubf
3^|5
QO!5
Y<9=
$H>>L
f!2&rp
;FA|
Hrha
zMo}
:j >
Og|Y
<=y-a
t9Z(g
RV4IXH3EYofs
N^NhNWN/NmN2NhNVN_NUNQNCNAN6NrNsN\N
SZ5M
BB)k
p\`
BCVf
6zjO
m\d
#LOH
QgZ+ p
z9'Z
h`[C
<s4:0t
qtl(YQ
D4R!~
If!(
&i3~
t2{I
_>2> -
\wAN
/h\3
]I[n1U
:hto'
*MUJH3qbYVg02UydQD2tIbv2kG3V3cHu3izKHX32pN4
F(C=
?}OqT
C#Z?z
>(i L\
oo2s
n4o/
%{b!a
-%E7
):x*
}B[(
t=);
czUc
k CM
>tqe
t dT
uZFi
,$E:lz5
r=~IZ
0>$
~ "`Z
:R |
K3n7c
K?_U
%luQ
R$Z"
~ydi
{E3&
zyK]
&;Yx
9mI
L'RAs
3jp;f|
'&I&n
%BhF
C X?]
C.~V|
112Y
LV~'z
IL6MTVk
>er#
*VBA
M;H>
C0]R
"+~$r
>:BjI\
(e]|h
W6cE\<
oq]WP
NF1@
:(OJ2
c+}T
~v|HA9 VE
#'t{
)a3J
ym;=
EG9/
{FZuON
n2q_
O)w!`
g-?6
je O
9c\/
N N@N~N`N_N
FhQ^
5{lm
g-?
qwt}
.Q(\
?}UeJ
n{IB
&Bsg
z]4A
)TW~G
$>ku+VC
g@ZP
ly"{_;e
L\o;
e e/
"A{V
IgZ4
:yLa
219>
a #Q
g0[=
}MXm
-c80E0[#
G ^_
,4!
Y~=C
_XEy
*[k
5%*F
~Njx[
<YF\7*i,
V^s[
DlA
LA@&h
^:)
P)za
gfmBF
a<<]
.pWT
K-53
x~FY
0k?d
Le.Q
h%&
\2 0+v
P^sp
Ex|r-6
]vHt
>g7R
}6QmP=
f;?O<
@9l:Gg
Km/i
4\"(
R[ cK
py}8R i
eZZ"V"
;!6N%4
mz\'
U&c8LA
Y :O
7$7T8<y
^rS.
JOq-
k&t5
4F>!
ICryptoTransform
QnyWl
00a=
Fm ^
? fx
_[a
)M]
[=C"
;h3P
gFo/
K;)i
cYW
#Q".-
G74i
I2 H
KXnH=
=lmC
l(=*Ux
.`z]>
tJ#OV8z`
m+GP
j J7KBFI+^
Y:Ka
ok)z.;
~ o{d
a{*]
czVcQH=/
*ARN
>Unf
\g6J_
3\po
` hW
y^hxM
ekg$
([n5
` h`
U+a`
eS>.
L2]Y?
N'NvNFNCN!NkN
M/A
V8 "
n/3
iV[!O
}?hD&
a)'sVB
A[2J
MRGU'*
Dy=A
79*U
{Ub;[
jz}'
D2o{
Z 0/
X{[R
,tmX[
_QHDpM
1a-"Ap
u)ZF
D2oK
get_Chars
`.mGDQ
*#}9
(e*1Y
s5r s*
\bS
dTd}
=Wv4nC
PCX
FTZ5
X.4u
apR5
!$,G
&Df0
*kCJ
Tfst
dIF2
|TX"
+7h:
KLu~f
#U~o3
F$hk
TMtC
T-$.
8k%
6@ R#
%K1O(~Kta
TjtD
!|U^
?\;[e/<&
dYg&
X-w_
UK|1
I.eKwn?LR
iiD;
>|g)
:GN!SJ
(oJP
p= e
BpT3
CV5"N
T)YGT.
CQ E
,\a|
jqP(>*Z
4hL^U
A*hK=|7
+70et
'*ZF^Z|
T7:/
xIU]
yJ|PF^
fC` q
b8M
5ZI3j@
|Hmw:=
;(7V
nZhCT
n%c:
RFU`
,\2?
Kp7z{
fzDJFO
BuZl
NhN#NCNoNWNAN9NeN]NzN
.ls#w*
K#q
"H u,
gr5XU
} )k
KMzgU;
u1
U&rc
6x=f6
S"ss
Bxf^
+ %>(
wJj>
? CE
8ETc
[vSU
(&K,;^h
\= J
f<;%
xT=,
84hxi*X
]9]_q
ck \
h_ UCe
bC,
F2o<1I}
l vO?U*
iZ.D
BJ\C
L)J1
,}X(
g3(:@
{4Yz
Jl\d
G^Xn
z XWYh
`59z9
OUde
(8xj
[nF!
F%:D
%E5m@
H\<r
JKkR
A#6t
e`oz|
_B6wFVnNu
`TO F
LEAi
)K08
{=%m
Za?wU
/ALXY|t
e8-}CY
-g v
i9?^P
#P`h
ILya
\U6
&nKa&
KQ+XZ
bLto
z;b4
Nx 75
}Ld
H77^
a.u
w5M7
hXW$
U!+WN
phwQ
iI7(
(p<9-
gJDk
P1%k
S8~QU
8G t
uQwL|
Fiut
.R z
4uK
Q%s$3}
\a% n
L\93
5 xL
A+~_
lO2v
}s((TJE9Df
'(<zd&
gve`
nC1X
]B/?
&/ v
g- -
i~4>+'
&cn _
7W&o
2=K7C
7m%
P+Ma[
ed(^
X[d[
b.;?
/ma0j2P
VF}ou
1X[1
R =vz
-XFw
Cx`8
_*zr
Ac0)
j~3MK
^<14
xxsd`B_
_01w
HMQ\
rj,
/KpE
JG`m
!0s
MO92
h#no
`K9u~
7gG
D"5)
3,)7
stV#
"'#uV(
_fcL|
$p5)}
(GS!
`;1Q
6ptY.'
1G|yQ
l y}
FX6i6s?
@rD, Z
;=v f
>]&d
h($f
+;w2 B
!'J3
)@Xc4-W;
WXf|
AngH
752}R\
p71<
03F
iAU0
(= eO)
*1 ,}
Jqb3_
~f1H
*/$$
5!AR
;<DK[
.w\<
xcqw
2p>e
?.LP
`Gd;
J(>`
1G_\BB
Zg2D
zw};
0{\
<hkP
GetMethods
n5$!
=p!7
'Qf)
tWo?7*
8AoQ4
O'%8c
u]|&
y~G|
AM1B
5&S?[
ZUZ&<
i#~H
WM T
yx1LI
'1hF
x`dN
P=$
E< k
j;>R
24-n
g6Fz
(5#P
O\#H
Ivk#
1U?$
IRnq
ZN]a
33vurqO8r2bb9o
UWo~
}[}n
)'&
'64=
Fdp.|N!
lr1V[
"; G!Hpi
#= 0
><B0
NaJi
eQO_r
v];j
)&8nf
^``e
i4?~
]/Vp
i70(
\u2P>
iu%?
a^Ax\
Gb$.[
N6iQ
NDN`NEN~N
mSI9B
[7MA
!Mgr/k
>V+
:|F5+
/`;w
/}*:
hl1WFP
4=r/
Osf7J @R
Ypv!|
x}l//
YZi`
,(Y~
%TEw
0{>L+L[
kU*q( =
/`;C
MgZV2R
}ft`
cSx
aY}*
&S%F
M A])
. <Pzj
}J5OpY
/U`523
BwJg
*po`
R/;8
$4ck
jA?z
kswU[i
z'QW
!Pkmd
*HKl
/@o
S44e
JET8,r
J 3t
9=M|w
"(X>
dy@$
7&
MLOP
Wau>1s
k`k]
N([RI
X$ +
Z{O:
hLkAKK
'.m)
~pov
,.> D
;Ln5U
!9TU3vKW
-LvR
>|u >
Eo/o
AnB
>ry)JXb
a<M>
' )
<r66D
D''g
N-45
X\{E
q 5c-
*rRG
Y]!V*cX^
~U`h
@->V_
\Xhc>
_D>t
USkpB
( < =
Cb]+
zd;$&
elb
>WYU
x)ehi
9k
:@8?
7E$\v;
9~+x
zgW"
us
)m59Qk'
NT]c
`7-@;
i_yl
IhT:
0*J6
T&m:B
S;d cT
NMbz
\)%M
"/]up
$M
NDpY#
.L$.
VEikMU0XrLv
@kv.
fS#C
9I]'
wPAT8
U3xH
,: |
C8%6
CVgN
<{PZ
4 \2
mAh\<
)I=w
wfd=X
^HY|V
eI$K
7^E
c7 Q
Jb o
ZC 7VG^
F-{R(
sk~S
IeAE
vhTh
!DY8
.<s
=Fa,l
v2+C>6L
DL0S
rsx?$
0gaY)U!|
@ |7
F]\
0et[
@v<>J
`2}C
N"NvN8NQN\NCN`N
6\ tF/.
_MKZ
z)nE
s^e#
m.a
iY@ m
s(v)
g.3<H
)3F\S
l{Di
cU?jh
Z l<
6k[S
lWwCf7{
)::
GW^j
zV!C
LI*3
J#xqX?&
!0?k
x5^i4_
tvzH
3A3s
@0"P_
P!&)
enup'
ht R
hH6W
bsm_Jw
SR .|
( N N
rSJ3:3:
%X z
Kc|*
[CH|
PUX(o
]i1j
6h[[
M;"7 G
fOF%6]W$
tLP
a||:
[mE'
7agb_
7F6_7!
wMb<
b|B>7
dT %
gsLL
h06]
6 M0
jB]b
Z-7:
e}F1
zRU[
3r!l
.G4o
RpX02
ePNw'?
za/
5)77
J5Mp
!?yzCI"'U'g
! [
^NQb
%Hx i
ChJb:
yt L/
,uai
B)`?
8<<N
=dOm
>4oF
L=_w
<\a V
'ipy
*8cYuS
H}hL
System.Resources
tgFgf
];o,
hlci
&v$!9
y4F7
elY5
+nq8
R][$4
>p*K!
&Sz^_
]h]j=
<aa6
lE7
1>m{
fd0P
%wY|
6J8J
;8"]H}\
jY1q
ol0nuos8
$NJ2z
=mo@
0Ut S
T>V7
dG4
n_nf
U8/<f
sY*
> m4Z
N[KS;
'Q8
v<?}{T
]9 zv8
wsdf
A%yz2~
wxph
r!]~T*
'U $G3
\^@'
mP|m
I>Em
;kue
ofw]k
3*(L
.#t
`? (
(KY/
k>)U
ex7H,
p Gq
] 9/
P0_e9
CLth
\+{7
x }J
.0Mx
2Q$
iI!}V
{I}[
NJ.yR
GP#0
]tta
^(a18eD
4~k^j
L{W;-
ve$_
ud6Czb
I2XTatr1Rq34WheU
nh|3
0(R2
GX L]:
H $w
~$;L
P*Pj
$*8l
&|td
>5l|
3KR
b(d9
wjXLZwGsEtBj4
x%iAT
'}/9
*u0)
HI).
[xT"@+h
`#3B
K025
5 >t
%6 8
P]iQ
; h[
|s~!Au
,-R<
=Jyj
'-YU<
T64i
uV|w[
1%21]
Z:L<>
gxcn
J3%s
vUAT
`4rjn
50t/
< [
`VBt
9Z6y
m[R
& "B
o[CqN
_[^:
^..BY
j; L
|V3} y]{Y^
C3fn
T%.
b:p^
<z25
Nl a[C
?&Bel
+P=.
N0v
YSnos
fa{L0f
?xNV
UU "
6:<ZzD
w y:
@p(S
1`Tc
N N/N>N?N3N N)N
+r3B\l
ED yf
w0ax
]r>[
ljA
IG`.E2a
>icX
71{f{6
%zG3
)Ic8
<> f
)m*
":syT
.$a|
9j5f
,g' 3@
P ;r[IQ
^Ma}\G
i@Y<
%swp
([X(O"
L3WNL
~:K@
M@1
BR>!
$J?y
A$c]1
i%;y
v~gx
& HB
=wbK
.};4
[+}/
@QB
A)m
E{w<
I+PE1
N4NRN>N NoN(N+N
"Rz)X
*n]"
(j`$
$,[]l4
N(v+s8
upR&7-
fVA>
L Z#
_]Z+7
s3zM
l!=~
h)A_
l^ H
=P.:!
Debugger
D5m>
(S;GT
h&C~
TL:[V
.T%}
4`%1
;J?it{)
X82xO
{M~oNF
u"ckz9T]
:M`A
4]w}
gOj`
(t~;
Gsxn
=h?W
^jn
lXq >"
Djd
|$\"&
\\{$7
Y ~`
V4u;
7Mcp
ziR9
q%b(
% Z:E
UVP5
08hA
[Y_Ww|
v2.0.50727
NBN4NuN
2a\R
v4 % I
_>H
G"O=
vG~&
*4H
Z#Vh
MdVwY
: A`
(LbQ
ZZ:c
j^"gX
0s~>
zdqM
so}\
!3L7
-]If
ADO,B&
S~RC
$9cE
qn)g
PJWC
fD$"
~oy c
hQ>xX
_A;}(
VZJG
SymmetricAlgorithm
o!5Z
b:]O
mX%x
/~5c.
RT#?
+j@p
!OV
]eF>&^
N Pm
x |.
$#Ml
O <}w
jR<2
Pn8Lyr
JJ W
)JFQ
r- [
XXC(
( }b
/Yw'm
;uIt
p{-lc)R
"-l#
}L6g?
$ TR
" cQ1
:2a\X
$<t -W
@B_*{
}as5
g,O#
#R ^
!piqw
J6`>
dP($
b$t"
3IJ(
_nkC
;hvBN
<#{q
hMS<
h>;R
gk8c{
NMN%N
z^ G
TYNlg
g$hjR>
p`8^
aV)A
Cj$
CpJJ
0h0#
&r|@
#/ o
/XnD
!X5a6
wQ]|
RF *
3 ?E
6zGl
0h0K
M/HE
7Q>8
&[(2
")W4
cu)Y
6N^ +
)c~
M '=
e'Rh
3HL
:>"F
^>dd
Eh\F
VtgsnwlwyzJSpAZvDBW
oCE4
2@',
V~ 1N1
%:`
NRN"NWNGN
4dOY
Xz N
}B.s
$eM8L
UHr>F
q-2Rw
Equals
`?K+
gz*#
t] oy
lMRk
>( Gu
K ex
3fh[0r
WPow
yc
"j%%
riTf
X wPpu@
1jfl:
riT]
O`PB
]X8\
c3MD9;
yvlI04MHYbs
J.B~)
mg"#\
%4Ts
V`z/
Y &]2
4(nP
RWFn
FK8N
Td@@,
#;LU@
_#+MZ I+?
7*r`
] 5l
1bpf
fL9
m<_^+
+,t5V
<w=B
7o
E%-[
,y.c
~[/ #NAA
'^rg
^Zp`(
3X>}_
Y'm8
AuF1_
Rmxq
M>()
A;Ps
XbG&C
_:\Oz
^X0 "
',6m~
*8pU
=A58
2rtYQN18e64fqldiQl
J\xA
]>1M0
Xl@g~
41GZ
X=eiD
SR"L
#Zk7
&1:1
R*x1
Mg@q
]Fz_
7mx'
A:Vw
X&<+9,
GbcN
K#I
8D(\
C\!3V
,N2v
iWLf
HJ%@
2MFF
_RM4
=NW^g
na"Yp
pHF\
!#<D
qon0
v1oz
W%+3
NPVd
|n A
E=;H
]Yk(I
e4-g
Tv>D
`$?r
^:
6^uu
o|Uc
> :t
z*znss&
)%A/gI
,o$y
}wK?
J
fH6n
,Ud%
E!3j0
_ ,
cwE
=>Z.G
w &i
#EY
tGlV}
6q{ M
eu7
~MWhlc
; PO
oSyA
Ok#'
xt`
o=S0
8\@o
-^YXL
~~<d
m;ac
;%~[
<"of]A,
7+?g
]xIi
|7daQ
zD}_6W
PNh</
EI-O
t xf
@~bq
ps`+5+
N[N7NzNBNkNQN/NeN2NKNyN
^_t
4X0P
7#N Jo&
^cGg
rQ:%
9Ws>
LVLK?
.@iX
mS]H4m-!fHW
<i06
3RI2
9D-k
1dAqm:
tuFd
2_8t
oUo*
z$jt^
[Z]"
ZE$$})!
J_SV7
RWM
ZIV)b
u(1+t]
m0{P
@-`k
E DAVw
ir<_d
]#'"o
O6gp(s
s'pm
Y7<}
*jXq
eH<oh.
*VtD
mvsA
O"~ ;
C@L(
%Oza
) @6 a
&_*A"
5ap[
s`z;
(*>rl
%^}V
Nuk=F
" E t
znPn
zj1A
Y4f`
E10Y
Q.q=-
!FLA{
99zQ
Orh
a.}S
zQg*
fU2\ecL|
6f33K
jU|T
T+El
'C$<
n$&.
3mM 1g
0`"!
*8U%
IGRsX
sw)
06yf
v~5b
.5T)P2
R W6
FR9a
3" %
1v?$
;H?m
:1!+
gat@
C9hO
`6ca
\i>y
\ GC
z\~e}
?we]
?f `J
dp? e
IZ l
Ga6p
J'v+
.+5z9'
Y@>}
LTlM2
|moB
S_uh^
xk!N
;S"4
jW# D
-H_>
7Uyq
ibAK
8X.i
0]M!
hxXy f9
|Ejp
W[x4R
u=Q%b
7 N#
.)N%G
N]N~N
c;Bem
Mvuwn
&Hb5q
UALk
EbY
s`9@?
hM &
l 1}
-2f=
'= ]
8MTo-
m>7[T
$8`W
!&\u
$rqA'9
@2f{
jh#6
NN~.
6hy}1X0
0Nd[
{\4
0uPS
Se{y~S
tT1
kn {
mc,4$
C0R_U
u-Tg4P
4)4C,e
(.r8
Rtid
4Au?N
*Lmk9b
,V-1.
GzP@
xZa8
u)+p x
<T*;
oD[ 3O
xmSy
Gc|j
uv b
?%2b
8B^A]w
myvHY^
VKMR
]a\+
e3D-
o3D"
"`Kf2U9
SWAL$
F>/J/@
X Kp
X{jrq
6 xz
/1iae
o8EL
.S4/9
Jxgt
\O!D
<m"
\U!{
"[Ql
J9mW
= .#D
j 6KZ
ynTv
mcr6
5>1 >q
j A7^
G;P9
`3Ji
8C*rj
$jNQ
Rfr
D<k3
Ty7"
Wg U
>B<=T
MPk;
+1X#(
( :Un
Q.0_K
Aq w
^~.8
Z( ;
;]d%
@$(4o
1BP
ChIOX
phdo
7+fz
HFinu
FX,$|
Ic >
] k4
DlYL
nC c
"y*Hf
R/3J
/<V!
oSR&Q
7d.[4V
"+R)
ejM1
Rcr[
$7lgU
kaJ^_y
Q3HsY
9}$m
,!>r$
*'2D
U} E
))0x
Y60Q
Idp"
A e9
unB%
j$?
G]8N~*3
(V;J
--Jr
% x
s;T/^
8!h}~ {(
'H!r
`'n@
V5e h
'2bVYcT
4tRXCHypVoiwkiyBFb
u9ryHx3
It%4
p.^imr,B'}
PNou
LsjQ
Z2OHp
nZr!
3z('L
c,Ug
e6v$K
Q~+X
K9"D
r)+D
elzY
3Z H
.y6D
9G&]b
\-FY
2G5.-
+ <3C
G)IY "A
&o G
nP%-
S6/`4(O[H
l4br!M
{ r
2NE`
UUMQ
l+* _
I2vDMRIur1AFlxa
$W+Pm
!rn4{D
0*7A.
a+Pj
%*dA>!k
reM/9,P
Wv6 X
_wY/
sSR?
aVz
_gXJ
VQw~y6^
z=zTg
GjZJ
AT+fCe
1- g
\hRW
rQl#
I\vu&ny
M^)X
`M#6
Ea~^
r9IJ~$
R 23W
6&2,7
bbz |#
XYH6
\.2F
IoFT
2a(F
WF?L#
Bx8P)
w"J4
DrG
(wA<
#s2YC
H#HnI
gp8f
A$&-
i:P`
MrLGA
24^M
Q9$H
KSg3
>*,8
ZRmA
i:PR
84)B
gY(r
XtG)
(^NI
otA;
kyS,
nBo%
j d@
{ F^
$WSi
zJ=!
`]ylY>
DmR
!BFn
I> K
,R?X
^4.Zo
U%I6
NsN9NQN
Oi w
Jr$^
N@Rv
pw(U
Piu9
ZVw{`J[
>9 q*
B-; <:
Ft;H
&4#19
N B
ZH|y
MeBU6
^j,
>=7!
C]sm
C lF
&^xy
qB"n
t3Q?
wP|!C
mY]4
d:s}
!?Qm
Sf.4n
~r0
1%`9
K sZ
*`>M(
N2N/N4N
l_e
6}1#nA
_^I90ox
txj`
4~gl
kzdp_
Ept@*
r`@TW
+Tk$H
+j~q
,eHV
-X0[
xioEVz5CYhDcZ9qNI
~#F}
)Uag
nxrn{qOy
Ap7#
[SgH
v.c"
K@]Gx;P%D
QlC@
~6BA
?27v
65p~X
uK|L
H@ v
WA4yg
vD&*
Hu;7@9
dY0)
-e `
{!0l
rH+
Nf##
RJeA
#vaO
r4_
"!K`
kdMc
Lq$W
m[lo
jfR\
0a8O
HyG@L
.e`PS
f_MO
j+ ,
tseb
1"EG(
w1nGm
o6vsGd5
H/C|
zf,S
j|"V:
QK;i
nC r;
@i@B\T
xO?:#
#}`4
)WuE
-=xT
Aj A
h V7
/nQ+s
@Wyt
nN#]
[4 :
~'X8t>
Ais>?
HTTi
|,PCCxP
x* x
NoNdNYN"NEN]N N
V> 9
]yg< Q
Z 4Z
\+$0
2y5,
&^iiK
++7C<Q
a0<[
BJ Z
Tdm<
D*N
! E^
5b}2
bX[mpa
ob+\
%%w
|Q$I
ggu2
x;C*
N`NONDNYN=N N$N N+NMNsN)N
Ozq[
c`uA
#[AQ
yK5C
/q0R
)d(@
get_Length
hML-97
`TY0_
0 Rb
v <9
;5zU
(KQi
QftX
_;hQ_
Y\{ @rf
L:"=
$o!(
)2a1
Bm
.DyM
-lK)
xG5A"a
&JO;V
}7P6
Hemk
"6 P
S fy
L^ol
mQQMZ
-]$3d
Xxpc
h*rB
BE<9
@\:k
ao"0
3Sef{| <
W"H
39vL
SKt-
[<;a
VQ;N#c
]+I%
B%<=_
H-KZ*
,(+)
^!g&J
ok^%
!K0{
6'#+
MBsf~ j
doxa
V =g'1
e/=2
"B}q
|q#6FU><
0V1>P
. A)
uU8*
L%Th b0
j~^I=l
5qtS
^kwdc
%q i
d?gn\
Y8K(
Z^_:psEk4
N0+ M
[S@:
3@\,
LD}:
AteI
LKRA
r*Vq
f:-N
%8Z
5N:~s
@U\mR
O#L*
9d~C
pU&\
Iwp?
s;:=
i,{
6o6f)
?U*x
F]p&
Q![y;
ZwYl a
l..9
g,lh
qN4D
^78FX
H
Xv
pHYs
APq2c8+y=3H
05V-h
WuxC>
t")^{
Mk0R1
r4Xd
Ik1F
`}$UuS
x.pSv:n
wu]o
l~7
6p:T
P F(U
T9$I&
<:f^
<-f_2
lzZo
[v7a
*0z_
Np ,
C[SX
I3 B7
k*pKgY?
C+"lm
hL ax
J;JV9
iJ+p
4Gq{
q]J<4
Et/y
~ub7"
5;bU
cJ.k u
]~2/g
)P1
7e)n
5#sJ!ub
HAL-_
23EG
C_~q
6 J
*KnT
^,c]U/
PPiZ
z<Mr
Hle>
Q ]n%
[a.[|
|H4-
2Z|EH
8St&
5o"#
1=PvC2
~M<q
2Ul#
w6.
(]v
i}qiW
2AH7
=M1G^
r\<4%
.:7l
cd'%
"P6Q
DPa bZ
!!(b
G4Fn+
H4\#
Izb:
] w]r
`="\
cBz}
$,
'x);|
Z3Xs/
/Dg$
pAc9A
4u @
Wx f
B [
<n-\+c{
K BRT
j +2
P/91sN
Qu(7
,E}H/
TU(mF V-h
B i3
LK(S12
Nr;`
ep4@
s )Mov
w" S
K:NW3P
w=-
b#N_
IjL2 e
/g 9
{!Di
\{RP\
GVC
yt G=Z
P/`/
.XSv
Y<&0~ zE
5Whv{Klu
6S%M
Z_#Y
7w4m
xniTf/
4%zbX1It
S8PK_g
J^(v
[#Ei
n~7>$
(C9B}}
Q}@_
jSA
Q?F
Ywic
gTN2
DuftPc
]w8OGH
[ Rp
l|}h=Q
v`Wu
g]VH
q(Kb
'T|%|
#Pb d
&m0qO
{cJ^
-ub4}|
Z0j`
8=>
r4EL
rL;9
~etV
UZ (o
.ib
mQDm
xpuN
~*m[
lW0S
NUjDd>
H)9`
Jro
cNVmY
a!#>
[ed0
'TK!
a /
&xX{Z
F/q=
vk9
J|@|
V;^=*Q
3q/R
}i3+
9"J*
W%'d R
U%'[
g9N#c
rnXh
ZsV&
B qa(
?^ '
sXB ^B
<dU'
phx M8
#*!q
>}Zf
?*{m
IDATA^
j CU~
,K,#
Uk%x(
Z!?/
4W#B2
oVu?6
DW5x
?8N51
9yA6
(H.#
`6mW
gX y
fD-.i
)E4o3Y
miQ!
Dajpz
UiW a7
BgWU>T
J</(|2o
R~L$E
u6-DD
do2#
#|@b
`{o.q,A,0
*Jq/+?=D5
@mUnb
N5Q^Bp
"0ou
$.Ecq
pPA
f,zj
QfE?!
Z!=F]
Eaf"i
Oi r0
:5#;
_.Dx
+,+1w
ltQp Nb
;I )
33w!
bd ~
;jk UB.
l_2z
NnNANVN
apB(
ZvB$
tr!DO6B
!dVf
b7RO
<8FP
fwp9
DzCd
=~5K
;iv0
<#y:}
BzAT3
9 $R
x&ez2y
&p
?Ul'
hF >
&n2*
7I[u
ozot
MwGOC
F+,ZQ
6*0e.
[%-S
_A[,
ze@o
X*fN
?6:Mf
4vk1~(t]
mO{!N
|W/N
SvY\Ipy;
;}#
UoI
B02Q@
:NBE
J;=~a
t xd
,N*%
6 i&7%-
d@&#
!^$t
op_Equality
fxpxK
SuBj
-, S#
"3\B
u25i7
q`cD*
b4yv
h?3
7EE/c
%vI
+#G"k
`L7c
[f35Ri
JJcT
Ix-F
=qG?lDpA
Gf;H9
5MTPP
i<g:x
24UKFnNOfF7Ns3EsLCo
$8C4
}I"B
BCVdR
D$<W
g@8,~>
!@,b
}tr^
uT>o
xW*:
0 zk
j']|~
8c[1R
NR/^
`?ew
H-YK
5HC
"E@|t
Q7bI
e*l@
j^M6
!R-ai
,/bN
`qXe
BFc]QC
Zr9qT
7^ 0
R%NtQF
{ 4c
lIU{
|j#R
]a!_p)9;
og?6 }
+b *
tl6cj$B
R^kw
F!R[
a,D3M
K+=(Y
DI8x{
dzp
ByYNQO
$>)4S
,tO"
"iDz
eM7.T
|F]b
M{U
[CG2p
]3;\
IntPtr
|MgB
S$2!J
81odP
#p^zo^K
3#=@
3'Qi|
uw1
l 3z
"Kc`
yB.C}
-<(
W.b345
hE/{Y
amL@{
ZN0z
9jr
^<vB^
p&h'
.uwd
r^~~
hR'ko
,4,^rk;
yH&r
$T >
=^&N
\UFj
!O;3LL%Uj
fjOm
ROL;
xk9X
#K2E#
wS.t
Fvb9
5Kc@
d9![00
PW]"
nemYa0kuTWY8Q6MKI
RmG#
\xeWi
~1p%'P
LQ<V
1((}q@
DW`2\pcofb
<lUr
1Tq
8}vS
~9@MV
,\k
18#\G
h\&b
('Ue
n2 &
&5X2
(|m}
v>D_W
o/}\*A
:JX|
Bt%z
Z:d@
9C +*
-a^D
Ner. 1
x0MF
G?u+
d
syZ>
Kq\U
#]\0L
f>l
\(:O
VBaPb,u
N'NMN
tKZMs3r4FFEqDBHyA
1z,4/
x~u,/d
`M*DN
;;.Q
-Dma
lgK(
gdKh
d| _
U|G.j
<vQ$
7RW9
\CG&
4\|t
U{j3
jS>(
A0w]
h^x^Q
! Cy
[k`b~T
N5NcN<NWN|N'N9N`NJN
Qw9v
nKF%
$~jd
NgN@N>N
`(U"
BK% _
% oL
N(Sh
=+Mk
W _$`
*1E2
P!^({
K2/2
.gQ1
g?~Z
auSb#~n
L6522
d %R
:w2_}n
4~?
zN'C
q%m#|
Kexx
Mk*n6J
[[QJ
=8_6
MgkirHc
A#+O
y0l
SplZ
D~ECj
W3`dp ] M
Ki9m
a m-
V o;D
|1c
'GPV
/. W2<N
bG2u
oV$pW
Q UP
L?_K
h^ZU
:0YhJ
kBjEPcs~d
tQL p
?n>l
4iXn
JWJw
2fZLx+
HR "b
J0Aw
/5f4
q) B
aIkV
BpVi T
U$3M
i25#Ws
%<[^
( ,T
/vPJ?
2A#t
/nJ'
P>wBw
o\0X5l_
T{,bXa
@AEA
OQZq
W E`
V/>j
=W({
0=M0!
EMbZ
_mj n,'K
^)FZ
#&b-
%,g/Rj8
^@p3
%#:
Sn8VS7rObAMSHxsQ4
".05A
|}YV
F 14
x$"la
BFuD
]+iW#
(Fdv
L0Q v8
R`Xb
7#%T
cH=:.6%
8,o
wDOuo
cHH{
Tz}
>h%KPRk6$
c =U
D">C
:Vwiz
;G!a
a;Wv
*|[c
e7q T
`b m
cocO)
a<2_J
Z)C"
oQf9M
FXQn
:6r*TW
\nVp
UlRg
mH'|
OjW4;
N{NLN;N&N,N
MBWA
I&H}31
Cl)'
7Xs[
t]h1
_Tzx.
Z7 Qyv
M3,3
}VuH
&Ia
yu=$
XsGp
HK-_
jb`9'
{**%
Nl<Z
[ObK:
7[7v.
,v4|
;zH!I
+Thg
~C D
w\ 0L
a&s
\=+H
Hl^h
oa &s
J*WH
m>_
-u%:L:
pM%Nvb
gSk0T
6mF5
g/Z^
Z03_8
E&~#
SpG<
NtY`
K]o_^
bCrR
~?' Q
!<e!
~Yb~
xy C6,
75f<!
M~ $
q*q,
W\%;iB
]:Bg
H]Dw
bSs/
b+mk
X[3
m`P73
R> 0
EAkJ
3!h7r
gu_I
R;we`
>X:k]F
H`wny
tRWB
O?k$0
;Y<V}
\||v
Q7CZqIDjkEpPs7fbT
ew4"
[so
'JA$
GIs(
!!j!
"y_/
t0 1
3WHX
^XgX4
[ G6
p(I8/\>
fRzycZ
/6jZ
NS+X
!0/'
`&qO
QL` |
}0a1
N8CS
q qX
dds;X
] S}K:
|B`w
Z 8 #XX9W
ai}xf>:
2g I
YW`.T
3JDUujBKw
j,9.I%
Nn1}N
1{X3
&}#1
8%BI
_27/}
*K0m
wIap>
_Ya6>
7+foM
4n}:B
1:1
9v)6
e5`C
]l,B
Y00^
ZZ~ .0
|TL`{7t
#Ag/x
%]r J
4$~4
X' r
:I H
loXs
y}^Q
{q$S X
a *%:D
YsK"8D
g#gLw
G`F Y
" |<
%;:Znw
*$srs
H}x:
V~ f
&b u
hP9L
Ada6
( W~
}j/t
Jz_C
P#fi
49VnoVVVuW6Uq
NQNwN.N NwN2NfN
M 8P1*
C|eU
Pt&;
;1X?w5
8UqojW
)[+jV B
H Nj
E]oNG
VntE
a`&Z
1xZ#H
ox@ Y
T]M m
H~n5
{g*TJ9X
@Fb3
B*(Dl
`V)I
soTUU
% wn
7G%Wb
nN;c
V Q#<
N2"i
CQfU
8PsJe+
jf'^TC=
PI`R
>mM#
%%ii
F7vY?
e-w>L
*Mi9n6cErWtg0Acys3qr9iZGmEj9KXSrzhf7jn11MPp
T#q`
~\jZ[
g%gU
*GW%<#Q
iNj8mE
uy9h
w z#u
cS:*
F3;T
*?uB
Kk4 V
;rrG
T[\t[
vu#A
i{=H
k^s1
>EBFt
Wg[2
?)h{
T& n'U^
6} @
e 7*!
,}%J
*@4u
8d"ss*
0QG+
W5wA
zMPY
N1N`N
~R5.n'
oZJa
UPq{
#{#7
DVOy[Xov
G*kR
]@GZJ
gl=8
/[0&|
iNAr
7Kfn
X3l<
:@{4`~q
4R6)
qtjZ
u#,
)HB-:
b&2C
jZeJ
3A8
A#,nF
,9>vb
q@NI
*+<T{
qs~s
a9B+{
RaC\Q
+V6g
nSsm
@ifW
0s+G
`EsX
LPQ0
stxtG >z
3QS0
3Va
?(<b
5M'?%P#p
' x
8CBF
System.Runtime.CompilerServices
mna0/
- Z
+CrW

=UC4J
BVTJ
=>'c$
dBSM9
yr4I
p/9
~?]p
.RfI
o`XP
_^% e
8F=~Y
efZR
#zYU>
+y;X
5z?s
c|lA
NC;9
GBPE
r4m#D5
$B5w
_BU\N
UHj
KA 4
]Ps9
~-)'>Wb
LnDo
L Ua
+z E
JRgy
>1gf
oDsB
y+EG"
J =|k
`&YM@
` j-9X
jg]U
mHF^nK
J\Dvg>
k X"
SWvj:`
&vzW
\1xh
]@p*
*g<V
r=Ay
}/3)r
K l
fd%x
@%Fr
,@@p
z~YRj
O)HO&m
`VRs
MORR
pX7<
)j?Y
/W=g
7+5Q]
[fJ7
R CS
u\eoG
,$8`
j^!K
k^Np
`EB_T
$*BxA
WI6R(I(
NX?Q
%`ZN,
G}qWN
KGCI1
*Q$cv
"gRH
x /d
&'m4
* Y.
4rA/
J|m4lh
fXGt
D96]
It#~<
BjHE3qGVbDpPUYKkx
pU>z
1\yF
C @2
-<kr
gW3B
AC*kG
jgqa,
/s j
0K?*
sfs
YX+R
a9[6w
TNmlO Kv
0fEueW\
yN3$
9"oa
A(m,
o7e)
o= "$$;R
ri)*
c`@F
%4a
il=y
/VsH
=XV_
=f/}
Q' +
MZ6=
I-s7
|V\)
) 0)
c 4Z
5LFtL
y_:|,
s2b ~
ZNgf
U!U+
\845
fiHG
jx40!|
TmbD5
ep
) '
'FsT?
h[0,
;`iX
zZn9
D 5G
`IGP7o
.)a'
$ j&?nd
\+o]#:8
764g
Sg}y
ry"ce@
?Fkk
XGSZ
Wf8R
NVF`
'pAz7j
@6Yxa
p>gKk
s-!N
E>:,
tk W
$4$s<i
7z[0
l_W>
g+QL
fP"f
'`lL
$Di
u>[0
Y_}
xV1w
"{*d
=TvC
0Fh&
1f$+
itPS
8!PW
2 q9
4>(H*
WMCu#
`eiN(]
Z2_ 4
Uya'
/y:)
-m tu0
s6B*{
0z,O
d?<~
V>oQl;@
j8HS)
B4*Z
!biD
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2018-04-14 14:39:32 2018-04-14 14:42:38 186

16 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2018-04-14 14:39:32 2018-04-14 14:42:38 186

11 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\u2.exe.config
C:\Users\Seven01\AppData\Local\Temp\u2.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\u2.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\u2.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\u2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\u2.resources\u2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\u2.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\u2.resources\u2.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\u2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\u2.resources\u2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\u2.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\u2.resources\u2.resources.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\msvcrt.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\NGpp.exe
\Device\NamedPipe\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2432.15671843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2432.15671843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2432.15671875
C:\Windows\System32\Branding\Basebrd\Basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\NGpp.exe"
C:\Users\Seven01\AppData\Roaming\NGpp.exe.config
C:\Users\Seven01\AppData\Roaming\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\NGpp.exe.Local\
C:\Users\Seven01\AppData\Roaming\NGpp.INI
C:\Users\Seven01\AppData\Roaming\it-IT\u2.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\u2.resources\u2.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\u2.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\u2.resources\u2.resources.exe
C:\Users\Seven01\AppData\Roaming\it\u2.resources.dll
C:\Users\Seven01\AppData\Roaming\it\u2.resources\u2.resources.dll
C:\Users\Seven01\AppData\Roaming\it\u2.resources.exe
C:\Users\Seven01\AppData\Roaming\it\u2.resources\u2.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\it\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\msvcrt.dll
C:\Users\Seven01\AppData\Local\Temp\Update.txt
C:\Users\Seven01\AppData\Local\Temp\171947752.xml
\Device\NamedPipe
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Users\Seven01\AppData\Local\Temp\525722800.xml
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Users\Seven01\AppData\Local\Temp\1574982584.xml
C:\Users\Seven01\AppData\Roaming\TcPR.exe
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
\??\MountPointManager
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2684.15673468
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2684.15673468
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2684.15673468
C:\Users\Seven01\AppData\Local\Temp\schtasks.exe
C:\Users\Seven01\AppData\Local\Temp\schtasks.exe.*
C:\ProgramData\Oracle\Java\javapath\schtasks.exe
C:\ProgramData\Oracle\Java\javapath\schtasks.exe.*
C:\Windows\System32\schtasks.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\Tasks
C:\Windows\sysnative\Tasks\*
C:\Windows\sysnative\Tasks\Adobe Flash Player Updater
C:\Windows\sysnative\Tasks\Update\Update
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\*.*
C:\Windows\SysWOW64\ui\SwDRM.dll
C:\Windows\SysWOW64\schtasks.exe
C:\Windows\sysnative\Tasks\Update
C:\Windows\sysnative\Tasks\Update\
C:\Windows\SysWOW64\shdocvw.dll
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Users\Seven01\AppData\Roaming\
C:\Users\Seven01\AppData\Roaming\*.*
C:\Users\Seven01\AppData\Roaming\ui\SwDRM.dll
C:\Windows\SysWOW64\netsh.exe
C:\Windows\SysWOW64\it-IT\netsh.exe.mui
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64\net1.exe
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\Temp\fwtsqmfile01.sqm
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\ProgramData\Microsoft\Network\
C:\ProgramData\Microsoft\Network\Downloader\
C:\Windows\sysnative\tzres.dll
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\it-IT\sc.exe.mui
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
\??\PIPE\samr
C:\DosDevices\pipe\
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\*
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
\Device\LanmanDatagramReceiver
C:\Windows\sysnative\WerFault.exe
C:\Windows\sysnative
C:\Windows\AppPatch\AppPatch64\sysmain.sdb
C:\Windows\sysnative\
C:\Users\Seven01\AppData\Roaming\TcPR.exe.config
C:\Users\Seven01\AppData\Roaming\TcPR.exe.Local\
C:\Users\Seven01\AppData\Roaming\TcPR.INI
C:\Users\Seven01\AppData\Local\Temp\401883642.xml
C:\Users\Seven01\AppData\Local\Temp\1069340872.xml
C:\Users\Seven01\AppData\Local\Temp\76590864.xml
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b8d41a36c0f1de1ae26bf020f0fd54bc.exe
C:\Users\Seven01\AppData\Roaming\ntdll.DLL
C:\Users\Seven01\AppData\Local\Temp\886795670.xml
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\System32\tzres.dll
C:\Users\Seven01\AppData\Local\Temp\1238154552.xml
C:\Users\Seven01\AppData\Local\Temp\1646863775.xml
C:\Users\Seven01\AppData\Local\Temp\1233746797.xml
C:\Users\Seven01\AppData\Local\Temp\2102812751.xml
C:\Users\Seven01\AppData\Local\Temp\36491117.xml
C:\Users\Seven01\AppData\Local\Temp\2020352697.xml
\Device\Http\Communication
C:\Windows\System32\p2pcollab.dll
C:\Windows\System32\qagentrt.dll
C:\Windows\System32\dnsapi.dll
C:\Windows\System32\DHCPQEC.DLL
C:\Windows\System32\napipsec.dll
C:\Windows\System32\it-IT\napipsec.dll.mui
C:\Windows\System32\tsgqec.dll
C:\Windows\System32\EAPQEC.DLL
C:\Windows\System32\it-IT\eapqec.dll.mui
C:\Windows\SysWOW64\it-IT\P2PNETSH.DLL.mui
C:\Windows\Temp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
C:\Windows\ServiceProfiles
C:\Windows\ServiceProfiles\LocalService
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
C:\Windows\ServiceProfiles\NetworkService
C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
C:\Windows\sysnative\LogFiles\Scm\b4bdb6a0-417f-4e60-a0ac-aa00b1c79b4c
C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
C:\Windows\sysnative\Tasks\Microsoft\Windows\RAC\RacTask
C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
C:\Windows\Fonts\arial.ttf
C:\Windows\Fonts\ariali.ttf
C:\Windows\Fonts\arialbd.ttf
C:\Windows\Fonts\arialbi.ttf
C:\Windows\Fonts\batang.ttc
C:\Windows\Fonts\cour.ttf
C:\Windows\Fonts\couri.ttf
C:\Windows\Fonts\courbd.ttf
C:\Windows\Fonts\courbi.ttf
C:\Windows\Fonts\daunpenh.ttf
C:\Windows\Fonts\dokchamp.ttf
C:\Windows\Fonts\estre.ttf
C:\Windows\Fonts\euphemia.ttf
C:\Windows\Fonts\gautami.ttf
C:\Windows\Fonts\gautamib.ttf
C:\Windows\Fonts\Vani.ttf
C:\Windows\Fonts\Vanib.ttf
C:\Windows\Fonts\gulim.ttc
C:\Windows\Fonts\impact.ttf
C:\Windows\Fonts\iskpota.ttf
C:\Windows\Fonts\iskpotab.ttf
C:\Windows\Fonts\kalinga.ttf
C:\Windows\Fonts\kalingab.ttf
C:\Windows\Fonts\kartika.ttf
C:\Windows\Fonts\kartikab.ttf
C:\Windows\Fonts\KhmerUI.ttf
C:\Windows\Fonts\KhmerUIb.ttf
C:\Windows\Fonts\LaoUI.ttf
C:\Windows\Fonts\LaoUIb.ttf
C:\Windows\Fonts\latha.ttf
C:\Windows\Fonts\lathab.ttf
C:\Windows\Fonts\lucon.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\malgunbd.ttf
C:\Windows\Fonts\mangal.ttf
C:\Windows\Fonts\mangalb.ttf
C:\Windows\Fonts\meiryo.ttc
C:\Windows\Fonts\meiryob.ttc
C:\Windows\Fonts\himalaya.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msjhbd.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\msyhbd.ttf
C:\Windows\Fonts\mingliu.ttc
C:\Windows\Fonts\mingliub.ttc
C:\Windows\Fonts\monbaiti.ttf
C:\Windows\Fonts\msgothic.ttc
C:\Windows\Fonts\msmincho.ttc
C:\Windows\Fonts\mvboli.ttf
C:\Windows\Fonts\ntailu.ttf
C:\Windows\Fonts\ntailub.ttf
C:\Windows\Fonts\nyala.ttf
C:\Windows\Fonts\phagspa.ttf
C:\Windows\Fonts\phagspab.ttf
C:\Windows\Fonts\plantc.ttf
C:\Windows\Fonts\raavi.ttf
C:\Windows\Fonts\raavib.ttf
C:\Windows\Fonts\segoesc.ttf
C:\Windows\Fonts\segoescb.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\seguisb.ttf
C:\Windows\Fonts\segoeuil.ttf
C:\Windows\Fonts\seguisym.ttf
C:\Windows\Fonts\shruti.ttf
C:\Windows\Fonts\shrutib.ttf
C:\Windows\Fonts\simsun.ttc
C:\Windows\Fonts\simsunb.ttf
C:\Windows\Fonts\sylfaen.ttf
C:\Windows\Fonts\taile.ttf
C:\Windows\Fonts\taileb.ttf
C:\Windows\Fonts\times.ttf
C:\Windows\Fonts\timesi.ttf
C:\Windows\Fonts\timesbd.ttf
C:\Windows\Fonts\timesbi.ttf
C:\Windows\Fonts\tunga.ttf
C:\Windows\Fonts\tungab.ttf
C:\Windows\Fonts\vrinda.ttf
C:\Windows\Fonts\vrindab.ttf
C:\Windows\Fonts\Shonar.ttf
C:\Windows\Fonts\Shonarb.ttf
C:\Windows\Fonts\msyi.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\tahomabd.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\angsa.ttf
C:\Windows\Fonts\angsai.ttf
C:\Windows\Fonts\angsab.ttf
C:\Windows\Fonts\angsaz.ttf
C:\Windows\Fonts\aparaj.ttf
C:\Windows\Fonts\aparajb.ttf
C:\Windows\Fonts\aparajbi.ttf
C:\Windows\Fonts\aparaji.ttf
C:\Windows\Fonts\cordia.ttf
C:\Windows\Fonts\cordiai.ttf
C:\Windows\Fonts\cordiab.ttf
C:\Windows\Fonts\cordiaz.ttf
C:\Windows\Fonts\ebrima.ttf
C:\Windows\Fonts\ebrimabd.ttf
C:\Windows\Fonts\gisha.ttf
C:\Windows\Fonts\gishabd.ttf
C:\Windows\Fonts\kokila.ttf
C:\Windows\Fonts\kokilab.ttf
C:\Windows\Fonts\kokilabi.ttf
C:\Windows\Fonts\kokilai.ttf
C:\Windows\Fonts\leelawad.ttf
C:\Windows\Fonts\leelawdb.ttf
C:\Windows\Fonts\msuighur.ttf
C:\Windows\Fonts\moolbor.ttf
C:\Windows\Fonts\symbol.ttf
C:\Windows\Fonts\utsaah.ttf
C:\Windows\Fonts\utsaahb.ttf
C:\Windows\Fonts\utsaahbi.ttf
C:\Windows\Fonts\utsaahi.ttf
C:\Windows\Fonts\vijaya.ttf
C:\Windows\Fonts\vijayab.ttf
C:\Windows\Fonts\wingding.ttf
C:\Windows\Fonts\modern.fon
C:\Windows\Fonts\roman.fon
C:\Windows\Fonts\script.fon
C:\Windows\Fonts\andlso.ttf
C:\Windows\Fonts\arabtype.ttf
C:\Windows\Fonts\simpo.ttf
C:\Windows\Fonts\simpbdo.ttf
C:\Windows\Fonts\simpfxo.ttf
C:\Windows\Fonts\majalla.ttf
C:\Windows\Fonts\majallab.ttf
C:\Windows\Fonts\trado.ttf
C:\Windows\Fonts\tradbdo.ttf
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\david.ttf
C:\Windows\Fonts\davidbd.ttf
C:\Windows\Fonts\frank.ttf
C:\Windows\Fonts\lvnm.ttf
C:\Windows\Fonts\lvnmbd.ttf
C:\Windows\Fonts\mriam.ttf
C:\Windows\Fonts\mriamc.ttf
C:\Windows\Fonts\nrkis.ttf
C:\Windows\Fonts\rod.ttf
C:\Windows\Fonts\simfang.ttf
C:\Windows\Fonts\simhei.ttf
C:\Windows\Fonts\simkai.ttf
C:\Windows\Fonts\angsau.ttf
C:\Windows\Fonts\angsaui.ttf
C:\Windows\Fonts\angsaub.ttf
C:\Windows\Fonts\angsauz.ttf
C:\Windows\Fonts\browa.ttf
C:\Windows\Fonts\browai.ttf
C:\Windows\Fonts\browab.ttf
C:\Windows\Fonts\browaz.ttf
C:\Windows\Fonts\browau.ttf
C:\Windows\Fonts\browaui.ttf
C:\Windows\Fonts\browaub.ttf
C:\Windows\Fonts\browauz.ttf
C:\Windows\Fonts\cordiau.ttf
C:\Windows\Fonts\cordiaub.ttf
C:\Windows\Fonts\cordiauz.ttf
C:\Windows\Fonts\cordiaui.ttf
C:\Windows\Fonts\upcdl.ttf
C:\Windows\Fonts\upcdi.ttf
C:\Windows\Fonts\upcdb.ttf
C:\Windows\Fonts\upcdbi.ttf
C:\Windows\Fonts\upcel.ttf
C:\Windows\Fonts\upcei.ttf
C:\Windows\Fonts\upceb.ttf
C:\Windows\Fonts\upcebi.ttf
C:\Windows\Fonts\upcfl.ttf
C:\Windows\Fonts\upcfi.ttf
C:\Windows\Fonts\upcfb.ttf
C:\Windows\Fonts\upcfbi.ttf
C:\Windows\Fonts\upcil.ttf
C:\Windows\Fonts\upcii.ttf
C:\Windows\Fonts\upcib.ttf
C:\Windows\Fonts\upcibi.ttf
C:\Windows\Fonts\upcjl.ttf
C:\Windows\Fonts\upcji.ttf
C:\Windows\Fonts\upcjb.ttf
C:\Windows\Fonts\upcjbi.ttf
C:\Windows\Fonts\upckl.ttf
C:\Windows\Fonts\upcki.ttf
C:\Windows\Fonts\upckb.ttf
C:\Windows\Fonts\upckbi.ttf
C:\Windows\Fonts\upcll.ttf
C:\Windows\Fonts\upcli.ttf
C:\Windows\Fonts\upclb.ttf
C:\Windows\Fonts\upclbi.ttf
C:\Windows\Fonts\kaiu.ttf
C:\Windows\Fonts\l_10646.ttf
C:\Windows\Fonts\ariblk.ttf
C:\Windows\Fonts\calibri.ttf
C:\Windows\Fonts\calibrii.ttf
C:\Windows\Fonts\calibrib.ttf
C:\Windows\Fonts\calibriz.ttf
C:\Windows\Fonts\cambria.ttc
C:\Windows\Fonts\cambriai.ttf
C:\Windows\Fonts\cambriab.ttf
C:\Windows\Fonts\cambriaz.ttf
C:\Windows\Fonts\Candara.ttf
C:\Windows\Fonts\Candarai.ttf
C:\Windows\Fonts\Candarab.ttf
C:\Windows\Fonts\Candaraz.ttf
C:\Windows\Fonts\comic.ttf
C:\Windows\Fonts\comicbd.ttf
C:\Windows\Fonts\consola.ttf
C:\Windows\Fonts\consolai.ttf
C:\Windows\Fonts\consolab.ttf
C:\Windows\Fonts\consolaz.ttf
C:\Windows\Fonts\constan.ttf
C:\Windows\Fonts\constani.ttf
C:\Windows\Fonts\constanb.ttf
C:\Windows\Fonts\constanz.ttf
C:\Windows\Fonts\corbel.ttf
C:\Windows\Fonts\corbeli.ttf
C:\Windows\Fonts\corbelb.ttf
C:\Windows\Fonts\corbelz.ttf
C:\Windows\Fonts\framd.ttf
C:\Windows\Fonts\framdit.ttf
C:\Windows\Fonts\Gabriola.ttf
C:\Windows\Fonts\georgia.ttf
C:\Windows\Fonts\georgiai.ttf
C:\Windows\Fonts\georgiab.ttf
C:\Windows\Fonts\georgiaz.ttf
C:\Windows\Fonts\pala.ttf
C:\Windows\Fonts\palai.ttf
C:\Windows\Fonts\palab.ttf
C:\Windows\Fonts\palabi.ttf
C:\Windows\Fonts\segoepr.ttf
C:\Windows\Fonts\segoeprb.ttf
C:\Windows\Fonts\trebuc.ttf
C:\Windows\Fonts\trebucit.ttf
C:\Windows\Fonts\trebucbd.ttf
C:\Windows\Fonts\trebucbi.ttf
C:\Windows\Fonts\verdana.ttf
C:\Windows\Fonts\verdanai.ttf
C:\Windows\Fonts\verdanab.ttf
C:\Windows\Fonts\verdanaz.ttf
C:\Windows\Fonts\webdings.ttf
C:\Windows\Fonts\coure.fon
C:\Windows\Fonts\serife.fon
C:\Windows\Fonts\sserife.fon
C:\Windows\Fonts\smalle.fon
C:\Windows\Fonts\smallf.fon
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF
C:\Windows\Fonts\ARIALUNI.TTF
C:\Windows\Fonts\CENTURY.TTF
C:\Windows\Fonts\WINGDNG2.TTF
C:\Windows\Fonts\WINGDNG3.TTF
C:\Windows\Fonts\BKANT.TTF
C:\Windows\Fonts\GOTHIC.TTF
C:\Windows\Fonts\OUTLOOK.TTF
C:\Windows\Fonts\TEMPSITC.TTF
C:\Windows\Fonts\MISTRAL.TTF
C:\Windows\Fonts\LHANDW.TTF
C:\Windows\Fonts\ITCKRIST.TTF
C:\Windows\Fonts\JUICE___.TTF
C:\Windows\Fonts\FREESCPT.TTF
C:\Windows\Fonts\ARIALN.TTF
C:\Windows\Fonts\GARA.TTF
C:\Windows\Fonts\MTCORSVA.TTF
C:\Windows\Fonts\ALGER.TTF
C:\Windows\Fonts\BASKVILL.TTF
C:\Windows\Fonts\BAUHS93.TTF
C:\Windows\Fonts\BELL.TTF
C:\Windows\Fonts\BRLNSB.TTF
C:\Windows\Fonts\BERNHC.TTF
C:\Windows\Fonts\BOD_PSTC.TTF
C:\Windows\Fonts\BRITANIC.TTF
C:\Windows\Fonts\BROADW.TTF
C:\Windows\Fonts\BRUSHSCI.TTF
C:\Windows\Fonts\CALIFR.TTF
C:\Windows\Fonts\CENTAUR.TTF
C:\Windows\Fonts\CHILLER.TTF
C:\Windows\Fonts\COLONNA.TTF
C:\Windows\Fonts\COOPBL.TTF
C:\Windows\Fonts\FTLTLT.TTF
C:\Windows\Fonts\HARLOWSI.TTF
C:\Windows\Fonts\HARNGTON.TTF
C:\Windows\Fonts\HTOWERT.TTF
C:\Windows\Fonts\JOKERMAN.TTF
C:\Windows\Fonts\KUNSTLER.TTF
C:\Windows\Fonts\LBRITE.TTF
C:\Windows\Fonts\LCALLIG.TTF
C:\Windows\Fonts\LFAX.TTF
C:\Windows\Fonts\MAGNETOB.TTF
C:\Windows\Fonts\MATURASC.TTF
C:\Windows\Fonts\MOD20.TTF
C:\Windows\Fonts\NIAGENG.TTF
C:\Windows\Fonts\NIAGSOL.TTF
C:\Windows\Fonts\OLDENGL.TTF
C:\Windows\Fonts\ONYX.TTF
C:\Windows\Fonts\PARCHM.TTF
C:\Windows\Fonts\PLAYBILL.TTF
C:\Windows\Fonts\POORICH.TTF
C:\Windows\Fonts\RAVIE.TTF
C:\Windows\Fonts\INFROMAN.TTF
C:\Windows\Fonts\SHOWG.TTF
C:\Windows\Fonts\SNAP____.TTF
C:\Windows\Fonts\STENCIL.TTF
C:\Windows\Fonts\VINERITC.TTF
C:\Windows\Fonts\VIVALDII.TTF
C:\Windows\Fonts\VLADIMIR.TTF
C:\Windows\Fonts\LATINWD.TTF
C:\Windows\Fonts\BOOKOS.TTF
C:\Windows\Fonts\ANTQUAB.TTF
C:\Windows\Fonts\ANTQUABI.TTF
C:\Windows\Fonts\ANTQUAI.TTF
C:\Windows\Fonts\GOTHICB.TTF
C:\Windows\Fonts\GOTHICBI.TTF
C:\Windows\Fonts\GOTHICI.TTF
C:\Windows\Fonts\BSSYM7.TTF
C:\Windows\Fonts\REFSAN.TTF
C:\Windows\Fonts\REFSPCL.TTF
C:\Windows\Fonts\ARIALNB.TTF
C:\Windows\Fonts\ARIALNBI.TTF
C:\Windows\Fonts\ARIALNI.TTF
C:\Windows\Fonts\GARABD.TTF
C:\Windows\Fonts\GARAIT.TTF
C:\Windows\Fonts\BELLB.TTF
C:\Windows\Fonts\BELLI.TTF
C:\Windows\Fonts\BRLNSDB.TTF
C:\Windows\Fonts\BRLNSR.TTF
C:\Windows\Fonts\CALIFB.TTF
C:\Windows\Fonts\CALIFI.TTF
C:\Windows\Fonts\HTOWERTI.TTF
C:\Windows\Fonts\LBRITED.TTF
C:\Windows\Fonts\LBRITEDI.TTF
C:\Windows\Fonts\LBRITEI.TTF
C:\Windows\Fonts\LFAXD.TTF
C:\Windows\Fonts\LFAXDI.TTF
C:\Windows\Fonts\LFAXI.TTF
C:\Windows\Fonts\BOOKOSB.TTF
C:\Windows\Fonts\BOOKOSBI.TTF
C:\Windows\Fonts\BOOKOSI.TTF
C:\Windows\Fonts\marlett.ttf
\??\SPDevice
C:\Windows\sysnative\spp\plugin-manifests-signed\sppwinob-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppwinob.dll
C:\Windows\sysnative\spp\plugin-manifests-signed\sppobjs-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppobjs.dll
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
C:
\??\PhysicalDrive0
\??\pci#ven_8086&dev_100e&subsys_001e8086&rev_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{c2d43895-0262-4873-a789-c2f96d24b693}
\??\root#*isatap#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{684bb8b6-2793-49a5-8012-e0a941b4b4df}
\??\root#*isatap#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{5f6d61d9-d207-449a-bd48-652a5d1f25be}
\??\root#ms_agilevpnminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{29898c9d-b0a4-4fef-bdb6-57a562022cee}
\??\root#ms_l2tpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{e43d242b-9eab-4626-a952-46649fbb939a}
\??\root#ms_ndiswanbh#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanbh
\??\root#ms_ndiswanip#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanip
\??\root#ms_ndiswanipv6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanipv6
\??\root#ms_pppoeminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8e301a52-affa-4f49-b9ca-c79096a1a056}
\??\root#ms_pptpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{df4a9d2c-8742-4eb1-8703-d395c4183f33}
\??\root#ms_sstpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{71f897d7-eb7c-4d8d-89db-ac80d9dd2270}
\??\root#system#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
C:\Windows\sysnative\shell32.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
\??\PIPE\lsarpc
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\ProgramData\Microsoft\Windows\WER\ReportQueue
C:\Windows\sysnative\winxp\triage.ini
C:\Windows\sysnative\WINXP
C:\Windows\sysnative\winext
C:\Windows\sysnative\winext\arcade
C:\Windows\sysnative\pri
C:\ProgramData\Oracle\Java\javapath
C:\ProgramData\Oracle\Java\javapath\
C:\Windows\
C:\Windows\sysnative\wbem
C:\Windows\sysnative\wbem\
C:\Windows\sysnative\WindowsPowerShell\v1.0
C:\Windows\sysnative\WindowsPowerShell\v1.0\
C:\Windows\sysnative\WINXP\dbghelp.dll
C:\Windows\sysnative\winext\dbghelp.dll
C:\Windows\sysnative\winext\arcade\dbghelp.dll
C:\Windows\sysnative\pri\dbghelp.dll
C:\Windows\sysnative\dbghelp.dll
C:\Windows\sysnative\WINXP\ext.dll
C:\Windows\sysnative\winext\ext.dll
C:\Windows\sysnative\winext\arcade\ext.dll
C:\Windows\sysnative\pri\ext.dll
C:\Windows\sysnative\ext.dll
C:\ProgramData\Oracle\Java\javapath\ext.dll
C:\Windows\ext.dll
C:\Windows\sysnative\wbem\ext.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\ext.dll
C:\Windows\sysnative\WINXP\exts.dll
C:\Windows\sysnative\winext\exts.dll
C:\Windows\sysnative\winext\arcade\exts.dll
C:\Windows\sysnative\pri\exts.dll
C:\Windows\sysnative\exts.dll
C:\ProgramData\Oracle\Java\javapath\exts.dll
C:\Windows\exts.dll
C:\Windows\sysnative\wbem\exts.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\exts.dll
C:\Windows\sysnative\WINXP\uext.dll
C:\Windows\sysnative\winext\uext.dll
C:\Windows\sysnative\winext\arcade\uext.dll
C:\Windows\sysnative\pri\uext.dll
C:\Windows\sysnative\uext.dll
C:\ProgramData\Oracle\Java\javapath\uext.dll
C:\Windows\uext.dll
C:\Windows\sysnative\wbem\uext.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\uext.dll
C:\Windows\sysnative\WINXP\ntsdexts.dll
C:\Windows\sysnative\winext\ntsdexts.dll
C:\Windows\sysnative\winext\arcade\ntsdexts.dll
C:\Windows\sysnative\pri\ntsdexts.dll
C:\Windows\sysnative\ntsdexts.dll
C:\ProgramData\Oracle\Java\javapath\ntsdexts.dll
C:\Windows\ntsdexts.dll
C:\Windows\sysnative\wbem\ntsdexts.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\ntsdexts.dll
C:\Windows\sysnative\taskhost.exe
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\
C:\Windows\ServiceProfiles\LocalService\AppData
C:\Windows\ServiceProfiles\LocalService\AppData\Local
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp.appcompat.txt
C:\Windows\sysnative\*
C:\Windows\sysnative\kernel32.dll
C:\Windows\sysnative\it-IT\kernel32.dll.mui
C:\Windows\sysnative\ntdll.dll
C:\Windows\sysnative\sqmapi.dll
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_*_7533c1e35911683ffb23e331adec3b567026ef5b_cab_*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_*_7533c1e35911683ffb23e331adec3b567026ef5b_cab_*
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp.WERInternalMetadata.xml
C:\Windows\sysnative\drivers\*.mrk
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp.hdmp
C:\Windows\sysnative\KERNELBASE.dll
C:\Windows\sysnative\msvcrt.dll
C:\Windows\sysnative\ole32.dll
C:\Windows\sysnative\gdi32.dll
C:\Windows\sysnative\user32.dll
C:\Windows\sysnative\lpk.dll
C:\Windows\sysnative\usp10.dll
C:\Windows\sysnative\rpcrt4.dll
C:\Windows\sysnative\oleaut32.dll
C:\Windows\sysnative\imm32.dll
C:\Windows\sysnative\msctf.dll
C:\Windows\sysnative\advapi32.dll
C:\Windows\sysnative\sechost.dll
C:\Windows\sysnative\api-ms-win-core-synch-l1-2-0.DLL
C:\Windows\sysnative\sspicli.dll
C:\Windows\sysnative\CRYPTBASE.dll
C:\Windows\sysnative\clbcatq.dll
C:\Windows\sysnative\RacEngn.dll
C:\Windows\sysnative\aepic.dll
C:\Windows\sysnative\version.dll
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp.mdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\*_*_*_*
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER45C4.tmp.appcompat.txt
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER59DA.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER5A48.tmp.hdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER69F9.tmp.mdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\Report.wer

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\u2.exe.config
C:\Users\Seven01\AppData\Local\Temp\u2.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
\Device\NamedPipe\
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Roaming\NGpp.exe.config
C:\Users\Seven01\AppData\Roaming\NGpp.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Users\Seven01\AppData\Roaming\TcPR.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\Tasks\Update\Update
C:\Windows\SysWOW64\cmd.exe
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\schtasks.exe
C:\Windows\SysWOW64\shdocvw.dll
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Users\Seven01\AppData\Roaming\
C:\Windows\SysWOW64\netsh.exe
C:\Windows\SysWOW64\it-IT\netsh.exe.mui
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64\net1.exe
C:\Windows\Temp\fwtsqmfile01.sqm
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\sysnative\tzres.dll
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\it-IT\sc.exe.mui
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
\??\PIPE\samr
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
\Device\LanmanDatagramReceiver
C:\Windows\sysnative\WerFault.exe
C:\Windows\AppPatch\AppPatch64\sysmain.sdb
C:\Windows\sysnative\
C:\Users\Seven01\AppData\Local\Temp\171947752.xml
C:\Users\Seven01\AppData\Local\Temp\525722800.xml
C:\Users\Seven01\AppData\Local\Temp\1574982584.xml
C:\Users\Seven01\AppData\Roaming\TcPR.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b8d41a36c0f1de1ae26bf020f0fd54bc.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\System32\tzres.dll
C:\Users\Seven01\AppData\Local\Temp\401883642.xml
C:\Users\Seven01\AppData\Local\Temp\1069340872.xml
\Device\Http\Communication
C:\Windows\System32\DHCPQEC.DLL
C:\Windows\System32\napipsec.dll
C:\Windows\System32\it-IT\napipsec.dll.mui
C:\Windows\System32\tsgqec.dll
C:\Windows\System32\EAPQEC.DLL
C:\Windows\System32\it-IT\eapqec.dll.mui
C:\Windows\SysWOW64\it-IT\P2PNETSH.DLL.mui
C:\Users\Seven01\AppData\Local\Temp\76590864.xml
C:\Users\Seven01\AppData\Local\Temp\886795670.xml
C:\Users\Seven01\AppData\Local\Temp\1238154552.xml
C:\Users\Seven01\AppData\Local\Temp\1646863775.xml
C:\Users\Seven01\AppData\Local\Temp\1233746797.xml
C:\Users\Seven01\AppData\Local\Temp\2102812751.xml
C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
C:\Windows\sysnative\LogFiles\Scm\b4bdb6a0-417f-4e60-a0ac-aa00b1c79b4c
C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
C:\Windows\Fonts\modern.fon
C:\Windows\Fonts\roman.fon
C:\Windows\Fonts\script.fon
C:\Windows\Fonts\coure.fon
C:\Windows\Fonts\serife.fon
C:\Windows\Fonts\sserife.fon
C:\Windows\Fonts\smalle.fon
C:\Windows\Fonts\smallf.fon
C:\Users\Seven01\AppData\Local\Temp\36491117.xml
C:\Windows\sysnative
C:\Windows\sysnative\spp\plugin-manifests-signed\sppwinob-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppwinob.dll
C:\Windows\sysnative\spp\plugin-manifests-signed\sppobjs-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppobjs.dll
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
\??\pci#ven_8086&dev_100e&subsys_001e8086&rev_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{c2d43895-0262-4873-a789-c2f96d24b693}
\??\root#*isatap#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{684bb8b6-2793-49a5-8012-e0a941b4b4df}
\??\root#*isatap#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{5f6d61d9-d207-449a-bd48-652a5d1f25be}
\??\root#ms_agilevpnminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{29898c9d-b0a4-4fef-bdb6-57a562022cee}
\??\root#ms_l2tpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{e43d242b-9eab-4626-a952-46649fbb939a}
\??\root#ms_ndiswanbh#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanbh
\??\root#ms_ndiswanip#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanip
\??\root#ms_ndiswanipv6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanipv6
\??\root#ms_pppoeminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8e301a52-affa-4f49-b9ca-c79096a1a056}
\??\root#ms_pptpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{df4a9d2c-8742-4eb1-8703-d395c4183f33}
\??\root#ms_sstpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{71f897d7-eb7c-4d8d-89db-ac80d9dd2270}
\??\root#system#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
\??\PIPE\lsarpc
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\winxp\triage.ini
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp.appcompat.txt
C:\Windows\sysnative\taskhost.exe
C:\Windows\sysnative\it-IT\kernel32.dll.mui
C:\Windows\sysnative\kernel32.dll
C:\Windows\sysnative\ntdll.dll
C:\Windows\sysnative\sqmapi.dll
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp.WERInternalMetadata.xml
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp.hdmp
C:\Windows\sysnative\KERNELBASE.dll
C:\Windows\sysnative\msvcrt.dll
C:\Windows\sysnative\ole32.dll
C:\Windows\sysnative\gdi32.dll
C:\Windows\sysnative\user32.dll
C:\Windows\sysnative\lpk.dll
C:\Windows\sysnative\usp10.dll
C:\Windows\sysnative\rpcrt4.dll
C:\Windows\sysnative\oleaut32.dll
C:\Windows\sysnative\imm32.dll
C:\Windows\sysnative\msctf.dll
C:\Windows\sysnative\advapi32.dll
C:\Windows\sysnative\sechost.dll
C:\Windows\sysnative\api-ms-win-core-synch-l1-2-0.DLL
C:\Windows\sysnative\sspicli.dll
C:\Windows\sysnative\CRYPTBASE.dll
C:\Windows\sysnative\clbcatq.dll
C:\Windows\sysnative\RacEngn.dll
C:\Windows\sysnative\aepic.dll
C:\Windows\sysnative\version.dll
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp.mdmp

Write Files

C:\Users\Seven01\AppData\Roaming\NGpp.exe
C:\Users\Seven01\AppData\Local\Temp\Update.txt
C:\Users\Seven01\AppData\Local\Temp\171947752.xml
\Device\NamedPipe
C:\Users\Seven01\AppData\Local\Temp\525722800.xml
C:\Users\Seven01\AppData\Local\Temp\1574982584.xml
C:\Users\Seven01\AppData\Roaming\TcPR.exe
C:\Windows\sysnative\Tasks\Update\Update
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\Temp\fwtsqmfile01.sqm
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
\??\PIPE\samr
\Device\LanmanDatagramReceiver
C:\Users\Seven01\AppData\Local\Temp\401883642.xml
C:\Users\Seven01\AppData\Local\Temp\1069340872.xml
C:\Users\Seven01\AppData\Local\Temp\76590864.xml
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b8d41a36c0f1de1ae26bf020f0fd54bc.exe
C:\Users\Seven01\AppData\Local\Temp\886795670.xml
C:\Users\Seven01\AppData\Local\Temp\1238154552.xml
C:\Users\Seven01\AppData\Local\Temp\1646863775.xml
C:\Users\Seven01\AppData\Local\Temp\1233746797.xml
C:\Users\Seven01\AppData\Local\Temp\2102812751.xml
C:\Users\Seven01\AppData\Local\Temp\36491117.xml
C:\Users\Seven01\AppData\Local\Temp\2020352697.xml
\Device\Http\Communication
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
\??\SPDevice
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
\??\PIPE\lsarpc
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp.appcompat.txt
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp.WERInternalMetadata.xml
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp.hdmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp.mdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER45C4.tmp.appcompat.txt
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER59DA.tmp.WERInternalMetadata.xml
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER5A48.tmp.hdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\WER69F9.tmp.mdmp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskhost.exe_7533c1e35911683ffb23e331adec3b567026ef5b_cab_0830f5da\Report.wer

Delete Files

C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2432.15671843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2432.15671843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2432.15671875
C:\Users\Seven01\AppData\Local\Temp\171947752.xml
C:\Users\Seven01\AppData\Local\Temp\525722800.xml
C:\Users\Seven01\AppData\Local\Temp\1574982584.xml
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2684.15673468
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2684.15673468
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2684.15673468
C:\Windows\sysnative\Tasks\Update\Update
C:\Users\Seven01\AppData\Local\Temp\401883642.xml
C:\Users\Seven01\AppData\Local\Temp\1069340872.xml
C:\Users\Seven01\AppData\Local\Temp\76590864.xml
C:\Users\Seven01\AppData\Local\Temp\886795670.xml
C:\Users\Seven01\AppData\Local\Temp\1238154552.xml
C:\Users\Seven01\AppData\Local\Temp\1646863775.xml
C:\Users\Seven01\AppData\Local\Temp\1233746797.xml
C:\Users\Seven01\AppData\Local\Temp\2102812751.xml
C:\Users\Seven01\AppData\Local\Temp\36491117.xml
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER45C4.tmp.appcompat.txt
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER59DA.tmp.WERInternalMetadata.xml
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER5A48.tmp.hdmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\WER69F9.tmp.mdmp

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\u2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\751cfd\16dd7af5
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3379f94\13084162
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|u2.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|u2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|u2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3379f94\5f0d23d8
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NGpp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|NGpp.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|NGpp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|NGpp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\di
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\NGpp.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F459EC53
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_CURRENT_USER\Software\Classes\AppID\schtasks.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\cmd.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\schtasks.exe
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\shdocvw.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\TcPR.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\netsh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net1.exe
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileMinMemory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\PerfMMFileName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\BackupRestore\FilesNotToBackup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_metadata
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\BITS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobInactivityTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TimeQuantaLength
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobNoProgressTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobMinimumRetryDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TransferBufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackBegin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackEnd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackDuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TestFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\ForceFileFlush
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\UseLmCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\IGDSearcherDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2085F28-FEB7-404A-B8E7-E659BDEAAA02}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2085F28-FEB7-404A-B8E7-E659BDEAAA02}\TreatAs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sc.exe
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\BITS\Throttling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileChunk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileWriteBuffer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StateIndex
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BackupRestore\FilesNotToBackup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_LOG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_BAK
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\BITS Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Triggers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST
HKEY_USERS\S-1-5-20
HKEY_USERS\S-1-5-20\Control Panel\International
HKEY_USERS\S-1-5-20\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceClasses\{CAC88484-7515-4C03-82E6-71A87ABAC361}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Triggers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceClasses\{AD498944-762F-11D0-8DCB-00C04FC3358C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WerFault.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TcPR.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|TcPR.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|TcPR.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|TcPR.exe
HKEY_CURRENT_USER\Environment
HKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_CURRENT_USER\Software\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER\Software\b8d41a36c0f1de1ae26bf020f0fd54bc\[kl]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\DisabledComponents
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iphlpsvc\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\config\Connectivity_Platform_Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NapAgent\LocalConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enable Tracing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Tracing Level
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79617
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\PlumbIpsecPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79619
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79621
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79623
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\UI
HKEY_CURRENT_USER\Software\Classes\AppID\netsh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F6C4EC9A
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\PeerDist
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PolicyProvider
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\PeerDist
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\PolicyRefreshInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\CryptoAlgo
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Protocol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Protocol
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Download
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Download
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Discovery
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Discovery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Upload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Upload
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\UtilityIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\UtilityIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Peers\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Peers\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\SecurityManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\BlockSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\NumBlocksPerSegment
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\SecurityManager\Restricted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted\Seed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CacheMgr\Republication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CacheMgr\Publication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HandleMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HandleMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HostedCache\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HostedCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ServerRole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ClientAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousUploads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingOffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\DoNotUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CooperativeCaching
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CooperativeCaching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DiscoveryManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\RepubQuorumSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\MinBackoffWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Roaming
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\ForceRoamingDetect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
HKEY_USERS\S-1-5-19
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-19\Environment
HKEY_USERS\S-1-5-19\Volatile Environment
HKEY_USERS\S-1-5-19\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\Volatile Environment
HKEY_USERS\S-1-5-20\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\svchost.exe
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\sppsvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ServiceSessionId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\EnableTestVolumeIntervals
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLActivationInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleTolerance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime
HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
HKEY_LOCAL_MACHINE\System\Setup\Status
HKEY_LOCAL_MACHINE\SYSTEM\Setup\Status\AuditBoot
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Reboot.SL_BRT_COMMIT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\InactivityShutdownDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\KeepRunningThresholdMins
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\DeviceNotificationCallbacks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\DeviceUpdateLocations
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_CLASSES_ROOT\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}\SuppressionPolicy
HKEY_CLASSES_ROOT\CLSID\{21EC2020-3AEA-1069-A2DD-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21EC2020-3AEA-1069-A2DD-08002B30309D}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\SuppressionPolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{21EC2020-3AEA-1069-A2DD-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{21EC2020-3AEA-1069-A2DD-08002B30309D}
HKEY_CLASSES_ROOT\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\SuppressionPolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{35786D3C-B075-49B9-88DD-029876E11C01}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{35786D3C-B075-49B9-88DD-029876E11C01}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\NameSpace
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\NameSpace\DelegateFolders
HKEY_CLASSES_ROOT\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace\NameCustomizations
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\LocalizedString
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.HideOnDesktop
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\OpenIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.FileAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ThumbnailCache
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.DateModified
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\taskhost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\SystemCritical
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\w32time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogEntries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\RefreshSettingsFlags
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\TimeProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\InputProvider
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\TimeProviders
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PhaseCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\UpdateInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FrequencyCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PollAdjustFactor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LargePhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\SpikeWatchPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\HoldPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MinPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\AnnounceFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LocalClockDispersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxNegPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPosPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxAllowedPhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\TimeJumpAuditOffset
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\TimeProviders\NtpClient
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\AllowNonstandardModeCombinations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\CompatibilityFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMinutes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMaxTimes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\LargeSampleSkew
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\NtpServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollTimeRemaining
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization\VML
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rpc\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider\Parameters\IPC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup
HKEY_USERS\.DEFAULT\Control Panel\International
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wersvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\TraceFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MiniNT
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession
HKEY_CURRENT_USER\Software\Microsoft\Windiff
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\NewUserDefaultConsent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\BEX64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\BEX64
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\BEX64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\HeapControlledList\taskhost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\taskhost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\SYSTEM32\ntdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\kernel32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\KERNELBASE.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\msvcrt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\ole32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\GDI32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\USER32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\LPK.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\USP10.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\RPCRT4.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\OLEAUT32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\IMM32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\MSCTF.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\ADVAPI32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\SYSTEM32\sechost.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\api-ms-win-core-synch-l1-2-0.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\SspiCli.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\CRYPTBASE.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\CLBCatQ.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\RacEngn.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\AEPIC.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\VERSION.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6FD5A890
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskhost.exe

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\di
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F459EC53
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileMinMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_metadata
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobInactivityTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TimeQuantaLength
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobNoProgressTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobMinimumRetryDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TransferBufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackBegin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackEnd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackDuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TestFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\ForceFileFlush
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\UseLmCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\IGDSearcherDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileChunk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileWriteBuffer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StateIndex
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Triggers
HKEY_USERS\S-1-5-20\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Triggers
HKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER\Software\b8d41a36c0f1de1ae26bf020f0fd54bc\[kl]
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\DisabledComponents
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\config\Connectivity_Platform_Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enable Tracing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Tracing Level
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\PlumbIpsecPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F6C4EC9A
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\PolicyRefreshInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\CryptoAlgo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\BlockSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\NumBlocksPerSegment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted\Seed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ServerRole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ClientAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousUploads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingOffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\DoNotUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\RepubQuorumSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\MinBackoffWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\ForceRoamingDetect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\EnableTestVolumeIntervals
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLActivationInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleTolerance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime
HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
HKEY_LOCAL_MACHINE\SYSTEM\Setup\Status\AuditBoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\InactivityShutdownDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\KeepRunningThresholdMins
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21EC2020-3AEA-1069-A2DD-08002B30309D}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\LoadWithoutCOM
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\LocalizedString
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.HideOnDesktop
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\OpenIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.FileAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 13
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.DateModified
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\SystemCritical
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogEntries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\RefreshSettingsFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PhaseCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\UpdateInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FrequencyCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PollAdjustFactor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LargePhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\SpikeWatchPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\HoldPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MinPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\AnnounceFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LocalClockDispersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxNegPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPosPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxAllowedPhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\TimeJumpAuditOffset
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\AllowNonstandardModeCombinations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\CompatibilityFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMinutes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMaxTimes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\LargeSampleSkew
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\NtpServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollTimeRemaining
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\TraceFlags
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\NewUserDefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\BEX64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\BEX64
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\taskhost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\SYSTEM32\ntdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\kernel32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\KERNELBASE.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\msvcrt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\ole32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\GDI32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\USER32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\LPK.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\USP10.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\RPCRT4.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\OLEAUT32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\IMM32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\MSCTF.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\ADVAPI32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\SYSTEM32\sechost.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\api-ms-win-core-synch-l1-2-0.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\SspiCli.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\CRYPTBASE.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\CLBCatQ.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\RacEngn.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\AEPIC.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls\C:\Windows\system32\VERSION.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6FD5A890

Write Keys

HKEY_CURRENT_USER\di
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4940F29-D552-40BA-A78E-2D17571D94FB}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176B1E51-2168-4E90-AA59-8BABEFD9FBA9}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D47FB098-DF56-4545-B578-3FF8BAF0E531}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C4B478-C8A3-484C-B98D-5CCC31EDDF77}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6EDD4BAE-440A-4848-9807-143CCAF74865}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFA18DEF-6A36-4081-85E9-61446D8C7872}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50CE6643-875C-4E34-AD43-6864464E7DF4}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03BF19D3-0CBF-48B6-A5EE-7351687A01E1}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBD47CED-659A-4AC7-AA4F-607DFB3A8DBE}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71C9384-25C1-4DDB-95DB-0454105E7F97}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\PerfMMFileName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_LOG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_BAK
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\BITS Writer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF8D4FE-1DB3-413D-9494-7CD3E0E08E8F}\DynamicInfo
HKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_CURRENT_USER\Software\b8d41a36c0f1de1ae26bf020f0fd54bc
HKEY_CURRENT_USER\Software\b8d41a36c0f1de1ae26bf020f0fd54bc\[kl]
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-100
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-101
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-103
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-102
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-1
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-2
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-4
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-3
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-100
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-101
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-102
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-103
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-100
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-101
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-102
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ServiceSessionId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollTimeRemaining
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
b8d41a36c0f1de1ae26bf020f0fd54bc
Global\.net clr networking
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs
Local\WERReportingForProcess2248
Global\\xe5\x88\x90\xc2\x98

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.VirtualProtect
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.GlobalMemoryStatusEx
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.GetSystemInfo
kernel32.dll.VirtualQueryEx
kernel32.dll.ReadProcessMemory
msvcrt.dll.memcmp
kernel32.dll.WriteProcessMemory
ntdll.dll.NtQuerySystemInformation
kernel32.dll.GetModuleFileNameW
shfolder.dll.SHGetFolderPathW
kernel32.dll.CopyFileW
kernel32.dll.LocalFree
kernel32.dll.CreatePipe
kernel32.dll.DuplicateHandle
kernel32.dll.GetStdHandle
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.CreateProcessW
kernel32.dll.GetFileType
kernel32.dll.GetConsoleCP
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.GetConsoleOutputCP
kernel32.dll.WriteFile
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.SetThreadUILanguage
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
ntdll.dll.NtQueryInformationProcess
kernel32.dll.GetTempPathW
kernel32.dll.CreateFileW
kernel32.dll.LocalAlloc
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
advapi32.dll.LsaClose
advapi32.dll.LsaFreeMemory
advapi32.dll.LsaOpenPolicy
advapi32.dll.LsaLookupSids
kernel32.dll.DeleteFileW
kernel32.dll.SetFileAttributesW
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
advapi32.dll.RegSetValueExW
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.RtlMoveMemory
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
ole32.dll.CoWaitForMultipleHandles
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
comctl32.dll.#321
cryptsp.dll.CryptReleaseContext
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
sspicli.dll.GetUserNameExW
advapi32.dll.WmiNotificationRegistrationW
wtsapi32.dll.WTSQueryUserToken
pcwum.dll.PerfDeleteInstance
ole32.dll.CLSIDFromString
pcwum.dll.PerfStopProvider
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzInitializeContextFromSid
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeContext
authz.dll.AuthzFreeResourceManager
oleaut32.dll.#8
oleaut32.dll.#2
oleaut32.dll.#9
ole32.dll.CoCreateGuid
oleaut32.dll.#6
oleaut32.dll.#7
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
advapi32.dll.WmiCloseBlock
propsys.dll.PropVariantToVariant
ole32.dll.CoDisconnectObject
wbemcore.dll.Shutdown
qmgr.dll.ServiceMain
advapi32.dll.SetEntriesInAclW
ws2_32.dll.#115
ws2_32.dll.WSASocketW
ws2_32.dll.WSAIoctl
ws2_32.dll.#111
bitsigd.dll.InitializeEx
upnp.dll.DllGetClassObject
upnp.dll.DllCanUnloadNow
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcStringFreeA
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.I_RpcExceptionFilter
sechost.dll.OpenSCManagerA
sechost.dll.OpenServiceA
sechost.dll.StartServiceA
rpcrt4.dll.RpcBindingFree
ws2_32.dll.#116
advapi32.dll.LogonUserW
sspicli.dll.LogonUserExExW
wtsapi32.dll.WTSEnumerateSessionsW
wtsapi32.dll.WTSFreeMemory
advapi32.dll.QueryAllTracesW
vssapi.dll.CreateWriter
ole32.dll.CoRegisterClassObject
iphlpapi.dll.GetAdaptersAddresses
rasapi32.dll.RasEnumConnectionsW
rasapi32.dll.RasConnectionNotificationW
iphlpapi.dll.GetIfTable2
iphlpapi.dll.FreeMibTable
user32.dll.SendMessageTimeoutA
kernel32.dll.GetStartupInfoW
kernel32.dll.WaitForSingleObject
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
kernel32.dll.GetModuleHandleW
user32.dll.GetClassInfoW
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.DefWindowProcW
user32.dll.GetAsyncKeyState
kernel32.dll.GetExitCodeProcess
user32.dll.RegisterWindowMessageW
user32.dll.GetKeyState
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
user32.dll.GetSystemMetrics
gdi32.dll.GetStockObject
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.PeekMessageW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
ws2_32.dll.WSAStartup
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
advapi32.dll.CreateWellKnownSid
kernel32.dll.OpenMutexW
kernel32.dll.GetProcessTimes
ws2_32.dll.inet_addr
ws2_32.dll.WSAConnect
user32.dll.GetKeyboardState
user32.dll.MapVirtualKeyA
user32.dll.GetForegroundWindow
user32.dll.GetWindowThreadProcessId
user32.dll.GetKeyboardLayout
user32.dll.ToUnicodeEx
kernel32.dll.FormatMessageW
kernel32.dll.GetProcessWorkingSetSize
kernel32.dll.SetProcessWorkingSetSize
ws2_32.dll.shutdown
user32.dll.GetWindowTextLengthA
user32.dll.GetWindowTextA
advapi32.dll.RegCreateKeyExW
rasmontr.dll.InitHelperDll
nshwfp.dll.InitHelperDll
dhcpcmonitor.dll.InitHelperDll
wshelper.dll.InitHelperDll
nshhttp.dll.InitHelperDll
fwcfg.dll.InitHelperDll
authfwcfg.dll.InitHelperDll
ifmon.dll.InitHelperDll
netiohlp.dll.InitHelperDll
whhelper.dll.InitHelperDll
hnetmon.dll.InitHelperDll
rpcnsh.dll.InitHelperDll
dot3cfg.dll.InitHelperDll
napmontr.dll.InitHelperDll
nshipsec.dll.InitHelperDll
p2pnetsh.dll.InitHelperDll
wlancfg.dll.InitHelperDll
peerdistsh.dll.InitHelperDll
cryptsp.dll.CryptEnumProvidersW
user32.dll.LoadStringW
sechost.dll.QueryServiceConfigW
httpapi.dll.HttpInitialize
userenv.dll.RegisterGPNotification
userenv.dll.UnregisterGPNotification
gpapi.dll.RegisterGPNotificationInternal
bcryptprimitives.dll.GetHashInterface
bcryptprimitives.dll.GetCipherInterface
mprmsg.dll.MprmsgGetErrorString
oleaut32.dll.#500
httpapi.dll.HttpTerminate
gpapi.dll.UnregisterGPNotificationInternal
comctl32.dll.#388
ole32.dll.CoInitializeSecurity
fntcache.dll.ServiceMain
fntcache.dll.SvchostPushServiceGlobals
ntmarta.dll.GetMartaExtensionInterface
advapi32.dll.EventWrite
advapi32.dll.EventEnabled
ntdll.dll.ZwQueryInformationProcess
ntdll.dll.NtQuerySection
ntdll.dll.LdrProcessRelocationBlock
sppwinob.dll.SppPluginInitialize
sppwinob.dll.SppPluginShutdown
sppwinob.dll.SppPluginCreateInstance
sppwinob.dll.SppPluginCanUnloadNow
sppobjs.dll.SppPluginInitialize
sppobjs.dll.SppPluginShutdown
sppobjs.dll.SppPluginCreateInstance
sppobjs.dll.SppPluginCanUnloadNow
advapi32.dll.NotifyServiceStatusChangeW
setupapi.dll.SetupDiGetClassDevsW
setupapi.dll.SetupDiEnumDeviceInfo
setupapi.dll.SetupDiGetDeviceRegistryPropertyW
setupapi.dll.SetupDiDestroyDeviceInfoList
wintrust.dll.WinVerifyTrust
setupapi.dll.SetupDiEnumDeviceInterfaces
setupapi.dll.SetupDiGetDeviceInterfaceDetailW
kernel32.dll.GetSystemFirmwareTable
w32time.dll.SvchostEntry_W32Time
w32time.dll.SvchostPushServiceGlobals
dsrole.dll.DsRoleGetPrimaryDomainInformation
dsrole.dll.DsRoleFreeMemory
sspicli.dll.LsaRegisterPolicyChangeNotification
w32time.dll.TimeProvClose
w32time.dll.TimeProvCommand
w32time.dll.TimeProvOpen
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.#23
ws2_32.dll.#21
ws2_32.dll.#2
vmictimeprovider.dll.TimeProvClose
vmictimeprovider.dll.TimeProvCommand
vmictimeprovider.dll.TimeProvOpen
ws2_32.dll.GetAddrInfoW
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.WSAAddressToStringW
ws2_32.dll.#3
sspicli.dll.LsaUnregisterPolicyChangeNotification
wersvc.dll.ServiceMain
wersvc.dll.SvchostPushServiceGlobals
advapi32.dll.RegGetValueW
faultrep.dll.WerpInitiateCrashReporting
wer.dll.WerpCreateMachineStore
shell32.dll.SHGetFolderPathEx
ole32.dll.StringFromGUID2
profapi.dll.#104
userenv.dll.CreateEnvironmentBlock
sechost.dll.ConvertSidToStringSidW
userenv.dll.DestroyEnvironmentBlock
imm32.dll.ImmDisableIME
wer.dll.WerpCreateIntegratorReportId
wer.dll.WerReportCreate
wer.dll.WerpSetIntegratorReportId
wer.dll.WerReportSetParameter
dbgeng.dll.DebugCreate
ntdll.dll.CsrGetProcessId
ntdll.dll.DbgBreakPoint
ntdll.dll.DbgPrint
ntdll.dll.DbgPrompt
ntdll.dll.DbgUiConvertStateChangeStructure
ntdll.dll.DbgUiGetThreadDebugObject
ntdll.dll.DbgUiIssueRemoteBreakin
ntdll.dll.DbgUiSetThreadDebugObject
ntdll.dll.NtAllocateVirtualMemory
ntdll.dll.NtClose
ntdll.dll.NtCreateDebugObject
ntdll.dll.NtCreateFile
ntdll.dll.NtDebugActiveProcess
ntdll.dll.NtDebugContinue
ntdll.dll.NtFreeVirtualMemory
ntdll.dll.NtOpenProcess
ntdll.dll.NtOpenThread
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtQueryMutant
ntdll.dll.NtQueryObject
ntdll.dll.NtRemoveProcessDebug
ntdll.dll.NtResumeThread
ntdll.dll.NtSetInformationDebugObject
ntdll.dll.NtSystemDebugControl
ntdll.dll.NtWaitForDebugEvent
ntdll.dll.RtlAnsiStringToUnicodeString
ntdll.dll.RtlCreateProcessParameters
ntdll.dll.RtlCreateUserProcess
ntdll.dll.RtlDestroyProcessParameters
ntdll.dll.RtlDosPathNameToNtPathName_U
ntdll.dll.RtlFindMessage
ntdll.dll.RtlFreeHeap
ntdll.dll.RtlFreeUnicodeString
ntdll.dll.RtlGetFunctionTableListHead
ntdll.dll.RtlGetUnloadEventTrace
ntdll.dll.RtlGetUnloadEventTraceEx
ntdll.dll.RtlInitAnsiString
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlTryEnterCriticalSection
ntdll.dll.RtlUnicodeStringToAnsiString
ntdll.dll.NtOpenProcessToken
ntdll.dll.NtOpenThreadToken
ntdll.dll.NtQueryInformationToken
kernel32.dll.CloseProfileUserMapping
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.DebugActiveProcessStop
kernel32.dll.DebugBreak
kernel32.dll.DebugBreakProcess
kernel32.dll.DebugSetProcessKillOnExit
kernel32.dll.Module32First
kernel32.dll.Module32FirstW
kernel32.dll.Module32Next
kernel32.dll.Module32NextW
kernel32.dll.OpenThread
kernel32.dll.Process32First
kernel32.dll.Process32FirstW
kernel32.dll.Process32Next
kernel32.dll.Process32NextW
kernel32.dll.ProcessIdToSessionId
kernel32.dll.SetProcessShutdownParameters
kernel32.dll.Thread32First
kernel32.dll.Thread32Next
kernel32.dll.GetTimeZoneInformation
kernel32.dll.Wow64GetThreadSelectorEntry
advapi32.dll.CloseServiceHandle
advapi32.dll.ControlService
advapi32.dll.CreateServiceA
advapi32.dll.CreateServiceW
advapi32.dll.DeleteService
advapi32.dll.EnumServicesStatusExA
advapi32.dll.EnumServicesStatusExW
advapi32.dll.GetEventLogInformation
advapi32.dll.OpenSCManagerA
advapi32.dll.OpenSCManagerW
advapi32.dll.OpenServiceA
advapi32.dll.OpenServiceW
advapi32.dll.StartServiceA
advapi32.dll.StartServiceW
advapi32.dll.GetSidSubAuthority
advapi32.dll.GetSidSubAuthorityCount
version.dll.GetFileVersionInfoSizeExW
version.dll.GetFileVersionInfoExW
dbghelp.dll.WinDbgExtensionDllInit
dbghelp.dll.ExtensionApiVersion
wer.dll.WerpSetDynamicParameter
wer.dll.WerReportAddDump
wer.dll.WerpSetCallBack
wer.dll.WerReportSetUIOption
wer.dll.WerpAddRegisteredDataToReport
wer.dll.WerReportSubmit
advapi32.dll.CheckTokenMembership
sensapi.dll.IsNetworkAlive
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcBindingSetAuthInfoExW
user32.dll.CharUpperW
wer.dll.WerpAddAppCompatData
apphelp.dll.SdbGetFileAttributes
apphelp.dll.SdbFormatAttribute
apphelp.dll.SdbFreeFileAttributes
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
dbghelp.dll.MiniDumpWriteDump
kernel32.dll.GetLongPathNameA
kernel32.dll.GetLongPathNameW
advapi32.dll.RegOpenKeyExA
advapi32.dll.RegQueryValueExA
powrprof.dll.CallNtPowerInformation
version.dll.GetFileVersionInfoSizeA
version.dll.GetFileVersionInfoA
version.dll.VerQueryValueA
verifier.dll.VerifierEnumerateResource
ntdll.dll.NtSuspendProcess
ntdll.dll.NtResumeProcess
advapi32.dll.QueryTraceW
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
advapi32.dll.AddAccessAllowedAceEx
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetSecurityDescriptorDacl
advapi32.dll.RegisterEventSourceW
advapi32.dll.ReportEventW
advapi32.dll.DeregisterEventSource
wer.dll.WerpGetStoreLocation
wer.dll.WerpGetStoreType

Execute Commands

"cmd"
"C:\Users\Seven01\AppData\Roaming\NGpp.exe"
C:\Users\Seven01\AppData\Roaming\TcPR.exe 
schtasks.exe  /Delete /TN "Update\Update" /F
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\171947752.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\525722800.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1574982584.xml"
netsh firewall add allowedprogram "C:\Users\Seven01\AppData\Roaming\TcPR.exe" "TcPR.exe" ENABLE
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\401883642.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1069340872.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\76590864.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\886795670.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1238154552.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1646863775.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1233746797.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\2102812751.xml"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\sc.exe start w32time task_started
taskhost.exe $(Arg0)
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k WerSvcGroup
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\36491117.xml"
C:\Windows\system32\WerFault.exe -u -p 2248 -s 288
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\2020352697.xml"

Started Services

SSDPSRV
WerSvc
W32Time

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2018-04-14 14:39:32 2018-04-14 14:42:38 186

1 Host(s) detected

IP Address Hostname Reverse DNS
212.83.167.116 France 212-83-167-116.rev.poneytelecom.eu.

Host(s) by Country

Hosts Country 1
1 France France